4 ms·
I need an expert to explain something to me: If we enable E2E encryption on the end points, why do we care if Huawei makes it since the local gov't retains loc
by sdfasf 5y ago
I need an expert to explain something to me:
If we enable E2E encryption on the end points, why do we care if Huawei makes it since the local gov't retains local monopoly of force? The reasons I can think of are:
- meta-data
- denial of infrastructure. This is a big reason and a good enough reason.
Aside from reason number two, I really don't see the security threat. Not to minimize the threat of meta-data, but I think, on a national level, it too is solvable for the sovereign (by, for example, having phones make fake random calls to each other to poison the information)
EDIT: For the record, my question is genuine - I really want to understand this - and not some backhanded way to defend Huawei
- Beached 5y agoencryption is good at ensuring data confidentiality in the near term, but not long term. all major state actors vacuum up and retain encrypted communications and store them until the time it is possible to crack. the average Joe's vacation planning with his friends over txt won't matter too much. but a senators phone call, or a ceo phone call, or even an engineers txt, email and phone calls can lead to io theft, Intel leak, etc. once encryption is cracked a few years later.
- sdfasf 5y ago"encryption is good at ensuring data confidentiality in the near term" Very interesting. I knew that state actors syphon everything, but I assumed it was since they can afford and it's a Hail Mary if they stumble on a breakthrough or a side channel. Some further Qs: - What's near term? - What's in the far term? - I thought that encryption could be made arbitrarily more difficult to crack at little cost. Is this not the case? - Does this future assume quantum computing is feasible? Finally, if encryption is no longer believed to be safe in the long term, shouldn't we be moving towards making one-time pads practical? Given modern data storage densities, it's not that unpractical for many use cases (say embassy communication, etc)
- nradov 5y agoIn theory if large scale quantum computing becomes practical then it might become possible to decrypt traffic encrypted using certain public key algorithms. Basically by using Shor's algorithm to factor large numbers. But there's no guarantee that will ever work in practice, and even if it does there are alternative encryption algorithms which are resistant to quantum computing attacks. It's also not easy to identify and exfiltrate high bandwidth data streams even if you compromise a piece of network equipment. If Chinese intelligence services want information on a certain politician or business leader they're more likely to skip the decryption nonsense and just recruit one of the target's associates as a spy.
- HeavenFox 5y agoFortunately encryption does not need to work forever. It just needs to work long enough until the information it's protecting ceases to be valuable.
- kube-system 5y agoDenial of service/parts/maintenance is a very real concern. Telecoms put a lot of effort into deploying this infrastructure. If we end up with a telecom system entirely of Huawei gear, we're one sanctions declaration away from a completely unsupported, unpatched, unmaintainable telecom network. The US already puts tech sanctions on China. It is not at all hard to imagine China reciprocating. And, even if they never actually do anything -- once our telecom system is mostly Huawei gear, they can now use it as a political chess piece against us. And on the opposite end of the spectrum, if we hypothetically go to war, they unquestionably would use that power to their advantage. All of our public/government services rely on functioning telecom networks. China does the same stuff. They know if we go to war, we're likely to cut them off from GPS service, which is why they have their own system: https://en.wikipedia.org/wiki/BeiDou https://en.wikipedia.org/wiki/BeiDou
- chrischen 5y agoI don't see how they can possibly exfiltrate meta-data undetected, unless that's explicitly in their terms of sale. As for denial of infrastructure, that's possible if we're running huawei software... in which case don't? Is software really their strong point anyways?
- gwbas1c 5y agoEven when something is encrypted, you can still make educated guesses based on who's communicating with who.