No offense but I don’t think you have a clear enough definition in your head and you’re making it up as we go along and you get challenged.
>> I'm probably mistaken, but I've always referred to password resets as backdoors
> Password resets aren't "backdoors" unless they contain a flaw the defeats any security protections.
You really have to make up your mind. It was “always” but then it wasn’t, and even as you put it you’d have been wrong almost every time to call a reset “a backdoor”.
> I'm surprised the hidden aspect of backdoor is so forward in folks minds.
Only because you misunderstand the meaning of the term, as made very clear above. Go through the wiki page for a “backdoor”.
> In my thinking nothing in cyber security is hidden
I wonder what all those security researchers do all day, with everything being so out in the open and known by everyone.
> I drop the obviously present hidden part of backdoor definition when it's used in yhe cyber security context.
You can drop it but then you’re just using the wrong definition and wrong understanding.
no offense taken. i shouldnt have included password resets in my def. it muddied the conversation. covert is part of a def, at least sometimes, but i think its still acurate to drop it. consider a machine with two copies of ssh running, one of 22 with authentication and another on 2222 with an automatic root login. the instance on 2222 would be considered a backdoor, even though its barely hidden. Swap the ports and it's an unauthenticated frontdoor, but i'd still call it a backdoor and expect everyone to know what i mean. the important part is its bypassing securit, not that its hidden.