A backdoor is a typically covert method of bypassing normal authentication or encryption in a computer, product, embedded device (e.g. a home router), or its embodiment (e.g. part of a cryptosystem, algorithm, chipset, or even a "homunculus computer"—a tiny computer-within-a-computer such as that found in Intel's AMT technology).[1][2] Backdoors are most often used for securing remote access to a computer, or obtaining access to plaintext in cryptosystems. From there it may be used to gain access to privileged information like passwords, corrupt or delete data on hard drives, or transfer information within autoschediastic networks.
In the United States, the 1994 Communications Assistance for Law Enforcement Act forces internet providers to provide backdoors for government authorities.[3][4] In 2024, the U.S. government realized that China had been tapping communications in the U.S. using that infrastructure for months, or perhaps longer;[5] China recorded presidential candidate campaign office phone calls —including employees of the then-vice president of the nation– and of the candidates themselves.[6]
A backdoor may take the form of a hidden part of a program,[7] a separate program (e.g. Back Orifice may subvert the system through a rootkit), code in the firmware of the hardware,[8] or parts of an operating system such as Windows.[9][10][11] Trojan horses can be used to create vulnerabilities in a device. A Trojan horse may appear to be an entirely legitimate program, but when executed, it triggers an activity that may install a backdoor.[12] Although some are secretly installed, other backdoors are deliberate and widely known. These kinds of backdoors have "legitimate" uses such as providing the manufacturer with a way to restore user passwords.
Many systems that store information within the cloud fail to create accurate security measures. If many systems are connected within the cloud, hackers can gain access to all other platforms through the most vulnerable system.[13] Default passwords (or other default credentials) can function as backdoors if they are not changed by the user. Some debugging features can also act as backdoors if they are not removed in the release version.[14] In 1993, the United States government attempted to deploy an encryption system, the Clipper chip, with an explicit backdoor for law enforcement and national security access. The chip was unsuccessful.[15]
Recent proposals to counter backdoors include creating a database of backdoors' triggers and then using neural networks to detect them.[16]
Eckersley-2017
was invoked but never defined (see the help page).Hoffman-2017
was invoked but never defined (see the help page).privacy researchers to call out the US government for maintaining a confidential "backdoor" to enable internet-based wiretapping. "Case in point: there's no way to build a backdoor that only the 'good guys' can use," tweeted Meredith Whittaker, president of the encrypted chat app Signal
For months or longer, the hackers might have held access to network infrastructure used to cooperate with lawful U.S. requests for communications data
targeted the phones of former President Donald Trump, his running mate, JD Vance, and people affiliated with Vice President Kamala Harris's presidential campaign
Wysopal-Eng
was invoked but never defined (see the help page).Zetter-2013
was invoked but never defined (see the help page).Ashok-2017
was invoked but never defined (see the help page).Microsoft-Back-Doors
was invoked but never defined (see the help page).Ars-Technica-2017
was invoked but never defined (see the help page).Backdoors-and-Trojan-Horses
was invoked but never defined (see the help page).Linthicum
was invoked but never defined (see the help page).Bogus-story
was invoked but never defined (see the help page).Clipper-a-failure
was invoked but never defined (see the help page).Menisov-2022
was invoked but never defined (see the help page).