An overview of why the US has problems with Huawei
latimes.com
latimes.com
This report is why the US government is taking action against Huawei. In it, Huawei refuses to answer some key questions about the structure of their company that strongly indicates they are controlled by the CCP. So what did Huawei think was going to happen after that?
This comment misses the whole point entirely. Obviously this is not a simple issue about cultural differences. The key point is that a telecom company that is a major player in the telecom infrastructure busines and is desperately trying to control the world's telecom infrastructure is actually surreptitiously controlled by the Chinese government. This fact is not minor cultural nitpicking.
How hard is it to miss the huge red flag?
There's not evidence for that. It's a private company. It's not a state-owned enterprise, and doesn't function like one.
> This fact is not minor cultural nitpicking.
No, but it is part of a campaign to demonize China and Chinese companies. Many people in the US foreign policy establishment are worried about the existence of a peer-level competitor, and cannot accept that the US is no longer the sole superpower in the world. That's the fundamental issue here. It's why there's such a huge disconnect between all the fear about Huawei and the utter lack of evidence of backdoors in their equipment. This isn't about Huawei. It's about people in the US government trying to head off China as a competitor.
> Huawei’s failure to provide further detailed information explaining how it is formally regulated, controlled, or otherwise managed by the Chinese government undermines the company’s repeated assertions that it is not inappropriately influenced by the Chinese government.
In my book, that translates roughly to, "We have no evidence that Huawei is controlled by the Chinese state, but we're going to sow fear, uncertainty and doubt." That's typical of the US government's approach towards Huawei so far. They refuse to provide evidence of backdoors, but keep insisting they're there.
At this point, if there is evidence in the report, it would be easiest if you would to cite it.
Indeed. It is telling, however, that you keep saying the report is full of evidence on every page, but won't actually mention any piece of evidence. I find that very typical of the political campaign against Huawei in the US.
Again, you haven't provided any evidence, despite saying that there's evidence on every page of the report. That speaks for itself.
>There's not evidence for that. It's a private company. It's not a state-owned enterprise, and doesn't function like one.
What about the LA Times article?
>A study by professors Christopher Balding and Donald Clarke published April 17, 2019, argues Huawei is effectively state-owned because it is 99% owned by a "trade union committee." Trade unions in China are controlled by the government.
"China" views it that way. All 1.4 billion chinese do?
> The ecosystem is fundamentally different from in the US
This is simply not true. The history of US began as a government created to protect US business interests. The first major act of congress was a tariff to protect american companies. Every war we fought against the native americans, chinese, middle easterners, south americans, mexicans, etc were to further the interests of US companies. Whether you are talking about railroad companies in the 1800s or US oil companies in the 20th century. Maybe you might want to read up on where the term banana republics came from?
> and western observers dont seem to be aware of this.
Actually western observers are aware of it because it was the "west" which helped china industrialize. Do you want to know what country china modeled itself after to modernize its economy? The 1800s US. Which is the modeled followed by south korea, japan and taiwan as well.
Pretty much every major world economy works the same exact way - collusion between state + companies + military.
The only difference between US and china is that the US is the inheritor of the european colonial word order and hence is leading the "western/white" bloc. China has no bloc ( at least yet ) so is going alone at it.
The separation of companies, government and military is a western notion - one that no western power practices. Which wasn't lost on the chinese, south koreans, japanese, taiwanese, etc.
Alternatively, the primary difference between the USA and PRC is not that the US necessarily has more global influence, but that the PRC does not pretend to value the autonomy of its citizens.
I imagine is an American company can fight back in court thou we’ve seen stories about companies being unable to fight back or comply very willingly
Serious question
Eg. Solar power, steel, ... They used to take care for entire countries and they lost it all thanks to dumping prices.
Regarding 610, it might exist it might not. Supposedly operating as a “CIA within a CIA”, they are kind of like a Praetorian Guard that reports to the highest levels of the CCP.
Anyway Ren Zhengfei, the founder, is a former Army Colonel in the PLA. He was a specialist in comm systems, and was “laid off” in 1983. This was the same year the MSS was founded, which wound up kind of “stealing” all the intelligence work and signals stuff that had previously been the domain of the Army.
Later the MSS would find it much more advantageous to establish front companies, and it was this wave of front companies with unlimited black budget funding that began in mid 1990s that Ren rode all the way to the top.
FUN FACT: The Green Army, one of the original Chinese hacking groups from 1996-1997, eventually all of its first members came together and established Nsfocus.com which still exists today and is quite big.
Not that any of this really matters. So many parts of software are broken from a cybersecurity standpoint that it's more a matter of degree than secure versus not secure. I'm sure the Chinese are able to have open source contributors have their patches applied to Linux or Python with innocent bugs in them. Still though, network attacks break a lot of what keeps the internet secure, and I doubt the Americans are making it up when they say that Chinese manufactured network gear is a national security threat.
There are no US companies that compete with Huawei’s 5G technology, so my government is going after them anyway they can. Seems simple enough to me. That said, there is another factor: Huawei smartphones sort of compete with Apple gear, but at lower prices. This also helps a US company (Apple).
It think it is fairly common that governments do back-flips to help domestic industries. The Chinese government certainly helps their industries.
Although I suspect the US will discover their treatment of Meng Wanzhou is crossing a line. The idea that the US can regulate commerce between a Chinese company and an Iranian country is breathtakingly audacious and the idea that the US can go after individuals on this pretext is outrageous. If someone pulled this stunt on them and black-bagged Tim Cook for violating labour laws they might start to realise they've opened a can of worms.
I assume we both agree that fully open hardware and software is better here, but given that I guess it's just a matter of which country you're most okay with giving a backdoor into your private life.
I guess I still trust the US in this regard more than China, even with the NSA leaks. But I definitely think that if I was individually targeted they'd get whatever they want. Well, either country really.
It certainly has terrible optics - the US decides to bully a strategically threatening Chinese company with superior capability? That is likely to disrupt their extensive data gathering and surveillance operations? In the middle of trade talks? Whatever legal quibbling they want to argue over, it is a tough sell as a rules-based decision. It looks highly political.
[0] https://en.wikipedia.org/wiki/American_Service-Members'_Prot...
https://www.theverge.com/2019/4/30/18523701/huawei-vodafone-...
Was that disproven?
It was never proven to begin with. Like any good backdoor it "could simply have been a mistake" (deniability).
Vodafone, the company that Bloomberg claims was targeted by these backdoors, publicly contradicted Bloomberg. They pointed out that the diagnostic software did not allow unauthorized access:
> The 'backdoor' that Bloomberg refers to is Telnet, which is a protocol that is commonly used by many vendors in the industry for performing diagnostic functions. It would not have been accessible from the internet.
> Bloomberg is incorrect in saying that this 'could have given Huawei unauthorised access to the carrier's fixed-line network in Italy'.[1]
Huawei routers had Telnet installed on them, which is completely standard. Vodafone, the company that was supposedly targeted, disputed Bloomberg's characterization of standard diagnostic software as a "backdoor":
> The 'backdoor' that Bloomberg refers to is Telnet, which is a protocol that is commonly used by many vendors in the industry for performing diagnostic functions. It would not have been accessible from the internet.[1]
This is not the first time Bloomberg has made sensationalist claims about Chinese backdoors. This one fell apart with even the lightest of scrutiny. One wonders if the Bloomberg reporter even understood what Telnet is.
I think the EU is playing this very smart because Huawei would not open its tech to security inspections without some pressure.
Imagine if a US company was founded by ex-Military officers, stole tech from Chinese companies, and tried to build China's telecom backbone while accepting huge subsidies from the US government. No one would bat an eye if they passed on that deal.
It is the British Empire.
The Saudis wouldn't even be in power if it weren't for the British endorsing them after the First World War.
https://spartacus-educational.com/SPYbsc.htm
>Roald Dahl was assigned to work with Drew Pearson, one of America's most influential journalist as the time. "Dahl described his main function with BSC as that of trying to 'oil the wheels' that often ground imperfectly between the British and American war efforts. Much of this involved dealing with journalists, something at which he was already skilled. His chief contact was the mustachioed political gossip columnist Drew Pearson, whose column, Washington Merry-Go-Round, was widely regarded as the most important of its kind in the United States."
But it is the exact correct response to a statement that "X is uniquely bad". People like you forget this obvious distinction and just use it as a general insult to shut down conversation.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
When someone brings up information isn't in fact comparable or relevant, the reasonable thing to do is to explain why it isn't, and give the other person a chance to respond. It's natural for people to disagree about what's relevant in an argument—that's part of having a disagreement in the first place. Trying to close off discussion so only your side's examples count as admissible isn't good discourse. Being first to raise a topic doesn't confer power to control the conversation.
Perhaps the more helpful broader point, though, is that all these canned arguments are repetitive and therefore low-quality. They're like slapping a sticker on something rather than engaging with it. Because of that, they make threads worse and more predictable. People tend to respond badly and strike back, rather than continuing in good faith—and it's easy to see why, because labels like "whataboutism" express dismissiveness.
And here is a video of our CEO talking more about it: https://finitestate.io/2019/10/03/security-weekly-podcast
I read the report itself:
- Devices came with a default username/password. Called a "backdoor."
- Devices used password auth instead of public key cryptography for SSH out of the box. Called a "backdoor."
- Default public key cryptography keys for SSH auth instead of password. Called a "backdoor."
- Devices contained public certificate authorities. Called a "man in them middle."
- Devices contained well known vulnerabilities in common open source software.
If I had paid Finite State for this report, I'd fire them on the spot and blacklist them. I particularly love the Schrödinger's cat of public key SSH auth. If the vendor doesn't enable it by default it is a "backdoor" and if they do it is "hard-coded certificates" and thus a "backdoor."
According to Finite State's logic I've never used a vendor that didn't contain multiple "backdoors." Particularly as doing so is impossible (since you need to enable public certificate SSH auth AND not provide users any way of actually using it).
The thing that surprises me is that they found "backdoors" in only 55% of devices? Shouldn't it be 100%, or did you feel like misleading that much was too unbelievable (and people might e.g. read the report and call you out)?
PS - No conflicts or stakes here (don't even run Huawei's stuff that I know of). Just decided to read the report because of the extraordinary claims made, found out there was nothing there.
Whoever paid Finite State for that report presumably was happy with the outcome that was arranged for them. Alternatively, they could have written the report on their own in order to drum up business and "reputation" in the cybersecurity industry.
And even if it's documented, although it's not a backdoor, it's still generally bad for security. Any device with non-unique default passwords or default keypairs will generally have hackers scanning the internet to compromise them. The keypair should be randomly generated on first use. The device should prompt for what password to use on first use.
Wouldn't surprise me if this newfound paranoia leads to a golden age for cybersecurity, and a wave of new best practices.
I'd be shocked if this happened. This requires politicians to both care about and understand cybersecurity enough to enforce it, and for there to be no opportunists looking to cash in on the ignorance of policy makers.
People demanded more security after 9/11. We got the Patriot Act and the TSA, so the government spies on its own people and an agency that has proven 95% (!!!) of the time to fail to detect a weapon.
https://onemileatatime.com/tsa-fails-tests-95-percent/
Ronald Reagon declared a war on drugs - I've already made this comment too political so I won't delve into that.
For anything complicated enough the general public cannot easily understand it, there is no incentive for politicians to actually care about it. They can just give it lip service with a few talking points and then never actually do anything actionable.
> Safe: memset_s
Yeah, if you’re just counting up occurrences then this is a stupid comparison.
That's perfectly believable. I, myself, am compelled to fiddle about with other people's technology.