There's not even such a thing as a "US phone" though, is there? Even phones manufactured by US companies like Apple are made in China with Chinese/Taiwanese sourced parts. Google always outsources its Nexus/Pixel devices to third parties like LG and Motorola. Speaking of Motorola, they are now owned by Chinese manufacturer Lenovo, which has also been in hot water lately over spyware and rootkits in their laptops.
I'm of two minds about the announcement. On the one hand, Huawei and ZTE have both been caught installing backdoors and spyware on their devices in the past[1]. On the other hand, the US three letter agencies have a vested interest in US citizens carrying around easily monitored and tracked devices, and they easily find ways around Constitutional protections against spying within their own borders.
I honestly don't know who to believe in this situation.
[1] https://www.fastcompany.com/4025254/new-phone-who-dis-huawei...
BLU?
[0] https://www.kryptowire.com/adups_security_analysis.html
[1] https://www.bitsighttech.com/blog/ragentek-android-ota-updat...
Exactly my thought. US gov't even outsources to private contractors that then subcontract and outsource to China for electronic components including chips that can easily end up in our DOD systems. I wonder if this is more of a money or market thing being pushed by the Existing Oligopoly?
Something doesn't appear to add up completely?
That's easy. And moreover, its a bigger threat. With a Huawei phone, the Chinese government has control over everything from the processor to the userspace software. With a small piece of silicon in a fab, the threat surface is much smaller; they'd have to sneak it in against Apple's will, past all of Apple's American-loyal QA.
In the software world, we tend to think about security as an absolute, because computer logic is absolute. In the real world, security is probabilities. How can you minimize the chance of breach while minimizing costs.
Is Apple's QA workforce mostly American or do they have a lot of Chinese H1Bs? I mean loyalty is a fickle thing.
If the 'threat' was real, that makes as much sense as hardening one door in your house, when you have 4 other doors because "you can't protect against every threat model".
Asking Apple to manufacturer their phones outside of the US is a highly expensive action.
That being said if you don’t control the software, modifying manually a handful of devices doesn’t scale. If you modify all of them the chance that you will be spotted is very high. If you control the software and it is encrypted / not readable, you can backdoor all devices of a whole country. So I can see how it is a step up in term of threat level.
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
Nope, per recent incidents.
I'd say that is a LOT of influence.
But, do they feel above the law? This is certainly a common complaint of South Koreans. These groups are definitely "too big to fail" and they know it. So yes the concentration of power in a few giant firms is remarkable, and not in a good way.
Even if they only had rough suspicions (with rigorous technical underpinnings, just like a security researcher taking their job seriously). The public security community has repeatedly discovered, reported and fixed serious security vulnerabilities without the NSA doing shit all to help out (which is their job) whether they knew about the vulnerability or not, going as far as deliberately pushing back.
The only reason I can see why you'd prefer one argument over the other is if you somehow believe the NSA always has the best interest of the people at heart. But I think we know a little better by now and they might support the people in theory, but there are usually other interests that are bigger and better and more important.
If it was just the NSA saying this I'd be a bit more skeptical. But if the FBI and CIA agree, that seems like sufficient reason to believe that their motives are honest.