Live data from Hacker News

Can you trust Chinese computer equipment?

itworld.com

1–10 of 32 posts

Re: Can you trust Chinese computer equipment?

#2
I've been wondering the same thing. But would it be so hard to detect? Presumably the information would have to be sent to some server sometime. While I personally don't really monitor outgoing traffic, I think some people do. So they should have noticed something by now?

Re: Can you trust Chinese computer equipment?

#3
post #2

I've been wondering the same thing. But would it be so hard to detect? Presumably the information would have to be sent to some server sometime. While I personally don't really monitor outgoing traffic, I think some people do. So they should have noticed something by now?

It doesn't have to be active, it might be passive. A small bug in the networking chipset that crashes the machine with a given packet... ;-)

It would be used only once. Like the nuclear weapon.

Re: Can you trust Chinese computer equipment?

#6
post #2

I've been wondering the same thing. But would it be so hard to detect? Presumably the information would have to be sent to some server sometime. While I personally don't really monitor outgoing traffic, I think some people do. So they should have noticed something by now?

I have also been thinking about this. Makes me want to null-route any traffic headed for China/Russia. However, I'm much more paranoid about the ripoff Cisco equipment made by Huawei.

Re: Can you trust Chinese computer equipment?

#7
post #5

The first thing I thought of was Trusting Trust[1]. If the system is untrustworthy down to its lowest levels, it can also cover its tracks completely or nearly-completely. [1] http://en.wikipedia.org/wiki/Backdoor_(computing)#Reflection...

Actually, as another poster points out, it's hard to fully mask outgoing network traffic unless you control the hub/router as well.

Re: Can you trust Chinese computer equipment?

#9
post #6
post #2

I've been wondering the same thing. But would it be so hard to detect? Presumably the information would have to be sent to some server sometime. While I personally don't really monitor outgoing traffic, I think some people do. So they should have noticed something by now?

I have also been thinking about this. Makes me want to null-route any traffic headed for China/Russia. However, I'm much more paranoid about the ripoff Cisco equipment made by Huawei.

I wouldn't assume the server is stationed in China.

Re: Can you trust Chinese computer equipment?

#10
post #7
post #5

The first thing I thought of was Trusting Trust[1]. If the system is untrustworthy down to its lowest levels, it can also cover its tracks completely or nearly-completely. [1] http://en.wikipedia.org/wiki/Backdoor_(computing)#Reflection...

Actually, as another poster points out, it's hard to fully mask outgoing network traffic unless you control the hub/router as well.

Yes, but e.g. data tunneled over DNS is pretty hard to detect. I'm sure the Chinese government could spare some (a lot of) domain names.

Also note that a network card with DMA access has pretty much free reign of the computer.

However, all this is a lot more complicated than just hacking the latest Windows hole; I doubt it would be cost-effective.

Post reply on HN