3 ms·
Does that also happen with, say, German or French governments? Or US government? What about the Chinese? Do they not ask to review source code of the tools th
by thresh 9y ago
Does that also happen with, say, German or French governments? Or US government? What about the Chinese?
Do they not ask to review source code of the tools they buy and use?
- secfirstmd 9y agoDefo the UK and US does
- jerf 9y agoI've seen "merely" large corporations, let alone governments, insist on root access to boxes customers are not normally given shell access to at all, for auditing purposes. To answer the implicit question, no, I don't think this is really all that abnormal, it's just that even many HN denizens may not be aware that this sort of thing happens more often than they realize. The idea that they're doing it to develop backdoors is at least sort of silly, on the grounds that they are perfectly capable of dumping the firmware of these boxes once they import one and developing exploits against the actual image. In fact, that's not even a "nation-state" level of capability, there are plenty of individuals who can and do accomplish that for merely "bug bounty" money. Given the restrictions they have at looking at the source code it's not clear to me that it's going to be much easier for them than just doing it based on firmware dumps.
- endorphone 9y agoA counter example is the F35 -- it is a fighter that is hugely contingent upon its software, but the US has denied partners (the people who also cofunded development) access to it. Given that software controls everything, that should invalidate it as an option for any other military at the outset.
- AnimalMuppet 9y agoNot everyone else can build something equivalent. That leaves them two options: Trust the hidden software, or fly inferior planes. It's not clear which one is the correct answer.