14 ms·
What are the "security concerns" for a direct cable between the Americas and Hong Kong?
by aritmo 5y ago
What are the "security concerns" for a direct cable between the Americas and Hong Kong?
- jpollock 5y agoIt's not just communicating between the US and Hong Kong, it's all the transit traffic. If there is a high capacity, low cost link between the US and Hong Kong, traffic to other Asian countries will then transit Hong Kong. At that point, the Chinese government gets to dictate whether or not that traffic is allowed, and to snoop on any part of it they can.
- throwaway202166 5y agoAt a large US cloud provider I formerly worked at our fiber between colos in HKG were all tapped, with unexplained db losses. Seemed to be not a secret this goes on there.
- deleted 5y ago[deleted]
- walrus01 5y agoa really good tap won't even have a perceptible loss if they're doing it right, it'll be indistinguishable when the link is first brought up (assuming you're renting dedicated dark strands) from just some older fiber with a very slightly higher dB per km loss figure. Modern singlemode for inter-city use can be 0.03 to 0.07 dB/km better than old stuff from 15, 20, 23 years ago. if you're paying for lit L2 transport service between two sites then all bets are off, you don't get to see the underlying optical characteristics except for the customer hand off port on each side, and the carrier can of course just mirror an entire port to some capture entity.
- remarkEon 5y ago>a really good tap won't even have a perceptible loss if they're doing it right I'm curious, how does one "do it right"? Is there a technical explainer somewhere on how this works (in theory)?
- walrus01 5y agosinglemode fiber splitters come in various ratios of light passed to light split off to your own thing. You fusion splice it in place. It's basically just a prism in a box. If you want to tap a circuit such as between two datacenters at the most fundamental (OSI layer 1) level, before the dark fiber is ever handed off to the customer, you would put in place a tap that passes 90% of the light and keeps 10% of it, splits it off, then feed that into your own local amplifier if needed before passing the tap to your interception/storage equipment, if the received signal level from the 10% is too low. the general principle is actually not much different from some things you do in ordinary DWDM system engineering (where you want to give an analysis port to a spectrum analyzer) or the various types of splitters that exist for GPON network builds. there are also lots of ways to hand-wave away the loss from a tap to a carrier customer, like "oh yeah there's some dirty patch panels over there" or "that segment of fiber was fusion spliced in an emergency repair at 3am eight years ago after it got taken out by a truck, there may be some slightly higher loss on some strands". And even more so for an inter-city fiber link that's way under 80 km (more like 30-40km, tops), where the optical link budget POP-to-POP isn't in question, and well within the reach of ordinary optics even when considering old or dirty fiber in between. The ISP customers might not look too hard at it. google "fiber plc splitter" for some manufacturer info and datasheets.
- throw0101a 5y ago> google "fiber plc splitter" for some manufacturer info and datasheets. See also "optical tap".
- rootsudo 5y agoMost insightful, same excuse for beigeboxing back in the day but with fiber/glass. Wow.
- vitus 5y agoI'd be surprised if there are any large players who don't encrypt everything e2e these days. (By e2e, I mean while data is in transit between datacenters.) That's at least been the case at Google for something like a decade since the China hacks, the Snowden revelations, etc. That said, I imagine there would be a big capacity crunch if all fibers transiting HKG were completely disrupted. As I understand it, HKG is primarily a stepping stone between SIN and TPE / NRT. There are comparably direct alternatives (e.g. MNL), but the capacity just isn't there yet. (Networking often uses airport codes to describe metros, e.g. TPE for Taipei or NRT for Tokyo (Narita).)
- nexuist 5y agoBy E2E you mean SSL and not actually end-to-end right? AFAIK no provider transports HTTP packets over the wire E2E in the same way that Signal or Telegram transports text messages E2E. It's not actually possible since there is no way to transmit a shared secret without first establishing a secure channel (which itself cannot be E2E). Anyways point being, China/HK could just subpoena the private keys for individual SSL certificates and decrypt traffic on their end while it passes through the pipeline. Having sovereignty over the cable is still an advantage for them.
- vitus 5y agoI mean e2e as far as the connection is concerned, whether it's a server talking to end-users via HTTPS, or a server in a datacenter in Singapore talking to a server in a datacenter in Atlanta using GPG or TLS or whichever proprietary encryption algorithm you want to use. If China / HKG has that subpoena power for arbitrary SSL certificates, then we've already lost. As I mentioned, significant traffic already transits through HKG. But even so, what enforcement mechanism does China have? Facebook as well as many other services are already blocked... And honestly, if China starts using subpoena power to take control of SSL certs, that's a _very_ strong incentive to leave that market entirely, as not only can they decrypt your traffic; they can also impersonate you. "True e2e" as offered by Signal / Telecom still relies on Diffie-Hellman key exchange, and therefore some notion of public / private keys with custom PKI servers. It's no different from an attacker's perspective -- instead of the global PKI infra underpinning the web, you're just dealing with a single entity. Compromise the PKI, and you can MitM to your heart's content.
- gremlinsinc 5y agocouldn't they just wrap up the lines at the U.S. embassy, and give U.S. full control over any "snooping" and "transit"?
- rootsudo 5y agoRight of way between the ocean and embassy and gives the consulate way to much power, you don't do that.
- guidedlight 5y agoThe article cites “security concerns”, but I think “geopolitical concerns” are more likely. However, MITM has always been an advantageous position for bad actors. So this is probably the concern, without evidence.
- rootsudo 5y agoBut Taiwan is also the same status of HK for China. Granted they do have more autonomy and are fighting back. Taiwan was a four tiger of Asia, now, not so much, and Philippines same. Philippines has geography and it's own internet issues with PLDT and Globe the two biggest telecom players are not doing changes because they are blocked by the government at all layers and vice versa, with the government more interested in bringing in and establishing a third telecom backed by China called Dito https://www.dito.ph/ https://www.dito.ph/ Until 2016, there was no internet peering in the Philippines because Globe and PLDT really did not want to cooperate with each other, all traffic had to exit the PH via SG/HK and come back.
- gscott 5y agoThe Chinese government isn't exactly arresting Taiwanese for walking alone with a yellow umbrella or alone holding a candle. No diabolical authoritarian government there to take away their free will, yet.
- xwolfi 5y agoThey re not either in Hong Kong. I do all that and am not arrested. The arrests are for slogans or song that sound independentist. An insecure phase other countries went through and usually grow out of with time.
- dillondoyle 5y agoWhat's the insecure phase to grow out of? Like CCP is insecure, as in like the connotation of a Napoleon complex driving a giant pickup truck? What does growing out of this phase mean to you?
- greyface- 5y agoI found the FCC filings at [1] to be useful to understand the government's position here. Particularly the "Provisional National Security Agreement" that the cable now operates under[2]. It seems to boil down to: (1) The PRC likely has visibility into the traffic, while the NSA wouldn't, and (2) The President has the authority to unilaterally deny the operation of undersea cables, so you'd better play by our rules. [1]: https://licensing.fcc.gov/cgi-bin/ws.exe/prod/ib/forms/reports/related_filing.hts?f_key=2252704&f_number=SCLSTA2020040200015 https://licensing.fcc.gov/cgi-bin/ws.exe/prod/ib/forms/repor... [2]: https://licensing.fcc.gov/myibfs/download.do?attachment_key=2256300 https://licensing.fcc.gov/myibfs/download.do?attachment_key=... (PDF download)
- kevin_thibedeau 5y agoThe Navy hasn't tapped these cables yet.
- walrus01 5y ago1) sovereignty issues: The US does not want traffic to other countries in east asia going through a PRC controlled chokepoint. 2) traffic interception/analysis (basically everything that the Chinese equivalent of the NSA is presently capable of doing now, or plausibly might be doing in 5, 10, 15 years from now). If you look at existing maps of submarine fiber cables coming out of WA, OR, CA going across the ocean, as the article points out, there's not many cables that land directly in hong kong first. The US, I think, wants to maintain the principle of landing cables in other places like south korea, japan, taiwan, singapore, malaysia, etc rather than straight to mainland china.