3 ms·
Disruptions would be there for sure. But I think building up that kind of capability is necessarily single-use only, and only makes sense if your goal is to use
by solstice 6y ago
Disruptions would be there for sure. But I think building up that kind of capability is necessarily single-use only, and only makes sense if your goal is to use it as a direct prelude to an invasion of a country. Because people will relatively quickly discover where the problems came from, punish whoever's responsible and then switch manufacturers. I don't see how this could be of benefit to secret services whether from China or any other country, except in the worst case stated above. A few billions in economic losses due to stock market disruptive etc dont mean much in the grand scale of things (and can't therefore be very attractive for intelligence services). Military planners would be foolish to outright dismiss this possibility, sure, but I don't think us-China relations are at this point yet. (And hopefully never will.)
The solution to all of this is to work together and increase the security of the overall system and ditch security through obscurity and security through NDA, go open-source and full inspectability for all critical infrastructure, be it comms, industrial controls, medical infrastructure, transport etc. And E2E encrypt all communications. Everything else is just screwing around with the symptoms instead of addressing the root causes.
- rtkwe 6y agoJust OSS isn't going to solve the paranoia around hidden backdoors in Chinese manufactured network equipment. A tiny co-processor looking for a trigger to brick the rest of the device would maybe require delidding to notice. The old adage is once they get access to your hardware there's very little in the way of attackers doing anything, how do you secure something when it's being manufactured almost 100% by an 'attacker' country's industrial base? I think the China-hawk paranoia is going too far but for national security paranoia it's relatively well grounded. It's hard to justify being able to certify that a thing is secure when the hardware could just be lying to you about the firmware checksum for example.
- solstice 6y agoThat's of course true. Which is another reason why I think that eg voting computers are an inherently bad idea (independently of who manufactures them). But my main point was that this sort of capability embedded in routers can only be used once and likely only in an end of the world scenario and therefore is of limited interest to "China". Now I'm wondering whether I'm mistaken? If my connection to a website/device is properly encrypted (SSL/TLS), can a mitm attack (eg by an embedded hw bug) strip that encryption away? If so, that would be bad and would invalidate large parts of my argument above. If it doesn't however, then it wouldn't really matter that much I think. Unless... the device somehow saves a copy of the traffic for later decryption with better hardware down the line. That seems doable but not really feasible at scale. (Then again, maybe a few bugs in the routers installed at a few critical facilities or locations like downtown DC are enough to gobble up enough juicy traffic?) I think on the whole it was a bad idea to offshore virtually all production capabilities for chips and computer hardware. (This is especially true for Europe which lost its hw production to Asia and its software production to the US.) Now we have to cope with this situation as it is though, and it seems to me that the best way to do that is to improve transparency by doing what I wrote above, radically reducing complexity of protocols and the tech stack (eg openssl vs wireguard) and forcing companies to clean up their act wrt IT practices. Not easy at all, I know.