The Clean Network – United States Department of State
state.gov
state.gov
"We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbook. Top-down imposition of standards is not what made America's melting pot great. Free and open discourse, with redundant structures designed to ensure that governance required the consent of the governed, did.
Furthermore, State is a decade or more behind the game. It is my impression that modern companies that care about security assume that all networks are compromised and act accordingly. See https://cloud.google.com/beyondcorp as an example.
Balkanizing the Internet will not make us free; we will instead tie our own hands. This is not the same as banning the import of presumed-compromised hardware.
Vote.
Unfortunately far from true. There's a small percentage who have the resource to run this kind of ops. Don't look at FAANG on how security is in companies, they're outliers by far.
We should expect our national-security infrastructure to be more resilient than commercial infrastructure, not less.
However, the infrastructure and scenario may be wildly different from your average (modern) big tech company.
There's always the notion that your national infrastructure needs the security applied as an afterthought, VS maybe more careful planning and less heavy "legacy" dragging them down in the tech companies.
Chromebook + google apps is what most companies need, and really good security for the most part.
No, you assume the network can be compromised like any other device in the system. You still defend the network and add in layers of access control. Employees of Google still use VPNs to connect into sensitive networks.
With the prevalence of 0-days and demonstration of usage by nation-state actors, you have to have multiple layers of defense to try to have any reasonable chance of preventing a compromise.
Not really. Maybe the people that keep BeyondCorp-related systems running, if at all. There are VPNs, obviously, but not directly accessed by 99.9% of employees.
Requesting VPN access is trivial, and it's used heavily in some large teams for pretty banal engineering workflows (i.e., not maintaining BeyondCorp or anything).
People think of a VPN as a secure perimeter (like a thick ship's hull), but BeyondCorp is layered security (like the many smaller compartments within a ship that can be isolated in case of a hull breach).
This is definitely in the "won't" category.
"The Clean Network program is the Trump Administration’s comprehensive approach to..."
Isn't that a bit odd? Surely these things would be worded as 'is the United States Government approach..' It almost smacks of 'errr, don't blame us guys, it wasn't our idea.
Love the low res images of the logos too.
God fucking damnit...
To put it another way; this is like allowing your enemy to design and manfacture your military jets.
I’d even say that’s the entire point of the internet - sharing and inclusion. There isn’t “our” internet and “their” internet - there’s just the internet.
A lot of political leaders are realizing that the communism of China, while different in many ways to the Soviet variety, is still incompatible with the USA.
It seems like a national pride thing that China cannot be subservient to the US, and the US can't survive a world where it's billionaires aren't in complete control.
There's maybe a synthesis where the Chinese billionaires take over America? That way it's still wealth in charge in the US, and the Chinese in control of china
China's specific ideology is irrelevant; "Capitalism with Chinese Characteristics" or balls out Marxism won't change the fact that the CCP needs to feed and manage a billion people. They will eventually engage in aggressive, even ruthless, behavior because they have to; 'tis the nature of Realpolitik. National pride and ideology have nothing to do with it, hegemonic competition is inevitable.
Do you think that it's really up to us? We weren't the ones who set up the Great Firewall. We have been trying to "build walls" for the past 30 years and it has gotten us nowhere. I get that people like to say things that evoke "positivity" or to feel good about themselves but there needs to be some semblance of reality if we really want to progress.
It is, unfortunately, a new field of warfare.
I like to think I'm the most free speech loving, liberal progressive in any room I walk into. But I think the wild west of the internet that existed in the 90s and early 2000s that leant itself to idealistic visions of what the internet could be is not what we have today.
You can't build bridges that are then used against you for espionage, theft of intellectual property, disinformation, tracking and abducting political dissidents, and infiltrating critical national security infrastructure, and then point at that and say "this is free speech!" And if there's no room to acknowledge that in your understanding of how the modern internet works in reality, then I don't know that we're operating from a similar understanding of reality.
I think more to the point, Google et al assume that all networks are compromised by state level actors. As in NSA. As in the people who wrote this "Clean" policy.
Reminds me of when Google security engineers...ahem...reacted...to the Snowden leak that the NSA was spying on internally decrypted traffic. [1]
It's insane to me that the US spied on an American company's internal traffic, got busted, and the only viable response was "well, I guess we have to make HTTPS mandatory in the protocol now".
Not that it was the wrong response. Just that it wasn't even on the table to say "hey, NSA, wtf..."
Unless you see the NSA as some sort of weird, legally protected black hat blue team.
[1] https://arstechnica.com/information-technology/2013/11/googl...
You basically have two levels of recourse against the state for redress of grievances: elections and litigation. You absolutely can, and I believe every major corporation should have, sued the NSA and the larger federal government post-Snowden. I'm not a lawyer so I don't know the specifics of what that would have looked like but it seemed like a pretty egregious violation of a whole list of rights. But litigation, especially against an intelligence agency, seems a little quixotic in this context.
Elections don't seem like they'd have much impact against the NSA. They're not elected officials, and only the top leadership is appointed. Most of them are career bureaucrats (I don't necessarily mean that in a negative way) and scientists/mathematicians. You could replace a third of the Senate and the entire House every 24 months and you're not going to get sweeping changes throughout the NSA. From a national security, somewhat hawkish perspective, that might be a feature rather than a bug? But from a civil liberties/freedom perspective it's definitely a concern.
Said rogue state is, of course, United States of America.
Back in 2014, China launched a crackdown on illegal online content, it was named "净网行动", which literally translates to "Clean Network Campaign/Action". The targets were illegal materials, mainly materials officially considered obscene, but also included unwanted cultural and political materials considered harmful. Since then, the name became a codename for most government crackdowns, and can be referred to in a satirical manner by the people. Naturally, after Michael Pompeo announced The Clean Network Campaign in the United States, it has immediately became a meme in China, comparisons were also made by the international press like the BBC in their Chinese editions. Now, if you search this keyword in Chinese, it's extremely amusing that you'll see news reports on both governments.
Rather than being afraid of a single hegemon, it's the internal opposition that stabilizes systems of control, and he also pointed out that this is even mirrored within the oppositional two party system of the United States, which while looking like it advances freedom and debate and so on really advances security, and it's much more efficient in doing so than monolithic autocratic governments which tend to collapse in on themselves.
A point here, a point there. That's real strategy.
China has an interest in anyone not Donald Trump being in office, since he's picked fights with the CCP and started a trade war.
Russia got him there in the first place, and wants to keep flexing, as it allows them to damage both China and the US.
When we look back at the archive.org copies of Clean Net, it will be like visiting a bizarre short lived theme park.
> short lived
Two predictions I really hope are correct.
>''People find it a little quaint, a little forced,'' said Deborah Tannen, a linguistics professor at Georgetown University and author of ''You Just Don't Understand'' (William Morrow, 1990).
>At worst, Ms. Tannen said, the phrase is associated with sinister historical precedents.
>''There is one particular group -- American Jews, and I am Jewish -- for whom it has a menacing association,'' she said.
>Nazis favored the word ''heimat,'' or ''homeland,'' and homeland defense forces were known as Heimwehr or Heimatschutz in Austria and Germany from the late 1920's.
Things will certainly be much cleaner when your public information comes from a short list of large companies with a lot to lose.
The melting pot makes non-white people idealize white people, which is hard to imagine as anything but a top down imposition of standards
It's literally 99% American culture here. There isn't any "love and tolerance" that you couldn't find in any Blue State, and most of hard left types take their cues from what they see in the US; e.g. the prevalence of BLM wankery despite the fact they're in a different country with wildly different histories regarding slaves. The only things you can't find in the US are Nanaimo bars and banknotes with the Queen's face on them.
Other observations:
-- "Remove untrusted applications from US mobile app stores": so, this would call for even tighter control by Apple, Google, over its app distribution and monopolies?
-- Clean Apps: "Prevent untrusted PRC OEMs from installing trusted apps on their apps store... should remove apps to ensure they are not partnering with a human rights abuser." Umm, seriously, we're going to open this can of worms?
Edit to add a last thought:
I have yet to understand or read a coherent description about how we do not have the technical ability to protect against eavesdropping/etc regardless of who owns the physical hardware. Why is CCP-owned infrastructure uniquely susceptible to this? If we can't protect our transmissions with encryption, secure data storage techniques, what does it matter that the equipment is supplied by China? What unusual attack do they get access to by owning or manufacturing the equipment?
I think it does the opposite. It says "if you're going to vouch for software, really vouch for it". Not "only let users install software you can vouch for". It means that non-app store distribution becomes more of a thing, not less.
It's almost like they ran it through jpegify.me on purpose as a joke, but really it's just another sign of the US's government technical incompetence.
300x169, blown up to at least double that size.
Interested in helping improve the state of things?
Plenty of jobs available with the USDS and various departments from Forestry to HHS!
Not "the government." "A person in the government."
The federal government has a very good design system. But for some reason, whoever built this page chose not to follow it.
Having no knowledge of how the federal government works, but having worked for fairly large organizations, I would still guess that the design system exists and is used in many places but a significant fraction may not even know it exists much less that they are supposed to use it.
It is incredibly easy to add almost undetectable backdoors to hardware, particularly inside ICs. Here's one particularly clever attack described by security researchers at U of Michigan, but there are many:
https://www.wired.com/2016/06/demonically-clever-backdoor-hi...
The solution to all of this is to work together and increase the security of the overall system and ditch security through obscurity and security through NDA, go open-source and full inspectability for all critical infrastructure, be it comms, industrial controls, medical infrastructure, transport etc. And E2E encrypt all communications. Everything else is just screwing around with the symptoms instead of addressing the root causes.
I think the China-hawk paranoia is going too far but for national security paranoia it's relatively well grounded. It's hard to justify being able to certify that a thing is secure when the hardware could just be lying to you about the firmware checksum for example.
Now I'm wondering whether I'm mistaken? If my connection to a website/device is properly encrypted (SSL/TLS), can a mitm attack (eg by an embedded hw bug) strip that encryption away? If so, that would be bad and would invalidate large parts of my argument above. If it doesn't however, then it wouldn't really matter that much I think. Unless... the device somehow saves a copy of the traffic for later decryption with better hardware down the line. That seems doable but not really feasible at scale. (Then again, maybe a few bugs in the routers installed at a few critical facilities or locations like downtown DC are enough to gobble up enough juicy traffic?)
I think on the whole it was a bad idea to offshore virtually all production capabilities for chips and computer hardware. (This is especially true for Europe which lost its hw production to Asia and its software production to the US.) Now we have to cope with this situation as it is though, and it seems to me that the best way to do that is to improve transparency by doing what I wrote above, radically reducing complexity of protocols and the tech stack (eg openssl vs wireguard) and forcing companies to clean up their act wrt IT practices. Not easy at all, I know.
Did you mean to do this? Because if not, it's what's called a bailey-and-motte fallacy. You've stated a very controversial, hard-to-defend position (what difference does compromised hardware make to a user's security?), mentioned it in a context where it would make a huge difference (smartphones), and now you've brought up a very specific scenario and context that is more reasonable (although still not as much as you appear to think).
Again, your original question was "What unusual attack do they get access to by owning or manufacturing the equipment?". Your original post made no reference to routers or switches.
To answer that original question explicitly, having a many types of hardware exploits on end-user equipment is game over - full access to all your data and communications on that device.
Edit: And regarding compromised routers, from https://www.welivesecurity.com/2019/01/17/new-years-resoluti..., here's a list of things that a hacked router could do to you, many of which would be of interest to nation-state attacker targeting a person or organization:
- redirect you to a web page that phishes for your credentials,
- dupe you into installing malware-laced versions of legit software,
- be hijacked to conduct man-in-the-middle attacks (MitM) on what you would believe are secure and encrypted connections,
- be corralled into a botnet in order to launch DDoS attacks against websites or even against aspects of the internet’s infrastructure,
- be co-opted as an on-ramp to attacks at other devices within your network,
- be used to spy on you via Internet-of-Things (IoT) devices,
- be compromised with malware such as VPNFilter, or, as another threat du jour, be misused for covert cryptocurrency mining.
Edit 2: And unless a website is only available via HTTPS, the end user is using an extension like HTTPS Everywhere, or the user carefully types in `https` as the URL protocol, then the end user is still vulnerable to SSL strip from a compromised router.
Edit: Would you agree to let me (or anyone) hook up a compromised router inside your home network?
Chances are, the US government is pushing for china-free networks to ensure it has a monopoly on hacking American systems.
If we as a whole drop the assumption that the network is safe, we can build things where I would trust you to hook up a compromised router to my home network.
I think 'Clean net' is a horrific, short sighted, dystopian joke that will be the subject of ridicule and fascination as a historical subject.
I also think there's no surveillance operation in the world as vast and as troubling as China's, and there's nothing fundamentally inaccurate or misleading about pointing that out.
Replace "China" with "US".
Their companies are by law forced to cooperate.
We Americans like to think we have the moral high ground against China. For some things, we do. For many others, they are just following in our footsteps.
The US has scarcely not been at war since I've been alive and the 2001 Authorization for the Use of Force has no end in sight. Wartime powers vested in the Executive Branch are far more expansive than we would like to think.
Who do you think re-routes shipments of Cisco networking hardware to the NSA TAO group? Cisco and FedEx/UPS. Same with any computing hardware and likely many other products.
Who do you think complies with National Security Letters? 99%+ of the companies that receive them. QWest tried to challenge their legality and that CEO wasted away in prison.
Patriot Act and Anti-Money Laundering statutes require that lots of industries participate with the USA government: financial, travel, hotel, telecom, etc.
Trump's USPS' Postmaster General replacement, along with who recently fired 23 USPS executives:
"Lawmakers Demand Removal of Postmaster General DeJoy Over 'Nefarious' Efforts to Destroy the Postal Service and 'Aid Trump Reelection'" - https://www.reddit.com/r/politics/comments/i71z41/lawmakers_...
1. Check your voter registration.
2. Register to vote if you need to and it's still open for registration in your state.
3. VOTE as soon as you can. If you're voting absentee then drop off your ballot early if possible. If you're voting in-person then look into early voting to avoid lines and keep everyone safe.
https://www.forbes.com/sites/danielcassady/2020/08/06/postma...
https://www.washingtonpost.com/business/2020/08/07/postal-se...
The issue here is that the current Postmaster General fired the administrators who were pushing back against the "optimizations" he is making and wants to make to USPS policies. The final goal is to privatize USPS, which has been a Republican dream since the Reagan era.
However, I'm simply looking for a direct, factual claim that supports that these firings were directly intended to slow down mail delivery so as to cause problems during the forthcoming election. So far all the claims I've seen are indirect; further, the PG has explicitly said they are prepared to handle mail-in votes during the upcoming election.
It's entirely unclear whether firing administrators (rather than mail carriers and postal office workers, etc) has a direct effect on mail delivery rates and accuracy in the short-term.
You realize that this is an absolutely inane thing to ask right? The direct implication is that Trump is slowing down the USPS in order the guarantee his re-election - are you looking for a quote from Trump himself that he's doing this, because I doubt we will ever see one until it's too late.
1: May 6th, Trump appointee Louis DeJoy confirmed as Postmaster General and CEO.
2: June 30, Trump suggests that mail-in voting is fraudulent and suggests delaying the election because of it https://twitter.com/realDonaldTrump/status/12888181603895582...
3: July 15, DeJoy starts cutting costs and overtime during one of the most trying times the USPS has ever seen, resulting in delays: https://apnews.com/59c25efd4d325c4895f8ba85517f9bfd
4: August 7, DeJoy fires or reassigns 23 top executives, dramatically changing the existing power structure and centralizing decision making at the top. https://www.fastcompany.com/90538378/whats-happening-with-th...
No, those executives don't deliver mail. They did make all the decisions about how mail is delivered, who does it, and when. By centralizing the power structure DeJoy has put himself in the position of being able to make arbitrary decisions about postal delivery with very little immediate oversight.
The USPS is playing an unusually large role in this election and Trump (and, let's not forget, state-level actors that continue to take active measures in US elections) has indicated that he's open to messing with mail delivery to win.
https://www.washingtonpost.com/business/2020/08/12/postal-se...
That seems the more pertinent question.
I just prefer to be vote by mail so I can fill it out at home without being rushed.
"Lawmakers Demand Removal of Postmaster General DeJoy Over 'Nefarious' Efforts to Destroy the Postal Service and 'Aid Trump Reelection'" - https://www.reddit.com/r/politics/comments/i71z41/lawmakers_....
> Chinese invented their great firewall for trump, that your logic?
That's a completely needless swipe.
gp edited his/her comment after mine
It will be interesting to see how EU/China/Russia/USA spheres of influence will develop. With the pandemic, a lot of "unthinkable" things have happened (travel prohibition from US to EU etc), so I think the various factions are emboldened to double down on
- keeping their data in their sphere - improve surveillance of own citizenry
* China of course has been pretty much on this track for years.
* EU is using privacy as the good cause to sell this
* US is now doing the same with national security as excuse.
I don't see the big picture changing just because the president and administration change (if they do).
Narrator: "It didn't."
Yuck. I read HN to avoid these kind of low effort canned responses.
At least to me it sounds like an announcement that they plan to "cut the lines" to countries that don't adhere to the standards of the current American administration.
A new protocol won't allow you to communicate with people in the United States if you're on a "blacklisted" comms company's network.
It sounds like "clean" American ISP's won't be allowed to peer with arbitrarily "unclean" service providers of any kind or else risk losing their "cleanliness" designation.
The only force I know of that has been able to moderate that feedback loop is organization. By very definition, what the elite few who consolidate power don't have is numbers. They are massively outnumbered, which is why they are constantly sowing discord (like fomenting racism). Because they know the only thing keeping them in power is the disorganization of the masses.
If you want people to act a certain way, you incentivize that thing, not punish the opposite of the thing.
You want people to stop doing drugs? Make programs designed to support them during the withdrawal process, provide counseling and other necessary supports, and make it free. You want people off of welfare? Provide career training and education, and assistance in the job search process, and make it free.
Punishment doesn't give you what you want, it gives you the appearance of getting what you want, while the people you punish spend their time trying to figure out how to lie their way around you.
> Generally the better educated are more prone to irrational political opinions and political hysteria than the worse educated far from power. Why? In the field of political opinion they are more driven by fashion, a gang mentality, and the desire to pose about moral and political questions all of which exacerbate cognitive biases, encourage groupthink, and reduce accuracy. Those on average incomes are less likely to express political views to send signals; political views are much less important for signalling to one’s immediate in-group when you are on 20k a year.
https://dominiccummings.com/2017/01/09/on-the-referendum-21-...
What is important is a well-rounded secondary education and/or liberal arts post-secondary education.
In seriousness, you do both.
So should European Companies also pull apps from Google and Apple?
I‘m all for standing up against the horrible human rights abuses of China, but it sounds unbelievably hollow from the US, which has a track record of putting their own interest before democracy and human rights abroad.
The whole website is pitched for other countries to join in, but I really don’t see that happening except maybe the UK and Canada.
Relations aren't great right now. Just last week Trump began yet another trade war with Canada. I don't really see Canada taking part in this.
Considering the NSA hacked and had backdoors in Huawei servers for almost a decade, I imagine direct evidence shouldn't be difficult to produce.
Have you tried searching in wikileaks though?
1. The Chinese National Intelligence Law requiring every citizen to "intelligence work".
2. Huawei had the potential to reach mass adoption outside of China.
3. Huawei is a company deeply connected to the PLA.
4. Therefore Huawei, not only is its HQ required to spy for China, but that it is very likely to work with the PLA to spy for China.
[1]. https://en.wikipedia.org/wiki/National_Intelligence_Law
[2]. https://www.cnbc.com/2019/07/08/huawei-staff-and-chinese-mil...
There's no shortage of "guesses" and "plausible connections" around but the parent comment is specifically asking for actual proof in this instance.
* NSA is a governmental agency that by construction is tied to the state. Bytedance, Huawai and Tencent are privately owned companies in China and all "ties" to the Chinese governments are unsubstantiated. Blanket ban on private companies because of their country of origin and unsubstantiated suspicions results in clear discrimination and suppression of open competition in my mind.
* For my understanding, could you help by providing context on what specific counter-measures have been taken against NSA's intelligence effort based on people's suspicion?
In terms of an anecdotal evidence... My father used to work for molex, one of his biggest complaints were fixing the molds after they were sent to Chinese factories. They would try to deconstruct them and couldn’t put them back together (this was the 90’s, early 2000’s). So they would be shipped back to the US operations to fix.
Eventually, he ended up spending years training up Chinese to replace him (my father, in China). Molex moved much of its tool making shop to China and shut down most US tool and die making operations.
Anyway, China has people who are trained, on factory floors, who are there to reverse engineer processes.
This has been known for decades, companies don’t really seem to care or know (I guess that’s possible as they are outsourcing manufacturing).
I have no doubt this is designed across all their industries and systems. It’s in their interest to do this.
EDIT: I want to point out, there’s no longer a need for China to reverse engineer. US companies ship the designs straight to China. This is probably why we’ve seen China catch up so fast. We trained their workforce and now provide them all the IP before we build it.
My understanding from the tool & die industry is that’s only been happening the last decade or so. IMO that’s the real issue, because it’s decimating the ability to manufacture here and sure design can happen in the US, but if you can’t build the molds for the latest tech here then it doesn’t matter. Those designs are given straight to China, no need to reverse engineer.
https://www.lightreading.com/5g/huaweis-patents-wont-save-it...
"what has company X done?"
"company Y did this bad thing"
"all companies in Z do bad thing"
GGP: Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"?
GP: My father used to work for molex, one of his biggest complaints were fixing the molds after they were sent to Chinese factories. They would try to deconstruct them and couldn’t put them back together
Taking apart competitors' products is standard & ethically accepted practice virtually everywhere, there are lots of published anecdotes. Eg the one in Soul of a New Machine, where the team at Data General analyze a VAX. And there's no relevance to the surveillance state.
I only read this once and don't know if it is true. Supposedly Technology Transfer was/is a distinct engineering specialty in China, up there perhaps with Civil, Electrical.
Coincidentally this was while working with a US manufacturer which somehow could never satisfy a Tech Transfer arrangement completely enough to get the final contracted payment. (Mixed reasons there.)
Frankly I wonder if China will [thus] preserve aspects of industrial civilization while the US works and/or collapses toward a relative dark age. (One case in point: nuclear power generation.)
Of specific concern is a 2017 intelligence law that obliges companies to "support, assist and cooperate with state intelligence services in accordance with the law, and maintain secret all knowledge on the national intelligence services." Another is China's cybersecurity law, which contains similar requirements.
https://www.bloomberg.com/news/articles/2019-04-30/vodafone-...
Vodafone asked Huawei to remove backdoors in home internet routers in 2011 and received assurances from the supplier that the issues were fixed, but further testing revealed that the security vulnerabilities remained, the documents show. Vodafone also identified backdoors in parts of its fixed-access network known as optical service nodes, which are responsible for transporting internet traffic over optical fibers, and other parts called broadband network gateways, which handle subscriber authentication and access to the internet, the people said. The people asked not to be identified because the matter was confidential.
"Bloomberg is incorrect in saying that this 'could have given Huawei unauthorised access to the carrier's fixed-line network in Italy'.
"In addition, we have no evidence of any unauthorised access. This was nothing more than a failure to remove a diagnostic function after development.
"The issues were identified by independent security testing, initiated by Vodafone as part of our routine security measures, and fixed at the time by Huawei."
That's a nice way of saying that Bloomberg made up most of the article.
Or the fact that Huawei is a de-facto public company, with massive subsidies by the CDB?
https://www.rfi.fr/en/contenu/20190530-huawei-key-beneficiar...
Huawei inked a $10 billion credit line with the China Development Bank (CDB) in 2004 to provide low-cost financing to customers buying its telecom gear. It was tripled to $30 billion in 2009.
https://www.wsj.com/articles/state-support-helped-fuel-huawe...
And it's funny, because they admit this is normal
https://www.scmp.com/tech/big-tech/article/3043558/huawei-sa...
“Like other tech companies that operate in China, including those from abroad, Huawei receives some policy support from the Chinese government,” Karl Song, vice-president of the company’s corporate communications department, said in a statement. “But we have never received any additional or special treatment.”
There's no large corporation in China that got there without financial backing, and board control, from the CCP.
Thus, all major Chinese corporations are a extension of the CCP.
> Thus, all major Chinese corporations are a extension of the CCP.
I believe that to be true. I also believe that to be true for all corporations in all nations. They're independent from the state until it matters.
I don't buy the cynical well, they're all the same. ByteDance employees attend CCP-indoctrination meetings in the regular. Is that the case for any US corporation? How many of them are lead by former former military, like Huawei?
So, no.
One other point of concern from Western governments is that Chinese law compels Huawei to cooperate with Chinese intelligence services, which presents a vulnerability whether that law has been taken advantage of or not. This is much different than say, Apple, which has refused (or it has been simply impossible due to E2E) for them to cooperate.
https://en.wikipedia.org/wiki/Criticism_of_Huawei#Espionage_...
The problem is not that the claim is false, but rather the one-sided focus on it that justifies the USG surveillance state continuing to turn on its own people. If this were just some defense contractor pork for internal USG networks nobody would really care, but it sounds like they intend to fork most common Internet features while dictating how they operate.
Spies to spy things. It's safe to assume that everyone with the power to do so is exploiting any advantage that they have.
Surely we can be less shitty about answering the OP’s question. As a start, it sounds like at some point there were unsecured Telnet servers in some Huawei devices: https://www.theregister.com/2019/04/30/huawei_enterprise_rou... It’s not entirely satisfying evidence because the Register believes it was legitimately for diagnostics. They also point out that there were comparable “backdoors” in Cisco equipment: https://www.theregister.com/2019/05/02/cisco_vulnerabilities...
If anyone replies with an example of an actual unambiguous Huawei backdoor for which there isn’t a corresponding Cisco “backdoor” I’ll be happy to buy them a coffee. But why are so many of the replies to the parent comment just pure noise?
What kept happening, from the perspective of people who worked there that I've talked to, was that Nortel would do heavy R&D investments and then a few months later Huawei would be selling identical hardware with zero R&D budget- for lower cost, naturally. It took Nortel years to finally figure out their network was highly compromised, likely by the PLA[0]. The PLA would steal industrial secrets and hand them to companies owned or controlled by the Chinese government, like Huawei.
One fellow I met at a wedding party once told me how he had actually read Huawei source code that included Nortel copyright notices. It was a joke by the end. Everyone knew.
As for as being an arm of the PRC, Huawei claims they're owned by their employees Trade Union. But Trade Unions in China, by law, are highly controlled and managed by the party. You can't have a trade union that isn't highly associated with the Communist Party. Huawei counter these arguments by saying it's very complex- but provide no evidence to the contrary.[1]
[0]https://en.wikipedia.org/wiki/Criticism_of_Huawei#Nortel
[1]https://en.wikipedia.org/wiki/Criticism_of_Huawei#Opaque_own...
Yes, Huawei is an arm of the PRC surveillance state.
https://www.bloomberg.com/news/features/2019-02-04/huawei-st...
Same playbook.
As it is, this just makes it seem like China was right this whole time and the US ideals of an open internet were a failure.
Strategically, this position is untenable. The free world is defenseless until we demand reciprocity. Balkanization, be that as it may, it's not the end, but a means to an end, the end should be all open for every one.
No. This is the conceit of the humanities to attribute the past few centuries of industrial and scientific progress to their work. The Soviets, the Nazis, and the Japanese Empire all managed to progress useful knowledge while believing in completely different ideologies. Your John Lockes and Thomas Paines made no real contribution to the discovery of Penicillin or the Transistor. The idea that censoring ideology will stunt technological growth is a fantasy believed in only by ideologues.
And yet they still managed to adopt all the useful ideas they needed despite heavy political censorship.
Please, let's stop the whole thing of "he doesn't have the power to do this". Maybe he cannot do everything, but the last four years have proved that he can do pretty much everything he wants with a few minor problems with justice that he will also disregard. Think about mass imprisonment of immigrants, travel bans, attacking protestors in major cities with unidentified military units, diverting money fro the military to build a wall against congress wishes, not allowing his co-conspirators to testify in Congress, affirm he will not accept the election results, etc. All of these things supposedly were not legal. But he doesn't care about the constitution, and the constitution only has any power if the government is willing to uphold it.
There are a lot of people around me taking that as a list of companies not to do business with. As if this will save them from the global surveillance dragnet. But here's the thing, you either submit to american surveillance and tracking, or you submit to some other nation's surveillance and tracking. You will not be able to choose companies that don't partner with their national governments for surveillance and tracking. So people taking this as a list of cooperating companies, and asking how to avoid this system, are being a little naive. Thinking that somehow, not being on our network will save them from surveillance. It won't. Best case, it saves them from surveillance by us.
It is a sad future. I'll concede you that.
However, they are listed as if they are following the directive rather than having been long in front of it. It's gross political posturing, useful or not.
This is tragic & dangerous bc we need shrewd & wise people to make decisions + build coalitions in the opening decades of 21st century, not hyper-partisan kooks.
Some of the worst actors in cyber space rn is the Russian gov’t & their intelligence + “security” services —- it sure is funny (funny as in strange, not humorous) how difficult it is to get any of these apparatchiks to publicly acknowledge that
(As non-native speaker) I always interpret A-Team as your most competent team for a given task.
Like, we want clean networks free of foreign influence and sruveillance, full stop. Or are they implying that Five Eyes surveillance is good and OK?
There was no need to call out the CCP in the document, it's obvious who this measure is primarily directed at. Also, characterizing it as an initiative of the "Trump Administration", instead of the United States Government or State Department, was unnecessarily political and also obvious.
Also as mentioned above, China already has a Clean Network initiative. I wonder if the Trump admin copied that name, or chose it accidentally.
1) There are too many in/out points and encrypted paths in and out of the network to actually make this worth spending time on. Think of walling off the entire country, yet there is still air above the wall, movable earth below the wall.
2) It creates a false sense of security if you're on the "clean network" and may make some developers less considerate of securing apps, websites, etc, and some consumers of questioning the security and privacy of the apps they install. I.e. it weakens those within the "clean" firewall.
The proper solutions to protect us from "China" are the same as the solutions to protect us from NSA - E2E encryption, P2P communication, decentralized namespaces, and making data transmission (ie trust) as non-interactive as possible.
I don't see how it's possible to answer whether this will "function". None of the simplistic actions stated in the press release address any of the actual threats - hence everyone is filling in their own imagined technical specifics. This is basically another "series of tubes" moment, with politicians not understanding that while they can control the physical wires, they cannot control the emergent complexity of communications happening over the wires.
How about as a lover of liberty, _nobody_ snoops on our data?
But in general, backdoors for "the good guys" are just more surface area for "the bad guys", and developers of products which take security seriously lock themselves out too.
[1] For example, https://en.wikipedia.org/wiki/Crypto_AG
In short, calling this a "clean" network continues a long history of racist and xenophobic language in the U.S.
Step 2: describing anything in negative terms is racist?
Second, I do not contend that describing anything in negative terms is racist. I am linking the specific history of describing Chinese immigrants as dirty with the Clean Network's choice of names. It behooves us not to think of it as a benign coincidence but rather an intentional act to signal the Trump administration's commitment to xenophobia.
China already has a similar system also called (the Chinese word for) "Clean". Is the Chinese government racist against Chinese?
He's using it metalinguistically, for God's sake.
How would we characterize the law under the one-child policy specifying that minorities are free to have two children, but Chinese are limited to one?
The img tag has a "srcset" attribute with resolutions from 85x48 to 1920x1080, but the "sizes" attribute is "(max-width: 300px) 100vw, 300px".
Only that it used to gather a lot before Snowden.
Edit: Downvoted for a question. Keep carrying on with the idiocy.
But on the other hand, isn't it a violation of First Amendment protections if the US government can dictate certain apps aren't allowed to be distributed in the US?
Since software's subject to copyright, doesn't it logically follow that banning software is legally similar to banning a book?
Software is protected by 1A, so there’s nothing the government could do to prevent China from publishing software or source code, and allowing people in the US to download it. But it can certainly prevent a Chinese entity from providing services to US customers.
I don’t see anything about content filtering. Just transport integrity.
The closest we come to that is the prohibition on apps, but that’s still an ocean away from censoring text messages mentioning the Tiananmen massacre.
https://www.voiceofsandiego.org/topics/public-safety/sdpd-is...
The startup might win the court case, but you might lose your money before the government gives up its appeals and injunctions.
Seeing the partner list this seems like more of a ploy by telecoms to attack tech companies than any legitimate attempt to secure networks.
> To prevent U.S. citizens’ most sensitive personal information and our businesses’ most valuable intellectual property, including COVID-19 vaccine research, from being stored and processed on cloud-based systems accessible to our foreign adversaries through companies such as Alibaba, Baidu, China Mobile, China Telecom, and Tencent.
Am I missing something?
Securing the routers and network cables removes the means for man in the middle attacks (or at least makes them preventable with router security). Not connecting to telecos does the same (because of bgp highjacking and the like).
Removing chinese apps and not storing data on Chinese servers makes decreases the amount of data that can be extracted from large portions of the population by the CCP. E.g. preventing the "who knows who" graph from leaking wholesale (even if individual nodes can still be investigated via other means).
This doesn't fix all security problems, but it removes some of China's current advantages in cyberwarfare.
Not putting apps in Chinese app stores and devices looks to be an outlier in that it's a form of sanction (in response to human rights abuses) rather than a defensive measure.
Removing "Chinese apps" just means that different Candy Crush clones will be collecting that data, either directly or through their advertising networks. Or it means the Chinese companies who need to collect data will collect it through data breaches.
The best thing you can say is that this puts a speed bump in front of attackers, but since speed bumps aren't a security measure the reality is that it won't do anything.
How? It makes attacks slightly more expensive (because you need to use infrastructure in a "clean" country), but it doesn't stop anyone that's dedicated and has money to spend.
Want your spy-app on the app store? Don't register your company in China, just do it in the US. Voila, you're "clean."
Sort of like how the CFO of Huawei is currently in jail.
Creating orwellian straw man arguments is not a productive method of conversation. Please stop.
Why would you need to? I don't understand the point you're making. It's not about the money, it's about data, right? Presumably the Chinese aren't using Tik Tok to fund their government, they're happy to spend money on data collection. From the outside, you can't tell whether a company is collecting user data to give them to the Chinese intelligence service or just to engage in "good old American surveillance capitalism". That these kinds of operations can collect data and fund themselves is just the cherry on top.
My point is that if "location of development" team and "immediate source of funding" are the criteria, you might keep the average Chinese developer out that just wants to release his hobby app. But you're not keeping out anyone that's dedicated, has money to spend and can just do it in plain sight, because the actual acts are not the criteria you look at, because they're identical to the things your companies do (which they obviously don't want to stop from collecting data).
If the initiative was for simply protecting companies and individuals from tracking and spying, I'd be on board and I could easily see how that might have some success. But it's not, and short of forcibly removing anyone with Chinese heritage from the US and doing lie detector test on everyone else to make sure they're not secretly working for China, there's no way to keep anyone safe from Chinese data collection invasive anti-privacy companies while not interfering with the regular invasive anti-privacy companies. Well, maybe by looking at growth rate and use of dark patterns, the Chinese agents might fear being uncovered and won't go all out with the abuse...
> Creating orwellian straw man arguments is not a productive method of conversation. Please stop.
Not everybody is a Chinese agent. "We will build a wall, it'll be great, nobody will be able to come through, and China will pay for it" just doesn't sound like a good plan to me.
It's inevitably about both. You don't make an app with the reach of tiktok without a huge amount of money changing hands. You need to advertise it, you need to motivate content creation, you need to buy servers, you need to pay for that (probably by selling advertising - but funding from the government works as well), and so on.
If someone made a popular app without a source of revenue, that would be just as much of a red flag that I would expect the government to look into (for tax reasons even).
You can't stop small things no one uses, big things have but noticeable footprints. Big things are also the things you care about stopping if your goal is to do things like "not let China collect a complete social graph".
This just feels like an attempt to control who is the middleman spying on data, not actually securing Americans data. Which makes sense, coming from the government and whatnot - but i'm just trying to make sense of if there's an actual reason i should like this "Clean Network" (which is to say, my comment is an honest question, not an attack on the proposal).
Perhaps i'm just biased because of my (pet) passion for distributed systems. I don't trust any MITM, so i think i struggle to understand the concern for _who_ is in the middle.
I'd be far more interested in this type of pitch if it came with heavy support for encryption, distribution, etc.
Moreover the middle can just shut down. Especially for things like embassies it's not a good idea to give the adversaries an easy off switch.
I agree that "encrypt all the things" would be a very nice addition.
This information has already been had by hackers (e.g. Equifax) and/or people from within US companies doing corporate sabotage to steal trade secrets from within a company, etc.
For instance, Rogers (Canadian telecom company) hasn't released any statements [as far as I'm aware—to date] following Pompeo's announcement. They've been set up to use Ericcson for their 5G rollout for several years.
It's misleading on the part of whoever drafted the document.
I was just pointing out that the Canadian telecoms did this long before the US admin started honking their horn about "Clean Networks TM" and not at all to comply with American [government executive] directives like "if you are freedom loving you'll join us".
But what surprises me more people are not up in arms about it. I mean, who would not love only government approved code floating around and only child appropriate messages being visible before 10PM.
If there is a real reason to dislike this administration, this is it.
I am beyond disgusted at my government. This Republican administration has been an unprecedented disaster on every front.
edit: in case someone was confused, talking about the initiative, not the government in general
Right now I don't care whether China or USA spies, they are identical countries in my mind.
Keep in mind that China can still spy on even with this Clean Network.
https://web.archive.org/web/20200808170849/https://www.state...
Together we stand, divided we fall.
The US wants to maintain dominance over Asia. Can't do that with China, the usual Asian power, getting stronger
* balkanized/siloed instead of globally standardized;
* permissioned instead of permissionless; and
* monitored via backdoors instead of optionally secure.
I'm reminded of this passage from George Orwell's classic piece, "Politics and the English Language" (http://www.public-library.uk/ebooks/72/30.pdf):
"In our time, political speech and writing are largely the defense of the indefensible. Things like the continuance of British rule in India, the Russian purges and deportations, the dropping of the atom bombs on Japan, can indeed be defended, but only by arguments which are too brutal for most people to face, and which do not square with the professed aims of political parties. Thus political language has to consist largely of euphemism, question−begging and sheer cloudy vagueness. Defenseless villages are bombarded from the air, the inhabitants driven out into the countryside, the cattle machine−gunned, the huts set on fire with incendiary bullets: this is called pacification. Millions of peasants are robbed of their farms and sent trudging along the roads with no more than they can carry: this is called transfer of population or rectification of frontiers. People are imprisoned for years without trial, or shot in the back of the neck or sent to die of scurvy in Arctic lumber camps: this is called elimination of unreliable elements. Such phraseology is needed if one wants to name things without calling up mental pictures of them."
--
EDITS: Simplified language, and removed quotes from OP as well as several paragraphs from the Orwell quote to make my comment shorter and easier to digest.
I'm no fan of anyone involved, but we should accept that the Internet as we may have known it has been compromised by exogenous governance structures and their gatekeepers in service of non- and even anti-internet agendas, and it can no longer seriously be considered a free territory for divergence and innovation. The U.S. and their Clean network seems naive in a way, but in this case, I don't object because I think it is the devil we know.
If the problem is that China is copying designs, then the solution is to stop moving sensitive production there.
If it is that Chinese manufacturers are putting remote backdoors in products, then the solution is to make trustable designs with open firmware, and domestic production of sensitive parts to avoid hardware backdoors.
If the problem is apps with built in surveillance, then the solution is to secure mobile OSs to prevent data leakage.
If the problem is that Chinese groups are shitposting to manufacture political consent, the solution is better social media filters, reputation systems, and fixing our domestic institutions (eg the press) thus hindering the ability for anyone to manufacture consent.
None of these things are solved by top-down imposition of some blunt firewall, or whatever other misguided heavy handed ideas the politicians have in mind. From the perspective of network security, it's really no big deal if Internet addresses become 64 bits with the addition of a proxy.
Reality is, if the U.S. govt doesn't protect its networks, people and companies will have to protect themselves with encryption and hardware key management that keeps China out, which by extension means keeping US law enforcement out as well. It's a sovereignty issue.
2) China has the intellectual capacity to meet the US technologically without stealing IP. Putting pressure on them will just encourage faster technological development.
3) At this point, it seems China will continue to expand control of South China Sea, or US will go to war with China to stop them. Any middle ground is fast disappearing. Hawks in US seem to have won control of strategy.
> To prevent U.S. citizens’ most sensitive personal information and our businesses’ most valuable intellectual property, including COVID-19 vaccine research, from being stored and processed on cloud-based systems accessible to our foreign adversaries
I find it an interesting choice to specifically use COVID-19 vaccine research as an example of intellectual property.
What about all the talk that COVID-19 vaccines should be developed in global collaboration and that vaccines should become available to everyone worldwide?
Regardless, I think the site mentioning COVID-19 is needlessly inflammatory.
Many reasons, which I won't go into, but...ya never know...
1. If we have some valuable Covid-19 research, shouldn't we like, um, not keep that a secret?
2. Also, if we're going to take this farcical notion of "IP" seriously, it's only right that we give up all our guns, since gunpowder was invented in China, and we are infringing on their "intellectual property".
I wasn't totally alarmed by what I read. Maybe I'm misunderstanding something, but I take this as a sort of stamp of approval that a cloud/network/platform isn't compromised by China. It doesn't seem to say, "Only use the U.S. internet" as other commenters have mentioned. The stamp of approval seems to be global (if you look at the list that was mentioned it's worldwide, not just the US).
When I came back to look at the comments I was surprised to see a lot of noise. I feel like something must have flew over my head and maybe someone can explain it to me. I went ahead and read the link again but slower and I still don't understand the reaction I'm seeing on HN.
Maybe it's some sort of state of idealism. People want the internet to be a place that's free from tyranny or government, but that's not what's happening. China/Russia/US/whoever is abusing the internet to gain an upper-hand. The best solution is to reinvent the internet, which I know there are a quite a few projects going on that are trying to accomplish that, but in the meantime what is a government supposed to do? Let other governments siphon their citizen's data without a cost?
Again, I could use an explanation as I must have missed something that a lot of other people are finding very obvious. When a top level comment just says "Make sure you vote in November". I don't understand the context.
Disclaimer: I am definitely not voting for Trump and dislike pretty much everything the administration has done. Yet, I do try to look at everything in silos.
And I live here.
What is hyper scale? Did Trump write the copy for this site?
What bunkum. What about intrusion by parties such as Russian intelligence using legal methods, targeting ads using our "most sensitive information" on Facebook to benefit Trump? Trump wants to talk about the Chinese digging tunnels under the house while his cronies (domestic and Russian) walk right in the front door.
This is such an obvious ploy to change the conversation away from the now >160,000 Covid-19 deaths in the USA resulting from his disastrous management of the crisis.
Straight up consent manufacturing.
Kidding aside, this is so blatant I can hardly believe I'm seeing it happen.
Make sure you're registered, and make sure you vote in November.
Enforcing IP internationally is actually quite difficult anyways. Tariffs effectively restrict manufacturing overseas, as there's some breaking point in cost to produce.
I don't believe banning trade / manufacturing to China is a good idea, we depend on them for cheap consumer goods, and they depend on that revenue. We developed a dependency on Chinese manufacturing because it was cheap, and no with little to no manufacturing ability stateside, we're tied to their economy.
As someone who worked for the D.O.E for years, I can care less where consumer goods / technology is manufactured. The US government already has VERY strict rules about manufacturing for military / transportation equipment. "National Defense" isn't going to be decided by who owns TikTok or app-de-jour.
it is what's done with ip especially military and national security secrets
This makes me physically sick. The only freedom you have in the U.S. is being poor, controlled, and oh yea, you can Tweet whatever you want. While the U.S., both citizens and the government, have pointed fingers at Russia, China, and <name a country>, we've been under the assault of propaganda and control for decades, at increasing rates, all under the guise of so-called freedom and democracy. Instead of propelling us into the future, our government has dragged its feet to pull us back all in the name of pure greed and control, giving itself and corporations near limitless power by sacrificing the common people.
I don't want to be the bearer of bad news, but:
https://www.cracked.com/article_25266_6-totally-stupid-thing...