5 ms·
Every article I’ve ever read that cites “national security concerns” never, ever explicitly goes into the exact, computational mechanism in which it is a securi
by usui 4y ago
Every article I’ve ever read that cites “national security concerns” never, ever explicitly goes into the exact, computational mechanism in which it is a security concern. It’s always something like “Chinese company under Chinese government, therefore bad”. Never anything concrete or substantive from a software engineer POV, such as what exactly is phoned-home, or what actual subversions are happening currently, only hypotheticals.
- andsoitis 4y agoNot quite. Here you can read more about the underlying reasons: https://stacks.stanford.edu/file/druid:rm226yb7473/Huawei-ZTE%20Investigative%20Report%20%28FINAL%29.pdf https://stacks.stanford.edu/file/druid:rm226yb7473/Huawei-ZT...
- ghastmaster 4y agoThe underlying reasons detailed in that report, again, are gripes about the corporate structure, transparency, and illegal practices. There are no current or past hardware or software threats detailed in that report. The "National Security Threat" posed by these companies is potential not actual. The justification to eliminate this potential is predicated on corporate shenanigans. The real threat they pose, in my opinion, is likely to U.S. corporation's stock price.
- andsoitis 4y agoBut that is what risk (“threat”) is. It is something you assess before something deleterious happens in order to decide whether or not to take it on. If you think of risk = impact * likelihood, it is quite rational to block them.
- bitexploder 4y agoWould this help shape policy in some way or are you just curious as a technologist? I don’t really need to know, as a long time infosec practitioner I have a fertile imagination for the shenanigans they could be up to.
- usui 4y agoOf course it will help shape policy, AND I want to know, as a technologist! How can we know what standard to apply in our work when we don’t know which standard has been broken?! As a fellow infosec practitioner who works at one of the world’s biggest security companies, I don’t want to leave it up to imagination, I want to know exactly what the wrongdoing is, because my job may depend on it in the future!
- bitexploder 4y agoThat is fair, but the threat model is pretty open too, right? In a few hours in a room we could come up with a pretty credible one I bet. * hardware * deep backdoors in radio chips * physical supply chain TM goes here * etc etc * software * we can audit and monitor this easier * etc There is a lot to read between the lines, but it is guess work based on supply chain advisories and high level behaviors of govt entities on both sides and our community is good at missing the forest for the trees on this speculative thinking. I think also there is the possibility of minimal actual wrong doing. It could just be entirely political. Ahh well, I guess I have seen enough of this over the years that I accept there is stuff we will never learn about.
- skorpeon87 4y agoIt's national security, what do you expect? Even if specifics are known and they're not operating under a general precautionary principle (maybe they are, but so what?), the specifics would be classified, not broadcast to the public. That's just the nature of national security concerns. Everything gets overclassified.
- jser 4y agoMany examples, e.g. https://www.theverge.com/2017/7/31/16072786/amazon-blu-suspended-android-spyware-user-data-theft https://www.theverge.com/2017/7/31/16072786/amazon-blu-suspe.... “In November 2016, security firm Kryptowire detected pre-loaded remote surveillance software on BLU phones sold online through Amazon and Best Buy. In August 2017, Amazon pulled BLU Products from its website over security vulnerabilities that resulted in BLU consumer user data being covertly sent to China.”
- usui 4y agoThis.. doesn’t answer my question still. Even if data goes to China, how that data is used, what it is, and by what mechanism is what determines whether it’s a threat or not. Why do we continue to use boogiemen when it comes to explaining threats? Why don’t we apply this kind of scaremongering to any data exfiltration to every shady company ever? Also in your specific reference: > “Now almost a year later, the devices are still behaving in the same exact way, with standard and basic data collection that pose no security or privacy risk. There has been absolutely no new behavior or change in any of our devices to trigger any concern. We expect Amazon to understand this, and quickly reinstate our devices for sale.” So, clearly I’m not the only one who wants clear, explanatory, descriptive answers to these threat models.
- HNDV 4y agoI find it interesting how democrats fell into a pit that I used to think was something only Trump and his ilk followed. The two parties really are the same at the core. One may pretend to be conservative and the other screech in woke language but they always converge on the parts that actually matter like geopolitics. When Trump duked it out against China, democrats pretended to be offended. Now, democrats are in power, and they're pushing even harder to ban China. The US is such a sham democracy. You will not hear anything from the brainwashed apart from "things coming from China are bad because it's China !111!" when in reality those bans exist because American companies simply are not competitive and are looking for America to become a captive market for American corpos. Can't have people selling phones almost-as-good-as-iPhones for less than iPhones.
- 4y ago
- throwthere 4y agoThat’s because you’re reading the general news and not the primary sources.
- kube-system 4y agoBecause it (mostly) isn't an engineering vulnerability -- it is a governance issue. It doesn't really matter how good your lock is, if you give the key to someone who is in a position to abuse that trust.