Of course we have a lot of new judges so who knows.
Of course we have a lot of new judges so who knows.
I have met Bunnie, and he has a bit of a warped view of the world. I think it caused him to gloss over things like https://www.theregister.co.uk/2019/03/28/hcsec_huawei_oversi... where Huawei did not give a single shit about security in their cellular basestation codebase.
Sure, Huawei will read CVEs and sometimes deal with them, but really basic things like updating OpenSSL libraries seem near impossible for Huawei. Their hardware is thus vulnerable to exploitation by any ill intentioned person wandering by :c
Part of this is the whole stolen codebase problem, where Huawei (as Nortel's Chinese manufacturing partner) took their designs and code, without fully understanding them. They've been able to tack on a lot of neat stuff, but the underlying architecture is still not understood by their engineers.
The Huawei ban is very clearly a political anti-China move, not one based on technical reasons.
This is an anti-China move, but we do know Huawei builds vulnerable LTE basestations and products, and refuses to do the bare minimum to secure them, despite promising $20 billion in investment in software security (see the article I linked to earlier).
Samsung was embroiled in a very bitter IP dispute with Apple, in which it was found to have violated Apple's patents, essentially copying the design of the iPhone, and ordered to pay over a half a billion dollars.
Yet American companies aren't banned from doing business with Samsung, nor should they be.
I don't know Bunnie and I only follow his blog posts sometimes but he's a strong proponent of open source software and open source hardware [1]. Bunnie is helping to develop a fully open source hardware laptop, Novena [2], that requires companies providing components to not require non disclosure agreements [3]. Bunnie is also specifically interested in FPGAs and making them and their toolschains available [4].
Your post seems like it has a veiled nationalistic and anti-open source undercurrent. Is Bunnies silence on the matter of the Huawei security issue reason for you to have this view? If so, do others not mentioning Intel's vulnerabilities [5] the past years also mean they have the same "warped view of the world".
To be clear, I'm not trying to absolve Huawei or Intel of anything. I'm trying to address the claim that Bunnie turns a blind eye to proprietary chipset and hardware technology more than others.
[1] https://www.eff.org/press/releases/hardware-hacker-anti-acta...
[2] https://www.bunniestudios.com/blog/?cat=28
[3] https://en.wikipedia.org/wiki/Andrew_Huang_(hacker)#Novena
> Huawei (...) took their designs and code, without fully understanding them.
Do you want to say that there aren't people in China smart enough to "update OpenSSL" in their codebase? Whichever way the codebase started to be used by the company?
A lot of companies and developers inherit the products created in some other times in some other companies and generally are able to update them.
It is rotten corporate culture that is starving critical maintenance work at these companies, creating the internet of vulnerable shit.