The government chose to stop publishing HCSEC reports after 2021. I'm unable to work out whether HCSEC itself is still operating or not.
[1] https://assets.publishing.service.gov.uk/media/60f6b6be8fa8f...
By the time any highly-technical topic makes it to the mainstream discourse, the details tend to get stripped out simply because none of the 70 year olds watching CNN or Fox appreciate the difference and none of the anchors or panelists know what they're talking about either.
We built this city
We built this city
We built this city on broken codeYou trust China over your own government? Move then.
I am old enough to have seen several instances where organizations had internal reasons for their decisions and chose to argue something completely different in their outward communication. Given that an exclusion of Huawei had the obvious side effect of protecting domestic markets, this leaves quite some room for doubt around this specific instance. You say it yourself that governments have mandates.
From that perspective it makes a big difference whether the Chinese have mostly secure back-doors or their software is just generally insecure.
https://www.cbc.ca/news/canada/ottawa/rcmp-chinese-police-st...
The US bans the sale and install of Cisco hardware? (of course not but from the context not clear)
A quick search found: https://www.euractiv.com/section/politics/short_news/uk-bann...
I live in the UK. This may have been part of it, but to think that a communist dictatorship that (to pick a random example) harvests organs from political opponents is above backdooring their own kit is beyond naïve.
But I guess it’s like you said: a political experiment.
Now personally I would say that this is a crazy idea from the jump, given the usual asymmetry between attackers and defenders. But even if you grant that it's possible, it requires that you begin with extremely high standards of code quality and verifiability. Those were apparently not present.
So yeah, even if they are equal, there are A LOT of reasons to spend the extra money.
Also, even if all providers provide equally crappy versions, it's still slightly more secure to prefer a vendor in your own or an allied nation. At least your interests are mildly aligned.
But really, they are massively worse.
The question being tested is:
- Do Huawei devices have the capacity for adequate capacity
Not
- Are Huawei devices better or on par in terms of security compared to other vendors.
These are completely different questions with completely different methods of evaluation. And honestly, there is no control in the latter. To have a control you'd have to compare against normal operating conditions and at that point instead you really should just do a holistic analysis and provide a ranking. Which is still evaluating each vendor independently. _You don't want to compare_ until the very end. Any prior comparison is only going to affect your experiments.tldr: most experiments don't actually need comparisons to provide adequate hypothesis answering.
Let China sell their telecom bullshit to all the poor people of the world - they will learn hard lessons.
Maybe I'm being pedantic, but that doesn't answer their question.
Obviously Windows will send more telemetry if telemetry it sent at all, because it's doing more stuff. Then again, Window's telemetry is nothing compared to what Huawei phones will send to the mothership, and Huawei phones are nothing compared to an Amazon Alexa. Not that any of that is relevant.