3 ms·
They even offered their source code for the government for review, but Australian govt refused. They clearly mean business, and not spying. http://www.cso.com.
by shared4you 13y ago
They even offered their source code for the government for review, but Australian govt refused. They clearly mean business, and not spying.
http://www.cso.com.au/article/440054/huawei_offers_australia_its_source_code_wants_rivals_do_it_too/ http://www.cso.com.au/article/440054/huawei_offers_australia...
- mpyne 13y agoYou need to read Ken Thompson's Reflections on Trusting Trust: http://cm.bell-labs.com/who/ken/trust.html http://cm.bell-labs.com/who/ken/trust.html Merely having the source available for review is hardly a guarantee of safety, without a way to verify that what's embedded in the ROM and microcode is identical. And why should Australia pay to make this verification when it would bump the TCO higher than competing kit?
- Volpe 13y agoSource for huaweis bid being more expensive? There are ways to verify, surely, checksum builds/roms etc.
- mpyne 13y agoI'm not talking about Huawei's bid being more expensive. I'm talking about the cost of hiring Australian-certified source code auditors, developers of software to be used to certify Huawei kit, ongoing re-certification of Huawei firmware updates, the time spent by regulators even worrying about this on an ongoing basis, etc., etc. It all adds up to the total cost of ownership (TCO). So I feel sorry for Huawei but if people are truly worried about the Communist Party of China forcing them to sell pre-hacked kit then it's going to be a rough slog for them. Trust is easy to lose but hard to regain.
- SkyMarshal 13y agoEg, the problem of hardware backdooring. http://www.youtube.com/watch?v=yRxDvkKBMTc http://www.youtube.com/watch?v=yRxDvkKBMTc http://www.extremetech.com/computing/133773-rakshasa-the-hardware-backdoor-that-china-could-embed-in-every-computer http://www.extremetech.com/computing/133773-rakshasa-the-har...