18 ms·
U.S. bans equipment from Huawei and ZTE, citing national security concerns
- thinkmcfly 4y agoI have an online Chinese security camera system outside my house. I'd be happy to replace it if usgov wants to subsidize that. The SSH Honeypot on the network with it remains untouched for now.
- galdosdi 4y agoNo one is asking you to replace it. Keep it as long as you like. If you read the article you will see this applies to 3 specific companies, and prohibits them from selling new things in the future.
- javajosh 4y agoHe's assuming that the ban was caused by the discovery of malicious hw or sw from those manufacturers. If true, it puts into question their previous products as well. It may be that a recall was decided against for a variety of reasons from the practical difficulty to the more spy-related, that it would reveal techniques. It might also be we're witnessing masterful manipulation of the USG by corporations at (economic) war with each other, using every option to destroy the other's access to markets. Lots of speculation either way.
- grej 4y agohttps://archive.ph/zzMCh https://archive.ph/zzMCh
- Normille 4y ago
- deleted 4y ago[deleted]
- Kukumber 4y agoWhat it is called when the US sells weapons to European countries that are connected to the US network, share data and can only be activated by US officials? Should their customers retaliate? "we can do it, you can't" https://www.thedrive.com/the-war-zone/23052/foreign-f-35-users-spend-millions-to-stop-jets-computer-from-sharing-their-secrets https://www.thedrive.com/the-war-zone/23052/foreign-f-35-use...
- woooooo 4y agoIt's called realpolitik.
- sandworm101 4y agoIts called digital rights management (DRM). Why should weapons systems be any different than consumer products in that regard?
- wyuenho 4y agoIt's called the only 5th gen fighter jet Europe can buy
- qeternity 4y ago> "we can do it, you can't" Yes, exactly. The US knows full well how powerful that sort of control and access is, and other countries are (apparently) ok with that. The implicit social contract in the West is that the US maintains global peace anyway. Obviously the US (and other countries) do not have similar levels of trust and cooperation with China, hence these sort of responses.
- acidburnNSA 4y agoOriginal source: https://www.fcc.gov/document/fcc-bans-authorizations-devices-pose-national-security-threat https://www.fcc.gov/document/fcc-bans-authorizations-devices... This covers Dahua, which I believe is the supplier that underlies cheap security cams like Amcrest, which have been a common choice for people who want local-only non-cloud cams for a long time.
- nazgulsenpai 4y agoOuch, I own a few of these cameras. I chose Amcrest because they have a local US distributer who does all of the technical/warranty support. Interesting.
- namkt 4y agoAt this point you can't trust any 'cloud' camera regardless of who makes it.
- lupire 4y ago"Non-cloud" cameras that secrety use cloud are also a problem.
- javajosh 4y agoWhy ouch? If they are local-only the max mischief they might cause is relatively limited, right? Or do you suspect them of phoning home behind your back?
- kube-system 4y agoI have a handful of 'local-only' chinese import cameras (although no Dahuas). They all reach out to hard-coded IP addresses on the chinese mainland. (with no explanation why, nor a setting to turn it off) I put them on a dedicated VLAN without internet access for this reason.
- whiw 4y ago
- 71a54xd 4y agoThat took long enough! Glad we're finally looking out for national security interests, even if it was partially incentivized by economic protectionist ideas - it's naive to think China hasn't done the same to other foreign tech companies.
- baybal2 4y ago
- ausudhz 4y agoEricsson and Nokia sell their 5G technology in China. Actually funny enough they were siding China too on this in Europe because a ban of Chinese tech in Europe could've resulted in a ban of European tech in China. and for anyone that doesn't live under a rock, they know pretty well that china is far a bigger market than Europe
- DiogenesKynikos 4y agoEricsson essentially lost its 2nd largest market because of Sweden's decision to ban Huawei. From [0]: > Swedish telecommunication equipment maker Ericsson plans to restructure its operations in China, its second-largest market, after its sales in the country plunged for a second consecutive quarter in the wake of its home government's move to exclude Huawei Technologies and ZTE from 5G mobile networks. > Ericsson recorded a 74% drop in revenues from China, to 1.3 billion Swedish krona ($150.3 million), in the July-September quarter compared with a year earlier. This followed a 63% drop, to 1.5 billion krona, in China revenues in the second quarter when the company wrote off 300 million krona worth of Chinese inventories. 0. https://asia.nikkei.com/Business/Telecommunication/Ericsson-to-restructure-China-operations-after-sales-plunge https://asia.nikkei.com/Business/Telecommunication/Ericsson-...
- NKosmatos 4y agoThis might be true, but Ericsson currently has the biggest 5G market share, has more operators onboard and is doing fine even without the Chinese market. For sure it was a big blow, but that’s the way thing go if politics come into play. I don’t know what US people really feel about all these Chinese companies, but I for once don’t trust their software/hardware. This doesn’t mean that equipment from Ericsson or Nokia Siemens don’t have “backdoors”, but at least they’re clearly communicated with other governments. That’s the good thing if your company is neutral and sells to everyone. Chinese want to sell to everyone but they want the “backdoors” only for themselves ;-)
- tosh 4y agoCan anyone familiar with the topic ELI5 this? Does this mean you can't use (buy? (sell?)) ZTE or Huawei modems in the US going forward? Or is this just a restriction re US govt related entities?
- ranger47 4y agoELI5: The US and China are not very good friends, but Chinese goods still get sold to US markets. China's gov't has a hand in every company in its borders, or so it is suspected, since this is routinely denied by the companies and the Chinese gov't. Some of those companies make computers that can watch and listen to us, whether we ask them to or not. The US is no longer comfortable with that arrangement. Of course, it's a little more complex than that...
- skorpeon87 4y ago> China's gov't has a hand in every company in its borders, or so it is suspected Not merely suspected, it's a matter of Chinese law that the Party is represented in any company large enough for them to take notice of.
- beebeepka 4y ago
- skorpeon87 4y agoSorry, it's not clear what you think I'm wrong about or what you're trying to say at all. Can you please clarify? Preferably without the insults and layered sarcasm.
- protoc 4y agothere is no connection between rich powerful companies in the us and government /s
- 4y ago
- DiogenesKynikos 4y ago"National security" has been increasingly been used over the last 5 years as a justification for measures that are actually much more broadly geopolitical in nature. A private individual using a Huawei phone or router isn't a national security threat to the US. However, in a broader sense, the US government sees the technological development of China as a threat to American strategic dominance, and has been taking ever more drastic measures to try to hobble the Chinese tech sector. The campaign against Huawei, which began a few years ago, was the opening shot. Blacklisting various Chinese semiconductor companies (which does not only prevent American companies from doing business with them, but which also threatens companies around the world with secondary sanctions if they do business with the targeted companies) was a further escalation. This was also justified as a "national security" measure, with the claim that these companies do business with the Chinese military (these claims were not publicly backed up by evidence, of course). Biden dramatically escalated the "tech war" recently with even broader sanctions against much of the Chinese high-tech sector. The "national security" justification has become so broad that virtually any business with China is now being construed as a national security threat. Americans should consider if they really want to turn their relationship with the world's largest economy into one that is purely hostile.
- googlryas 4y agoWhy would this be considered souring the relationship, when it is child's play compared to the restrictions put on Americans selling in China?
- DiogenesKynikos 4y agoApple is the #1 smartphone brand in China. American companies are much more active in the Chinese market than vice-versa. If China starts reacting in kind, a lot of American companies will be in for a world of hurt.
- loandbehold 4y agoManufactured in China, with forced technology transfer.
- rgbrenner 4y agoReminder of how this started... when Huawei and ZTE decided that because they weren't American companies, they didnt need to answer questions from Congress, and even outright lied about the structure of their companies to conceal CPC/government involvement: https://stacks.stanford.edu/file/druid:rm226yb7473/Huawei-ZTE%20Investigative%20Report%20%28FINAL%29.pdf https://stacks.stanford.edu/file/druid:rm226yb7473/Huawei-ZT...
- sschueller 4y agoSounds like what Twitter will be facing in the EU but for quite different reasons. No one left to deal with the regulators.
- huntertwo 4y agoDoesn’t everybody have the right to not answer questions? Americans don’t have to do this either
- dghlsakjg 4y agoSurprisingly, no. You have the right to not testify/incriminate against yourself. Beyond that, you can absolutely be compelled to answer questions.
- amelius 4y agoZuck had to answer questions.
- deleted 4y ago[deleted]
- ghufran_syed 4y agoThat's correct, they certainly have the right to not answer questions...and the US government has the right to interpret that lack of cooperation any way it chooses, and, say, ban their products.
- k_paleologos 4y ago
- dingi 4y agoWhe you consider China's restrictions against US companies, these things are a drop in a bucket.
- keewee7 4y agoA lot gets buried in the privacy discussions but the unfair trade practices are also a problem. For example Western app makers don't have access to Chinese consumers the same way Chinese app makers have access to Western consumers.
- medellin 4y agoEven companies as large as Uber got strong armed in china. From having traffic shut off completely inside the country without warning (no net neutrality laws) to having to setup an entirely new business in china that didn’t touch the US one. I have little sympathy and i hope that the Us continues to push restrictions on china tech.
- namkt 4y agoUber probably isn't the best example given that the company prided itself in being 'fucking illegal', but your point generally stands. https://www.politico.com/news/2022/07/10/uber-investigation-global-expansion-00044914 https://www.politico.com/news/2022/07/10/uber-investigation-...
- protoc 4y agoApp needs to meet the standards of local laws, its not like China is just targeting American apps. The US has laws bases on color tone lol
- T3RMINATED 4y ago
- usui 4y agoEvery article I’ve ever read that cites “national security concerns” never, ever explicitly goes into the exact, computational mechanism in which it is a security concern. It’s always something like “Chinese company under Chinese government, therefore bad”. Never anything concrete or substantive from a software engineer POV, such as what exactly is phoned-home, or what actual subversions are happening currently, only hypotheticals.
- andsoitis 4y agoNot quite. Here you can read more about the underlying reasons: https://stacks.stanford.edu/file/druid:rm226yb7473/Huawei-ZTE%20Investigative%20Report%20%28FINAL%29.pdf https://stacks.stanford.edu/file/druid:rm226yb7473/Huawei-ZT...
- ghastmaster 4y agoThe underlying reasons detailed in that report, again, are gripes about the corporate structure, transparency, and illegal practices. There are no current or past hardware or software threats detailed in that report. The "National Security Threat" posed by these companies is potential not actual. The justification to eliminate this potential is predicated on corporate shenanigans. The real threat they pose, in my opinion, is likely to U.S. corporation's stock price.
- andsoitis 4y agoBut that is what risk (“threat”) is. It is something you assess before something deleterious happens in order to decide whether or not to take it on. If you think of risk = impact * likelihood, it is quite rational to block them.
- bitexploder 4y agoWould this help shape policy in some way or are you just curious as a technologist? I don’t really need to know, as a long time infosec practitioner I have a fertile imagination for the shenanigans they could be up to.
- k_paleologos 4y agoIs this an executive measure? Does the executive have authority to do such a thing, based on vague and nebulous claims of threat to national security? Were these companies providing sevices/supplying goods in the US market subject to necessary US regulatory approvals? On which grounds can such approvals be rescinded without evidence that will stand in courts? Moreover this is infact a restriction on US citizens/ firms from buying these goods? Does it not impinge on their rights to fair choice?
- MattGaiser 4y agoThey were given the authority last November under the Secure Equipment Act.
- galdosdi 4y ago> Does it not impinge on their rights to fair choice? What are you talking about. You just made up a legal right that has never existed. Try going and opening up a restaurant in any city in america without submitting to any health department inspection. You will get shut down. There is no such universal right under US law to "fair choice" when buying goods, whatever that might mean. There are millions of pages of laws and regulations affecting buying and selling of goods in all 50 states as well as in the federal government.
- chitowneats 4y agoDon't waste too much energy on the sock puppet. This person has less understanding of the U.S. system than my 5th grader, yet is commenting very confidently all over this thread. Account is 20 days old.
- GoatOfAplomb 4y agoThat's the quandary with sock puppets, though. The comment is written well enough to withstand a quick skim, and if no one rebuts it, it may convince some skimmers.
- kube-system 4y ago
- Syme 4y ago
- beebeepka 4y agoTop dogs hate competition. Simple as that. I fucking hate how the US pushed them out of Europe due security concerns when we fuckin know for a fact the US is the worst offender when it comes to spying and sabotaging the competition.
- pkulak 4y agoI love these cams, but also put them on a totally isolated network. Guess I'll pick another one up just in case they get tough to find soon.
- putlake 4y agoHere's the inside story of how the ban was years in the making and all the effort it took. From someone in the government at the time the process started: https://twitter.com/JoshuaSteinman/status/1596370645088350209 https://twitter.com/JoshuaSteinman/status/159637064508835020...
- paganel 4y ago> in celebration of a great professional victory, At first I was intrigued about why did that guy call all this industrial protectionism act as something "professional", afterwards I saw that he is an active part of the industrial defence complex (he's a National Security Council staffer), so that started to make a little bit more sense. I'm wondering though for how long will the MIC ghouls continue to have the upper hand in this. There are huge opportunity costs to be paid by the side that goes all "Corn Law League" on something as fundamental to our age as grains were ~200 years ago, but, then again, when said pro-protectionism side also controls the media, which means no Cobden [1] to take it all down, the US could be in for the long-haul. [1] https://en.wikipedia.org/wiki/Richard_Cobden https://en.wikipedia.org/wiki/Richard_Cobden
- nine_k 4y agoMaybe this may help US manufacturers get better deals. But I see it as a side effect. The main effect is that we should not buy key communication equipment from a country we cannot trust. Its government can strongarm any of its business entities to comply with its orders, and these orders are not going to be friendly to the US. It's a bit like buying communication equipment from the USSR. Maybe the equipment is fine! But accepting even such a thing as the US national emblem from the USSR proved to be... a decision detrimental to security [1]. [1]: https://en.m.wikipedia.org/wiki/The_Thing_(listening_device) https://en.m.wikipedia.org/wiki/The_Thing_(listening_device)
- factsarelolz 4y ago> The main effect is that we should not buy key communication equipment from a country we cannot trust. We should not buy anything that is internet connected from a country we cannot trust.
- javajosh 4y agoIt's not beyond the realm of possibility that in the event of a real war between China and the US that our Chinese-made smartphones and drone toys would suddenly not be trustworthy. The NATO IC's (and SV) software wizardry (like super clever driver weaknesses snuck into mainline linux) always gets trumped by a little this and that added to hardware (an extra component on the pcb or worse, a tiny corner of a chip image). To what extent do the industrial designers of consumer hardware take into account the threat of a last second modification of the design to suit the needs of the manufacturer? To what extent would such modifications be detectable by...anyone, ever? And what would it look like? The software version would be a bad network driver that examines all traffic for a specific triggering pattern that would take over the machine at first as uninvasively as possible, starting by modifying the kernel and the boot image (to stay activated). Establish contact with attacker and examine the user and their accounts. Some users are more valuable than others, having privileged positions in large companies, control or knowledge about important infrastructure, and so on. Or they may be celebrities or other people of note. Or they may be friends of those people. It would be useful to undermine everyone at once, but using a stochastic process that minimizes a torrent of data. Oh and it's probably better for china to maintain at least some of their C&C outside of China to make it less obvious who the actor is, and to maintain connectivity for longer. Ideally the adversary C&C would exist within the target country. In the USA you'd want a confusing relationship that is plausibly legitimate, and turn it into a free speech issue, slowing down the legal system, and so working to China's benefit. While the justice system tries to do it's job, you use the data you gather to build a very accurate and detailed picture of the nation's capabilities, all with names and leverage attached. Over a short period of time, say a few days, what havoc could such an entity do to our nation, if it could send messages as anyone to anyone and be undetectable as illegitimate? And we worry about DDOS botnets! (Note: if we had on-shore manufacturing it wouldn't solve the fundamental issue which is that humans can mass manufacture invisible machines that can't be inspected. These machines are so small they cannot be perceived, not even with the most powerful magnifying instruments[0].) Of course, all of this could be way off base. An equally valid (if more cynical) reason for sanctions like this is that regulatory capture and campaign generosity is finally paying off for someone. 0 - https://en.wikipedia.org/wiki/Electron_microscope https://en.wikipedia.org/wiki/Electron_microscope And the preparation methods required destroy the object under test, such as a chip image.
- blurbleblurble 4y agoWhy are the stakes so high? Well, research "integrated communications and sensing" to find out. IEEE is pushing this paradigm shift. The radio hardware isn't just being used for communications between active devices anymore. It'll be useable for passive and biometric sensing applications, including but not limited to passive localization and identification of people without phones. Next generation wireless standards are being explicitly designed to facilitate this. That said, for some reason I doubt that hardware deployed in the 5 eyes nations won't also be used for surveillance purposes, just that the institutions controlling the systems will be different.
- l33t233372 4y ago> reason I doubt that hardware deployed in the 5 eyes nations won't also be used for surveillance purposes Well that makes sense. They didn’t cite privacy concerns.
- bogomipz 4y agoCould you elaborate on what exactly "integrated communications and sensing" is and why it's so important here. I tried to do some quick reading but I failed to find any good high level overview of what it is. Most of what I was able to find seemed like academic research papers around beam-forming.
- saurik 4y agoThe status from 3 years ago was already pretty scary. https://web.ece.ucsb.edu/~ymostofi/IdentificationThroughWalls https://web.ece.ucsb.edu/~ymostofi/IdentificationThroughWall...
- bogomipz 4y agoWow, this is equally fascinating and frightening. Is it correct to say Cross-Modal-ID is an application of "integrated communications and sensing" technology then? Am I understanding relationship correctly?
- seaourfreed 4y agoFinally
- yumraj 4y agoShouldn’t it ban these companies from having US offices too? And, while they are at it, can TikTok be added to the list as well.
- kube-system 4y agoNo, the FCC does not regulate real estate.
- deleted 4y ago[deleted]
- LatteLazy 4y agoStill can't actually show any actual security issues though right?