U.S. telecoms are going to start physically removing Huawei gear
bloomberg.com
bloomberg.com
The simple story is that core infrastructure is of strategic national importance, and an elevated risk that infrastructure is compromised can never be worth whatever the benefits are of using a particular supplier's equipment. There is no practical way to 100% ensure that every piece of software, and every chip, in every piece of equipment is clean. Chips are especially scary (the push to have domestic chip fab by the US and other countries is about more than just supply chain).
This is true when it comes from what are considered trustworthy suppliers as well, but you're dealing with probabilities. I think that regardless of whether this move fits into a political narrative about China, or "economic warfare", the practical basis is that for some types of equipment, the risk is just too large and the ability to mitigate too limited, in general.
Unfortunately this was figured out with Huawei/ZTE after the fact, but tbh I don't think the specific company matters at all, it just happened to be they were in this business at the time & based in the wrong country.
It's clearly political. If it was a real threat then they'd be forcing operators to throw at all Huawei equipment, OR banning future installs, but at getting them to trash just 5G equipment is a political stunt, IMO.
They've already forced removal from core/security-critical roles, but that takes serious time to actually implement.
If this is such a big security problem then surely 10+ years is an unacceptable amount of time to have potentially compromised equipment in the supply chain?
No, it is not a purely political farce. There is a fundamental architectural difference (that amounts to a technical one as well) that translates into a reason why 4G deployments are more «secure» as opposed to 5G deployments.
Unlike in 4G, where the data that is tunneled through the core network is always encrypted, 5G allows for encrypted tunnels to get terminated near 5G base stations to enable the mobile edge computing amongst other reasons. Server equipment that is deployed at the 5G base station site then can take an advantage of the substantially decreased latency for latency sensitive workloads (ehrm, 5G enabled Doom/Quake, anyone?). AWS have a product, Wavelength, that does precisely that, and I am pretty confident there are other telcos/products doing the same.
4G, on the other hand, never terminates encrypted tunnels and passes them through the core network unchanged. Therefore, retaining the potentially compromised 4G core network equipment alongside the 5G one is somewhat «safer» – in the sense that at least the unencrypted email etc traffic won't leak out. Especially considering that 4G is on the way out (medium to long term), hence there is no need to rush and start pouring massive amounts of money into replacing/decommissioning the 4G equipment now, although it might speed up the demise of 4G in the UK and other countries.
Also, nearly everything is HTTPS these days so I still don't see a massive attack vector here (at least one that wouldn't be spotted immediately like MITMing TLS connections).
I think the much greater "threat" rather than messing round with traffic itself is just to shut down masses of the towers and core networks remotely. In that case, switching off 4G would be way worse as (at least in the UK) all networks doing 5G require a 4G signal as well to bond against. So having separate 5G equipment wouldn't help one iota if the 4G stuff is down.
The major attack vector for the compromised 4G equipment is the remote deactivation (or a wipeout or both) of it by an adversary. Breaking the encryption on the fly for volumes of traffic traversing mobile core networks is still technologically challenging. Hence the plain text communication can still be considered somewhat protected.
Is that an euphemism for corruption? It's almost certain hands were greased. That however seem to have been aligned with many interests, also of those who are supposed to protect us, but nevertheless it's worrying that there is no investigation of any kind.
You vastly overestimate the competence of government.
In the middle of a global pandemic and resulting supply chain crisis, a rapidly intensifying fight against climate change and other expensive issues it's probably not a great idea to throw more billions away.
Of course it could be a risk but it can be mitigated in other ways like multiple layers of encryption. That's never a bad idea anyway.
If we really cared about security and reliabilty, all critical infrastructure would be open source, both software and hardware, so that multiple suppliers could produce the parts.
Instead we choose 'free market' with a thumb on the scale. This does nothing to protect from random hackers and criminals, ignorance, sloppyness and lazyness.
[1] Corruption doesn't look like mobster movies. It's mostly backyard barbecues, buddies helping their buddies' business grow by throwing them a bone. At so many different scales.
"Mr. Worf, villains who twirl their mustaches are easy to spot. Those who clothe themselves in good deeds are well-camouflaged."
- Picard and Worf, discussing both the investigations and the misguidedness of Admiral Satie
Season 4 Episode 21
The Drumhead
https://memory-alpha.fandom.com/wiki/The_Drumhead_(episode)#...But let's suppose everyone working for the government or subcontracted by them is 100% loyal and CCP never manages to blackmail them.
What does it take to bribe a DPD guy on minimum wage delivering your 'American produced' equipment, who can't afford a dentist and is in pain every day? Let's say you ask him to 'mistake' one package for another, and have millions at your disposal?
You talk about "techniques even under X-ray to mask a rogue chip", but do network operators even bother opening the casing of the router to validate the motherboard has not been replaced entirely? What if it's networking equipment where China replaced a single chip, who is ever going to find out? Does the network operator validate firmware of every single chip?
We have security holes all over the place, this talk of 100% certainty is basically fantasy.
In this case, it's pretty low hanging fruit to make a policy w/ financial backing that says "we won't use hardware from companies controlled by slightly hostile countries with incompatible values".
I don’t think open source is the panacea you think it is, exploits will exist as long as they’re profitable and state actors have incentives to stock pile zero days. My guess is it’ll make it even easier to identify zero days if everything was open source.
There's a talk from Bob Beck of OpenBSD on pruning OpenSSL, it's pretty hilarious [3].
In that case open source was at least able to react appropriately, even if it didn't act preemptively.
You'd have to randomly sample some statistically significant number of the chips in the distribution/retail/whatever pipeline and, I guess, scan them with the appropriate tools? And verify them that way?
But, perhaps there's a nondestructive way.
Short of putting every chip under an electron microscope you can't really guarantee that either
Functionality testing could verify known behaviors, but could never formally prove the non-existence of unknown, hostile behaviors.
- "time bomb" style hostile functionality that only unlocks after a certain time
- hostile functionality that can be remotely unlocked by obscure behaviors. think: more advanced versions of port knocking, specially (mis?)crafted TCP/IP payloads
- etc
Even really-high-profile open-source security suites have seen critical bugs that have been around for many years. Being open source is a good start but it's hardly sufficient to guarantee anything about the supply chain. The opposite may actually be true in some cases.
How is everything you just described not "politics"? In fact it is the epitome of political action, and this doesn't make it of lower quality thinking. China has been identified as geopolitical adversary, and all decisions flow from that distinction.
"The specific political distinction to which political actions and motives can be reduced is that between friend and enemy." - Carl Schmitt
They took what had been viewed as simply a free market, or technology, or economic competition and applied "politics" to it.
Here is 2012 story from the Economist – Who’s afraid of Huawei?
https://www.economist.com/leaders/2012/08/04/whos-afraid-of-...
And the supply chain issues alone are alarming enough, if your high-tech military (and its vast civilian tributaries) rely on chip factories within easy bombing distance of your largest geopolitical competitor.
During the last administration there were multiple reports of Huawei hardware containing backdoors, which were originally criticized by the mass media; a Bloomberg piece comes to mind. I don’t think that the political nature of the initiative has changed at all. It has always been about national security.
This is not just about security in a narrow definition, but in a large part about ensuring that mastery of strategic functions remains with European firms.
Like armaments, telecommunication infrastructures are not a normal market.
I don’t disagree, but how far are we going to take this? Under the strategic regime of 超限战, is any sector a “normal market”, or do all sectors take on strategic significance?
At it's core, the world absolutely cannot trust China. Because Huawei is a de facto company owned by the Chinese government, it stands to reason that the distrust must be extended to Huawei. The product may be good, but China has very little credibility anymore, and should absolutely not be trusted.
Should you really trust a modern nation? All three nations I've mentioned prove that they spy on their own and each others citizens.
Its been well established that encryption standards have been tampered with from the outset, all our modern CPU's exploitable microcode, if not backdoored.
I don't even consider this a conspiracy, from a strictly technical perspective, if it's possible, its probably either been tried or fully implemented to exploit.
I prefer a revolving door of elected leaders more than a false democracy. It's more the non-transient "state" that worries me how we get to elect our representatives, but many of their staff are in practice there across many terms influencing the direction of the country across their career[1].
I prefer countries with a better track record on human rights and freedoms than the CPC.
[1]: Edward snowden talks about this in his book Permanent Record
Because the United States track record on human rights and freedoms is so much superior?
The US keeps trying to paint it as if the CCP decided (for some reason) that what would best help their goals is to kill millions of their own population and plunge their country into a food crisis.
It would be like the CCP pretending like the mass deaths of the indigenous people of America from smallpox was intended genocide by the Europeans instead of a consequence of the lack of knowledge of microbes and the lack of domesticated animals for the indigenous peoples, except at least that lie is some level of plausible.
The difference is that many of us believe that the authoritarian communist style of government they have causes these issues. No one believes that the US government of the time causes small pox.
Now there maybe a good argument about the profit motivated system not placing sufficient value on human life over growth & exploration.
The beauracrats were ironically sent to those rural communities precisely because Mao was worried that the government was becoming overly Byzantine in it's structure so the motivation was in fact to flatten power structures. The problem is that those bureaucrats were motivated to misrepresent the level of success the agriculture project was having out of a desire for increasing their standing.
Mao primary fuck up here was in assuming that these cushy officials would somehow be "purified" by being forced to interact with the salt of the earth rural people. In fact, they just recreated the social hierarchies that they were used to prior to the revolution - using Mao as their justification which would have been fairly effective since he was fairly beloved in the rural communities at the time prior to the cluster fuck that was about to unfold.
Ultimately, the real lesson is that the myth of the "strong leader" is innately counter revolutionary. Mao should have realised this since he had studied some anarchist theory as well as what happened with Lenin when he decided to patronise his entire population and murdered all the independent worker communes and any chance of democracy in the post-Tsar Russia.
Mao tried many experiments including trying to form equitable arrangements with capitalists and land owners, and a national day dedicated to facilitating criticisms of the government. Ultimately though, a combination of ego and niavity ruined what could have been a far more successful and less destructive revolution than what happened in Russia.
Of course the modern day CCP is so byzantine in structure and dehumanising that even Mao's worst nightmares couldn't have imagined it.
As for crimes abroad during the period you selected, China actually annexed an entire country (Tibet).
None of this is to excuse US failures to defend human rights and civil liberties, but China is in a whole different ballpark.
I'm not even sure what this is trying to do except lowballing numbers? African Americans were not just killed, also not only "152", they were assassinated and locked up as political prisoners [0].
In places like US occupied Japan, it was weirdly enough only black soldiers that got court martial and executed over the blatant mass rapes that were going on [1].
> As for crimes abroad during the period you selected, China actually annexed an entire country (Tibet).
As opposed to the US, who never annexed any countries? I wonder how the people of Hawaii would feel about that claim, or any of the people in the dozens of countries the US has bombed to rubble and left with mines and unexploded ordnance for many future generations to worry about? At least they didn't get annexed! At least most of them didn't.
> None of this is to excuse US failures to defend human rights and civil liberties, but China is in a whole different ballpark.
"Failure to defend human rights"? Wow, that's some seriously weird language you are using there to handwave away the fact how the US government didn't "accidentally" commit atrocities but in many cases committed them with full intent.
Tbh it's saddening to see these "American exceptionalism!" response on HN out of all places.
[0] https://digitalcommons.law.yale.edu/cgi/viewcontent.cgi?arti...
China's stance on freedom is a calamity and the magnitude and impact of its state policies is one of the great tragedies in human history.
[1] https://www.un.org/en/chronicle/article/freedom-expression-f...
This is a world of difference than a 2021 report of torture and sexual assault of Uyghurs[1]. I think the most damning part to western cultures is just that we were willing to go to war over this happening to Jewish people, but not willing to do it over Uyghur people.
*: (i'm careful to not say Chinese, because there's a collision with race and this is not a genetic thing, there is actually many good aspects of long standing Chinese culture!)
[1]: https://www.cnn.com/2021/10/04/china/xinjiang-detective-tort...
Even if the US government is spying on us, that is not a good reason to also allow China to do it.
Yes, and it's not even close.
The IBC project has recorded a range of at least 185,194 – 208,167 total violent civilian deaths through June 2020 in their database.[8][19] The Iraq Body Count (IBC) project records its numbers based on a "comprehensive survey of commercial media and NGO-based reports, along with official records that have been released into the public sphere. Reports range from specific, incident based accounts to figures from hospitals, morgues, and other documentary data-gathering agencies." The IBC was also given access to the WikiLeaks disclosures of the Iraq War Logs.[9][87]
Iraq Body Count project data shows that the type of attack that resulted in the most civilian deaths was execution after abduction or capture. These accounted for 33% of civilian deaths and were overwhelmingly carried out by unknown actors including insurgents, sectarian militias and criminals. 29% of these deaths involved torture. The following most common causes of death were small arms gunfire at 20%, suicide bombs at 14%, vehicle bombs at 9%, roadside bombs at 5%, and air attacks at 5%.[88]
The IBC project, reported that by the end of the major combat phase of the invasion period up to April 30, 2003, 7,419 civilians had been killed, primarily by U.S. air-and-ground forces.[8][86] " -- https://en.wikipedia.org/wiki/Casualties_of_the_Iraq_War#Ira...
So about 7k directly attributable to US forces, a very large multiple of that due to instability, insurgency, and crimes. I'm not sure that's the most fair take on US culpability vs CPC direct action against Uyghurs .
So about 600 thousands well documented extra deaths attributable to US forces - because without US invasion none of that would happen. How does that compare to Uyghurs, which are - differently from their bretheren in Iraq - not being systemically killed off?
I wonder how the M-series Apple chips will do with this over time. The predecessors have done OK so far, but are definitely not bulletproof. As these move up the stack, I wonder how it will go.
The scare quotes here are completely unnecessary and inappropriate. A formal extradition request was made by the US government and Canada was treaty-bound to follow it.
There were formal fraud charges against Meng Wanzhou filed in the US and since there is equivalence in Canadian law (often a prerequisite for extradition), there was no legal reason not to proceed. There was no '"asking"' involved.
* https://en.wikipedia.org/wiki/Extradition_case_of_Meng_Wanzh...
https://www.zdnet.com/article/fcc-details-1-9-billion-progra...
It is called the 5th Amendment of the US Constitution
> .... nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation.
The US government decided to make a judgment call on the legality of Huawei; the US government in keeping with the Law, paid just compensation to the owners of the equipment.
It is the right call to make.
If we enable E2E encryption on the end points, why do we care if Huawei makes it since the local gov't retains local monopoly of force? The reasons I can think of are:
- meta-data - denial of infrastructure. This is a big reason and a good enough reason.
Aside from reason number two, I really don't see the security threat. Not to minimize the threat of meta-data, but I think, on a national level, it too is solvable for the sovereign (by, for example, having phones make fake random calls to each other to poison the information)
EDIT: For the record, my question is genuine - I really want to understand this - and not some backhanded way to defend Huawei
Very interesting. I knew that state actors syphon everything, but I assumed it was since they can afford and it's a Hail Mary if they stumble on a breakthrough or a side channel. Some further Qs:
- What's near term? - What's in the far term? - I thought that encryption could be made arbitrarily more difficult to crack at little cost. Is this not the case? - Does this future assume quantum computing is feasible?
Finally, if encryption is no longer believed to be safe in the long term, shouldn't we be moving towards making one-time pads practical? Given modern data storage densities, it's not that unpractical for many use cases (say embassy communication, etc)
If Chinese intelligence services want information on a certain politician or business leader they're more likely to skip the decryption nonsense and just recruit one of the target's associates as a spy.
The US already puts tech sanctions on China. It is not at all hard to imagine China reciprocating.
And, even if they never actually do anything -- once our telecom system is mostly Huawei gear, they can now use it as a political chess piece against us. And on the opposite end of the spectrum, if we hypothetically go to war, they unquestionably would use that power to their advantage. All of our public/government services rely on functioning telecom networks.
China does the same stuff. They know if we go to war, we're likely to cut them off from GPS service, which is why they have their own system: https://en.wikipedia.org/wiki/BeiDou
As for denial of infrastructure, that's possible if we're running huawei software... in which case don't? Is software really their strong point anyways?
Whiskey Tango Foxtrot?!? Tons of perfectly good, top notch quality and 100% reliable RF gear are going to be destroyed because they fear there is spyware contained in the digital chips? I totally understand the arguments, but it's like throwing away a car because one doesn't trust the brakes. Just strip out the logic and sell the rest! Pollution aside, this is an insult to those who struggle to buy RF parts because of the shortage prices.
Even if the government finds one, they won't say it out loud. Nobody would hold them accountable. You cannot just incite WW3.
It is suboptimal but probably the best that it can be.
Remember the Malaysian airline that was shot down? I remember.
Isn't this arguably what happened with the SuperMicro hack and the subsequent denials?
Remind me: How many of these chips were actually found and presented as evidence? Not a single one, yet to this day this story remains alive and repeated...
Did Snowden incite WW3 when he blew the whistle and delivered literally troves of evidence?
> It is suboptimal but probably the best that it can be.
That's just the same old "You just have to trust the government/intelligence services, they can't reveal their evidence/sources without endangering them!".
After decades of civilians getting droned and innocents getting tortured I think we should maybe have learned something from trusting such accusations from institutions who do not only have a history of lying, but literally a agenda to do so.
Particularly when timing wise most of these accusations fit very neatly into a pivot from the ME to Asia while also serving as a bit of "whataboutism" for the recent nasty reveals coming out of the Five Eyes camps in regards to human rights abuses and mass surveillance.
They’re saying “org X wouldn’t tell us even if they found evidence”
However, on Capitol Hill, I think the idea is more to harm China than protect. I remember that the Washington metro trains were almost blocked because they are built by a Chinese company. Someone in congress dreamed up a Tom Clancy plot where the Chinese could bring down Washington by hijacking their transit system.
Assuming that you know what your exact attack surface is is a pretty clear sign that you are very vulnerable to attack.
But hey: The poop was thrown, some of it stuck, and now you are repeating it as established fact, when even the sources named in the Bloomberg piece found it quite lacking after publication [0]
So the narrative successfully did it's FUD job, and here we are under a post about yet another Bloomberg headline that nobody even questions in the slightest.
I wonder if some data center workers received a list of serial numbers that had to fail in the next few days and get decommissioned.
Maybe the request came from the same people operating exit checks in the worker's home country.
There's no way of knowing.
We are talking about dozens of data centers here, thousands of server racks, across half a dozen different companies and geographically spread pretty much all over the US.
Pulling that off would require a massive conspiracy involving hundreds of people, in addition to China being able to manufacture magic super tech that's even too advanced for the US.
> There's no way of knowing.
Sure there is a way of knowing: Show such a server board with such a super spy chip. But as long as we lack such extraordinary evidence such extraordinary claims should be taken with a massive grain of salt and not given the benefit of the doubt.
Particularly when they come out of a government/industrial complex that has a rich history of lying and making up stuff to serve their particular foreign policy narrative.
It would be exceptionally irrational for the US to utilize the telecom equipment of a quasi enemy nation that is all but guaranteed to be a future enemy. It doesn't matter whether anyone likes those terms or not, that's how the US Government is increasingly viewing China - and vice versa - and that's what is coming.
There are certain things that a country, or group of allies, absolutely should retain control over. Communications infrastructure is absolutely one of those things.
There is a reason China and Russia both have their own GPS alternative.
There is probably no good reason to distrust Huawei. But equally there is no good reason to trust Huawei.
Backdoors? Being caught red handed doing espionage? Cozying up to bad actors like North Korea and Iran?
It simply isn't possible - any more than you could get an audit guaranteeing the Linux kernel is bug-free.
Are we talking about Huawei here or any number of US companies?
You'll probably feel a need to shit on a flag when you realise that an allied Swiss company (ABB) sold North Korea a two nuclear power plants when Rumsfeld was on the board of directors.
https://www.swissinfo.ch/eng/rumsfeld-was-on-abb-board-durin...
The reason the press focusses on it so much is that it is, thus far, the only real step that the west is taking against Chinese hegemony. It's expensive and it's real. The rest of Cold War 2.0 hasn't really started yet. A couple of Mikes, a couple of tariffs, sure, but realistically if we really snap into a true standoff with China it's going to absolutely devastate the world's total economic output and stability.
I suspect it has been raging for some time now, online, by bots and so called shills in the form of information warfare.
For example:
[1]: https://en.wikipedia.org/wiki/BYD_e2
This car looks like a decent entry level car, 190-250 Miles. starting at around ~16k. Even if it sells for 25k in the US, it seems like good value.
The issue is that China is beginning to aggressively take out interest in Democracies in their sphere: first Hong Kong, and everyone knows that Taiwan is in their crosshairs now.
We didn't (and wouldn't) go to war over Hong Kong. Taiwan however... that's different and is truly a serious threat.
---------
If anything: additional trade and cultural exchanges are needed to foster a spirit of competition / cooperation even in the face of our nuclear weapons being trained upon each other. We don't really know if the Moscow Circus prevented a US / Soviet nuclear exchange... but maybe it did??
Surely they will then become national security threats?
$16k is great though. The base Nissan Leaf is $27k for 150 miles. At the same time, I'm not sure how much importing it would raise that. If, like you said, it sells for $25k in the US, that's a decent value if it's other features are comparable to a base Leaf, but I don't think it would decimate the competition.
Didn't Nortel go under because of accounting fraud?
Huawei only started releasing competing products years after Nortel went bankrupt.
It's sad, but this is one of the only avenues I can imagine that will bring real benefits and change for a lot of Americans.
Post-WWII, the ownership class had to offer a good deal compared to the Soviets, lest they risk communism coming for them, too. They had to provide working people opportunity and had to help build a thriving middle class in order to stave off sympathy and collaboration with the USSR.
Today, if owners don't want Americans to be bribed by the CCP into spying for them and handing over the IP they own, they're going to have to offer Americans another good deal in comparison. That's my optimistic take, but I can also see jackboot tactics being implemented instead of raising Americans' standards of living.
That said, helping Iran shouldn't be a crime until they actually pose a tangible threat, and at my little level, I think the US is being way too strict on them, and I dont dislike Huawei trying to help them... as long as we're able to control the risk and focus them rather than have it blow up in our face "US in Afghanistan"-style.
What's incredible is how submissive Trudeau was.
The charges were completely made-up yet he couldn't secure their release for three years. That's weak.
It's like your daddy wants you to take the neighbourhood bully's toy, so you stole his toy, and now the bully came and took two of yours. What are you supposed to do?
https://thediplomat.com/2019/02/the-huawei-dilemma-insecurit...
> The findings to these lines of inquiry proved troubling to the Intelligence Committee. The probe examined Huawei’s and ZTE’s ties to the Chinese state, including support by the Chinese government and connections to the Communist Party of China, and their work done on behalf of the Chinese military and intelligence services. For instance, Congressional investigators were concerned with the background of Mr. Ren, Huawei’s founder, who had links to the 3PLA – China’s signals intelligence division – and the Communist Party, such as serving as a member to the 12th National Congress. They did not find credible claims or evidence that the company was, in fact, an employee-owned and controlled enterprise or had an independent board of directors.
> Instead, the Intelligence Committee found that the Chinese government and Communist Party exerted influence over and supported Huawei as a “national champion.” For example, Huawei admitted that an internal Party Committee existing within the company, consistent with Chinese law, but refused to discuss or describe the role, membership, or impact of this group on corporate decision-making. Huawei’s failure to provide further detailed information explaining how it is formally regulated, controlled, or otherwise managed by the Chinese government undermined, in the view of Congressional investigators, the company’s repeated assertions that it is not inappropriately influenced by the Chinese government.
> Huawei also refused to provide answers to direct questions about its financing and connections with Chinese state banks, nor did it provide internal documentation or auditable financial records to evaluate its claims that any financing arrangements comply with standard practice and international trade agreements. In support, Congressional investigators cited the earlier finding of the U.S.-China Economic and Security Review Commission that enterprises like Huawei rely on generous state-backed financing to make an investment project in a new market viable. To the detriment of U.S. competitors, financial subsidies from the Chinese government can enable its national champions to penetrate markets by offering products below the costs of production.
> Additionally, the Intelligence Committee found that Huawei exhibited a “pattern of reckless disregard” for the intellectual property rights of U.S. companies. Congressional investigators cited Huawei’s settlement in civil litigation with Cisco, in which Huawei agreed to remove certain products from the marketplace due to violations of Cisco’s intellectual property rights. Whistleblowers – former employees of Huawei – also offered testimony that the company deliberately used the patented material of other firms. In the judgment of the Intelligence Committee, these issues with intellectual property rights raised broader concerns of Huawei’s compliance with U.S. laws in general.
Not just US companies. Huawei has stolen a ton of Nortel IP. This is largely the reason for their 5G tech edge[0]
https://nationalpost.com/news/exclusive-did-huawei-bring-dow...
The US government supports Cisco, and its diplomats are used to sell Cisco products. The forced replacement of Huawei equipment is an example of that.
If China were doing diplomacy and passing legislation that made US products illegal internationally, it would be worse than any of the accusations made here against China.
Only if you're already convinced that China and its people are evil, and that their winning an economic war against the US is a sign of the end times, will this reasoning convince you. China has triple the population of the US; it should be doing better.
I have been living in Asia and for the past several years have lived approximately 100 miles away from the Chinese shores in a free and democratic country that is in grave danger because a man who can't stand being compared to a cartoon character and his sycophants believe that it belongs to them.
The US is not the land of saints, but to anyone who feels the urge to engage in whataboutism regarding China, I encourage you to read about the history of the CCP, what it has done and continues to do to the Chinese and Tibetan people, its ongoing genocide of the Uyghurs and what its goals are for the Indo-Pacific.
> China has triple the population of the US; it should be doing better.
Doing better by what metric? Look at China's GDP per capita. The country is desperately trying to escape the middle income trap and a lot of the growing tensions in the region are related to the fact that the real picture of what's happening in China is not as pretty as the one the CCP projects.
>This can be summarized as "The Chinese Government Supports Huawei" + a lot of appeals to authority and claims of refusals to answer arbitrary questions that US companies certainly wouldn't answer if China asked.
how can you make this statement while ignoring the difference is basic relationship fundamentals between US corporations and the US government, and Chinese corporations and the Chinese government? the two are nowhere near equivalent.
1) Huawei had a tech / competitive lead vis a vis western firms, so those firms have been pushing / lobbying / this narrative of distrust around Huawei.
2) Huawei has done itself NO favors by just ridiculous actions - I think not realizing they are trying to sell into a western market where some of these stunts don't come across so well. In China helping N. Korea not a big deal and makes sense, China doesn't want N Koreans flooding over border. But then I thought the claims that no assistance etc offered was silly, just say yes, for x reasons we helped y country with their telecom.
> There is a reason China and Russia both have their own GPS alternative.
As does the EU (ie Galileo).
> There is probably no good reason to distrust Huawei.
Here I disagree. Chinese companies are extensions of the state and tools for domestic and foreign policy to a degree that Western companies simply aren't. China's massive censorship policy doesn't exactly instill confidence in the principles of openness or independence either for either the Chinese government or the companies that enable these policies.
NSA paid RSA Security $10 million in a secret deal to use Dual_EC_DRBG as the default in the RSA BSAFE cryptography library[1]
Juniper routers had an apparently deliberate Dual EC backdoor allowing VPN traffic to be decrypted.[2]
I'd say that there is probably more evidence of the west putting state-level backdoors in things than there is of China doing so. (although there may be sampling bias in this!)
[1]: https://www.reuters.com/article/us-usa-security-rsa-idUSBRE9... [2]: https://eprint.iacr.org/2016/376.pdf
https://upload.wikimedia.org/wikipedia/commons/8/89/Room_641...
I don't believe this. Nearly anything complex and networked, after a few months investigation by a good security professional, will have a good number of exploits found.
These could be plain old bugs, or they could be planted backdoors. (usually indistinguishable)
Even after months of effort, there is a high probability there remain undiscovered security issues (either deliberate or accidental) that more effort would have found.
For that reason, I don't believe any claim when they say "nah, we couldn't find anything". They either didn't look, or don't want to reveal what they found.
Further, when America's anti-Huawei panic started HMG were looking for an excuse to ban Huawei kit. If problems had been found it's likely they would have been mentioned.
Unless you have access to secret information and are for some reason burning your life down on HN, you have no idea what they found or didn’t find.
That's not true. GCHQ looked at source that was provided and found many unpatched vulns, and then found that the firmware binaries were not matching the source that was provided (with a single exception), so only Hwawei really knows what their devices do.
The data you show isn't proof of anything other than ineptitude of western agencies and the freedom of the press in the west. Go look for ICMB and warhead leaks, you'll always find better and more extensive documentation for NATO weapon systems. Does this mean the former communist block had no such weapons? No. It has to do with freedom of press and the legal system in the west making plans and docs public knowledge compared to a pretty locked down system in Russia and china.
At no point was any surveillance detected on any kit.
Removing it all (as opposed to just the "smart" kit) is extremely costly and if security was the real concern, not worth it.
They did bug the african congress but they were invited to set everything up in that building and nobody paid attention to anything they installed.
I suspect it's an attempt to wage "economic" warfare. Under WTO rules national security is a virtual get out of jail free card for protectionism. Huawei had just recently proven that China can overtake western technological capabilities in a key industry. That's the point when America flinched.
It also explains why they bullied all their allies into taking out all the tech all at the same time after years of seeminglh not being concerned about their own networks (let alone their allies) and without any evidence of a breach or anything.
If the US implements all Huawei equipment, and China sanctions the US from receiving support/updates/parts from Huawei (or worse, go to war and use it as a weapon), then the US telecommunication infrastructure is at risk.
Mass population is moved by fear, but is that how concordance is manufactured across the executives of a set of countries: a few terrifying top-secret presentations, and IC has successfully reputation-assassinated a foreign company? Why would these countries agree if there was no breach and a cheaper price? What offer or threat besides a more expensive but more secure infra? I suppose if you view telcoinfra as defense assets then it's a no-brainer, but was this the calculus? Blackmail/Mafioso-tactics would be a good one, maybe: You have to buy from us, or we will reveal/do such-and-such horrible thing.
But if it's true this is economic, not security, and also that Huawei has superior value for money, then is it not just these countries accelerating their already decaying infrastructure, for the sake of pride?
"The phones are down." "Yeah, whaddayagonnado? At least we're not paying the Chinese to make them work."
Replace phones with other critical things China makes better for a better price, and the future of these countries may look like the past of the former-Soviet ones: a whole bunch of weird anachronistic tech resulting from an (in this case self-imposed) embargo. But at least it will be 100% built by subjects of approved countries. I suppose that is one strategy to fight back against the dominance of Chinese industry: just outlaw it.
The hilarious thing is, probably all these "approved suppliers" will have to purchase significant inventory from what is essentially Huawei's supply chain anyway. Seems much more like the tail wagging the dog, with corporate dishonesty dictating so-called natsec policy. Could it really be so twisted?
Governments don't operate exclusively through sticks. The US has plenty of carrots to give out.
It should be noted that up until early 2020, US campaign against Huawei had spanned 10+ years long, and only secured a few committments to ban Huawei, not even all of FVEYS. It was a spectacular failure. It wasn't until successive US sanctions against Huawei access to semiconductors that countries relented, not due to security concerns but Huawei's ability to supply hardware long term due to sanctions.
Most major corporations deal with this by just registering IP in multiple jurisdictions simultaneously and litigating internationally, which can also be done in China just as you would do it in France or the UK. Redundancy is easier to manage than cross-border cooperation with foreign court orders.
That may be true in the strictest legal sense when a Chinese company is the one doing the stealing from a Western corporation. But in reality, that's so laughably incorrect that it makes me question why you said it.
Put simply, American courts have no authority over Chinese in China, Chinese courts have no authority over Americans in the US, and our courts do not cooperate reciprocally as they do in other countries with alternative diplomatic and legal relations.
Fortunately, this is of no significant barrier.
It is not a barrier because we, in the US, can ban their hardware anyways, and cause serious economic damage to them anyway.
So it doesn't particularly matter if we use IP law itself, in the courts, against china, when we have other options, such as simply banning their products in this other way.
No we wouldn't. Literally we are commenting in an article, about what I am suggesting is happening.
So the stuff that the article says is already happening, is what I suggested.
Could it go faster? Maybe. But like I said, we are literally commenting on an article, about how US telecoms are being required to replace certain equipment.
To my knowledge this has not previously been used as punishment for theft of trade secrets (Hwawei was sanctioned for doing business in Iran), but the legal mechanism is there.
So for example, in France, there are many acts which are trademark infringement in France that are not trademark infringement in the US. A Frenchman can accuse an American of trademark infringement for an act that is not trademark infringement in the United States, but is infringement in France. They can bring a lawsuit in France, win, and potentially enforce that judgment on assets in the US with the cooperation of an American court despite the fact that the American did not, by the definitions of American law, infringe on anyone's intellectual property.
There are no such cooperative arrangements between the US and China despite recent attempts to set them up. There are also only limited agreements on what is and what isn't permitted.
We hear that the device was sending uploads to China in the middle of the night. But what type of uploads? And was it firmware based, or OS based? That whole Hussein(-Addis affair just seems very suspect to me.
There are 1000 different ways they could have done it.
I too would be interested in hearing more though.
Free software might be an exception, but free hardware equipment really sounds suspicious.
Having spoken to someone involved in the investigation, it really did happen but like anything this politically sensitive it was quickly hushed up to avoid making it more of a diplomatic incident. The AU had tried to prevent the news from leaking in the first place.
That's quite typical for espionage, where unless there's a desire to publicly burn a few bridges countries would rather have it handled quietly through regular diplomatic channels.
Generally, trusting Western media on Africa reporting is never a good idea. But at the end of the day, this, and Snowden's revelations show - if you don't make it, then you don't own it.
[0] https://www.lemonde.fr/afrique/article/2018/01/26/a-addis-ab...
According to the person I spoke to on the team that responded, and helped set up the new replacement system and network, there had been warnings for years about the adoption of the system and the lack of any real monitoring, but those were ignored because it was considered politically sensitive to double-check on what the Chinese had provided.
It was a new member of staff who did their own experimentation without authorisation who found it and sent it up the chain, to point where it couldn’t be ignored or hidden anymore. Mostly because that made the delegations aware of how terrible security was, whereas before it seems they’d assumed the organisation had that covered.
Here I was thinking it was because Tony Podesta et al were involved with keeping them clean in the first place!
All it takes is one firmware update.
[1] https://www.washingtonpost.com/context/huawei-cybersecurity-...
All it takes is one tiny bit of proprietary software in the build chain that behaves non-deterministically (and they probably have several) and that's it. No equivalence until you rip it out and replace it. That's an expensive ask.
I'd be surprised if any vendors have achieved this. Hell, Cisco source code is probably riddled with spyware that they could spot at a glance, but "American IP considerations" 100% trump UK national security so I doubt they'd even get to see the source code.
I would love it if all of the vendors were made to have source code reviews and reproducible builds, but being realistic it's a standard that's only be demanded of Huawei. Even if they passed this high bar they'd only find some other excuse to rip them out.
Even so, unless you're talking about firmware for complex devices attached to the internet (what BT calls "the core", e.g. routers that they ripped out without much protest) you can still develop reasonable confidence that the firmware isn't exfiltrating sensitive data.
If it is simple and it is tightly scoped (e.g. firmware for an aerial) the spyware would have to be very clever and probably pretty obvious, assuming it was even possible. These kinds of devices are where the costs to rip out and replace every bit of hardware also became eye watering.
It's a question of eye watering costs of ripping out ALL of the very expensive hardware vs. simply vetting it & ripping out some of the more complex stuff that cant be vetted.
Nope. Scorched earth.
I have no doubt that they would have already bugged the west if they thought we wouldnt catch them in the act.
Which we likely would have.
Hence, probably economic, not national security (unless its about america wanting to install its own bugs in which case lord help us).
I think ripping them out is likely much cheaper.
likewise anything that can address anything else on a network.
If it's, say, a radio antenna? yeah, you can.
The core was the cheapest and easiest thing to replace. It's the rest - the stuff it would be implausibly difficult to hack while we are watching which is eyewateringly expensive to rip out.
You say that as if there haven't been clever spy techniques using crazy things that took ages to detect:
https://www.mentalfloss.com/article/584493/soviet-spies-bugg...
That's not proof of absence...
> I suspect it's an attempt to wage "economic" warfare. Under WTO rules national security is a virtual get out of jail free card for protectionism. Huawei had just recently proven that China can overtake western technological capabilities in a key industry. That's the point when America flinched.
That is a legitimate national security concern.
It's not like the US has to care too much about the WTO as the WTO has effectively been out of business for these past years due to the US blocking the appointment of new appeal judges [0]
So even if the WTO rules in favor of China, which it actually did on the steel tariffs [1], all the US needs to do is to appeal the decision and the WTO ruling will be stuck for all eternity in the appeals court, as that can't rule on the appeal without at least three judges.
[0] https://www.dw.com/en/wto-judge-blockage-could-prove-the-beg...
[1] https://www.washingtonpost.com/business/2020/09/15/wto-trump...
For one, it's now quite clear that all network infrastructure has backdoors controlled by the respective producing governments. I know for fact that alcatel do, for example. Why else the strict purge against huawei; a spy can spot a spy.
And I think there are quite serious implications for free and open markets in certain sectors.
I think it's the opposite. Without all of the anti-Chinese bluster, this would be seen as a simple government giveaway to privately-owned telecoms and domestic telecom equipment manufacturers. These press releases are being written by their lobbyists, not Huawei.
This isn't 'anti-chinese bluster' it's just critical thinking.
Have you thought through the consequences of what you are advocating? If EU starts removing US equipment, or Brazil or India?
US is not seen as a 'trusted ally' outside of English-speaking nations, certainly India, etc.
Not GP, but that's a good thing. Every country should secure their own telecoms. Resilience against spying from all sides.
Huawei pays for "sponsored" pieces in major media outlets. Politico, Reuters, Wired and others are paid by Huawei to run puff pieces, clearly labeled as "sponsored" content. Should a sudden spasm of inner dialog cause you to wonder whether the checks getting cashed have any influence on editorial decisions related to non-sponsored news you're expected to suppress that as much as possible and also keep it to yourself. Thanks!
I can understand why they remove network equipment and have no problem with that, but as a happy Huawei smartphone user from a non-US country, I'm still pissed that I need to change to another brand (and I don't see anything on the market that is as attractive, by far) because a foreign government decided to cripple this one.
I know, in theory I could go without Google, no one is banning Huawei from selling their phones to me. In practice, that's not feasible when e.g. your everyday banking apps rely on Google services. For all intents and purposes, a foreign government has banned me from using the phones I like. Imagine how many Americans would feel if new iPhones stopped being useful due to some foreign political offensive. This is similar (Huawei was the top-selling phone brand in my country). Thus, many people are interested in this kind of news about Huawei, even if they don't understand what network hardware is.
I know what you mean about bank apps working only on unrooted Android devices and only with Google Play Services. It's an OS- and device specific restriction, because the desktop website does not have these limitations (besides 2FA, which is understandable).
The solution for me was to wait until I have my laptop on me to do banking. But I understand that not everyone will have this ability due to the nature of their business or workflow.
We are a civilization based on sanctified violence: nowadays that sanctification comes from the news media.
Just to be clear: I am not blaming the media for war. I am also not definitively "anti-war" as I don't know precisely what that means.
So is the media.
Perhaps it is not on account of the tremendous PR efforts of Huawei that American media outlets appear to be on the same team as the Chinese communist party, on many fronts.
We literally do not know who owns Huawei, legally. We know that the CCP wants to monitor all communications, everywhere, do the extent they can. We know that de facto, the CCP has the final say, and can bend Huawei at will to do as they please and interdict without consequence (see: Jack Ma).
While it's obviously a much more complicated question, there are other issues for sure, but in the end, it's as easy as that.
The same should be held for any bit of critical software, and legislation should be introduced to protect citizens from CCP oversight in consumer apps like TikTok.
The 'smart play' would be to play into the financial incentive of the companies - most of them are 'profit first' and adhere to CCP policy mostly 'because they have to' but with maybe some degree of national loyalty in some parties. But just like Hollywood can be very easily manipulated with the threat of China-blackout into making films the way the CCP wants ... Zoom and TikTok will act reasonably with the right regulation and oversight i.e. 'All US data has to be kept in the US, in certain terms, with some regulatory process etc'.. If they are forced to keep a firewall between non-China and China users by host nations, it makes it easier for them to rebuff CCP demands for interjection i.e. "Sorry Xi, but the data is kept on servers in the US on a different business unit, if we pass data across borders they will shut us down"
Can we first protect citizens from Facebook, or if our companies commit crimes it's ok?
What is Facebook doing wrong? They're allowing people to share content. Some of that content, some people want censored, because they believe it has a negative influence, many (most) others would disagree. That's mostly it.
If Facebook, Google, Snap, Insta were all actively sharing all of their data with the Government, so that the Government could censor any and all criticism, throw people in jail arbitrarily, use FB to track down an ethnic group of citizens and throw them in brainwashing camps with no oversight, control the entire media, and stop people from accessing information outside the USA - then I would agree with your point.
I don't have a dog in that fight, I am reffering to them spying on people who have enevr even signed up tp facebook, enabling electoral fraud in Uk and conspiring with Google to manipulate the ad market. All of those activities are illegal and well documented.
Speaking of which, Huawei ads have been all over the NYT app for the last week or so.
It doesn't require malicious intent, just negligence, ignorance, lack of awareness and/or poorly worded instructions.
It’s like when your insurance company destroys your car, that just means selling it to a wrecker that parts it out and eventually crushes what remains. The vehicle can’t be registered but as long as you have a frame with a good VIN you’re good to go.
> All over the country, hardware from Huawei Technologies Co. and ZTE Corp. keeps American telecom networks humming. In the coming months, many of those networks are going to start ripping it all out.
I'm curious how this is going to affect the end user. Are some users going to have slower speeds?
Am I being too cynical? This seems high. Searching around about how long it takes once work begins, it appears that upgrade time is roughly half of that. Which leads me to believe that network operators will be perfectly happy to take the money while padding their expenses significantly.
Ban Tik Tok next, too. It's ridiculous that we allow foreign intelligence to operate social networks in the US. And before anyone says "ackshually" in response, yes, I think it's ridiculous that other countries let FB, Google and YT operate within their borders largely unimpeded, rather than force them to create local subsidiares whose execs could be hauled off to jail for violation of local laws.
It is just have to wake up on both sides not to rely upon each other. China should not use USA thing as well … if they can choose.
[0] https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
Same for a lot of other sectors and western companies on the background the Chinese market is by far their biggest market. I'm all for it that western companies lose their Asian market share means more internal consumption for Asian made products.
https://www.asiafinancial.com/ericsson-vow-to-win-back-china...
[0] https://web.archive.org/web/20180901090946/https://in.pcmag....
[1] https://web.archive.org/web/20181007013846/https://medium.co...
[2] https://www.politico.com/news/2020/02/08/mike-pompeo-governo...
> As many of you know, I was unceremoniously fired from PC Magazine on Sept. 20th, 2018 after over 30 years of service. I just figured it was the new people coming in and I was an unneeded throwback to the old regime.
Edit:
> but I personally haven't seen an actual use case for 5G to date
Incidentally, the most "compelling" use cases I've seen for 5g are always-connected smart devices that don't rely on WiFi. E.g. a smart TV where you can't pihole its advertising or view-tracking "features".
Imagine all those resources used to produce spying hardware that now will be decommissioned.