US says it can prove Huawei has backdoor access to mobile-phone networks
arstechnica.com
arstechnica.com
I love this quote. The US is essentially complaining that Huawei has access to the backdoor channels that only the US government was supposed to have.
How is surprising? The defining characteristic of a nation state is that it has a monopoly on violence within its borders. Having a monopoly on intercepting telecom traffic is a logical consequence of that. For other countries though, yeah I'd prefer if neither China nor US have backdoor access.
So would I, but having lived in both countries, one of the two governments is decidedly more evil than the other.
Can you support this assertion?
https://www.justice.gov/usao-edny/pr/nine-fifa-officials-and...
To quote a Chinese citizen: “Give us a baby and we’ll let you go.”
https://www.hrw.org/report/2019/03/21/give-us-baby-and-well-...
China does not respect the sovereignty of other nations, nor the rule of law. They are not above intimidating, blackmailing, or otherwise exerting their influence on foreign nationals on foreign soil when their views become too politically inconvenient.
Those residing and holding citizenship abroad but that have family back in China (which are many) have proven especially vulnenable.
Stories of China arresting foreign citizens for activities abroad and never allowing consular access, funding and manipulating groups in foreign countries (especially on university campuses) and then directing them to silence others, and more are a dime a dozen.
While the US's hands are quite dirty here as well, China has shown repeatedly that given the opportunity they are more than willing to try and implement the kind of oppression and thought policing they have at home in places abroad. It is more dangerous for the entire world to have China spying on them than it is the US.
How is China worse than the USA? Your claim seems to rest entirely on greater reporting of China’s aggressions by the US and their allies.
Do you think the US is harvesting organs?
However I am truly afraid of the way Xi has enacted its horror policies in China.
The US routinely massacres innocents in foreign countries then retroactively declares all the victims “terrorists”. China — to my knowledge — doesn’t engage in anywhere near the level of military aggression that the USA does.
When you compare the number of organ harvest victims to the number of “terrorists” slaughtered by incorrectly targeted missiles, who comes out ahead in the ethics game?
Do you think killing people for the sake of imaginary goals is better or worse than killing people to harvest organs?
Acknowledged this already.
The policies the US is trying to enforce with these measures are less bad for most of the Western world than those that China is. That's it.
While the US has taken quite a slide on freedoms over the past couple decades, they're still nowhere near China's level and I find it pretty laughable to even try and put them on the same playing field in that regard.
The ideal would be to use open-source hardware and e2e encryption, but if this is not possible I would suggest these scared of the US to use Chinese phones and these scares of China to use US phones.
China has historically not engaged in violence far from its borders. America frequently does.
unless you are under 25 or deeply religious, I'd suggest to think twice before using 'evil' on subjects of international politics.
Was George Bush Jnr performing the actions of an evil man? Discuss.
So if I had to choose I would prefer china over the NSA, Of course neither is the best option but .....
if I lived in China the inverse would be true
If they have access to an enormous volume of potential blackmail or datamining, you think they won't use that against us for political gains? They could blackmail a programmer to insert a subtle vulnerability into a piece of code by threatening to expose his extramarital affair, or threatening to tell his employer/family/friends what kind of porn he watches. Or they could easily datamine and target those with monetary issues to see who is vulnerable to a bribe. Or they could threaten to frame you for child porn using their backdoor access.
This is from a government that isn't afraid to 'disappear' political dissidents, send people to "re-education" camps, harvest organs from their own people. You think they're going to be friendlier to American citizens?
Yes, because American citizens are none of their business. Law enforcement and prosecution on the other hand is very interested.
China, and the US for that matter, will generally do what they think they can get away with to further their interests. Regardless of a bunch of imaginary lines drawn on a map.
Now let's imagine I am an American citizen/businessman competing with a Chinese businessman. I have a better product, better networks. Let's also imagine the scenario where the Chinese govt has more power and dominance than anybody else in the world. Do you still think an American citizen is none of their business?
How about if an American citizen happens to write an article criticizing Chinese govt? What would happen in the above scenario?
Not to lambast china while excusing the US Government that requires that type of spying by law.
Do you believe that the US Government is above " blackmail or data mining" or "won't use that against us for political gains", both of which has been proven to be true
Everyone is Soo fucking afraid of foreign influence on our politics they ignore the domestic influence of the same nature.
Personally I believe the NSA and CIA to be more dangerous to our liberties than China or Russia.
As Lincoln said many many moons ago, If we lose our freedoms it will because we destroyed ourselves
As far as the tech companies / Hollywood censoring because of china, for the product in china sure but they censor their products here because they want to, china is just a convenient excuse that naive people believe. It is a way to shit shift the blame "no no we did not want to, big bad china made us" bullshit
So long as those steps are designated as a "free speech zone".
People always seem to forget, all government actions and regulations no matter how small are acts of violence. They are not voluntary and are backed by the threat of legal violence to anyone that dare resist.
Pedantry FYI, that’s just a state. The term “nation” has more to do with distinct communities and culture. And so a “nation state” is when those overlap.
Furthermore, since a nation is a group of people bound together by shared culture, values, religion, language, etc., while a state is a piece of land with a defined border, then nations and states are not necessarily the same thing.
A "nation-state" is the intersection of the two, where cultural boundaries align with political and geographical boundaries, and not a redundant synonym of "state".
That seem like a good reasons for people within US borders to prefer to be spied on by the Chinese government rather than the US government and for people within Chinese borders to prefer to be spied on by the US government rather than the Chinese government.
If I have to be spied on, I will choose whoever is less likely to subject me to violence.
The theory behind the lawful intercept concept is that with the appropriate legal authorization a law enforcement agency can get a capture of a subscribers traffic in a somewhat standard format - that way the LEA doesn't have to have a different way to process the data from each network equipment vendor.
Here is a description of how the feature is commonly implemented: https://en.wikipedia.org/wiki/Lawful_interception https://www.arubanetworks.com/techdocs/Instant_40_Mobile/Adv... https://www.cisco.com/c/en/us/td/docs/routers/10000/10008/fe...
There's a huge difference between a documented authorised-only interface and an undocumented backdoor.
Let China keep the nsa out of their networks and we’ll keep China out of ours.
I found something strange that affects SMS in Canada. You can send the lower case text "secure communication", but it will never be recieved by the recipient. I am not sure if this behavior is reproducible outside of Canada. It might be a software defect, or perhaps there is something capturing the text and trying to interpret it as a command. The issue is more difficult to reproduce if both the sender and recipient devices are iphone's due to the default behavior of sending via iText.
I originally posted about this late last year [1]. I intend to investigate this issue more deeply, but my time has been consumed by another more pressing matter. The original HN post links to my blog post [2]. Originally I jumped to the conclusion that it was a case of censorship, but I backtracked on that because the issue is case sensitive. I would love confirmation if this is reproducible in other countries.
[1] https://news.ycombinator.com/item?id=21593276
[2] https://bloggerbust.ca/post/text-messages-are-being-censored...
I can't verify it is send over SMS or MMS though. In theory there's no reason for my cellphone to send it over MMS.
The exact word used: secure communication
The Google Android client is nice because it displays what protocol it is sending over. It is important to confirm that it is sent over SMS. Also, it is important that the words "secure communication" are sent in all lower case which I see that you did.
Thank you for taking the time to test this. If you are sure it is being sent over SMS then I will add your entry as an example where it can be both sent and received
"secure communication"
from within the twilio API, via pure SMS (no imessage, etc.) to an iphone SE with a US Mobile (verizon MVNO) sim card.
Was sent from a US number to a US number.
No issues.
I did it from my S10 to someone else A8.
Consider the other cases - it could be something like an anti-spam system; back when MSN Messenger was a thing, it would abruptly close any conversations in which certain virus-related keywords were said (mostly including ".exe", which is how I discovered it), presumably in an attempt to stop them spreading.
Or it could be a bug - there have been plenty of these, from simple strings causing mass IRC disconnections, to eerie conspiracy theories (see "bush hid the facts"[0], a conspiracy caused by a bug in Notepad).
Or it could just be a bit of debug code accidentally being triggered. This past week, I had to explain to some users why a website was talking about "DEAD BEEF". The reason was innocent (glitch in a web server config), but to the end user it was incomprehensible.
All that said, if you want to investigate further, it's simple to disable iMessage on iOS devices. If you go to Settings->Messages, there's a toggle for it.
Thanks for pointing out an easy way to disable imessage on iphone. Apparently after doing that iphone defaults to MMS. It still might be best to just turn off data and wifi.
On MSN Messenger, one way around swear words in your username/status was to use the ASCII equivalent for a letter, which would get skip the filter but render as the letter.
So I looked a little down in my chart and hoped that 0x7 for BELL would do something, but it didn’t.
But 0x0 for NULL would cause all members of your contact list to immediately sign out and back in ad Infinitum.
Super busy now for a while...
[1] https://bloggerbust.ca/post/text-messages-are-being-censored...
Also seems to not deliver SMSs that contain other combinations with 'secure communication' within it.
E.g.
'Hahahaha juice secure communication james'
or
'Not secure communication'
Having said that, this is not working for everyone. I am trying to gather data on this to figure out where the issue might stem from. Would you be comfortable disclosing the make/model and carrier service of the sender and receiver. If you would prefer, you may contact me directly with this information and I won't include your identity in the record. My email is linked in the header of the blog post. I also have a public key [2] if you feel so inclined to send me a secure communication :-P
[0] https://bloggerbust.ca/post/text-messages-are-being-censored...
from: Freedom Mobile to: Freedom Mobile Location: Ontario
Mobile data: off Wifi: off
Side note: So cool to see so many Canadians on here! If requested I can send SMS to USA numbers.
Yes please! Also, if you have US contacts that would be willing to test US-->US and US-->Canada that information would also be valuable and appreciated.
Please include as much of this information as participants are willing to provide:
- OS+version of mobile device
- if WiFi / data was on or off
- Carrier of sender / receiver
- region
- exact text sentThis reminds me of how, until just a few years ago (as late as 2016), people were wondering why you couldn't tweet the phrase "Get better".
It turned out that you can't tweet any phrase that begins with "Get" because... you guessed it, posting tweets from the web interface still shared backend code with the SMS-based system[0]. So it would interpret "Get foo" as an API request to fetch tweets, not a tweet itself.
[0] Twitter was originally designed to work on dumbphones! You could text your tweet to 40404 and it would post for you, or you could fetch tweets by saying "GET chimeracoder" and it would fetch the latest tweets from user @chimeracoder.
I could get it to deliver US to US, though.
These are common problems for those that try to go “data-only” and sign up for a virtual SMS service: they can’t receive 2FA SMSs.
I guess the positive is that it’s hard(er) for a bad actor to pretend to be bigger than they are.
Messages containing "secure communication" failed when sent by SMS.
Both are iPhones, but one phone had wifi and cellular data disabled to force the SMS failover.
A bit of a tangent but ...
How I hate this term "lawful purposes". It's a non-sequitor / dark pattern deployed to confuse consumers into not understanding that they mean "spy on you". "Lawful" just means compliant with the law. In other words, they are are NOT saying "necessary to enforce the law" which is what they want you to think. They are only saying, hey, we won't break the law when we use this feature, aren't we great? Like breaking the law would ever be OK and as if this disclaimer somehow adds any sort of reassurance. The implied logic is "normally we would just break the law to access your data but in this special case we'll follow it.
/tangent
(This argument hinges on that pesky word “necessary”. But it’s worth thinking about which conditions you’d be ok with the state surveilling others, and who exactly “others” refers to.)
Historically, people of color and political dissidents.
I know it will not affect me and people like me, because implemented rules will ensure that.
My parents lived in a society you seem to yearn for. Hard pass.
However that's exactly why I think they should not use deceptive language to confuse people. People need to understand exactly what is being done to have trust in it and to debate it so they can form reasonable opinions - not be deceived into thinking one thing is happening when actually something much more intrusive is going on.
Joking, but I honestly wonder- If the software is compiled in California... and the hardware is made in China. You could have two implants in the same gear. Now that's Thinking Green! Twice the government implants in one product.
Violence tends to be the way nations define rules outside their own borders.
1: https://en.wikipedia.org/wiki/Communications_Assistance_for_...
So yes, any intervention like that seems to me to be less about "the Chinese can snoop" and more about "we can't".
I'm going to assume that you probably update your server's SSHd at least semi-regularly and that if SSH turns out to be broken 20 years down the line, you will probably be switching to something better either manually or when you eventually replace your hardware and reinstall the OS.
This kind of infrastructure is meant to last for decades. Imagine if the original GSM contained a backdoor with the state-of-the-art crypto of the time. Would it still hold up today? Hell, you don't have to imagine - a mid-range smartphone these days can crack a lot of GSM traffic.
Besides that, there's also the problem that not only are these things usually not done with state-of-the-art tech, but leaks happen all the time and it only takes one mistake* for the privkeys to become known.
Okay, let's say the telecom equipment doesn't have a backdoor for lawful intercept. What happens if the telecom is served with a warrant? Are you expecting that the telecoms will refuse to cooperate with the authorities?
Actually, backdoors could be implemented to require a cryptographically signed warrant. Think e.g. lawful intercept on mobile network routers, US (or any other nation's) law could just add this as a requirement. You could even develop a complicated scheme to apply this to E2E crypto.
But of course skewing the RNG to be predictable, or implanting some hardware backdoor, is much easier and has the added bonus of being usable to spy not only on your own citizens, but also on other nations.
Nobody that matters needs to be convinced of the value 'back doors'. Only a minority of the American public and privacy types are very concerned.
Certainly the other government agencies i.e. UK/Germany would take it as a given in terms of 'why' such back doors are there.
There's a reference above to the WaPo article yesterday revealing the longest-running and best surveillance program by the US. It was run out of Germany. The Germans were wary of using it too broadly, but they were otherwise fully behind it, and their intel agencies balked at closing it down.
It's not really even very political: certainly, Democrats would be 'mostly' onboard - there isn't really much of a political base against it other than perhaps the Libertarian crowd.
I should add, some major US industrialists like Apple and Google probably do care a lot, and they do matter and do have influence. But probably not enough.
So while many of us may disagree, it's not at the end of the day as controversial as we may think it is.
To catch bad guys and protect the children.
>“request relevant organs, organisations, and citizens provide necessary support, assistance, and cooperation”. According to Article 16, intelligence officials “may enter relevant restricted areas and venues; may learn from and question relevant institutions, organisations, and individuals; and may read or collect relevant files, materials or items”
https://www.canada.ca/en/security-intelligence-service/corpo...
Anyway, there is a new bill trying to kill e2ee in America https://news.ycombinator.com/item?id=22202110
There are some specific carve-outs for telecom companies that their networks must have the ability to tap into specific traffic when a government agency comes knocking with a warrant.
But, as you point out, backdoor-free e2e encryption is not yet illegal, and the US gov't can't force e.g. Apple to put a backdoor in iMessage or in iOS's device encryption.
I expect that this is not the case in China; if the CCP tells a company to do something, anything, to allow them to spy on their users, they do it, or they get destroyed.
Bills like the EARN IT Act scare the hell out of me, but at least there's a process by which it becomes law, and we can affect that process and (hopefully) kill it. That's just not possible in China.
In theory, in the same sense that one could influence what CCP does by becoming a member of it and rising through the ranks.
China risks one of their largest companies, knowing they will eventually get caught, over one department in the US just puts out a statement they are 'spying' and everyone believes it without proof.
We don't actually live in a Hollywood movie.
"US officials said they have been aware of Huawei's backdoor access "since observing it in 2009 in early 4G equipment," the Journal wrote."
So the USA admits it's allowed all these counties, many allies, be spied on? Really? We are excepted to believe that?
I'm sure there's a technical 'thing' here. But whether they have fked up on the USA side or the Chine side we can only know from the US actually saying what this is. But then the US might lose it's 'Huawei is spying' attack on Chinese commerce.
Edit: a word
[1] https://www.militarytimes.com/flashpoints/2020/01/23/deploye...
It's probably secure against phone company snooping. But I wouldn't trust it much past that.
I haven't gotten around to using Wire. But when I've needed secure, private, and semianonymous messaging, I've used Tox.
My hope is to be able to add ephemeral user ids so to my work folks I'm JustMe but family folks I'm FamilyMe and internet blog readers I'm MyProfessionalMe
I'd certainly pay a 20% premium on my hardware for verifiable protection from phone-home. I'd probably pay that premium for the manufacturer to claim that the device doesn't phone home.
Obv different situation for infrastructure hardware where the end-user (me) isn't the same as the buyer (german telecoms, apparently). But I suspect some of the verification / testing tools will be similar.
I'm happy these topics are getting press, whoever the players are.
If you had to assume that U.S. 5G equipment manufacturers would provide backdoors to U.S. officials, and Chinese 5G equipment manufacturers would provide backdoors to Chinese officials, and Europeans had to use one or the other, which would you choose?
For one thing, Swedes are less and less excited by the stream of Middle Eastern migrants caused by American adventures there.
Also, probably the point of whatever the fuck Russia is doing with the EAEU (really should've picked a better name if they want it to stick).
No one wants our specific dental bills, mortgages or tax returns, but governments and corporations love mass statistics.
FVEY exists so that the UK or Canada can legally spy on my communications and turn that data over to my government - which couldn’t otherwise get it without warrants and other pesky civil rights protections.
I think I’d rather take my chances with an adversarial government. I know they’d be spying but their ability to act on it is far more limited.
Now, it may be fair to argue that the information collected from a 5G radio doesn’t mean much at all to my government. But I’d still rather depend on defense in depth.
1: https://dodsioo.defense.gov/Portals/46/DoDM%20%205240.01.pdf...
2: https://www.archives.gov/federal-register/codification/execu...
How well do you think the FISA warrant process is going in reality?
If we're still comparing the US and China, I'd say it's working a great deal better than whatever system is currently (not) protecting Uighurs from systematic unjust search and seizure.
Moreover, there's much more than anecdotal evidence. The recently-released report on the Trump investigation proves this. Even if you hate Trump, there's no getting around the fact that the FBI completely abused the FISA court system, getting warrants by lying and misleading the court. This is a systemic problem.
Today in America it is de facto legal for law enforcement to do this stuff. The fact that a piece of paper somewhere might say otherwise has no bearing on what's actually happening.
https://www.computerworld.com/article/3124641/cops-run-unaut...
> The act imposes some new limits on the bulk collection of telecommunication metadata on U.S. citizens by American intelligence agencies
https://en.wikipedia.org/wiki/USA_Freedom_Act
And shortly thereafter:
> The National Security Agency (NSA) has formally recommended that the White House drop the phone surveillance program that collects information about millions of US phone calls and text messages. The Wall Street Journal reports that people familiar with the matter say the logistical and legal burdens of maintaining the program outweigh any intelligence benefits it brings.
https://www.engadget.com/2019/04/25/nsa-drop-massive-phone-s...
Sure, the US isn't perfect.
But I'm still very certain that I trust China's approach to data privacy a little less, since they currently do all of the following to happen, without suspicion of a crime:
* mass collection of blood and hair DNA samples for citizens living in minority regions
* literal government occupation of people's homes to take photos and collect information
* installing government cameras inside of peoples homes
* using that information to track, detain, and send ~1 million minorities to re-education camps without being charged or accused of a crime... where they are subjected to forced sterilization and torture.
https://www.hrw.org/news/2018/05/13/china-visiting-officials...
https://www.nytimes.com/2018/09/08/world/asia/china-uighur-m...
https://www.rfa.org/english/news/uyghur/abuse-10302019142433...
The institutional attitudes to privacy are simply not comparable to the US. US authorities are not nonchalant enough about privacy that they think anything close to that that is remotely acceptable in the US.
This isn't actually what's at issue here. The existence of law enforcement databases is a very different thing than the facility for spying on communications. And I still see no evidence that anyone has been punished for that, or that any active measures have been taken to protect abuses of those programs.
However, if this intercontinental extortion were so common, I suspect we would have heard of a single case by now.
https://www.theguardian.com/world/2020/jan/21/revealed-the-s...
But here's the thing: with the platonic ideal of "civil liberties" in mind that might bother me, but practically speaking? Chinese legal protections or threats have no bearing on me. None whatsoever.
I don't have a secret clearance. I don't know anyone who does. I don't know anything of significant value to the Chinese state that they couldn't use their existing sources to steal. My "deepest darkest secrets", at worst, would get me in trouble with my local government. They're not enough of a lever to make me an agent of China.
If, however, the information that could get me in trouble with my local government made it to my local government? That might be more of a concern for me.
Do you see why I might not care in the slightest what China knows about me, while simultaneously caring a great deal what my local government knows?
There will also be effects on your peers, neighbors, and society around you. There are nation-state actors currently using stolen data for blackmail, extortion, and propaganda campaigns, to influence the economic and political stability of other nations.
Whether or not you are a direct target, you will be affected in some way. While you feel much more closely connected to your local government, they are not generally acting out of malice.
The intent of my government or of a foreign government has almost zero bearing on my life, for the life of any other average American – someone who does not have a secret clearance, is not committing major felonies, etc.
What matters is material condition, and the ability of that government to project force and change a person’s material condition.
If Chinese intelligence knows who my weed dealer is, or that I on occasion drive my car faster than the posted speed limit, agents of the MSS aren’t going to tail my car and pull me over. If proof that I’m pirating DVDs hits the great firewall I’m not going to get an email threatening me with legal action.
I don’t care if my government really thinks that weed purchases should be illegal or that driving 5 over the speed limit is a societal crisis or that pirating DVDs is a moral wrong: I care that they can project force against me and impact my life.
I'm sure you can concede that it will, however, be used against organizations, institutions, and people who are important.
Some of those will directly impact your life. This isn't a new idea, the power of both espionage and propaganda are well studied and long established to be effective.
For example:
https://www.nbcnews.com/news/world/russian-documents-reveal-...
https://www.reuters.com/article/us-dea-sod/exclusive-u-s-dir...
>Opium profits funded many leading Boston institutions. Thomas Perkins and a brother helped found Massachusetts General Hospital, left, and Perkins donated one of his homes for a new school that ...
https://www.wbur.org/commonhealth/2017/07/31/opium-boston-hi...
Yet.
The PRC has been internationally relevant for a few decades. The US has been internationally relevant practically since its founding.
And for whatever reason, people don't think the PRC has continuity with pre-Mao China -- which has been internationally relevant since long before the US existed, and which doesn't have a very nice track record.
Who Was Sun Tzu’s Napoleon? https://news.ycombinator.com/item?id=22296312
>Millennia later, during the Second World War, Mao Zedong seized on this historical vignette to announce that the Chinese Communist forces would not abide by any political, military, or moral limitations in its fight against the Japanese, stating: “We are not Duke Xiang of Song and have no use for his asinine ethics.”
As an American, I choose European / EU 5G equipment in all scenarios over Chinese 5G equipment. I don't care what the cost is.
Europe, broadly (other than Russia primarily), is aligned with the US in all the ways that matter and will continue to be. China is not in almost any regard. The sole things the US and China have in common is trade and that the next century will be defined by persistent US-China superpower tension all around the world and in most all respects.
Geopolitics is much less unpredictable than "the future." Even the current administration is not so short-sighted to alienate the US to the point of having no powerful allies. If Europe is not considered an ally (it is, not "more or less," it 100% is), where would the US turn? Even if you take a scenario where Trump and Russia are allies, and the US positions itself closer to Russia, Russia's allies are anathema to US interests and ideals, and will be for the foreseeable future.
I just can't see any reality outside of borderline sci-fi where the US is not a close ally to just about every Western European country.
Some European agencies want the US government to spy on European citizens because it is illegal for them to do it themselves but it's not illegal for them to obtain information about European citizens from US spies. Whether the European citizens want to be spied on is another matter.
If you're a European citizen or company you might well prefer to be spied on by the Chinese because there's little danger of the Chinese getting you kidnapped/extradited. Also, if your competitors and business contacts are more US than Chinese then the possibility of Chinese commercial espionage is perhaps less worrying than the possibility of US commercial espionage. It seems likely that US agencies sometimes provide information to Boeing to help them compete against Airbus, for example. I'm thinking more of contract negotiations than technological secrets, of course.
Getting equipment from several suppliers seems like the best plan, generally. You can then play them off against each other not just for price but also for openness and forcing the supplier to allow security audits. I've heard that Huawei has been very helpful in that respect, because of the pressure they're under.
I've always wondered how that works so that employees dont know about the gov involvement. I suppose they could hire a "consultant", but someone in the company still needs to know dont they?
Bingo, data sharing agreements between intelligence services.
NSA can't spy on US citizens but GCHQ can, and GCHQ can't spy ok UK citizens but NSA can.
Then just come up with a sharing agreement, and you're "golden".
It's all ridiculous.
There's no point choosing a Chinese back door over an American one if people you talk to are going to entrust your private messages to gmail/ icloud/ aws/ backblaze/ whatsapp.
The major and decisive difference between USA and China is not what they have done, are doing or might do. It is simply that the USA is a democracy and China is not.
In the USA, most of the people in positions of power /have to leave that position/ and /can't do whatever they want/ even when they have it.
That fact alone makes all the difference and is so substantial that it in my mind totally invalidates any whataboutism in this question and any other comparison between the USA and any dictatorship.
Even if a democracy happens to do more evil things in a period of time than a dictatorship, they are the better choice simply because they are a democracy and thus enables the people to both protest and also actually end the evil, through the legal system in the nation. (This does not mean that evil actions are OK when democracies are guilty of them of course, I'm not saying that.)
If and when the day comes that China has had at least two transfers of power to new leaders as a result of internationally observed and validated democratic elections by the people of China, then it would be something to think about. But not as of now.
Based on the premise that I have to choose a spying nation, of course, which I'd rather not do in real life! :)
If they reveal the backdoor and Huawei closes or replaces it, they'll be locked out
Will somebody with access to WSJ please corroborate this quote in OP which is attributed to WSJ?
> Telecom-equipment makers who sell products to carriers "are required by law to build into their hardware ways for authorities to access the networks for lawful purposes," but they "are also required to build equipment in such a way that the manufacturer can't get access without the consent of the network operator," the Journal wrote.
Most of your infrastructure has multiple interfaces. Bearer. OAM, Backup, etc.
If your vulnerability scanning program only scans Bearer interfaces, you are fucking up. You can spin up vulnerable services on only one interface. If you don't scan ALL interfaces, you don't know all your entry points.
If you work for an MNO and are reading this, you should take action after reading this content.
How the CIA used Crypto AG encryption devices to spy on countries for decades
You had to initiate some specific knock sequence to trigger it.
Did they find something like this in their source code?
RDG is the author of masscan
https://blog.erratasec.com/2014/03/we-may-have-witnessed-nsa...
tl;dr they watched someone login with a huawei tech support account from mainland china.
They might be right about Huawei or they might not, either way saying "we totally have proof!" without providing proof is effectively meaningless.
If they haven't done it, it means: a) there isn't any backdoor, or b) exposing their backdoors would expose their own backdoors.
I'm betting on b.
d. Admitting how they found the backdoor would reveal other issues (a source in the pipeline, or their own backdoor in something Huawei made use of).
And probably e-z too.
- Revealing how the backdoor works would show methods the US agencies are also using.
- There are multiple backdoors, or there might be, and they don't want to tip their hand.
A) They did show 'proof' ostensibly, to the specific agencies of interest i.e. UK/Germany.
B) Your 'a' and 'b' are missing the most important point, in that the revelation of their knowledge may compromise some ongoing intelligence program. The information may very well have been provided by spies who'd be put at risk.
Literally yesterday WaPo published a story on the most comprehensive US intelligence program ever and it quite nicely illustrated the challenges of how to reveal how much you know, and the consequences therein.
This is not 'open source land' where we like complete transparency, it's a different game.
C) There's also another issue, and that this may not be 'black and white'. For example, the ostensible 'back door' may not be clear cut: it may be that it doesn't yet exist, but there are elements in the design prepared for backdoors to be very easily added at a later date.
Could you (or anyone) link a source where the NSA, or other USA agencies discuss this with technical detail?
They've provided ostensible 'proof' to the authorities in Germany and the UK who are the entities they are trying to convince of the issue, which is reasonable.
We'll have to wait to see how the Europeans respond.
In any case, my point is not that they aren't plausible reasons why they might not make any proof public. My point is that they aren't above using those plausible reasons to propagate disinformation. So their statements are meaningless to us (the public) because it's impossible to discern truth from lies without further information.
The British badly need to negotiate pst-Brexit trade deals with all major powers. Pissing off the CCP before the negotiations won’t help the UK’s plans.
Like 'you know how your mobile phone system works quite well, let us help ruin that for you by messing with it politically', great.
This might be wrong in a couple of ways.
First - without knowing any details, there certainly are many good reasons why the information might not made public, most obviously because it would possibly compromise their methods of acquiring such information. There's a 100% chance that any information they divulged will be acrimoniously parsed by the Chinese to determine the means by which the US obtained the information. The information will likely betray how the Americans are thinking about the problem as well. (Reference yesterday's WaPo article on US/Germany surveillance program and how it was compromised).
Second - there's very limited upside in making the information public, are many downsides. The US, UK, and German agencies don't care about you, or I or any other privacy advocate, or really the knowledge that might arise from a number of public voices piping in. This isn't like open-source SSL software, where it makes sense from a security perspective to be open about it.
Also, I'm doubtful if the 'evidence' the US presented is purely technical in nature. My guess is that this is not a situation of "hey, look at this source code, on like 501, there you go, back door!", it's probably much more complicated. If you read the article, you'll indicate that the US has evidence that China is using its gear to surveil state actors, etc..
Revealing the 'evidence' almost surely involves sensitive information regarding state officials from other countries, insight into US spy programs etc..
If the US is legitimately trying to convince UK/Germany that Huawei gear is a legit threat, then providing them with the necessary information in confidence is obviously the rational thing to do.
I had totally thought after Apple and Microsoft were caught working on PRISM Americans and corporations would be doing drastic steps to avoid their communication being intercepted.
But for some reason that never happened.
In other words, do they just want to intercept calls, or steal customer information, or crash the network?
“Trust us” is no longer something we can blindly accept.