
DEF CON 33 - Unveiling IoT Vulns: From Backdoors to Bureaucracy - Kai-Ching Wang, Chiao-Lin Yu
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 19:44
The talk reveals how IoT devices often contain manufacturer-installed backdoors that create security risks, and demonstrates the challenges researchers face when reporting these vulnerabilities to companies who frequently ignore or delay fixes 1:23-1:38.
Key Takeaways:
• Researchers tested over 30 devices and found more than 50 CVEs, revealing widespread backdoor issues in IoT products 3:09-3:19
• Backdoors include hardcoded passwords, hidden user accounts, unprotected services, and debug features left in production devices 6:44-6:54
• When reporting vulnerabilities, vendors often respond that devices are "end of life" and won't issue fixes, leaving thousands of devices at risk 13:13-13:23
• Vendors sometimes refuse to acknowledge vulnerabilities, delay responses for years, or pressure researchers with NDAs to keep findings secret 12:38-12:48
Improving IoT security requires manufacturers to stop leaving backdoors, governments to enforce better regulations, and researchers to responsibly report findings rather than exploit them 19:15-19:33.
Sources:
- 1:23-1:38 Explaining how backdoors come from manufacturers, not hackers
- 3:09-3:19 Overview of research scope with 30+ devices and 50+ CVEs
- 6:44-6:54 Examples of manufacturer-installed backdoors
- 13:13-13:23 Vendor refusing to fix "end of life" devices
- 12:38-12:48 Challenges in reporting vulnerabilities
- 19:15-19:33(https://w
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Okay. So, next welcome to our next speaker Stephen and Canver. Oh, Stephen, it's me. Yeah. Okay. So, hello everyone. Thanks for being here today. Our talk is called unnerving IoT vulnerability from back door to blueprint. We are not here to share something big vulnerability like in the smart Bluetooth or something instead we want to talk about the hidden back door in IoT device and what happened when we try to tell company about them we test more than 30 device and report over 50 CVE we will share what's like to tell company about this problem and how often they ignore or delay or say oh it's not a real issue if you want to deep hacking trick check the main track later but if you want to hear the real IoT research works stay with us yeah if you are interested please talk to us after the ta…