61°F
weather icon Clear

Backdoor in security means hackers could tap into corporate conference calls

NEW YORK — Lots of companies — and even the White House  use a conference calling system that could possibly be tapped by hackers, according to new research.

On Thursday, cybersecurity experts at SEC Consult revealed a secret doorway that's built into a popular conference calling product built by a company called AMX.

AMX makes tablet panels used to control conference calls for businesses, government agencies and universities.

The company hard-coded backdoor access into its system. AMX created a "secret account" with a permanent username and password, which means a hacker who already sneaked into a computer network could tap into actual meetings, if the hacker knew the backdoor access code.

It's a glaring security hole.

SEC Consult researchers discovered the questionable computer code, detailing it in a blog post Thursday.

Harman, the American tech firm that makes AMX systems, acknowledged the issue -- but called it an intentional feature. The company said it disabled the access point through a software update in December.

But cybersecurity experts say it's still serious.

"This is tantamount to handing over an unlocked military/government smartphone or computer system to an enemy," said Phil Hagen, who teaches cybersecurity professionals at the SANS Institute. "It's a huge problem that anyone with the 'secret account' credentials could theoretically access those devices."

The White House didn't immediately respond to questions about security concerns.

David Kennedy, CEO of cybersecurity firm TrustedSec, compares the seriousness of this AMX problem to last month's discovery of a backdoor hack in Juniper Networks computer equipment used by the U.S. government and corporations everywhere.

Some, like WhiteHat Security's Jeremiah Grossman, went as far as to say that anyone who uses this conference calling system "should be considered compromised."

An innocent mistake?

Computer security experts told CNNMoney this seems like a case of sloppy computer programming. The access point was probably built for fixing problems during product development and accidentally left in.

In its report, SEC Consult points out that AMX created a secret account with a coded name that translates to "BlackWidow." The cybersecurity firm notified AMX, which fixed the problem sometime in the next seven months.

But then SEC Consult researchers looked again and discovered that the secret account still existed -- only this time it was called "1MB@tMaN."

The fact that both names are references to comic book superheroes has cybersecurity experts asking whether this backdoor is a deliberate attempt by AMX to create a secret access point.

Actually, BlackWidow was indeed a backdoor.

Harmon company representative Darrin Shewchuk explained that BlackWidow was a "diagnostic and maintenance login for customer support of technical issues." Though it was never meant to be secret, he said.

Meanwhile, the Batman reference was "an entirely different internal feature" that let internal devices talk to one another. It wasn't a replacement backdoor.

Shewchuk said the names were just internal company humor.

In the notoriously paranoid computer security field, this existence of a backdoor leaves some wary of the potential for espionage.

"There can be no other explanation for the presence of this other than to provide a secret backdoor into the product," said Jeremiah Talamantes, president of cybersecurity firm RedTeam Security.

Either way, it's a deemed a risk.

"It's a massive problem, even if accidental — unconscionable if deliberate," Hagen said.

MOST READ
Don't miss the big stories. Like us on Facebook.
THE LATEST
Breaking down the next big food trend

Americans have been boosting their protein intake for years. Now comes a new food push: an uptick in high fiber foods.

Old-school form of fitness gaining popularity again

These days, content creators, independent gyms and megachains alike are promoting calisthenics, an age-old form of fitness that uses little or no equipment.

This 3-ingredient snack can help manage your blood sugar

Though it may sound counterintuitive, eating snacks can actually help stabilize your blood sugar and prevent erratic swings, Dr. Florence Comite says.

Mark Wahlberg glad his family plan included Las Vegas

“I love living in Las Vegas,” says the 54-year-old actor and father of four with wife Rhea. “This was such a great decision for us as a family.”

What are your life insurance options beyond age 65?

Many Americans wait too long to purchase a life insurance policy. They do not realize how their health issues can factor into the application process.

How to locate an age-friendly doctor

Choosing a geriatrician as your primary care doctor in your 70s is a good idea, especially if you’re dealing with age-related health problems.

MORE STORIES