Huawei’s Ace in the Hole: Undersea Cables
asia.nikkei.com
asia.nikkei.com
I don't understand this at all... if the communications across the cable are properly secured then it shouldn't matter what cables it runs across.
Plus, it’s not just about access. A malicious actor could always damage or destroy the cable, cutting off a primary channel of communications.
If you're an ISP, Netflix will even send you (free!) servers for this. https://openconnect.netflix.com/en/
startyourownisp.com
I think this might be a bit much for getting some freebies. It would be fun, though. Unfortunately, it would take me a lot of work in the place I'm at for this to make any sense at all.Also note that would be the backbone encryption channels, but inside those people would be using https which is encryption further up the networking stack.
It's encrypted turtles all the way down.
Few and big backbones are responsable for almost all traffic. Few and big CDNs serving most of the contents that are used by everybody. Even few apps are "essential" for daily life.
Big money was/is created when internet become business as usual: few and big corps taking the biggest share.
I think the history of human communications is an ample demonstration of why this is a poor assumption.
When they don't usually means something else is the problem.
Source? Encryption has not been treated as a munition by the United States since the 90s.
Far as export, I looked into that in 2014. I found that only a few things, like mass market and ecommerce, got reclassified. High-assurance systems (EAL6/7) they couldnt hack were still munitions. So were custom crypto and some other things. People got fooled: NSA reclassified just the stuff they'd be able to hack anyway. Big progress but not what people thought.
https://www.schneier.com/blog/archives/2014/11/the_return_of...
They tried to pull more crap about a year after I wrote that:
https://www.computerworld.com/article/2925339/us-proposes-ti...
I don't know what current state of affairs is. I assume they've set it up where they can deny selectively if they feel the need to. So far, most "security" products are too insecure for them to need to do that.
Similarly, it's understandable that the Chinese want to start building their own backbone infrastructure so they're cannot be cut off from the world if they end up in a conflict with the U.S.. From that perspective, it makes sense that Huawei would start laying these cables. It can be seen as a defensive move.
I've long been wondering whether the Chinese have subverted IP infrastructure hardware, which is all produced in China, often by Chinese companies like TP-Link. How much of that stuff has a kill switch in it that they can activate if a conflict with the West breaks out?
Perhaps the higher end, non-consumer facing, equipment might have it. But for the cheap tp-link devices I highly doubt it.
All the more reason it's not in the cheap TP-Link routers but in the mobile phone chips which can't be examined so easily.
Won't 5G also have dedicated hardware?
> srsENB has been tested and validated with the following handsets:
LG Nexus 5 and 4
Motorola Moto G4 plus and G5
Huawei P9/P9lite, P10/P10lite, P20/P20lite
Huawei dongles: E3276 and E398
That's a very limited set of handsets. I wonder what's stopping them from adding support for more devices: Is it lack of contributors (no traction, lack of interest), or the cost of development (insanely difficult to reverse engineer, potential IP infringement etc), or limited and buggy functionality (doesn't work with certain carriers etc)?
How is not critical one might ask - the amount of battery time when power goes down. It's in range of minutes, sometimes there isn't even a UPS.
Meltdown was only discovered last year, despite being a vulnerability in virtually all Intel CPUs made since 1995. I suspect there are substantially more eyeballs on Intel, too.
Nobody can afford this in breadth. Granted, you can manufacture a rigged batch and keep it secret. But you can't have a broad capability and expect it to remain secret for long.
I guess they consider their own country to just be a large intranet, and the internet- the web between countries, is the thing they want neutral? Politics is not fun to deal with.
I imagine every undersea cable would be cut in the first week of a US-China conflict, regardless of who built it.
I don't think you're thinking like a military person.
I mean, if it's total war? Well, sorry, but it's total war.
I wouldn't count on too many undersea cables not being cut.
Given the manoeuvring requirements for the orbiting explosives, and the requirement to launch them with enough plausible deniability for it not to be obvious "there's a bunch of commercial satellite killers!" - I wonder if they could build and launch 60 of them for less than SpaceX paid to get the first 60 Starlink birds in orbit?
Nevertheless, this is such a terrible idea, I hope this is not the future.
Very very big...
A China-US conflict means dozens of nuclear weapons dropped on populous cities across the world in a matter of hours.
How anyone seriously entertains this idea is unreal.
An example of what limited conflict looks like is the Sino-Indian war which was kept confined to a limited geographic area. Its not a forgone conclusion that a conflict has to become "total".
most likely at sea
There's no way a threat to navies won't quickly jump to very serious warfare, of a kind that breaks open to involve lots more than just limited seaborne engagements.An oceanic conflict in the Pacific is going to ruin air traffic, and with both air and sea lanes compromised, you see the beginnings of blockades and economic business as usual encounters entanglements all over.
If big expensive ships start sinking, and the projection of air power changes, everything else heats up very quickly, because replacing military fleets (and the sailors to match) is a slow process, and any major setback could prove permanent and lasting.
Don't expect a naval limited war to stay limited for long.
If availability is compromised, that is obvious to the end user(s).
Availability is still important, but, as I said, much less important than integrity. (The importance of confidentiality varies.)
And having a problem you know about is pretty much always a significant upgrade compared to having a problem you don't know about.
Especially when it comes to attacking infrastructure, removing the availability of operations on this infrastructure is a good attack vector. This can be done by, for example, creating a temporary ban on logging in. It can be done by reporting a hacking attempt from the legitimate IP address range.
The US spent billions routing international telecom infrastructure through US and allied points of presence for a reason.
Spoofing IP's alone isn't enough, but CA infrastructure is very much based on a trust that is weaker than we'd like to admit.
Platforms like this are common for submarine applications: http://carrier.huawei.com/en/products/fixed-network/transmis...
It's possible, perhaps even likely that all communications would be recorded for decryption later when if / new techniques become available.
Somewhat tangential, but not I'm curious about how undersea cables deal with the tectonic plate movements and any volcanic activity on the plate boundary. Then I found this interesting article: https://www.sciencemag.org/news/2018/06/seafloor-cables-carr...
"China Telecom (CT) entered North American networks at the beginning of the 2000s, and has since grown to have 10 PoPs, eight in the US and two in Canada, spanning both coasts and all the major exchange points in the US. Few other non-American ISPs has such a wide-spread presence on US soil."
"Using these numerous PoPs, CT has already relatively seamlessly hijacked domestic US and crossUS traffic and redirected it to China over days, weeks, and months as demonstrated in the examples below. The patterns of traffic revealed in traceroute research7 suggest repetitive IP hijack attacks committed by China Telecom. While one may argue such attacks can always be explained by ‘normal’ BGP behavior, these in particular suggest malicious intent, precisely because of their unusual transit characteristics – namely the lengthened routes and the abnormal durations."
:s/CT/Huawei/
Source: https://scholarcommons.usf.edu/cgi/viewcontent.cgi?article=1...
https://phys.org/news/2019-02-european-telecoms-dilemma-huaw...
This article is completely worthless.
Breaking News: The Suit is Back! http://www.paulgraham.com/submarine.html
https://en.wikipedia.org/wiki/Global_surveillance_disclosure...
As for you main argument, we can worry both for Huaewei and Google/FB. It's not either or the other(s).
From the article:
> The leader in the global undersea cable market is SubCom of the U.S. Japan's NEC and Europe's Alcatel-Lucent
Each of these have strong ties to their respective government and could build backdoors.
https://www.forbes.com/sites/zakdoffman/2019/04/20/cia-offer...
https://www.scmp.com/tech/tech-leaders-and-founders/article/...
It's not a coincidence that APT steals IP and "somehow" Chinese companies have advanced 20 years in research.
> The founder was literally a PLA
Along with literally millions of other Chinese people. Being in the PLA when he was young means next to nothing.
If you're afraid of a foreign country using its technology providers to spy on you, you have two options:
1. Don't use technology from that country.
2. Only use technology from that country that you are confident you can audit.
There's nothing Huawei can do, beyond what it's already done (offer to open up its tech for audits by foreign intelligence services), to allay the fundamental fears you're expressing. In the same manner, there's almost nothing American companies can do to allay the fears of foreigner countries (or US citizens, for that manner) that their tech won't be used by American intelligence agencies. The logical conclusion of this is that every country must develop its own technological base, and that's not a future I want to live in.The only concern about Huawei is that it cannot disobey Chinese government orders issued against Huawei's will. (Sounds familiar? All those companies that dropped Huawei due to an US government order? How so many were being apologists for Google because "Google didn't have a choice"?) Saying Huawei is "literally the Chinese government" without providing proof and asking us to simply follow the rhetoric by suspending all disbelief is a very lazy and dishonest tactic.
I don’t think a company that is “literally the Chinese government” would be sold to a foreign company.
Do you know which telco companies have more connections to the Chinese government? Every other Chinese company. Even Foxconn which manufactures your iDevice has Communist representatives in their management.
That said, it's really not a stretch. To give just one example: There are strong suggestions that Microsoft got NSA money to buy Skype, principally so that MS would revert Skype to a server-based model and take encryption out. Whether this case is true or not, it seems pretty certain that the US government makes use of national players. And it would be incredibly far fetched to even imagine the PRC not doing the same thing.
If enough people have a cold war mentality strategically it makes some sense. Combined with the chance to annoy the Chinese govt in the middle of a trade war, Trump will love it.
> The reality is, even if the U.S. succeeds in shutting out Huawei from 5G networks in major countries, the Chinese company could still thwart American efforts to maintain leadership in handling global data traffic.
> Security policymakers in the U.S., Japan and Australia have started working together to address this potential threat.
How is not maintaining leadership a threat? I would say it's a loss of market share and control to do as you please with the infrastructure. It's a threat in the same sense as citizens having encryption.
It's basically saying China doing what the US does is a threat, meaning that what the US is doing is a threat to others symmetrically.
Australia cut off Huawei first way back in 2012/2013 when they locked the company out of Australia's 5G network.
I'm no fan of Trump but I don't see how it's relevant to bring his name into this. This would have mostly likely been US policy under a democrat administration as well. Who wants to bet in 10 years we'll find leaked documents showing Apple and Samsung US lobbied the commerce department for this? Who wants to bet Intel, Microsoft and Google are about to sue because they're about to lose a few hundred million a peace?
I'm curious if we'll see a Federal Court case on this within the next three months.
Besides something tells me that the same people who oppose things like the GDPR wouldn't exactly applaud if governments decided to pass a law to make TLS mandatory for instance. I'm sure if that were to happen we'd soon hit semantic satiation for the phrase "regulatory capture" in this very forum.
So what exactly do you propose governments should do to solve this particular problem?
Widemouth Bay is the still active one with a GCHQ intercept nearby.
Minor correction: Tom Scott's video is great, but I was actually thinking of Motherboard's video which talks about modern undersea cables: https://www.youtube.com/watch?v=iMAThVcqzuk
[1] http://cryptome.org/eyeball/cable/cable-eyeball.htm [2] https://arstechnica.com/information-technology/2016/05/how-t...
Which is a common theme for this anti-China/Huawei push: Just accuse them of everything we are already guilty of. Anybody pointing out the hypocrisy can just be shut-up with a good dose of "whataboutism!".
[0] https://www.theguardian.com/uk/2013/jun/21/gchq-cables-secre...
[1] https://www.smartcompany.com.au/finance/economy/telstra-s-de...
And that would be a completely appropriate response if someone were to imply that the US' actions somehow justify China's actions. Or vice versa.
That's why I consider this current push of "China spying on everybody" quite cynical as it tries to sell a narrative where FiveEyes spying is the benevolent BigBrother only trying to protect us, but Chinese spying is evil incarnate.
At this point, Germany might as well just go full-on post-privacy and just share all data about everybody with everybody, instead of playing these pretend games of "We care about privacy, except when it's in the way of US national security interests", which is an extremely weird stance to have for any country that's not the US.
[0] http://www.europarl.europa.eu/document/activities/cont/20140...
I'd be mildly surprised if me posting this comment went through a cable at the bottom of the ocean, but who knows?
I can guess, but I'm sure other users know better.
EDIT: But back to the question. I think the answers make sense. It's easy to bypass if you are savvy (as we know already) but if you challenge govt they would take offense. I guess the grey area would be anonomous critique, but I digress; thanks for the response.
So in praising Tang Taizong, the official was critiquing Xi's inability to deal with differing opinions.
This isn't a new thing, BTW. Chinese scholar-officials have been doing this for ages. China has historically been a very authoritarian country and the same ideas applied then (kind of). This is one reason why historical Chinese officials were (ironically enough) criticized by the Communists for being backwards looking. Straight forward critique wasn't allowed during the imperial eras so they always had to find historical parallels to vail their critiques and advices.
Then it will stop.
Even though they may not be able to break the crypto, it's not hard from a DPI (deep packet inspection) and netflow analysis perspective to see that an IP in China has a high volume of encrypted traffic to/from a single /32 in the US/Europe, and then blackhole that.
The GFW has automated null routing/traffic blackholing functions in place for this.
For example, multiple SSH tunnels through something like sshuttle where you try to give the impression that you are not threading all your traffic through one "hole".
Always impressed that it still manages to work.
I paid for a vpn service so for personal stuff I was able to access every single site on the Internet. I did this for over two years and never got into any trouble. My impression was that nobody cares if you find a way to browse facebook, twitter, wikipedia as long as you don't use that opportunity to incite subversion of the government or some similar shit.