Lithuania says throw away Chinese phones due to censorship concerns
reuters.com
reuters.com
"It has been established that during the initialisation of the system applications factory-installed on a Xiaomi Mi 10T device, these applications contact a server in Singapore at the address globalapi.ad.xiaomi.com (IP address 47.241.69.153) and download the JSON file MiAdBlacklistConfig, and save this file in the metadata catalogues of the applications. A list of applications for which the MiAdBlacklistConfig file was found in metadata catalogues is presented in Table 13."
... "Once the applications have downloaded the file, the download date is recorded in order to facilitate periodically updating the list. The scheme for downloading the MiAdBlacklistConfig file is shown in Figure 11."
"This file contains a list composed of the titles, names and other information of various religious and political groups and social movements (at the time of the analysis, the MiAdBlacklistConfig file contained 449 elements). A fragment of the MiAdBlacklistConfig file is shown in Table 14."
Extract from table 14....
===================================================
No.: Original - Approximate translation
1 "宗教虔信者阵线", “Front of religious believers”,
...
22 "西藏自由", “Free Tibet”,
...
60 "蒙古独立", “Independence of Mongolia”,
61 "89民运", “89 Democracy Movement”,
62 "基督灵恩布道团", “Christian charismatic mission”, ...
145 "伊斯兰联盟", “Islamic League”,
...
201 "民运", “Democratic Movement”,
202 "妇女委员会", “Women’s Committee”,
203 "伊斯兰马格里布基地组织", “Al-Qaida in the Islamic Maghreb”,
204 "人民报", “People’s daily newspaper”,
205 "巴勒斯坦解放组织", “The Organisation for the Liberation of Palestine”,
=======================================================
My impression is that Sundar was all-in on Dragonfly, and he only rolled it back because of tremendous external and internal pressure. As that pressure abates over time, expect Dragonfly to return. Word of warning for those who trust Google as a defender of digital privacy and human rights.
[0] https://en.wikipedia.org/wiki/Dragonfly_(search_engine)
[1] https://www.theguardian.com/world/2016/dec/06/un-human-right...
[2] https://finance.yahoo.com/news/chinas-ink-girl-defaced-xi-09...
Surely that is literally nobody?
At this stage I would be seriously concerned for anyone who identifies with this description.
Because it is coming "from the bottom up" it can't be relied on when Google can pull the plug on these people at any point if they resist too much.
I can't say much for Apple/Microsoft, but to be safe I would tar them with the same brush.
https://www.wired.com/story/russia-apple-google-voting-app-n...
As for trust in Google, has anyone actually believed they are benevolent for the last decade or so?
Why not do this at network or server-side level? Why not use some kind of hash (ala Apple'e proposed child pornography hunter)?
In this design, everyone would have to have this plain text configuration file ... also other brands (Oppo, Huawei etc.) would have to have it. What if it needs an update? Suppose the hui muslims starts causing trouble ... Or if people starts using slang or deliberate misspelling ...
China doesn’t control the network/servers in Lithuania and other countries. Doing it client-side gives them the power to extend their reach.
Make no mistake: As and when they get caught out doing such things, the sophistication of their implementation is bound to increase, in response to it. Money is no object for state-actors and mega-corps.
An ironic form of chabuduo.
https://www.chinaexpatsociety.com/culture/the-chabuduo-minds...
You're right about this, including with backdoors. Electronics from China must be treated as treacherous computing devices that obey the orders of the Chinese Communist Party.
If the West was sensible, we simply wouldn't buy any electronics from them.
There's also all sorts of pretty reasonable whataboutism to be thrown about here but it's wrong either way.
yeah it's literally called MiAdBlacklistConfig, to stop certain ads from displaying in the browser.
So it's developed by the AD department. What do you think.
Could really be interesting to see the full list of words.
local, network, and content host
Last thing we need is to trigger someone into making a better mousetrap.
313 "台独万岁" “Long live Taiwan’s independence”
...do you want me to post 449 items? :-)
> 204 "人民报", “People’s daily newspaper”
People's Daily is an official Communist Party newspaper... Why on earth would they blocklist that if this is a politically-motivated censorship program (as the paper/many here are implying)?
First result, funnily enough via a site that tracks phrases censored in China.
The problem with replacing the OS is that I believe most banking apps I use will stop working. Might just need to write this phone off.
Restrict apps, but can still log in via browser.
I have one bank app that actually says to screenshot a payment screen for your records, while blocking screenshots via app policy.
This isn't paradoxical. You treat the browser as a less trusted security domain than a phone, which usually has a secure boot chain, strong sandboxing, encrypted disk, reliable hardware cryptography etc, and therefore provide a different/better service on the phone. If a phone is missing one of these expected components then you're not the target market for the app, I guess. (Of course, your phone OS might be perfectly good, and the stock one might be crap, but the app developers don't care.)
Next time when I'll be looking for a new Android phone to buy, stock Android will be a hard requirement. I was stupid to pick my Xiaomi phone for it's hardware, I should've just gone with a Motorola.
I don't think you can trust any proprietary firmware out there, its just a question of which you trust less than the others.
Simple. I do not "trust less". I just do not trust. My phone is a phone. No Internet activity. I spend enough time in front of my desktop, dragging another computer anywhere I go is the last thing on my mind.
QPST/QXDM allows you to mess with the modems by sending it commands and changing configs yeah. But if you want to flash the firmware that's something else.
Yeah the firmware integrity mechanism are not the best, and there's definitely vulnerabilities in the firmware. But there's still no way of installing unsigned firmware on more recent devices, and I've never come across a way of running unsigned code without it being really obvious.
There was a bug recently that allowed you edit baseband memory from within the OS, but again you'll never be able to hide that from Qualcomm on a million devices.
If their engineering is so poor that they haven't caught this in time, nor reacted by releasing a one-line software patch that can be applied manually (cause users sure as hell can't do it themselves - stock can only apply signed updates), they shouldn't be trusted with anything.
1. Approaching death, about to die.
2. Reaching obsolescence.
I learned a new word today, thank you.
What can they possibly be doing in the firmware or the ROM to break TLS (and other such authenticated key-exchange protocols)? The only thing I think of: Injecting a compromised https stack in to an app's classpath / ld_library_path. This may sound ambitious, but the Android modding community already uses such runtime swappers to great affect [1][2].
[0] https://news.ycombinator.com/item?id=9072424
https://www.reddit.com/r/Xiaomi/comments/pgk8y3/comment/hbf5...
[1] https://www.wired.com/story/apple-china-censorship-bug-iphon...
i sent this to a friend who owns a xiaomi phone and asked him to resent this back to me via sms. the message appeared just fine.
note: i am from india so this might not be enabled on the phones here for now
Another user below found the best link, the true original source:
Here's the official report: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi... (link updated)
this should work (note: direct link to pdf)
https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
It's insane.
https://blog.malwarebytes.com/android/2020/07/we-found-yet-a...
It's downright dystopian.
It sure is. No stopping it now though.
I'm old enough to remember being able to go to someone's place and expect privacy. These days literally anything can have an HD cam.
Not great for paranoia but what can you do?
> They could just be monitoring everyone,
They are. Snowden already proved this, and we apparently got into that particular situation to keep pace with China.
Not my job.
1. If you are a developer, consider buying a Pinephone [1] and contributing to the codebase.
2. If not a developer, you can submit bug reports and test fixes. Same for Purism Librem phone as well [2].
3. If you are neither, or have no time to spare but do have money, you can always purchase one for kicks or donate to open source like Ubuntu.
4. Finally if you have no time or money, simply upvoting privacy related threads on HN and talking with your friends about it helps too.
[1] https://pine64.com/product/pinephone-beta-edition-with-conve...
[2] https://puri.sm/products/librem-5/
edit: added numbering
I generally do my best to not only steer them away from invasive devices but also explain why.
Unfortunately this is more and more turning into a situation where I have hardware sent to me, reflashed with a known good rom and then mailed back out.
Why isn’t US Gov putting together legislation for this sort of a thing is beyond me.
HN discussion here: https://news.ycombinator.com/item?id=28499918
Do we know for certain that IME is not already doing this kind of spying though?
The implications of the rise of China's military for Mongolian security https://calhoun.nps.edu/handle/10945/5340
China accused of 'cultural genocide' in Inner Mongolia https://www.ucanews.com/news/china-accused-of-cultural-genoc...
China’s Crackdown on Mongolian Culture https://thediplomat.com/2020/09/chinas-crackdown-on-mongolia...
> against the Russians
This seems to be rewriting the history of Russia creating an independent country of outer Mongolia out of collapsing Qing territory. It'd be akin to saying an independent Alsace nation "serves as a buffer" against the Germans.
>Qing territory
Both China and Russia have been oppressive identity-suppressing culture-destroying mutli-ethnic empires (something very very very very bad) since forever. (The identity-suppressing culture-destroying part really started up in the 19-20th century, when it became evident that the empires won't survive without colonization and suppression in the modern age) "Qing territory" doesn't say more to me than the British Empire's "territory". Same for Inner Mongolia, Tibet, Xinjiang, and arguably even Canton.
China is pro Palestine if you follow the news. The relationship between Palestine and China goes back to 80s.
I don't think Xiaomi cares what people in Lithuania are reading, other than selling its phones. I don't think CCP cares about what people in Lithuania are reading.
Renminbao [人民报] is an independent Chinese online news website that criticizes the Chinese regime.
They are not that different from other Leninist inspired governments. Cuba does that. Vietnam does that. The Soviet Union certainly did that.
These governments always lose their minds with the idea of people organizing themselves and the controlling party having no control whatsoever about these groups.
I have no idea how the People's Daily plays into that. Maybe the readership is so small and it attracts a certain type of personality that Zhongnanhai thinks it is a good idea to report on them.
I've read that the major clique in the CCP certainly wasn't happy about students calling themselves Maoists and supporting workers striking.
I don't know much about China to say about that nor if the People's Daily has many people reading it.
Good YouTube overview: https://www.youtube.com/watch?v=NUa1mvaYNtk
Neither claims it anymore. The PRC never did. The ROC did at least until the 60s, but they changed position around 2002.
The ROC technically recognized the independent Mongolia in 1946 after some pressure from the Soviets, though they backpedaled on that and blocked Mongolia admission into the UN in the 50s. Taiwan certainly recognizes Mongolia since 2002 at least. They have good relation.
The PRC has good enough relations with Mongolia since mid 80s.
My iphone is made in China by Chinese contract manufacturer (Foxconn) - does that mean all iphones could be compromised with Chinese malware? It could be possible, but how can you tell? Is it possible to observe network packets going form my phone to a Chinese or Chinese-allied country?
Genuinely curious, btw. Any feedback would be very appreciated.
In theory sure, you could have a chip snooping on the bus. But it would have to have a lot of OS-level knowledge and then how would it exfiltrate the data without OS-level access to the IP stack?
Like the Bloomberg/Supermicro story, I am extremely skeptical.
A Chinese-built phone that comes supplied with an OS, that's a totally different matter.
Do iPhones use modems embedded in the SoC? Modem firmware can communicate with the cell network without the OS.
The core issue is the lack of end to end encryption and open source hardware and software. Options today are okay, but they need to be great to reach the right people. See my post in this thread about Pinephone and Librem.
I agree with you there, but I want to know how to analyze devices that are closed source.
The successful stories about western companies outsourcing to China do tend to fall into the category of building and running your own factory there, rather than contracting with a Chinese owned and managed factory to produce to spec, which suffers from all the ethical problems discussed in the parent post. E.g. these are all decisions taken by management, not individual factory workers, so if you want to reduce risk, then install your own management.
You just have to trust the manufacturer and its supply chain, and that applies to open source too.
While a lot of comments are rightly focusing on the censorship aspect of it, IMHO, the most concerning part of this is that this intrusive capability, while disabled for the EU region can be remotely enabled at any time. This implies that Xiaomi, and most likely all Chinese phone vendors and by extension CCP, has backdoors in all these devices.
This re-enabling is probably just the tip of the iceberg, wonder what all they can do via these backdoors?
They don't need backdoors. They are the "administrator" of your phone just like Apple is on iOS and MacOS or Microsoft on Windows boxes.You are just a guest.
It just happens that the chinese admins(aka vendors) don't mind being nasty and clumsy at the same time. All the manufacturers/vendors are controlled by their government(more or less).
That being said I don't buy chinese phones or software unless I have no choice but I don't trust Apple to shield my data from various governments either. It's just a matter of lesser evil.
This statement is absurd -- they don't need to keep a backdoor around because they control the front door.
You do realize that controlling how/whether/when core system software updates are pushed to a device is equivalent to having a backdoor, don't you?
The operating system on my phone can be 100% backdoor-free today, but if Apple decides that their next update is going to include backdoor, then tomorrow my phone is going to have a backdoor.
Basically all consumer phones (save for a few cobbled together exceptions) implicitly accept arbitrary software updates from their upstream vendor.
I doubt xiaomi and other Chinese company dares to enable censorship anywhere in international markets, or have a secret plan to control world's information discourse to support ccp. Any censorship or apparent support of ccp will be caught within seconds. Its commercial and political suicide. Also if they do have a secret plan, just blacking out whatever people are typing on their phones is such a dumb, stupid, and crude way of implementing censorship.
Also, this report found no censorship mechanisms on huawei and oneplus phones. Yet they said people should ditch all Chinese phones, which implies all phones originated from Chinese origin companies have censorship mechanisms. That is a much larger conclusion than what the evidence they provided, seem like a politically motivated desire to discredit and defame all Chinese origin companies and products.
I also doubt ccp has a marching order for Chinese companies to censor speech internationally and manipulate world's information discourse. Chinese phones have big market share already, and huawei's gear has wide market share in Europe, but no one ever experienced censorship on their device for speaking against China. And if there is a secret plan to control world's information, they are doing a terrible job at it. The covid origins, xinjiang Uyghurs, Hongkong. The point of view of Chinese side is non existent. For example the xinjiang Uyghur situation, I know people in xinjiang, many of whom are uyghur people, the accusation of mass genocide, 1 million imprisonment, wide spread physical abuse and rapes in prisons, massive internment camps with forced labor is wildly inaccurate from the truth. Yet, it hasn't stopped this from becoming the wildly believed truth, to the point where if you disagree with these statements, you are a ccp shill, a genocide sympathizer and brainwashed. For me and a lot of mainland Chinese people I know, we feel our voices and our personal real life experiences are being censored by international media and public discourse. Sometimes I read something about China in the international discourse, it feels its talking about an alternative universe than my real life experience. I have to wonder who is really controlling the narrative, censoring speech and pushing their political agenda.
But I'm still optimistic. Even in english reporting one can still be heavily biased towards negativity (e.g Russia, Ireland etc). As long as we keep the communication bridge open eventually we'll have a better understanding of each other.
No one trust China but this sure looks like politically motivated. Was someone else able to authenticate or reproduce the results.
It may be worth clarifying that all those keywords and terms are in Chinese. So when they say "Free Tibet" they mean that the phone has a blacklist file that contains "西藏自由" and which use is disabled in the "European region".
On the other hand, it seems that this blacklist file is actually downloaded into the phone, which suggests to me that they could update it to match any terms in any language if they wanted.
I think that Chinese manufacturers will really need to produce 'clean' firmware that satisfies independent audits instead of these superficial feature flags if they want to continue to sell in the West long term. If not they will suffer Huawei's fate one after the other when this sort of thing is found out.
[1] https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
About the same thing as Apple scanning iPhones for what they say is child porn.
suggests to me they could update it to match any images if they wanted...
This is a complex of censorship, data gathering, personalization and such. A few months ago microsoft accidentally turned on some china settings globally, and "tank man" disappeared from search results. Tank man is conspicuous, I wonder what less conspicuous switches can be flipped.
The main arteries of media & communication are strategic assets. These responsible for near 100% of Alphabet & FB's revenue. Ad businesses, app stores, etc. Google pay Apple more revenue for search defaults than MSFT earn in gross from their "2nd place in the market" position. Google pay OEMs and telecoms to be their default app stores. The complex is all about bottlenecks,
Control over these is the financial asset behind several of the world's most profitable companies. It is a primary intelligence target/asset. It's a major part of china's information/narrative control mechanism... has been for a while. The thing that's changing is that china's mass is starting to cause tides elsewhere.
This game is a "ring of power" game.
Considering that phone updates cannot be verified, every phone maker has the ability to secretly add such features at any time. And if the phone is link to a user account they could even do this in a targeted way.
if (iNativeAd.getAdTitle() != null && m12161a(iNativeAd.getAdTitle(), str)
If to believe the naming, it is filtering advertisements.Since others here are curious, how would one go replicating these results to find the MiAdBlacklistConfig file? Can I download the OS from a website and just search for strings in the MiAdBlacklistConfig file? I'm genuinely interested, rather than using this question to cast doubt on the 32 page research report.
From what I can gather from the report it should be possible to reproduce the analysis. Probably it is even possible to run the apps in question in an emulator.
Also it should be possible to get the full url of the censorship configuation file and also its full contents.
Given the extreme politics around this, I think it would be better if this type of analysis was done as open source and in a completely reproducible manner.
Not Pixel 6 though. Still made in China https://asia.nikkei.com/Business/China-tech/COVID-slows-Appl...
The problem is that you’re more or less screwed if you trust neither China nor Google. Generally speaking the iPhone is your best option, but partly due to a lack of options.
Though eBay.ca just blocked any listing containing the word “xiaomi”, though they make a ton of things that aren’t phones. I just took out xiaomi and left the model number and sold my thing.
Still waiting for my government to respond to my request to find out why.
(Amp link because Reddit is actually down)
https://www.google.com/amp/s/amp.reddit.com/r/Xiaomi/comment...
Though you can still roam in Canada with them, so I don’t know how that works. Shouldn’t base stations reject uncertified device IMEIs? I guess it’s all okay as long as there’s revenue to be had.
I don't know of any devices at all that get rejected on Canadian ISPs. Blocking Xiaomis would cause a lot of issues.
Just suggests that the restrict them are BS or maybe spyware/intelligence related.
Linked near the top of the thread, 32 pages of goodness: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
This is applicable equally for every other country.
Anyway, I always thought if I have to use American phone backdoored by FBI or Chinese phone backdoored by China, I choose Chinese because they really cannot arrest me, unlike FBI.
Especially since then they’d probably have you do things that would result in even more jail time if caught than the original thing. And since your data is transiting international borders all the time, it would make a nice juicy target for the NSA as well!
No.: Original - Approximate translation 1 "宗教虔信者阵线", “Front of religious believers”, ... 22 "西藏自由", “Free Tibet”, ... 60 "蒙古独立", “Independence of Mongolia”, 61 "89民运", “89 Democracy Movement”, 62 "基督灵恩布道团", “Christian charismatic mission”, ... 145 "伊斯兰联盟", “Islamic League”, ... 201 "民运", “Democratic Movement”, 202 "妇女委员会", “Women’s Committee”, 203 "伊斯兰马格里布基地组织", “Al-Qaida in the Islamic Maghreb”, 204 "人民报", “People’s daily newspaper”, 205 "巴勒斯坦解放组织", “The Organisation for the Liberation of Palestine”,
Let's see
Edit to add: page 24 of the linked PDF, for reference.
The capability in Xiaomi's Mi 10T 5G phone software had been turned off for the "European Union region", but can be turned on remotely at any time, the Defence Ministry's National Cyber Security Centre said in the report.
Wasn't everyone just outraged about apples csam because it could have the potential for intel agencies, like china's to abuse it by claiming political photos were csam?
More seriously no platform is trustworthy unless it’s airgapped these days.
But you also have a gmail address, so I don't understand the reaction.
I wonder if they might be skeptical of another communist regime starting to interfere with the country. Worked so well the last time...
https://foreignpolicy.com/2021/09/22/china-lithuania-taiwan-...
As the Cold War intensified, the frenzy over the perceived threat posed by Communists in the U.S. became known as the Red Scare. The United States government responded by creating the House Un-American Activities Committee (HUAC), which was charged with identifying Communist threats to the United States. HUAC often pressured witnesses to surrender names and other information that could lead to the apprehension of Communists and Communist sympathizers. Committee members branded witnesses as “red” if they refused to comply or hesitated in answering committee questions.
with the only exception that Americans could not flee from persecutions.
https://en.m.wikipedia.org/wiki/Excess_mortality_in_the_Sovi...
Lithuania has been capitalist for 20+ years and quality of life has increased by a lot ever since.
the three baltic states are frontrunners in gov digitalization, for example
That's what I said. Lithuania had it bad under communism (USSR). Maybe they are simply not interested in having an other communist regime (the CCP) meddle into it's internal affairs.
Contrast it with NZ - I had to send my documents via post. In 6 years I NEVER had to visit ANY of government agency but I did receive visas and passports, just simply by post (if you have local drivers licence you do get to use local online services, which is a stupid barrier to begin with, but whatever).
Whole report is worth a read, but page 22 is where this "censorship" is discussed. Given this is HN I think some of you would be interested in the technical specifics in order to give a proper, informed opinion here.
The censorship involves blocking certain personalized ads within some of the core Xiao Mi apps by filtering political keywords. The keywords are all in mandarin, so ads that would be blocked would be Chinese ads. The list of keywords seems to be controversial political statements or news organization based on the report, including a pro china newspaper. The code is only run in China regions, but is stored on all these phones. Technically a standard software update could modify the code to remove that block.
I understand concerns about censorship are high, but logically I don't see the concern here; that is if you're not in mainland China. If you're in mainland China the wrong personalized ad can get you into trouble so this very elementary ad censorship is necessary, but this is about the EU region. It's bold to assume they'd allow this to be run in other regions after the user updated the apps, there's just no reason too, nor is there anything particularly invasive or malicious going on here that is different from other smart phones, based on the technical report.
Related, in this thread the OP discovered that he couldn’t take photos of an election ballot - they were being overwritten with a big green block.
"Yesterday I was a bit in a hurry and could not do all tests that I would have liked to. Today I tried to repeat the whole process with the same setup, documents still laying on the same table untouched etc. Just the lighting changed substantially (morning sun).
I was unable to repeat the 'green picture effect' even once... all pictures taking with Xiaomi stock camera turned out well.
I am sorry that I jumped to unproven conclusions (censoring) :( "
Please read your full source in the future before posting. It clouds the discussion. (I just did this myself on another article)
Here's the official report: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
EDIT: As I really phrased it badly, I mean it doesn't proof anything if none of the above mentioned groups does it. It absolutely matters that Xiaomi is censoring and monitoring stuff based on key words. I oppose that even more than oppose Apple monitoring child pornography. Simply because Xiaomi is already doing the monitoring for a non Democratic repressive government.
"have a built-in ability to detect and censor terms such as "Free Tibet"
Censor by preventing one posting the phrase? Removing the phrase from web pages?
What are the steps to reproduce?
Xiaomi system applications (Security, MiBrowser, Cleaner, MIUI Package Installer and Themes) have been found to regularly download the manufacturer’s updated configuration file MiAdBlacklistConfig from a server located in Singapore. This file contains a list composed of the titles, names and other information of various religious and political groups and social movements (at the time the analysis was performed, 449 records were identified in the MiAdBlacklistConfig file). Analysis of the Xiaomi application code showed that the applications have implemented software classes for filtering the target multimedia displayed on the device according to the downloaded MiAdBlacklistConfig list. This allows a Xiaomi device to perform an analysis of the target multimedia content entering a phone: to search for keywords based on the MiAdBlacklist list received from the server. When it is determined that such content contains keywords from the list, the device blocks this content. It is thought that this functionality can pose potential threats to the free availability of information.
PDF here: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
edit: the downvoters think i am just bluffing? https://thekashmirwalla.com/not-pegasus-kashmiris-are-worrie...
What's more accurate is the use of the bear with reference to their leader (who looks like him!)
A better string would be "tianamen square massacre"
The first 4 smartphones I ever owned all came with preinstalled malware or malware was added after a “security update”
Its way to update that mod in real time without the user knowing about it as its system allowed due it running in a separate allowed system space.
The cynic in me says this is just part of American anti China warfare. And Lithuania is, how should I put it nicely, an American lapdog. Disclosure: yes this was typed on a Poco.
"This file contains a list composed of the titles, names and other information of various religious and political groups and social movements (at the time of the analysis, the MiAdBlacklistConfig file contained 449 elements). A fragment of the MiAdBlacklistConfig file is shown in Table 14." page 23
Linked elsewhere but here's the PDF report: https://www.nksc.lt/doc/en/analysis/2021-08-23_5G-CN-analysi...
It seems I should be more concerned about the proximate threat.
From the snowden leaks we know the NSA puts their own firmware into enterprise hardware.
One should assume that they're in american consumer hardware firmware as well
Surveillance doesn't belong on our devices. Period.
Once it's in, the dictators can clamp down even harder. Over time, freedom atrophies and the window slides closer to totalitarian control.
Don't invite the devil in. Scream it away.
"Member of the German parliament, Manuel Höferlin, who serves as the chairman of the Digital Agenda committee in Germany, has penned a letter to Apple CEO Tim Cook, pleading Apple to abandon its plan to scan iPhone users' photo libraries"
https://www.macrumors.com/2021/08/18/german-politician-lette...
https://appleinsider.com/articles/21/08/17/germany-writes-to...
Along with
"Apple photo-scanning plan faces global backlash from 90 rights groups"
https://arstechnica.com/tech-policy/2021/08/apple-photo-scan...
And 487 other articles, reports, fusses that went against Apple's plans.