Can you trust Chinese computer equipment?
11–20 of 32 posts
Re: Can you trust Chinese computer equipment?
#12Re: Can you trust Chinese computer equipment?
#13Re: Can you trust Chinese computer equipment?
#14Paranoia will destroy ya. Maybe you shouldn't trust anything you didn't build.
Re: Can you trust Chinese computer equipment?
#15Earlier quoted context omitted.
I have also been thinking about this. Makes me want to null-route any traffic headed for China/Russia. However, I'm much more paranoid about the ripoff Cisco equipment made by Huawei.
I wouldn't assume the server is stationed in China.
Re: Can you trust Chinese computer equipment?
#16I've been wondering the same thing. But would it be so hard to detect? Presumably the information would have to be sent to some server sometime. While I personally don't really monitor outgoing traffic, I think some people do. So they should have noticed something by now?
It doesn't have to be active, it might be passive. A small bug in the networking chipset that crashes the machine with a given packet... ;-) It would be used only once. Like the nuclear weapon.
Packet wouldn't have to crash the machine, just start up a more active trojan.
Re: Can you trust Chinese computer equipment?
#17There were reports that the Chinese attack on Google involved leveraging the law-enforcement door that is in some Google servers. And there's the problem - any time one entity opens a back door, they run the risk of letting another entity take advantage of it. Despite competing with the West and liking the idea of a quiet back door, the Chinese state would likely be unhappy with something the telegraphs their willing to completely steal all Western IP. That would put a bit of damper on Western investment (why Western companies ever imagined that the Chinese wouldn't just take their IP is beyond me, but I think a lot of companies still think their safe in China and that's a benefit to the Chinese economy).
Re: Can you trust Chinese computer equipment?
#18Re: Can you trust Chinese computer equipment?
#19Earlier quoted context omitted.
It doesn't have to be active, it might be passive. A small bug in the networking chipset that crashes the machine with a given packet... ;-) It would be used only once. Like the nuclear weapon.
Yes, if you install a passive hole in nearly every computer made, well, having those computers phone home is silly. You call the target machine, when you want something. Packet wouldn't have to crash the machine, just start up a more active trojan.
I mean, it depends on what do you mean as a trojan. I think it is entirely possible to create a hardware trojan that sends some packets somewhere. It'd make a neat DDoS. :-)
Less likely is a classic trojan that gains control over your machine. Do not forget there are many layers between the userland and the hardware (eg, drivers, the network stack etc.).
It is a completely different story if evil Bob created both the hardware and the driver...
Re: Can you trust Chinese computer equipment?
#20Can you trust American computer equipment? As far as i know, there are KNOWN backdoors in Cisco routing equipment. http://www.networkworld.com/community/node/57070
http://www.wired.com/science/discoveries/news/2006/06/71022
When the writer asked a vendor of eavesdropping equipment about the legality of his products, the response ...
"Do you think this stuff doesn't happen in the West? Let me tell you something. I sell this equipment all over the world, especially in the Middle East. I deal with buyers from Qatar, and I get more concern about proper legal procedure from them than I get in the USA."