3 ms·
That's of course true. Which is another reason why I think that eg voting computers are an inherently bad idea (independently of who manufactures them). But my
by solstice 6y ago
That's of course true. Which is another reason why I think that eg voting computers are an inherently bad idea (independently of who manufactures them). But my main point was that this sort of capability embedded in routers can only be used once and likely only in an end of the world scenario and therefore is of limited interest to "China".
Now I'm wondering whether I'm mistaken? If my connection to a website/device is properly encrypted (SSL/TLS), can a mitm attack (eg by an embedded hw bug) strip that encryption away? If so, that would be bad and would invalidate large parts of my argument above. If it doesn't however, then it wouldn't really matter that much I think. Unless... the device somehow saves a copy of the traffic for later decryption with better hardware down the line. That seems doable but not really feasible at scale. (Then again, maybe a few bugs in the routers installed at a few critical facilities or locations like downtown DC are enough to gobble up enough juicy traffic?)
I think on the whole it was a bad idea to offshore virtually all production capabilities for chips and computer hardware. (This is especially true for Europe which lost its hw production to Asia and its software production to the US.) Now we have to cope with this situation as it is though, and it seems to me that the best way to do that is to improve transparency by doing what I wrote above, radically reducing complexity of protocols and the tech stack (eg openssl vs wireguard) and forcing companies to clean up their act wrt IT practices. Not easy at all, I know.