Live data from Hacker News

Can you trust Chinese computer equipment?

itworld.com

11–20 of 32 posts

Re: Can you trust Chinese computer equipment?

#11
My iPhone to-do app phones home with usage stats. After I sold 5000 copies I had a user inquiring about the suspicious network traffic. There is practically zero chance that something like this goes undetected - you just can't hide this stuff.

Re: Can you trust Chinese computer equipment?

#15
post #9
post #6

Earlier quoted context omitted.

I have also been thinking about this. Makes me want to null-route any traffic headed for China/Russia. However, I'm much more paranoid about the ripoff Cisco equipment made by Huawei.

I wouldn't assume the server is stationed in China.

No, but it's a start. Raises the barrier, especially in a potential future crisis where the PRC is disconnected from the net.

Re: Can you trust Chinese computer equipment?

#16
post #3
post #2

I've been wondering the same thing. But would it be so hard to detect? Presumably the information would have to be sent to some server sometime. While I personally don't really monitor outgoing traffic, I think some people do. So they should have noticed something by now?

It doesn't have to be active, it might be passive. A small bug in the networking chipset that crashes the machine with a given packet... ;-) It would be used only once. Like the nuclear weapon.

Yes, if you install a passive hole in nearly every computer made, well, having those computers phone home is silly. You call the target machine, when you want something.

Packet wouldn't have to crash the machine, just start up a more active trojan.

Re: Can you trust Chinese computer equipment?

#17
This kind of thing is playing with fire but that doesn't mean it can't happen.

There were reports that the Chinese attack on Google involved leveraging the law-enforcement door that is in some Google servers. And there's the problem - any time one entity opens a back door, they run the risk of letting another entity take advantage of it. Despite competing with the West and liking the idea of a quiet back door, the Chinese state would likely be unhappy with something the telegraphs their willing to completely steal all Western IP. That would put a bit of damper on Western investment (why Western companies ever imagined that the Chinese wouldn't just take their IP is beyond me, but I think a lot of companies still think their safe in China and that's a benefit to the Chinese economy).

Re: Can you trust Chinese computer equipment?

#19
post #3

Earlier quoted context omitted.

It doesn't have to be active, it might be passive. A small bug in the networking chipset that crashes the machine with a given packet... ;-) It would be used only once. Like the nuclear weapon.

Yes, if you install a passive hole in nearly every computer made, well, having those computers phone home is silly. You call the target machine, when you want something. Packet wouldn't have to crash the machine, just start up a more active trojan.

Hardware level trojan is relatively hard to develop.

I mean, it depends on what do you mean as a trojan. I think it is entirely possible to create a hardware trojan that sends some packets somewhere. It'd make a neat DDoS. :-)

Less likely is a classic trojan that gains control over your machine. Do not forget there are many layers between the userland and the hardware (eg, drivers, the network stack etc.).

It is a completely different story if evil Bob created both the hardware and the driver...

Re: Can you trust Chinese computer equipment?

#20
post #18

Can you trust American computer equipment? As far as i know, there are KNOWN backdoors in Cisco routing equipment. http://www.networkworld.com/community/node/57070

Simple answer, no.

http://www.wired.com/science/discoveries/news/2006/06/71022

When the writer asked a vendor of eavesdropping equipment about the legality of his products, the response ...

"Do you think this stuff doesn't happen in the West? Let me tell you something. I sell this equipment all over the world, especially in the Middle East. I deal with buyers from Qatar, and I get more concern about proper legal procedure from them than I get in the USA."

Post reply on HN