U.S. Warns Of Spy Dangers Of Chinese-Made Drones
npr.org
npr.org
These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home").
I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them.
Just publish technical information. It isn't hard. It would do huge damage to the Chinese and reinforce the US's whole argument. But yet after over a year, nada.
There's a difference between individual invasions of privacy and national security. There's definitely Chinese apps that invade your privacy. There's also Western apps that do too. The question is of national security however.
"National security" is a vague term that is always abused to make money, take away liberties or kill people.
Remember when Strava's heatmap of running tracks leaked information about military bases? https://twitter.com/Nrg8000/status/957318498102865920
The better alternative: I don't want anyone to have my information - unfortunately is largely not going to be an option. The choice will mostly be between the US and China (or in some cases, European tech providers, which will frequently work with the US). If it's not already that way, it certainly is going to be in the next 10 or 20 years.
A classic example is the "we collect your data to provide X service" / "you can disable service X" that we see all over the place. Everyone reads it as "you can disable data collection" but that's not what it says, and it's not what really happens.
The better alternative is to not accept this kind of invasiveness but the ease and convenience of giving in is too seductive for most people, so we invent a comfort belief that it's somehow benign or at worst irrelevant.
Why?
https://www.nytimes.com/2017/07/25/technology/roomba-irobot-...
You don't think it would do a lot of harm to publish detailed analyses letting them know we've broken their encryption?
"Hey, what's a great way to deal with China if we go to war? Whataminute, they could do that to US!"
Just look at the havoc that has happened unintentionally due to bad updates being pushed out on a large scale and extrapolate to what could happen with a malicious actor at full control.
Such as, itself.
Certainly, if you and I started spending repeated 30 minute looking for examples of adversarial actions taken by the US and China against their people, neither of us would run out of examples before tomorrow.
So what are you claiming exactly?
I was also asserting that I personally do not believe that a government should conduct espionage on it's own people and that society needs to push back against such actions. Even in cases where another country is highly adversarial to you, the milder home country might be much worse because of their proximity and involvement in your day to day life.
Or even simpler have this hardware and software setup to only get OTA updates and commands only from central command.
This feels so hypocritical considering that many PC around the world run CPUs that have Intel ME or equivalent and there is no media coverage of known backdoors in CPUs(I know technically it is a fully featured remote management feature that had some bugs in the past but Intel assures us that there are no more critical bugs and for sure no intentional bugs and this enterprise feature is also included in all CPUs not only in enterprise ones)
I also agree with you that the solution to OTA updates is tight control, but that isn't realistic either. They are talking about drones in the article. These are devices bought and run by companies that build infrastructure in the US but are not directly related to the government. They want OTA because it has legitimate benefits in worker time and cost savings and helps keep their "fleet" running with all the latest features.
Now, an example attack might be an OTA update for the drone controller to shunt mapping data back to home base in China to give them high quality military maps of infrastructure for attack planning. The attack might be unrealistic, but the spying threat isn't. Alternatively, if car autopilot takes off, imagine the economic damage an OTA attack could do that causes 30% of the traffic in the US to just stop. To prevent this sort of attack, you would have to review ALL code coming out of China since you can't directly hold them responsible after the fact when they are out of your sovereign jurisdiction. The kind of dedicated and educated workforce required to code check all firmware/software updates for such huge classes of consumer products is just not going to happen and it can only get worse.
Intel ME is an abomination, but it's also well known and gets a lot of coverage. It's just not in the mainstream news right this minute.
It was probably only a topic on technical forums.
Technical question, can't you build a drone that does not need OTA updates from manufacturer ? You have it connect only to your trusted IPs.
Also sending the high definition photos to China won't appear on anybody network traffic? You just need 1 person to detect it and you have the some kind of proof(though when a similar thing happened with Amazon Alexa it was blamed as a bug and not espionage).
Of course you can, but even then you're still trusting the firmware that is being put out by the potentially hostile company even if you gate keep it. To check it would require a software team at least as large as the potentially hostile one for any serious attack. That's a big economic incentive to trust the manufacturer.
>sending the high definition photos
Or you could just send metadata, telemetry, and flight diagnostics that can be used to build up sensitive information under the guise of metrics. Remember that the NSA was mostly just using metadata too.
>it was blamed as a bug and not espionage
In these cases, the two look exactly the same in software, so proving one or the other is very difficult.
Wi-Fi makes that pretty damn hard to verify. In theory, malicious firmware could even opportunistically link up with other malicious firmware acting as a bridge via some undocumented protocol that would only be detectable by looking at the raw spectrum.
I understand not "making the economic situation worse", but sometimes things have to get worse before they get better. Obama had "good relationship with China" and China trampled all over American companies because of it, pretty much making up whatever demands they wanted if those companies wanted to do business there. Plus, even before the trade war, car imports had 25% tariffs in China, and I think 0-5% in the U.S. for the reverse.
It reminds me of when Google was "open" with the Gmail and GChat APIs, and then Facebook abused it to get all of Gmail's contacts through the mass-invite feature, while Google couldn't do the same with Facebook contacts.
Similarly, Microsoft was working on adding GChat support to Skype - but the reverse (Skype in GChat) wasn't possible. This example illustrates pretty well why you can't always be "open to everyone, no matter what", when some can become hyper-aggressive in exploiting what you have to offer when being so open, but not paying it back in any form.
I believe I also read a recent comment about RISC-V developers giving the Chinese the could shoulder in collaborations, because Chinese developers tend to "take take take" and not contribute anything back, ever.
I even see it all the time with people praising Samsung, etc for "innovating more than Google", forgetting the fact that 95% of the OS is Google's work.
"because Chinese developers tend to "take take take" and not contribute anything back, ever." It's not ture. For example, Siggraph is the best conference in the computer graphics field. In 2018, the number of papers that contain Chinese or ethnic Chinese is 45%.
Besides, many Chines and ethnic Chinese reasearchers are active in many frontier technology filed such as AI and Computer Vision field.
The acadimic and industry status and constribution of Chines reashers/company are increasing rapidlly.
Nobody cares about any "ethnic Chinese" fraction. We're discussing a trade war between US and PRC, not some racial struggle between Chinese and Caucasians or whatever.
No, I don't have to be sensitive to such delusions.
I doubt that it would damage China. The existence of the threat is already well publicized.
I think that U.S. intelligence does not talk about specific threats because the attack vectors would probably misunderstood and underestimated by the general public. There would inevitably be pushback like "Gee, we have to give up our drones just because of X?!"
The consequences from these types of events aren't felt immediately, and many people perceive that as being equivalent to no consequences at all.
> The existence of the threat is already well publicized.
Parroting the same vague "there's a threat, but the threat is secret so we cannot tell you about it" isn't well publishing anything. It is bordering on fear mongering. A well publicized threat would be a series of white papers describing in technical terms the weaknesses/backdoors/etc in Chinese manufactured hardware.
This is what's implied.
But if the US actually took that threat seriously, half of the Valley would be out of a job tomorrow.
Indeed. And for life safety uses it's appropriate. In safety-conscious settings such as those involving line voltages requiring NRTL (UL for ex) listing OTA updates are forbidden: One must have physical access to the device to perform a permitted [0] code update.
[0] And the code updates themselves are subject to IEC 60730/UL 1998 or it's back to the NRTL for more testing
Are you worried that your iPhone or Tesla will be hijacked the same way? You already know this happened before with the knowledge of the companies involved (secret subpoenas or national security letters) or without it (beacon implants).
There is hard evidence of the vulnerability, which logically follows from any OTA update capability, but there may be no hard evidence of exploitation yet.
Think of it this way: if your software has a RCE, you fix or mitigate it regardless if it's actively being exploited or not.
> Are you worried that your iPhone or Tesla will be hijacked the same way?
That's a very valid concern for some people.
Ultimately, software security boils down to "who do you trust?". Say what you will about the US, but your goals and values are very likely less incompatible with those of the US than with those of authoritarian China [1] [2].
[1] https://www.nytimes.com/2013/08/20/world/asia/chinas-new-lea...
Do you think it's more about your values or somebody's ego and interests?
The US has to convince their allies that buying from China is more dangerous than buying from the US. I don't think anybody doubts there isn't a threat.
I doubt intelligence agencies care about convincing public one way or another. I suspect they are worried about revealing details of their methods and thus have a blanket "say nothing" default mindset.
Why say anything at all then? Saying nothing is one thing, but they are saying something. Why the half-hearted messaging? I honestly don't get it.
It'd certainly damage Chinese companies and curtail those companies' utility as sources of intelligence. How many drones do you think DJI would sell if it became known that flight logs and aerial photos were being uploaded to the Chinese government? (This is all purely hypothetical but the DJI app is very aggressive about permissions and updates, so they absolutely could if they wanted to. I have a dedicated phone for mine which never gets to connect to the internet, for this very reason.)
Roughly about as many as today. A recreational or content production drone is sitting dead without a battery >>95% of the time. This is a much weaker threat model (both objectively and in the perception of consumers) than all those connected, always-on microphones and cameras installed in homes, offices and pockets.
I mention this as a precedent: to many people out there, "the Chinese government" isn't a lot more foreign than "some American tech empire" and data-derived unpleasantries are far more likely to have practical implications for them with US immigration than with the Chinese communist party (because the US is still more open). And yet those people still buy westcoast-designed (and connected) devices like hotcakes.
If there was indeed a threat to national security I trust my own government to make decisions not the US.
Isn't that the purpose? To fuel the trade tensions for the home team.
Don't expect truth in trade wars...
1. This class of device has known vulnerabilities
2. These devices are still sufficiently novel that they make economical new and different types of attacks
3. Organizations should consider how these vulnerabilities could potentially compromise your current security plans.
War only serves further destabilizes the country, and it definitely shouldn't be on the table unless someone is actually sending troops on our soil.
Last resort would be banning incoming visitors from that country. Not ideal, but a MUCH better solution than war in my opinion.
Though it's more jingoistic, I find the latter less infantilizing, when it's coupled with a guarded paranoia about the US too.
This is exacerbated by the very poor levels of security in these devices in general: DEF CON 23 - Robinson and Mitchell - Knocking my neighbors kids cruddy drone offline
https://www.youtube.com/watch?v=5CzURm7OpAA
However, to put things into perspective, purpose built security cameras -- even expensive ones from well reputed industry brands -- have had similar very poor levels of very poor security for many years.
https://www.youtube.com/watch?v=B8DjTcANBx0
It's not really a problem of drones. It's a problem with the poor levels of security in consumer devices in general. It's "as if" the situation has been engineered to let bad actors do lots of spying.
The following is a contrived analogy, admittedly not a great one, to illustrate why I suspect they can't give specifics.
Imagine if you have a gigantic elephant standing near a village. It's so big that you can only see one of the following, depending on where you stand: a trunk that can suck people up, legs that can smash, a tail that can create a wind that tosses people about. Three people are standing in different places to see each of these: Alice (trunk), Bob (legs), and Charlie (tail - poor Charlie). Someone comes running into the village and leaves an anonymous note saying a huge being is a threat and it is going to smash houses.
Except the villagers, if they can figure out who was standing where and what they could see, can tell who left the anonymous note. It was Bob, who could see the legs.
Giving the specifics they know about a threat reveals what they know, and what they don't know, and reveals how they might have gotten the information.
Anything to deflect away from US matters at home or abroad, anything to keep the populace in constant fear and suspicion - ooh, look what the nasty commies are doing, red danger, oh oh, now it's those terrible immigrants.. oh, now it's those dastardly commies again!
There is clearly one set of rules in operation for a chosen few whose companies get access to global markets without fearmongering and thus can grow uninhibited and then the real world where evidence-free scaremongering, demonization and sanctions are used to limit market access, sabotage others and destroy competition before it forms.
And citizens of the former get the privilege of articulating a set of free market values in a depoliticized context free world that don't hold in the real world. But its better this happens than it doesn't so the rest of the world can see through the self serving hypocrisy and plan accordingly. Those with this mindset will always find a way to limit others.
It's defined by law and law works very differently in China.
- China makes most of the drones
- A lot of them aren't very secure
Which isn't surprising to me considering the state of things like DVR cameras (also mostly made by China, also plagued with security issues) and similar tech.
The real problem is that consumers want cheap but quality and security aren't cheap. The cost of security isn't obvious and consumers don't really know how to evaluate it.
But, when things like drones and cameras start communicating over the 5G backbone then we should maybe be concerned about who controls both of them.
5G operates at OSI layer 1 (and maybe has some impact on layer 2). I've never heard of any aspect of it changing higher layers, which is where the concerns about control come in. Is there something I'm missing?
If not, 5G has nothing to do with application-level control (eg: controlling a drone's movements, intercepting a camera feed, etc). We'll still use TCP/IP, HTTPS, and everything else we use today. It may or may not be a concern right now (due to inadequate security at the higher OSI layers), but 5G -- or any other type of network topology -- does not change this. Please don't spread this type of psuedo-technical nonsense by making statements like this, especially with anything "5G" which is a current media fascination for some reason (starting to get bored with "IoT" maybe?).
If you control the cell infrastructure you absolutely can put cellular capabilities into products that aren't explicitly advertised. That would be a bigger risk for surveillance tech.
Your complaint ignores my original statement about controlling both components (cellular and device). There is no need to tamper with someone else's TLS-secured communications or anything, you can just plant cellular capabilities into the devices.
However I still don't think 5G is an important factor here. If you control both ends at a higher layer of the stack (eg, it's your own software connecting to your own servers) you can do whatever you'd like. If you have OTA software updates, you can do whatever you like at any point in the future. If this channel is properly secured with TLS no one can intercept or fake it, and if you want, you can design the devices so it won't work without this connectivity present (see: most cloud-based "smart home" devices on the market today).
> If you control the cell infrastructure you absolutely can put cellular capabilities into products that aren't explicitly advertised. That would be a bigger risk for surveillance tech.
So many devices already have internet connectivity built-in, and if money is not a concern you can already incorporate a GSM modem and pay for a link to the existing cellular networks -- it's not like AT&T (or whoever) is going to care what you are doing with the connection, so long as you're paying for it. You can also use other short-range radio links.
I'll grant you that 5G introduces the possibility to have this link without AT&T's knowledge -- at least assuming they don't have the ability to also detect the traffic coming out the tower's uplink. The big downside of this attack vector, aside from the immense cost and complexity of building this into 5G carrier equipment and all these devices, is if detected and blocked at the uplink all that effort is suddenly for nothing.
Basically, the 5G-specific attack vector is expensive and brittle, and thus pretty unlikely. The attack vector at application level is easy and cheap (no hardware-related costs), gets you almost all the same capabilities, and in many cases can be done today on existing in-field products with OTA software updates.
I think it's well accepted that there's high quality standards in China (there's the whole range of quality) - for drones DJI has been a reference for example.
But tech security is such an intangible thing that most of the population doesn't understand it.
And in all honesty it seems that there's no protocol, or standard procedure, or evaluation of tech goods that come to the market and must pass security testing.
For example, with GDPR, at least a framework came out for data protection and protocols were set in place. The adoption was and still is chaotic for a lot of organizations, and it has plenty of flaws - but it is indeed something that's working towards a goal.
So far, in terms of security, it's like there's nothing in place.
It's really not that different from the FUD about Kaspersky [1] or the still-ongoing saga of Huawei. In the past, such capability had to be deliberately planted at great effort, while these days we buy it voluntarily and spread it in our homes and businesses, fly them above our cities, and put them in networking closets to sit in the middle of all of our communication.
Sure it's FUD, but it's the government and military coming to terms with the implications of what just happened, and trying to shape the future to lessen a risk. This is orthogonal to whether they want the exact same capability for friendly-made goods, or whether there's any industry of comparable domestic goods left. Other countries, when they have a spare moment after dealing with domestic needs, are also well within their rights to feel the same kind of unease about Cisco, Juniper, Intel... hell, Tesla? Have you seen the number of cameras on that thing, and the fact that it can drive on its own?
This is the evolution of 'loose lips sink ships', where the capability of people to spread information has multiplied, but soon people won't even be necessary for information to be disclosed. Their consumer goods will do it for them.
It looks like the US technology is a national security risk for any other sovereign nation.
They're really beating the drum on China. Be intensely suspicious. China is a trading partner that does some shitty things (e.g. in Xinjiang province), but the nation focused on world domination is the one right here.
the US government could deploy an update to turn any phone into a spy device because both apple and Google are headquartered in the US
There is a lot of rebuilding the US has to do. First fix the politics which is rife with petty interests, lobbying, political imbalance very skewed towards corporations over citizens, extreme polarization, 2 party system, hypocrisy,etc..
But all that, with great effort, can be fixed. A purge is needed, not just try to shove the dirt under a carpet and pretend all is nice and dandy.
Once again, US has the ability to change, but it will take a lot of effort to do so and will have to start leading by example.
That's a great point. It's like the "credibility bubble" burst due to the increased inflow of information, and the public is correcting toward a more realistic valuation - which is to say, recognizing propaganda for what it is, and rightfully being critical of mass media.
I'm also seeing that there are massive investments being made to regain the trust bubble through social media. Historically, the public seems to have short-term memory though..
The problem, of course, is that runs afoul of US espionage and law enforcement demands that they have access to such data themselves.
They want it both ways in a world where you literally, cannot have it both ways. US cyber policy on this front has been a disaster.
Consumers can change a lightbulb and little else. Make it that simple.
I'm not sure they understand how bug bounties are supposed to work...
https://arstechnica.com/information-technology/2017/11/dji-l...
At the time Ronald Reagan and Margaret Thatcher were around and all of this was discussed. The predicted decline happened. There are capitalist rent seeker types that are okay with it, they also voted for the lunatic politicians. The people not so happy about it don't get to write for the capitalist newspapers giving the illusion to people with no skin in the game that 'nobody predicted this calamity'.
So predictions for forty years hence? It does not work like that, does it? Back in the 1980's you just knew that if manufacturing was gone that there would be no market for locally made goods, no possibility of exporting quality stuff on the world market and that we would not be able to drive prosperity on the back of financial services forever.
If you push someone over a cliff you are not sure whether they will break their neck, crack their head open or get impaled on a spike, all you know is that the outcome will not be a good one.
Right now we are using far too much in the way of fossil fuels, the climate is not right and it is getting worse. I don't know how ravaged the world will be in forty years hence, all I do know is that carrying on as we do is not a good idea.
So one problem I have with much analysis of Trump populism, is its failure to recognize that subcultures doing group-think, believe absurdities, and tolerating being lied to, are a broader problem, worthy of more fundamental analysis, and an opportunity for broader remediation.
You have to be kidding, no one is going to notice a white drone 3km[0] above them, if there even is anyone around to notice. Sure, a spy sat is better, but it's also orders of magnitude more expensive, can't loiter[1], and might still have inferior imaging. This is just embarrassing.
[0]: https://en.wikipedia.org/wiki/DJI_(company)#Phantom [1]: Spy satellites pretty much always orbit faster than the earth turns in order to have better coverage.
Source: I had a UAV related startup several years ago and got to know some of the security folks.
Oh, excellent, you are confirming that 'spying' issue is real and you seem to be the one who can give us some real insight - can you provide names of "the security folks", maybe some links to their research where we all could see proof for all these claims?
Apparently the army does have drones that are sufficiently american to be flown in restricted areas but my friend doesn't know who is making them or how a civilian like myself could acquire one.
I would like to get one for my biologist friend who would like to use it to detect invasive plant species.
[1] https://www.globenewswire.com/news-release/2019/05/28/185110...
I think that not only the Communist Party of China but all the political systems around the world have the ability to demand lawful access to information from virtually every company that is supposed to comply with their laws.
No, but the amount of suggestive "Might" "Could" etc titles/articles now out there shows a whole other picture. China is now the new enemy. And everybody must know apparently.
Even respectable news outlets can't resist the temptation of completely unfounded copying of the American media machine.
I'm not stating China is so innocent, but sorry there is only one country in the world systematically spying, bombing and manipulating friend AND enemies alike. And that's the USA.
So please, my dear Americans. Stop it yourself and we might lend you our ear again. Sincerely, a fellow world citizen, located in Europe.
*and Germany. Don’t forget, every U.S. (and Saudi) Abrams tank has a Rheinmetall cannon.
https://spiegel.de/international/germany/german-intelligence...
https://www.thelocal.de/20190311/germany-fourth-largest-expo...
https://www.euractiv.com/section/economy-jobs/news/germany-e...
However, trump saying that Huawei could be part of the trade deal means banning Chinese companies has nothing to do with security. The US didn’t go after Lenovo simply because assembling isn’t a high value add process and doesn’t threat US tech leadership. Huawei got banned because its tech is too advanced.