Huawei: NZ bars Chinese firm on national security fears
bbc.com
bbc.com
The chosen solution in that case was to set up a dedicated engineering facility onshore, where evaluation of the products could be performed at various levels before deployment.
https://www.gov.uk/government/publications/huawei-cyber-secu...
Honestly, that doesn't seem like a good plan. While such a lab is better than nothing, it doesn't protect the UK against attacks it didn't understand or think to look for. I'm reminded of this Soviet bug that was given to the American embassy in Moscow and lay undetected for seven years.
https://en.wikipedia.org/wiki/The_Thing_(listening_device)
The fact that the lab was created for Huawei tells me they're not trusted enough. The smart thing to do is to pick vendors you already trust not to bug you, and then do the extensive verification as an additional check.
That said; in an age where a large percentage of physical devices/device parts are made in China - protecting against attacks you don't understand or think to look for is a non trivial exercise and can't be avoided merely by changing vendor (though doing so may make an attack harder).
BT saved a bit of money short term and Ben Verwaayen got his bonus but long term they are now dependant on products they can't really control where before they could pop down the road to Chelmsford and go and speak to the design team.
Think about the presence of Android in China, they worry about Android phones having Play services calling home with more data than it’s needed to work properly. This is not theory, it was shown in the past and we never know how much data we’re sending back to Google or even Facebook just by owning an Android device. So they block Google Play services, in the name of its citizens right to privacy or whatever. Now the same due diligence is not taken into account for the same kind of services provided by local companies. They can operate without a lot of backslash over data collection or backdoors. But for them (Chinese government) this is still a better alternative. Because the data is not siting on a data center in US waiting to be mined by some agency that happen to have three letters and no need for a mandate to look at data from non citizens.
So the reason to ban them is right, but it’s not just banning them to spy on us. This is also saying that if somebody is going to spy on our communications it better be on our side of the fence. Maybe Cisco could win without a lot of fuss about “possible threats that we don’t understand right now”. Maybe Cisco also have code with dubious quality, or even straight malicious, but at least the data exfiltration is not sitting on a data center in China.
How do the Five Eyes governments know this? Because they were doing the exact same thing, with help from e.g. telcos. But most foreign telcos are somewhat well monitored, so attacking the hardware is the next logical step.
There's no mystery here, it's just they can't come right out and say "this is how we would have done it", because they probably did.
Especially if said company is controlled by its government.
Especially if said company has been caught using said kind of access to spy for its owner government before.
Especially if said country has made a reputation of systematically stealing all the tech and spying any way it could on you to use it "against" you.
Especially if said country is not part of the same geopolitical block as you.
Especially if said government does the same thing to your own companies in the same field.
Confusing regular commercial dealing and critical infrastructure deal and acting like they have the same security need or that one leads to another makes no sense to me, so your comment is, in my opinion, out of line.
This is entirely trade propaganda at the behest of large cellular RF equipment manufacturers, and device manufacturers.
https://www.aspistrategist.org.au/the-african-union-headquar...
I want to point out that international postal rates are determined by the UPU [1] which has existed since the late 1800s. It is not only Americans who are subsidizing shipping from China, most postal services in developed countries are paying to subsidize postal rates in less developed countries through the UPU.
The fact that this system can be abused isn't even a new debate, it was occurring well before Trump arrived [2].
One can argue whether the UPU has been too slow to reclassify China relative to their development. But I think at the time of the conception of the UPU, and for much of the 20th century, before electronic communications became cheap and ubiquitous, it did serve a useful purpose. I imagine the UPU helped make sending postal mail to people in developing countries within financial reach, and I would also think contributed toward the development of postal systems in some of these countries.
[1] https://en.wikipedia.org/wiki/Universal_Postal_Union
[2] http://fortune.com/2015/03/11/united-nations-subsidy-chinese...
This is rampant capitalistic consumerism, nothing to do with China.
>Copying our IP?
Doesn't really matter. Who do IP's benefit? Not the consumer, only the already super wealthy. Hint: the very large majority of the world is not wealthy.
Taxes went up on products from Aliexpress. Shipping from China to USA is much more efficient than the other way around.
When I'm subsidizing health insurance, food stamps, and medicare on Walmart, Amazon, Starbucks, etc, to put billions more in Bezos pocket, I could care less about something that actually benefits lower income people with affordable products that would be well out of reach in USA. Raise wages and people who were using Aliexpress will start buying domestic.
I'm no fan of copyright or software patents, but that's a bit too simple. Good R&D is complicated and favours highly educated/skilled workers. Even if you don't like companies, it's quite unfair that people who have have spent a long time becoming domain experts should lose their livelihood because of outside forces breaking the law - international law mind (AFAIK).