However, as a citizen and resident of America I'd rather be spied on by China, because it's a lot easier for my own government to make trouble for me.
The values of the regimes in control are transient and ever changing. You might be okay with it right now - but maybe not in the near future.
There is no real way around the fact that national intelligence agencies need to conduct mass surveillance of various kinds. National intelligence is a competitive zero sum game, and if we don't do it, others will, and we'll be at a disadvantage.
The same is not true for policing, however. The real danger to citizen rights is when the crossover happens. I'm not worried when the CIA spies on me - i'm worried when the FBI does. I'm worried when the tools of international intelligence get turned to more mundane matters. And I think that is the transition that we have to fight tooth and nail. Fighting the "don't spy on me NSA" battle was lost decades ago, and you were never going to win anyway in any material way. Because even if you could stop the NSA from doing it, every other government in the world would be doing it.
What we need to do is fight to keep that surveillance contained within the international intelligence mission, and not let it creep into domestic policing.
They only care about what is valuable to protect and advance their geopolitical and commercial interests, which are remarkably similar.
Crypto AG was gold because their products were used by governments and perhaps high level business executives.
This company is a problem because it's controlled by an American intelligence agency. The owners knew that was a problem, of course, and went to great lengths to hide that fact. Note that Crypto AG appeared to be a Swiss company, not an American one.
Typical American companies aren't controlled by the CIA or other government agencies.
Typical Chinese companies are substantially controlled by the Chinese government.
It's a rather important difference when trying to figure out the risks of how much you can trust who you work with. There's subterfuge, of course, so there aren't hard and simple rules. This is an exercise in risk management.
It's a rather large mistake to conclude Chinese Owned == American Owned.
Have a gander at the companies they have had their paws on: Palantir, Inktomi, Docker, ArcSight, etc.
Unless the CIA has any interest in them, in which they get pwned pretty quickly.
They would need to somehow subvert key executives and subvert key employees to convince them to add back doors and keep quiet about it.
Their levers on such people (carrots and sticks, threats and bribes) aren't that easy to deploy either, especially en mass and in the US. There are a lot of legal hurdles. (The CIA has a lot more legal latitude outside the US than in -- that's very likely an important reason AG Crypto is a Swiss company and not an American one.) Not that the CIA always scrupulously follows the law -- they don't -- but they have to be careful about it.
I suppose you can just believe the CIA hits the "pwn" button anytime they like. But that doesn't have anything to do with the way things work.
True but that doesn't mean there aren't national interests in play when it comes to information security companies deploying crypto products. Think RSA e.g. who took bribes and implemented Dual EC DRBG -- a backdoored random number generator for a number of their cryptographic systems.
There are most likely others, thus transparency via open source (and verifiability via reproducible builds to split hairs) is necessary to avoid this ever happening again.
[0] https://www.businessinsider.com/cia-secretly-bought-encrypti...
Not because the Chinese are tapping it, but because they aren't.
The panicky US response makes most sense if the reply they can't say out loud is "but you're putting it in places where it interferes with our wiretapping!"
This is probably not accidental.