14 ms·
Spy agencies ban Lenovo PCs on security grounds
- harrytuttle 13y agoSeriously, shit or get off the pot. Its speculation and posturing until there is evidence. It sounds more like someone is not happy they're not in control of the hardware.
- CaveTech 13y agoPosturing so that they can convince others that it's true. And then shovel their own chips filled with backdoors. It's sad to admit, but I would be more suspecting of an American computer than a Chinese one at this point. Constantly pointing their fingers and everyone else so they can do the same things when everyone has their back turned.
- rhizome 13y agoNot to mention that these spy agencies will pass the information to each other no problem, as long as the price is right. Maybe that's what this is, though: a tell that (perhaps due to recent developments in the US intelligence sphere) China has raised its prices.
- glesica 13y agoWait, so they'll still buy a Dell or HP that is manufactured in China, by a Chinese company, but has the nameplate of an American company slapped on the front, but they won't buy a Lenovo? I'm so confused.
- harshreality 13y agoYou're confused because you didn't read the article very well. It's reporting allegations of specifically identified malicious elements of Lenovo hardware and firmware.
- deleted 13y ago[deleted]
- rhizome 13y agoThe fact is that "oh no, CHINA!" has most-favored-nation status with the US and is a major major partner in pretty much every way, including positive ones. The rending of garments like this is just a couple of boardroom loudmouths posturing, like Facebook and Google taking potshots at each other. Competitors, not enemies.
- samspenc 13y agoIMHO, there's a big difference between American companies that manufacture in China and can ensure certain functionality (I for one support "made in USA" and buy that if I can)... and Chinese companies, esp. ones with CCP connections, who can build electronics any which way they would like to.
- glesica 13y agoHow can Dell check for back doors when the entire design and manufacturing process is done by Chinese subcontractors? That makes no sense...
- 300bps 13y agoHow can Dell check for back doors when the entire design and manufacturing process is done by Chinese subcontractors? That makes no sense.. Through testing, just like the governments did to discover alleged backdoors in Lenovo chips. Did you read the article before you posted multiple times criticizing it? The ban was introduced in the mid-2000s after intensive laboratory testing of its equipment allegedly documented “back-door” hardware and “firmware” vulnerabilities in Lenovo chips.
- anonymousDan 13y agoI see such back doors as less of a problem for the general public than it is for intelligence agencies because because even a single malicious device could result in a major security breach and so randomized testing mightn't be as effective. If trying to snoop on the general public on an ongoing basis though then it would be hard to avoid randomized testing (presuming someone is actually doing such testing).
- glesica 13y agoDo they check every machine? From TFA: > A technology expert at the Washington-based Brookings Institution, Professor John Villasenor, said the globalisation of the semi-conductor market has “made it not only possible but inevitable that chips that have been intentionally and maliciously altered to contain hidden ‘Trojan’ circuitry will be inserted into the supply chain. So we aren't necessarily talking about every single machine being back-doored. My point is that Dell and HP aren't necessarily any more secure just because they're American companies. The home-country of the company whose badge is on the machine is pretty much meaningless in a globalized world. The article also contains some suggestion that this was motivated by rivalry in addition to security, so there's that as well.
- huhtenberg 13y agoWhat makes you think they buy off-the-shelf Chinese-assembled Dells and HPs?
- mhurron 13y agoIf they weren't buying off the shelf computers to begin with this announcement wouldn't have been required.
- glesica 13y agoI don't know for certain, but having dealt with Dell before (as an institutional customer), I know the government buys off-the-shelf Dells. Now, maybe the intelligence agencies have special arrangements, I don't know, but it seems unlikely to me. I'm sure they do more than just unpack the box and plop it onto the desk, but I doubt Dell or HP have special manufacturing facilities for intelligence agency machines.
- Zakharov 13y agoMost of the computers in a defence facility are unclassified or restricted. The rules are different for secret/top secret.
- Zakharov 13y agoThe article never stated that they would do so.
- samspenc 13y agoFinally. Given how Huawei routers are riddled with "Security 101" vulnerabilities [1], I doubt that Lenovo is any better. [1] http://news.cnet.com/8301-1009_3-57482813-83/expert-huawei-routers-are-riddled-with-vulnerabilities/ http://news.cnet.com/8301-1009_3-57482813-83/expert-huawei-r...
- revelation 13y agoBanning Lenovos PCs seems somewhat unreasonable, given that they are made mostly from parts you can buy on Newegg that are not suspicious, running Windows. The actual risk is in infrastructure, stuff like Huawei routers or telephone backends, most of which today are a fully functional computer on their own, with generally no access for the end consumer.
- harrytuttle 13y agoWindows is a bigger problem, especially when they admitted to handing zero days over to the TLAs (three letter agencies) before patching.
- guelo 13y ago> The alleged presence of these hardware “back doors” remains highly classified. Why wouldn't they want to warn citizens and businesses about this?
- darkchasma 13y agoI would guess that in the game of spy vs. spy, you never show your hand. If I declare that a chip has a backdoor, then the enemy knows, and won't use it. New chips and doors will be created. But if I sit on it, then the bad guys may try something, and you can intercept it, or defend against it, or even exploit it yourself.
- SkyMarshal 13y agoThis could be an intentional "leak" to do just that.
- ihsw 13y agoOne can also interpret this as Lenovo refusing to install American backdoors that Western-sourced devices have, but that's entering conspiracy-theory territory...
- chrischen 13y agoWe're already in conspiracy-theory territory.
- lifeisstillgood 13y agoJust lean back and enjoy the view :-)
- bowlofpetunias 13y agoGiven that the rest of the planet is more worries about American spying, I wonder if Apple may want to rethink their "made in California" slogan.
- mhurron 13y agoTheir slogan is to target jingoists who look at 'made in america' as something special. The slogan is "Designed by Apple in California." The new MacPro will be able to add 'Assembled in the US' if they wish, and I expect that they will. It's still all made in China, but flag wavers get to ignore that. Apple is not the only company that does this.
- zachrose 13y agoI also suspect that "Designed by Apple in California" puts their name between two words that have positive associations around the world. (I'm assuming here that "California" is held in higher regard than "America" or "United States".)
- wil421 13y agoThey are only paranoid because they know they have introduced backdoors into products their countries produce. Do you really think the US/UK/AUS has not introduced something into a Cisco product or some other hardware manufacturer in their respective country. Just look at what has come to light with the PRISM program. They already have access to the major software companies what makes people think they havent done some secret FISA order to Dell/Cisco/HP/Apple etc. edit: typo
- tnuc 13y agoThis is the same bullshit that was thrown around when IBM sold off their PCs to Lenovo. A British spy agency coming out with information like this but not in public? Sounds like bullshit to me. Britain would be well advised to steer clear of US branded computers as the NSA might have access.
- samstave 13y ago>...as the NSA might have access Might? Anyone recall how the USG was requiring backdoors into all routers/switches? I was told about this in 1997 from a Cisco employee who told me they were required to provide a method for the USG to be able to log into all devices they make.
- mrweasel 13y agoUSG? I've seen that show up quite often the last couple of days, but never explained. Google says it's USG Corporation or University System of Georgia.
- schoen 13y agoIt's possible that they were talking about CALEA, which has some wiretap capability mandates on hardware (and associated technical standards). If I had the choice between communicating over CALEA-compliant or non-CALEA-compliant infrastructure, I would far prefer the latter, but these particular backdoors aren't required to operate in an automatic, unattended, or surreptitious way (though some implementations might well have bugs that allow them to do so).
- superuser2 13y ago
- er0k 13y agoJonathan Brossard gave a great talk about this at defcon last year. Around the 2:30 mark in the video he talks a bit about the idea of China backdooring hardware. http://www.youtube.com/watch?v=yRxDvkKBMTc http://www.youtube.com/watch?v=yRxDvkKBMTc http://www.slideshare.net/endrazine/defcon-hardware-backdooring-is-practical http://www.slideshare.net/endrazine/defcon-hardware-backdoor... http://www.scribd.com/doc/101181012/Rakshasa-Whitepaper http://www.scribd.com/doc/101181012/Rakshasa-Whitepaper
- keithpeter 13y agoOK, so Lenovo is not being bought. What is? Anyone got any information? Most UK govt/corporate types I see have Thinkpads and and a Civil Service Blackberry but they are not covert.
- kazagistar 13y agoOnly sane way to reduce the risk of back doors is to have proper open architecture for at least the basic motherboard functionality, and then fully utilize IOMMU to limit what the devices can do. ... hahahaha, yeah right.
- marshray 13y agoBelieve it or not, I recently got a new Lenovo laptop with the intention of IOMMU-ing it as much as I can internally. I haven't let it talk to a network or much USB yet, so I'm hoping it's still secure.
- kazagistar 13y agoVery interesting actually. I would enjoy reading about how well you manage to pull that off; it seemed to me that support for IOMMU is still broken in both software and firmware, but I very well might be wrong.
- marshray 13y agoOK, I'll try to document my journey. It'll be at extendedsubset.com, which is down right now, but I'll bring it back in the next few days.
- lifeisstillgood 13y agoIf this is not a reason for government backed Open Source hardware I don't know what is. If you know the hardware design you can check it And I am willing to bet there is a way to take a circuit "fingerprint"
- RexRollman 13y agoConsidering the pressure the US is applying to gain access to people's data, I think I am equally critical of anything from from a US company.
- harshreality 13y agoFrom the article, for the commenters who don't seem to have read it and have a side discussion going about "how do we know Dell or HP hardware isn't compromised?" (answer: nobody knows that, but that's not the reason for the article)... The ban [on Lenovo hardware for classified networks by multiple western intel agencies] was introduced in the mid-2000s after intensive laboratory testing of its equipment allegedly documented “back-door” hardware and “firmware” vulnerabilities in Lenovo chips.
- DanBC 13y agoThis is fascinating to me. There are six countries mentioned - China, US, UK, Australia, New Zealand, and Canada. Do each of those know the actual exploits, or do they just know that exploits exist and to not use these computers? Assuming they all know, that's a lot of people who can have scary access to Lenovos. I'd be interested to see if that's going to affect the generally good image Lenovo had. My old thinkpad has a bunch of nice security stuff. I still think it's the most secure computer I use, certainly more tamper proof than most other machines I use.
- imrehg 13y agoI have a Lenovo X201, would love to see some details, and try to "hack" my own computer, to see what's there. Very little information about the actual details in the article. If really was a backdoor there and publicly banning a company because of that, wouldn't it make more sense to show the results publicly too? Otherwise it feels more like FUD than responsible research.
- minor_nitwit 13y agoUS, UK, Australia, New Zealand, and Canada are the Five Eyes. http://en.wikipedia.org/wiki/Five_Eyes http://en.wikipedia.org/wiki/Five_Eyes
- lsiebert 13y agoSo are these alleged hw backdoors low level enough that os doesn't matter?