FBI investigation determined Huawei equipment could disrupt US nuclear comms
cnn.com
cnn.com
I am a bit out of date on the latest designs, but presumably antenna resonance, array phase (directionality) and radio spectrum are all controllable with software now. Any or all of these could be modified remotely and changed back to civilian cell parameters again in a matter of seconds. Additionally the firmware, and hence general capabilities, can be remotely updated.
Hence, one can no longer look at a device like a modern radio cell and say "this is designed to work in such a way". If you impounded it, took it to a lab, what you'd see on the bench may have no relation to how it operated a few days ago. Given also that traffic to and from the device may be encrypted all the way back to Beijing, the operation of the devices cannot be attested even in principle.
This is a serious general problem in modern security - one of unfalsifiability and plasticity of form and function. It applies as much to Windows and Apple computers as to Huawei.
Unless we quickly reverse the trend toward vendor-trust models that give over total control to unverifiable remote entities we're all going to be seriously screwed soon. This is going to play out in the Intel microcode debacle, in Apple's iron control over devices in the face of EU interoperability edicts, and on many more fronts...
And last I checked, our clinically insane UK government still hasn't fully buried the idea the Chinese might build us a nuclear power station over here!
I predict that such a law would also be very popular with the citizens because people hate it when an automated software update breaks their workflow. And remote car firmware changes could be quite dangerous, too. https://twitter.com/anjilslaire/status/1537622856724426752
And some companies have been pretty notorious with their bait and switch, like the ad-free Samsung $10k TVs that got "updated" with popup advertisements a year later.
And all that e-waste from IoT products that no longer work because the manufacturer decided to turn off their servers. https://twitter.com/doctorow/status/1516144514984923139
BTW, I like reading https://twitter.com/internetofshit just to feel lucky that I didn't buy any of it :)
But then how will network operators outsource all of their infrastructure maintenance to vendors? That's the problem.
We have this naive idea that companies running networks employ staff to manage their networks. In reality, it hasn't been like that in a while because there has been a tremendous push in the industry to outsource everything to third parties. So the person who owns the cell tower likely has no idea who is maintaining it, much less has that person on their payroll.
This should be a political discussion: Do we want US internet infrastructure to be remote-controlled from China, in exchange for cost savings? Or do we mandate US internet infrastructure providers to train their own US-based employees?
Looking at Comcast's 36% gross profit margin, I don't think they would have any issues employing +100 network engineers to maintain their phone systems themselves ;) They just don't want to.
If you catch any of your own device doing that, you report it to a government agency and they'll check in their database if your finding is new, and if it is, they will immediately pay you $10k and announce it publicly.
And then afterwards, the government can fine the manufacturer $100k to recoup their costs.
Also, most of the updates that people hate have been pretty blatant. Like when your TV starts showing ads when it was ad-free before, it is pretty obvious that something changed.
Not just that, for about a decade now I've had a thought that you could just have a chip "self-destruct" when a signal goes out and bam a chip re-writes itself to be bricked.
If you bake this into some common chip (or just include it in a firmware update), or something used in say backbone level network hardware, or something in millions of cellphones you could send out the instruction in some previously routine traffic to and from the mothership and then a clock starts counting down. You build in long enough of a delay to ensure you get most devices to receive the signal, say a week or even a month, and you suddenly cripple millions of devices and create mild to moderate chaos which gives gives you a leg up for an invasion or has a massive impact on the markets, or cripples internet access for a large area for weeks or months until hardware can be replaced.
Also, I expect enthusiast users and large companies to purchase similar devices as small telcos. Scorned network administrators are probably even better bounty hunters.
But yes, I was focusing mostly on the end-user aspect because if you want to create such a law, you need your citizens to like the idea.
It's not really practical or enforceable. If a world power wants to hide something nasty in silicon or software, a bug bounty program isn't going to cut it. Maybe if the government had a genius-savant who could stare at silicon dies and find malicious circuits.
For example, kidnapping people who may or may not have information and torturing them.
If the bounty got high enough, it would pose a serious risk to low-level Huawei employees.
And do you think a bounty would help against a Stuxnet type attack? Stuxnet did almost nothing until it would up in a very specific type of device.
No implementation is perfect and it just takes one determined clever person to break or weaken wpa2 a bit more and it would be chaos.
Banning the devices all together because they're not worth a dam and are a security nightmare when not setup correctly though.
Now there's an idea.
The 5G crowd just didn't research fully. They are still right.
That's fascinating from a psyops/infowar perspective.
As they say, "where there's smoke there's fire".
I've never followed any of the 5G conspiracy tommyrot, but isn't it odd that in all likelihood they're quite literally correct, but for simply the wrong ends?
Were I to don my master-manipulators black Pilgrim hat and apply some extra-strength twisting wax to my comedy moustache... I'd be be just delighted to insert such "almost true" ideas amongst a bunch of credulous idiots in order to suppress belief in my actual plan.
It is unfortunate but the situation with Huawei is a matter of great FUD. On the one hand, they probably are dodgy as any organisation & in league with the People's Liberation Army. The major risk they pose is doing precisely what the the US is doing with their spy network and the risks of that are well understood.
But on the other hand, while this may be a real story, but it is just one thread of a bigger story where the Asia keeps challenging the US's high-tech edge. CNN + the FBI is not a combination known for fair, honest and reasonable journalism and this could well just be stirring up muck, trying to discredit a superior Chinese solution.
The Chinese government has overt control over any Chinese corporation of consequence. This alone should be enough to disqualify Chinese telecom equipment from critical areas in my opinion. I'd expect the CCP to take similar precautions where feasible.
Or the failure could be on the command and control side like what happened in 1983 [1]. Soviet early warning systems malfunctioned and reported multiple ICBM launches. The officer in charge basically decided to ignore it and single handedly prevented the end of human civilisation. This was at the height of the Cold War before the Russian army was drained of competence. I can't imagine those systems are working as well as they did back then.
[1] https://en.m.wikipedia.org/wiki/1983_Soviet_nuclear_false_al...
If a newcomer is able to bypass those costs it will kneecap the cycle of innovation which requires certain profit margin‘s to afford armies of PhD‘s. Otherwise game theory says the system goes ‘poof’.
If you write that they could capture these communications, it sounds like they could be read. But these comms must be encrypted, right? This story is a bit clickbaity - by that standard, some hobbyist with an antenna can "capture" DoD comms. And they could "disrupt" them as well with a cheap signal jammer near the receiver.
Amateurs aren't running around the country placing transmitters near all the government comms. Also there's many types of encryption (onion routing for example) that depend on being able to intercept communications at multiple locations. Also there's still metadata that can be learned even without being able to read the comms directly, for example who's broadcasting at any moment. Even amateurs were able to figure out when Russia was launching missiles at Ukraine even from their encrypted comms, if you have a more advanced surveillance system in-country you can learn a lot more.
(I get that “pouch” can mean shipping container)
huh, that's why security is hard.
Everything is fine until it isn't, the war starts and reality checks comes in.
I feel I must be missing something big.
Also, in some cases the expected destinations have been hacked already, I'm guessing
> multiple channels for exfiltration
If they can send via wifi, it could be almost impossible to detect? So much noise in the wifi space?
These sorts of vague accusations have been made against Huawei for several years now, but to date, no one has ever produced a shred of evidence that Huawei installs backdoors on its telecommunications equipment. Huawei devices are installed all over the place, and it's not as if there's been a lack of scrutiny. In the UK, Huawei even submitted to regular audits by British intelligence, and nothing was ever found. Every claim that's been made has turned out to be along the lines of, "We discovered that Huawei uses industry-standard tools to update firmware on its devices, and the network operators have the ability to oversee the updates."
The accusations are pure assertions, backed up by a general suspicion of everything Chinese. This really began with Trump, and it's been sad to watch Western countries fall ever deeper into paranoia and hatred towards China. It's Yellow Peril v2.0.
> This really began with Trump, and it's been sad to watch Western countries fall ever deeper into paranoia and hatred towards China. It's Yellow Peril v2.0.
Canadians have been skeptical of Huawei since at least 2012.
https://www.cbc.ca/news/politics/former-nortel-exec-warns-ag...
I think it's a reasonable security posture to treat technology from a country you don't trust with suspicion. Especially when they have long history of hostile espionage.
- https://www.ctvnews.ca/mobile/canada/dnd-may-abandon-1b-move...
- https://www.cbc.ca/news/canada/manitoba/winnipeg-lab-securit...
- https://www.cbc.ca/news/politics/wanping-zheng-china-comapny...
People are saying both of those things, for the same reason. Do you not think that having unprecedented access to the data of civilians poses a risk to national security?
Modern technology (smart phones, apps, websites, etc.) collects a terrifying amount of information on people. It also exerts a tremendous amount of influence, be it Facebook or China.
I also think that writing off the concern as "vague accusations" misses the point. As the current top comment points out[0], it's nearly impossible to verify what a device is doing. And even if you were to somehow do a complete software audit, malicious behaviour could be patched in at any time in the future.
This is not an excuse to make accusations without any evidence. At some point, the people making these accusations have a responsibility to either show evidence for their claims or to stop making them.
Huawei chips are installed all over the place, and foreign governments (namely, the US and its allies) are intensely interested in what Huawei is doing. We even know from Snowden that the NSA hacked into Huawei's internal networks and read sensitive communications between executives.[1] If Huawei is actually surreptitiously intercepting and sending foreign communications back to China, there should be evidence of that. Just saying that anything is hypothetically possible doesn't cut it.
1. https://www.reuters.com/article/us-usa-security-china-nsa-id...
That's also one example I gave at a trivial case. One can imagine much more sophisticated cloaking.
You're weirdly implying every country is an adversary of every other. There's no good reason for "every country should manufacture its own entire telco stack," but it is reasonable for them to only source equipment from ideologically-aligned natural allies.
Isn't it? Ideology is a lie, people are all the same all over the world (except maybe for some peculiarities like western chauvinism). Everyone wants to live contented lives, be free, raise kids in peace and so on.
Every country should have it's own sovereign tech stacks simply to avoid effects of corruption or irresponsibility of global elites. Otherwise we see stuff like US' economic and sanction wars, which create pools of poverty, which inherently cause plunge of observance of human rights, which causes immense suffering of ordinary folk -- all that so someone could make money on something like cheap rare earth metals mining for selling electric car batteries.
Have we already forgotten that US dropped atomic weapons on Japan yet are now fast allies or that US supported the Islamic fundamentalism in Afganistan before now becoming enemies. US + Saddam bosom buddies in the Iran vs Iraq war.
The sample size is not exactly small.
Real life isn't some RTS game. If a flip like that happens, it won't happen very quickly.
Also autarky isn't even possible for most countries, and is probably a weakness for most of those that could pull it off.
> Have we already forgotten that US dropped atomic weapons on Japan yet are now fast allies...
That's an example of an enemy becoming an ally, so not exactly relevant.
> or that US supported the Islamic fundamentalism in Afganistan before now becoming enemies. US + Saddam bosom buddies in the Iran vs Iraq war.
Those are allies of geopolitical necessity, not "ideologically-aligned natural allies." For the latter, I'm thinking of things like NATO (maybe sans a couple of members) and "the Anglosphere."
Fair enough if that is your view, but at least own it
No, obviously not. I gave examples, and even one of those was broader than that.
> Fair enough if that is your view, but at least own it
Why would I "own" your straw man's view?
Obviously there are competitive problems there, but it's better than the alternative.
Either that, or, more easily, no 'critical' infrastructure from China, Russia etc..
You gotta buy it form US, Canada, Europe etc..
You can buy grain, toys and beef from China, just not 5G gear.
Every consulate - Chinese, American, you name it - is a hotbed of spies. The closure of the Houston consulate was just a political move by the Trump administration.
https://cset.georgetown.edu/publication/chinas-foreign-techn...
> HOUSTON AS A GLOBAL S&T HUB Before its closure in the summer of 2020, the Chinese Consulate in Houston, Texas was a major hub in China’s global S&T information gathering operation. From January 2015 to July 2020, Houston Consulate staff identified more S&T projects than any other PRC diplomatic post in the world, and referred 89 percent of the projects originating from the United States.56 During that time, the United States was the largest source of information technology projects targeted by Chinese S&T diplomats.57 From 2017 to 2019, the Houston Consulate cosponsored a series of “matchmaking” events with several Chinese technology transfer centers, attracting approximately three hundred U.S. businesses each year.58 Since the consulate’s closure in July 2020, the MOST bulletin of “international technical cooperation opportunities” has registered only one additional project from the United States, a virtual reality therapy company in Massachusetts.59
> From 2017 to 2019, the Houston Consulate cosponsored a series of “matchmaking” events with several Chinese technology transfer centers, attracting approximately three hundred U.S. businesses each year.
This is a very good example of how completely normal diplomatic activity is being cast as somehow malign. The Chinese government seeks foreign investment. Part of that involves the type of public events this passage is describing, in which the government invites a bunch of companies to a trade fair and pitches the idea of investing in China. The US does this abroad. Pretty much everyone does. This document is trying to blur the line between espionage and normal diplomatic activity.
There is actual espionage that occurs out of embassies and consulates around the world. This isn't it.
I'm sorry, what? The city that hosts the Christopher C. Kraft Jr. Mission Control Center is not a science and technology hub? There is science and technology outside of social media apps and internet ad surveillance tech.
Yes, it's not a particularly important hub in the US. Boston, SF, and countless other cities are more important hubs. Having one space mission control center does not make a city into the foremost American science and technology hub.
The Trump administration decided to close down one Chinese consulate as a political message. They probably chose Houston because closing the consulate there is less disruptive than closing, say, the NY consulate. When the Chinese retaliated, they also chose a relatively unimportant US consulate to close.
Practically every consulate and embassy around the world is crawling with spies. "Diplomatic cover" is a standard way of sending spies to a foreign country. That's not why the US would close down a foreign embassy.
The closure of the Chinese embassy, with a big announcement and almost no forewarning, was meant as a political statement. It came in the middle of an escalating trade war, initiated by the Trump administration.
The post facto rationalizations about the Houston embassy being some extraordinary hotbed of espionage were absurd on their face, and I'm surprised by the level of naiveté in this thread towards these sorts of official government explanations for what are obviously political moves.
Ignore the trump part. Protect USA interest. Just like china protect theirs. And when Taiwan invasion occurs see how much protection USA has may I note.
Trump is a dirty hand, a wake up call, … ignore the dirty and call part. Need the hand and the wake up guy.
https://www.cnn.com/2019/05/16/business/huawei-trade-war/ind... https://www.cnn.com/2018/12/11/business/huawei-apple-china-t...