7 ms·
how does one manage a closed source binary with a backdoor in it in one's network equipment
by alt_f4 8y ago
how does one manage a closed source binary with a backdoor in it in one's network equipment
- arethuza 8y agoProbably by deploying another closed binary from a US supplier to "monitor" it.
- unmole 8y agoCSEC has access to the code that is runs on Huawei's kit. Huawei is required to have reproducable builds to show that the code running in the network is the exactly same as what was vetted by CSEC.
- roca 8y agoWhich provides exactly no protection against hardware backdoors. HCSEC had 30 staff in 2015. Are they claiming to have done a line-by-line audit of all Huawei's code by now?
- acqq 8y agoObviously software build reproducibility “Huawei is required to have reproducable builds” doesn’t protect from hardware backdoors. That solution is the proper solution to the software backdoors, again: “the code running in the network is the exactly same as what was vetted by CSEC.”
- roca 8y agoI know it's obvious. The point is that some tens of HCSEC staff (mostly Huawei employees) thoroughly "vetting" tens of millions of lines of Huawei code for backdoors would prove nothing, even if it wasn't ludicrous, which it is.
- acqq 8y ago> would prove nothing It could surely prove something: those are reproducible builds. That means you can prove after some breach is detected that it originates from the given sources, if it is so. That in turn means that if something happens it won’t be Huawei employees who would investigate these sources. I’m sure that once a company offers the sources like this the company itself won’t plan to mess with the sources. Because then the unwanten intervention can be proved.