Worried about Huawei? Take a closer look at Tencent
japantimes.co.jp
japantimes.co.jp
Fortnite BR, like other competitive online games, runs anti-cheat software in-order to detect cheaters. Fornite BR happens to use Easy Anti-Cheat and BattlEye [1] [2].
Anti-cheat software runs with very high privilege. More importantly, with many anti-cheat software, every session a new binary payload is downloaded directly from the internet.
Anti-cheat software seems like a great platform to launch targeted malware in-order to achieve a beachhead on a computer network: highly targeted, and effectively undetectable.
I would expect most software developers don't sandbox their gaming machines from their work-from-home environments.
[1] https://www.reddit.com/r/FortNiteBR/comments/82xyhb/launch_e...
[2] https://www.thesun.co.uk/tech/7446514/fortnite-cheats-beware...
I work for a western studio for which Tencent is a majority shareholder, and I can tell you, Tencent hasn't even hinted at wanting any of our data, let harvesting more.
As far as I can tell, their motives are simple and capitalistic. Somewhat ironically, it was all the western potential acquiring companies that had agendas that were very ethically distasteful to us.
Tencent certainly complies with Chinese laws in china, but can you blame it? Wouldn't you comply with the law of your country?
How would you know if they did? Most employees have zero interactions with their employer's investors.
The person who asked should have looked at your profile.
I was working for a telco hardware and software manufacturer and I remember when about 15 years ago, I was the QA, who was sent to China with an engineer to implement "a feature" onsite (yes it was a backdoor). Everybody could guessed in my team, why are we were sent there. Also worked at a cinema control software company and we had to implement the same feature.
So yeah, it only take one engineer to implement a feature. (or a bug)
So pretty widely known.
Also hello from NZ :)
One or two guys, working on cheat detection might know something, or most likely are just told to ignore whatever, they see.
Ntk only.
* You are a foreign intelligence asset and and any denials on your part are lies.
* You are not a foreign intelligence asset, but you know that strange things are afoot and have informed the FBI. In order to not jeopardize the counterintelligence investigation, you have been instructed to play dumb, and hence, any denials on your part are lies.
* You are not a foreign intelligence asset and you have not noticed the infiltration. In this situation, you're not lying when you deny that anything's going on, you're just ignorant.
Of course, if your company isn't being infiltrated by foreign intelligence, you will also, correctly, deny that the company is being infiltrated. I'm not saying that his company is being infiltrated or compromised; I'm saying that there's virtually zero informational value in someone in his position denying such a thing because no one would ever admit it.
Interesting, can you elaborate?
But in basically all cases western companies were much more interested in buying us for our users, which they could then subject to whatever their business model is. Selling ads, selling subscriptions, selling data, whatever.
Our companies profit was actually a negative to these western companies since it simply increases the price that they would have to pay to get at the users.
On the other hand how many knows how much Facebook and Google collects about you and where that information ends up some time later? There was a lot of scifi about the information society and how that could derail in the future, where machines decides if you might commit a crime in the future and take preventative meassures. We are not far away from it now, just takes a few small jumps in the imagination to end up there :-)
More importantly, there is a lot of literature about totalitarianism.
Since you've put yourself out here as CTO of a Tencent owned company... I've heard that in China, Fortnite requires a Chinese "real ID" to play. Aka China knows exactly who you are at all times.
They also "punish" you for playing more than 3 hours at a time if you're under 18.
And I can't prove, but assume they also record all conversations (otherwise... What is point of using real id??)
This doesn't sound like something Epic games would want to be associated with if Tencent wasn't a major shareholder. Are you saying you've had no pressure at all to implement similar features and make your games "more friendly to the Chinese market"?
To me it feels just like China buying up slivers of hollywood so nothing critical of the regime makes the big screen
I am not saying Epic/Tencent is good or anything just that you don't need to be partialy owned by chinese company for this to happen. It is financial capitalist decision. Similar to why other companies want to enter china market.
It would be more suspicious if Epic was doing it even when Fortnite woulnt be profitable in china.
No comment on the wider claims, but 40% does give them a tremendous amount of at least soft power.
That's one or two other shareholders you need to bribe / convince. Not difficult, especially when the company you just invested in is learning what it's like to have scrooge McDuck money and want more.
Heck, if China wants to spy on anybody, they don't even need to resort to technology to begin with... Unlike the PRC, USA is a more or less open society — want someone's secret? Just send your man there; Want to influence someone? Just ask......
I totally don't understand American concern with technology being used by espionage, while it lets this go.
Yes, stealing individual secrets is best done with old school tradecraft. Spies in suits, photos of scandals with dominatrixes.
But what if you want build a system which can identify homosexuals based on textual conversations? You buy Grindr.
Or what if you want to get a backdoor for future exploitation on almost every computer in the US? You buy Fortnite. Because one of those computers will belong to the child of someone important. It only takes one slip by them to get Stuxnet from their home PC to their work PC.
You mustn't be afraid to dream a little bigger darling.
I shouldn't have mentioned attack vectors, the first case is the better opportunity these days. Data data data.
Why would anybody need to do more than steal individual secrets they've been told to recon?
You can build that model if you have access to the data of 20 million people.
This depends a lot on who owns the other 60%. If it's one other party, the 40% effectively has no control. If it's a public company with a million other owners and they're the largest individual shareholder, many of the others won't even show up to vote their shares and their 40% of all shares will generally be >50% of the ones that show up to vote for anything.
But you would get to heavily influence what contractors and vendors the company works with are good vectors.
As well as partnership and integrations.
The literal thing I just said isn't even that unethical; suppose you own 100% of a company, then telling it to hire someone specific and pay them this much and put them here would be fully within your rights as owner. (There's probably a legal hurdle or two to clear, but AFAIK it's nothing that will actually stop you.) How that changes ethically as your ownership stake decreases I'll leave as an exercise for the reader. What's unethical is what they'll be doing when they get there, and who else is tainted ethically depends on how much they know and what they do about it.
A more reasonable case is that they can heavily influence what contractors and 3rd parties are used for projects. Not something that needs a board vote, but something a 40% shareholder has a lot of say in.
The benefit of partial ownership (or dual ownership) is that it opens up the network of internal employees and management to recruitment while also providing plausible cover as it is a branded and well-known "western" firm
It's about how important a target you are. You only have to make one mistake, and "they" only have to get it right once. There's no defense that you can put up against a team of dedicated hackers with nation state backing unless you are either not on their radar, or have nothing inherently hackable in your life.
But it's still worthwhile to protect oneself from being an easy target for a system which just scoops anything interesting off the disk it's installed on.
> I would expect most software developers don't sandbox their gaming machines from their work-from-home environments.
I have been worried about this for some time. In my country we have a lot of issues with metadata retention so I set something up like this[0].
I have separate VLANs:
• VLAN 1: Management (no tag, null route)
• VLAN 2: Untrusted (routes direct to ISP via ppp0)
• VLAN 3: Trusted (routes direct to ISP via ppp0)
• VLAN 4: Trusted (routes via tun0 - VPN connection for private browsing etc)
• VLAN 5: Null route for devices that do not require internet access of any kind, desk phones printers etc.
(Doesn't have to be a Raspberry Pi, you can use anything that Alpine Linux runs on which is x86_64, x86, ppc64le, s390x, armhf, aarch64 (ARM8 like Raspberry Pi 3), armv7 (Raspberry Pi 2, and friends).[1]
[0] https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
[1] https://alpinelinux.org/downloads/
The idea is that anything on VLAN2 is completely segregated at the switch and router level from the rest of my network.
There are essentially just two segments / types of switch ports (I may have stuck with the many-vlans thing if switch ports had RGB LEDs showing what zone they were in...). First, the "trusted" network, which does switch management, servers, reasonably-behaved hosts, etc.
Then, a second "access" segment. Ports in this segment are setup to not be able to talk to one another through the switching fabric at all - the only thing they can talk to is the router. Ports on the same switch are prohibited from talking by the switch's config, and different switches are given different associated VLANs. This is good for visitors, Android, Internet of Trash, etc.
For routing, the horizon seen by each device is controlled directly by its own macaddr on the router itself. Two hosts on the same segment can see drastically different routing tables and Internet connections. This isn't perfect, as it can be easily spoofed unless I start pushing the switchport-mac mapping out to the switches. But it works for now.
But I believe "sandboxing" in the original comment was talking about the machine itself, not network access. So PC gaming means being disciplined about getting another machine, or at least a second GPU for PCIE passthrough in a VM. In general I think we're in a time of decommodification. The easiest way to sandbox between security boundaries is separate machines, of which there is an inexpensive surplus of. No need to have banking and games on the same tablet, when a second hand nexus7 (flo) is $40 on fleabay.
But will your colleagues who play competitive online games be willing to buy a separate machine used only for remote employment, and be willing (and able) to construct such a network topology correctly?
Most household routers don't even support VLANs.
Yes essentially that's what VLAN 3 and 4 are (trusted). They are able to talk to each other but VLAN 2 (untrusted) cannot. VLAN 2 cannot access my server on the LAN or any other network resources, except in certain situations where I open a single HTTP port to a specific directory that is read/only. This is where guests would be. I use this to copy 'certain' files to my untrusted hosts. The exploitation surface area is extremely low. Switch configuration can only occur when on VLAN 1 (management). I also can control which VLAN people access via WiFi via my Unifi Controller. One SSID is a trusted network, the other is untrusted. I only use EAP so I can control exactly what users have access to what VLANs via FreeRadius. All of this is documented [0][1]
> For routing, the horizon seen by each device is controlled directly by its own macaddr on the router itself.
Remember MAC Addresses can be spoofed which means you can get things like VLAN hopping if you're not careful. My Windows machine where my gaming happens is "untrusted" and is in port 2 on the switch, my trusted machines are in port 3 and 4. My other family members also have certain devices they consider 'trusted' and those are in VLAN 3/4 while they have devices that are 'untrusted' in VLAN 2. It took some time to educate everyone, but I drew pictures, and explained it nicely. Unfortunately this is the world we currently live in.
I was concerned that a APT (advanced persistent threat) might have the time to monitor the system for idleness and then attempt such an activity. At least that is what I would do.
> But I believe "sandboxing" in the original comment was talking about the machine itself, not network access.
Well they are sort of the same thing in this situation because it's physical sandboxing.
> So PC gaming means being disciplined about getting another machine, or at least a second GPU for PCIE passthrough in a VM.
> In general I think we're in a time of decommodification. The easiest way to sandbox between security boundaries is separate machines, of which there is an inexpensive surplus of.
Exactly.
No need to have banking and games on the same tablet, when a second hand nexus7 (flo) is $40 on fleabay.
This is exactly my point. In regard to my mobile phone I use a Redmi Note 5, with LineageOS, without Google Apps. If I tablet gamed I would have a 7" tablet specifically for that. I would tether it to my phone via WiFi AP and the CPU/GPU would probably be more powerful than you'd get in a phone anyway.
I only install things through F-Droid. I have made a significant attempt to de-google my life and have been successful.
Right now all I have on there is
• andOTP org.shadowice.flocke.andotp
• AnySoftKeyboard com.menny.android.anysoftkeyboard
• Barcode Scanner com.google.zxing.client.android
• BusyBox ru.meefik.busybox
• Call Recorder com.github.axet.callrecorder
• DAVx⁵ at.bitfire.davdroid - Used for syncing with my private Radicale instance.
• Draw com.simplemobiletools.draw.pro
• F-Droid org.fdroid.fdroid
• Fennec F-Droid org.mozilla.fennec_fdroid
• Flym net.frju.flym - RSS yay.
• Ghost Commander com.ghostsq.commander
• K-9 Mail com.fsck.k9
• Maps com.github.axet.maps - Provides a native experience for OSM maps. If I need Google Maps I just use a web browser.
• Markor net.gsantner.markor - Awesome text editor/markdown editor
• MuPDF viewer com.artifex.mupdf.viewer.app
• oandbackup dk.jens.backup
• OpenKeychain org.sufficientlysecure.keychain - PGP mail yes.
• OpenTasks org.dmfs.tasks - Used for syncing tasks with my private Radicale instance
• OpenVPN for Android de.blinkt.openvpn
• primitive ftpd org.primftpd - I upload/download via sftp to my phone without plugging it in with ssh keys (ie /sdcard/.ssh/authorized/keys)
sftp_phone() {lftp sftp://user:DUMMY@{{ IP_OF_PHONE }} -e 'set sftp:connect-program "ssh -a -x -o KexAlgorithms=diffie-hellman-group-exchange-sha256 -o MACs=hmac-sha2-512,hmac-sha2-256 -i ~/.ssh/id_rsa"'}
• RedReader org.quantumbadger.redreader• Revolution IRC io.mrarm.irc - Yeah I still use IRC and not IRC bridges, yet with Riot because of https://github.com/vector-im/riot-web/issues/2320
• Riot.im im.vector.alpha
• Share to Clipboard com.tengu.sharetoclipboard
• Silence org.smssecure.smssecure
• VLC org.videolan.vlc
[0]: http://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a_...
[1]: https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
Also I don't see the need for hosts on VLAN2 to be able to talk to one another. Which enables me to default to putting decently trustable things in my access zone as well (like say an RPi running Raspbian/Kodi).
> Remember MAC Addresses can be spoofed which means you can get things like VLAN hopping if you're not careful
Oh for sure, which is why I alluded to eventually pushing out per-port mac address config to the switches. But my primary concern is browser/pocketsurveillance traffic not going out my ISP's IP, and this suffices for now.
(Thanks for the dump of Free android apps you find useful. Not really on topic for the thread, but I personally appreciate it)
Security establishments are treating domestic companies, infrastructure, data hosting and anything else they can as vectors for intelligence. Legislators are supporting them. No one is taking the higher ground because they're doing it too.
Meanwhile, the meatiest cash cows in tech are advertising businesses, and the technologies that make their money are ad-tech, which at this point is extremely adjacent to spy-tech. Facebook's ad-tech, for example, would be very good at narrowing down a list of people likely to go on Hajj... I'm sure tencent's is too.
China is more open/public/brazen about their domestic activities (we noticed that your friend went to Mecca) where the US is cagey about domestic operations (eg Snowden). They're more discreet about foreign surveillance, where the US is a little more public. Both are doing both. So are dozens of nations and probably few non state players.
Now we seem to have an arm's race, with spooks publicly "outing" rivals and simultaneously demanding (publicly and privately) legislatures and companies improve their access.
At best, we get technology and digital culture balkanization. At worst, we get stasi-on-steriods.
There doesn't seem to be any meaningful political force pushing in the freedom direction.
The thing is, we don't know what we need to hide tomorrow.
Or what others, such as journalists and whistle-blowers, need to hide today.
- If not for nukes we'd still be going full-on against each other in war.
- If not for Hitler, we'd probably still be engaged in top-down government driven eugenics. Something many do not know is that US "progress" on this topic was an early inspiration for Hitler.
And here too the solution will likely be letting things reach their natural climax. It's not difficult to imagine a practically infinite number of extreme scenarios when you have centralized authorities with effectively unlimited informational access on their population and perceived 'enemies' - foreign and domestic. One of these scenarios will eventually play out, at which point this dystopic nonsense can hopefully go the way of government driven eugenics as people realize what this can, and inevitably will, culminate in.
Oh no no, governments will only involuntarily sterilize the [not me] people. Oh no no, governments will only use mountains of personal and private information to exploit [not me] people.
It's always been that way. We're just more aware of it lately.
I just can’t help comparing this with William Gibson novels when I imagine the future: not all bad, society will go through interesting transformations, some will be good. But still worthy of concern.
When, in all of human history, has this ever not been the case?
Of course this kind of censorship shouldn't happen. What they are doing is wrong and I find it mostly just sad that the Chinese government can't function without such a degree of censorship.
On the other side though, people are being warned again and again about centralized platforms, and they never cared one bit. Even with China as a perfect example of how terribly that can go wrong, people just won't believe that maybe, just maybe, they shouldn't be relying 100% on centralized messaging and social media platforms.
We can't change the Chinese government; nobody can. It's a political monolith built from the ground up to maintain its own stability above all else. What we can do, however, is the way we think about software; not as something that just seems to grow on trees on its own, but tools that can and will be used for political purposes whenever possible.
People once thought the same thing about Soviet Russia, and they were wrong. The Chinese government can be changed, it's just that none of the actions "we" can do to help with that have any clear path to quick success. I think it'll be more an exercise of doing what one can (like refusing to cooperate with censorship. tying to subvert it, amplifying dissidents, etc.) and waiting.
Just to clarify, I'm taking "we" to mean all of us opposed to authoritarianism, across all national boundaries.
Soviet Russia in the 80s was falling apart after economic stagnation, then the perestroika and glasnost would make it open to critic communism itself, even some events like Chernobyl contributed to some extent.
You wouldn't have even dreamed to make Soviet Russia regime fall with "social pressure" under Stalin.
China is not regressing nor stagnating, it's peaking. You can't take it out from the inside so easily.
Edit : Also, remarkably, there's this : ...once an account is registered with a Chinese phone number, it remains subject to Chinese controls even outside the country.
And the article gives some examples about it and how the control is not limited to within China itself.
At this point the decision tree facing privacy activists, those concerned with human rights, and those who support the expansion of western moral aspirations is unambiguous.
Do you dislike Google fucking up the internet and assisting with totalitarian censorship regimes? Stop using their services. Stop letting them pay you to improve their services. If you're good enough to work at Google, you're uniquely positioned to get another high-paying job somewhere else. Same with the other big offenders.
Do you dislike FaceBook's scummy behavior on everything from censorship, to digital stalking of non-users, to psychological experimentation with unwitting human subjects? Stop adding fuel to the fire. Quit. Today. Now.
Are you uncomfortable with China's aggressive censorship, human rights abuses, and surveillance? Stop buying shit from them. Stop using their software. Nine times out of ten you don't need it.
Exceptions arise, and no one's behavior is perfect. But the 1/10 case where you absolutely MUST use a certain surveillance app or buy a certain widget made by slaves in another country is not an excuse for throwing your hands up and capitulating in the other nine cases you encounter every day.
Reach of Huawei (or other manufacturer) potential backdoor is bigger and more business focused than social media and games.
So the risk is still great to economy with Telco compromise, but the social and political risk is probably equal or comparable with social media.
A bit comparing apples and oranges still, but interesting anyway.
All of those sweet Fortnite hours-played are going to do well for your social credit score.
On the contrary, Chinese regulators have been forcing gaming companies - including Tencent - to impose playtime limits.
EDIT: Just to be clear, my original comment was sarcastic; gaming is bad for your social credit score under the new system. Just in case you thought I actually meant good.
No it isn't. The idea is popular, probably because it plays into the simple narrative of a totalitarian government doing a single big thing to control everything at once. But the "social credit system" essentially amounts to separate government departments trying to coordinate their actions. Here's the best-informed article I've read so far on the topic: https://foreignpolicy.com/2018/11/16/chinas-orwellian-social...
Although this may be the case now, we can't just dismiss the fact that any government or service provider can (and will) continue to develop these systems and in the future control and deny more rights and access to services based on people's lifestyles.
As the NHS struggles more in the UK, I can imagine a future where your lifestyle habits, bought from banks and retailers are used to decide on your entitlement to care.
Insurance companies already use profiling, employers have been guilty of it, even countries using your social media to make decisions on entry.
These things will continue to be eroded, and if we just simply dismiss it, because a statement is too "matter of fact" like mine was, were in danger of losing sight of the fact that this is happening everywhere, it just doesn't necessarily have a nice marketing name yet.
But he average consumer doesn't know what software Tencent has ties to. You think you're getting North Carolina's Epic Games, but you're also getting Shenzhen's Tencent.
You know for a fact not a single packet any of your devices have sent or received have traversed a Huawei device?
> BT has announced it is in the process of removing Huawei's equipment from the core of its existing 3G and 4G mobile operations
ie, a single packet going through a Huawei devices doesn't pose me any threat. Not really. If I signed up for a Tencent service, though, quite a bit of my information would be voluntarily handed to the Chinese government.
(and to be clear, there is a real risk to Huawei infrastructure, but it's not the rare possibility that I may never be able to avoid it as I sometimes use the internet.)
Man can make it, man can break it. One of the most valuable lessons taught to me during my times at Solectron Global.
You think you're secure in any way? No. The absolute nature of computer science makes 'security' a laughable goal.
See: Ghidra. I've already used it to pull out several 0-days from Windows 7 and 8+ (including 10 since it is based on 8.)
Your train of thought is good, but doesn't hold up to actual reality.
And while you think those packets hold no threat to you, try going overseas if you've said anything bad (I had to deal with this in Thailand after criticizing the King while living in the USA.)
Don't be naive - watch what these people in charge are doing.