5 ms·
Where is the proof?
by MaKey 3y ago
Where is the proof?
- kube-system 3y agoChinese law requires Huawei to cooperate with their intelligence agencies.
- DiogenesKynikos 3y agoThat doesn't prove anything. You're just saying that Huawei could theoretically be compromised, but the above commenter asked for evidence.
- kube-system 3y agoThey are compromised in terms of governance, and their legal environment is the proof of this. Nobody has ever claimed that Huawei devices have backdoors. The issue is that the supply chain is compromised by legal means, not the hardware or software currently being shipped has technical vulnerabilities.
- DiogenesKynikos 3y ago> Nobody has ever claimed that Huawei devices have backdoors. Just a few comments up in this thread, someone claimed definitively that Huawei equipment has been proven to be compromised, meaning backdoored. > They are compromised in terms of governance We don't have any known examples of Huawei being forced by the Chinese government to compromise its equipment. This is still a wholly theoretical discussion. In contrast, we know that the US government has inserted backdoors into American (and not just American) equipment, and is able to secretly compel companies to comply with US spying.
- lmm 3y agoIf you're using that non-standard definition of "compromised" then anything substantially made in the US, Australia, South Korea, Israel or Kazakhstan (non-exhaustive list) should be considered compromised. I'd love it if people actually stuck to some principles and stopped buying from any of these countries. But using that legal situation as a reason to single out China/Huawei is bullshit.
- kube-system 3y ago"compromised" might be a word used by the tech community to refer specifically to technical compromises, but the word means something much more broad outside of tech forums. > then anything substantially made in the US, Australia, South Korea, Israel or Kazakhstan (non-exhaustive list) should be considered compromised. Not really, because many of those countries you listed have mutual treaties of cooperation and are not hostile to each other.
- lmm 3y ago> Not really, because many of those countries you listed have mutual treaties of cooperation and are not hostile to each other. Doesn't seem to stop them from taking immensely hostile actions, e.g. the US spying on Merkel's emails, or helping killers and rapists who work for them evade arrest in "allied" countries. Governments are large and complex and have many competing interests. Why would/should one trust any of the ones I mentioned more than the government of China?
- kube-system 3y agoPeople/governments should trust whoever is more closely working in cooperation with their own interests over those who are working against them.
- lmm 3y agoAgreed, so how do you get from that to mistrusting only China? Everyone, including China/Huawei, has an interest in growing the pie. Some entities have an interest in zero-sum competition with me and mine. That's more likely to be someone closer - Chinese companies aren't competing directly with my business, but American, Australian and Israeli ones are.
- kube-system 3y agoI don't. It's just that this thread was about Huawei.
- Aachen 3y agoAs does the USA, so we shouldn't be using Windows or Yubico either, or virtually any other software/hardware from any other vendor because there's few countries that let you do illegal-over-there things without having a mechanism to force you It's a "pick your poison" situation, not a "they've got national security letters and so you can't trust them" one
- kube-system 3y agoThis is why security is not a "one size fits all" exercise. The first thing you must do is define your threat model. The reason the Chinese government doesn't want to build their telecom system on Cisco hardware is the same exact reason the USG doesn't want to do the same with Huawei hardware. Because neither government is delusional enough to think that parts/service/updates wouldn't be immediately sanctioned in times of war. The US and China are already sanctioning each other's tech. The risk of building critical infrastructure on it is obvious.
- DiogenesKynikos 3y ago> The US and China are already sanctioning each other's tech. It's not symmetrical. Since Trump, the US has been extraordinarily aggressive in its use of sanctions against Chinese companies, whereas China has been very reluctant to retaliate directly. The US has sanctioned hundreds of Chinese tech companies. China has only recently begun to retaliate in kind, but has so far only sanctioned a few US companies (Micron is the only prominent example that comes to mind).
- kube-system 3y agoIt isn't. And I didn't say it was. But the current state isn't the ultimate risk that is being considered. The ultimate risk is war, under which both the US and China would invoke defense powers to compel industry to act in their respective nations' interest, and would apply wide sanctions.
- DiogenesKynikos 3y ago
- HideousKojima 3y agoSince the Snowden leaks (and honestly since long before) it's been safe to assume that if a nation state has the means and motive to commit <insert form of illegal surveillance here>, then they will.