Meanwhile in the US we also have a long history of monitoring internet traffic, installing backdoors and allowing private third-parties to filter what we see online. Where do we get off critiquing the PRC? We should clean our own house first.
We do, but this is at a different, unprecedented scaled. As China vies for world hegemony, our future may look very bleak if China's Orwellian views are imposed at a global level.
Lenovo: Companies working in China may have to install local backdoors
61–70 of 90 posts
Re: Lenovo: Companies working in China may have to install local backdoors
#62Earlier quoted context omitted.
Isn't this just the physical manifestation of "Trusting Trust" - the seminal paper on backdooring compilers? It might be difficult, but who really inspects their own prints at a 100-micron resolution? https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7... - there's plenty of HN discussions to be found too.
The example in Trusting Trust was a very specific case: he modified the C compiler to replace a known bit of code in the login program. Along those same lines, you could possibly set up your minifab such that it inserts a backdoor into a particular RISC-V implementation. However, if I sat down and made my own chip, how would the fab figure out how to insert a backdoor? If you have code which can analyze a processor l…
You are aware that making a chip with any reasonable processing power either requires using existing designs, or teams of hundreds of people for several years, yes?
You're back to trusting trust. Or using toy computers.
Re: Lenovo: Companies working in China may have to install local backdoors
#63Meanwhile in the US we also have a long history of monitoring internet traffic, installing backdoors and allowing private third-parties to filter what we see online. Where do we get off critiquing the PRC? We should clean our own house first.
Re: Lenovo: Companies working in China may have to install local backdoors
#64> Does Lenovo put backdoors in if the Chinese government asks? > "If they want backdoors globally? We don't provide them. If they want a backdoor in China, let's just say that every multinational in China does the same thing. Even though not a direct answer, close enough. One could only hope to get a similar statement from Apple wrt iCloud so we aren't left with assumptions about lack of privacy.
While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time before this practice permeates into retail and OEM markets.
Re: Lenovo: Companies working in China may have to install local backdoors
#65Earlier quoted context omitted.
Last I checked, in the EU or the USA you don't disappear in the middle of the night never to be seen again because you are: -follower of different religion -saying the word "democracy" -critisizing a politician/the government so yes, first things first.
Really, does HN deserve that kind of idiotic post? You can walk around China an say "democracy" all day. You think they don't report on eg elections in the US on TV there? People in China complain about the government and laws all day. There is a lot wrong with China that they deserve to be called out for, but what's your goal with a post like that? Show the world that you don't have a clue about anything besides tec…
https://news.ycombinator.com/newsguidelines.html
Edit: specifically:
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
Re: Lenovo: Companies working in China may have to install local backdoors
#66Earlier quoted context omitted.
The example in Trusting Trust was a very specific case: he modified the C compiler to replace a known bit of code in the login program. Along those same lines, you could possibly set up your minifab such that it inserts a backdoor into a particular RISC-V implementation. However, if I sat down and made my own chip, how would the fab figure out how to insert a backdoor? If you have code which can analyze a processor l…
"made my own chip" You are aware that making a chip with any reasonable processing power either requires using existing designs, or teams of hundreds of people for several years, yes? You're back to trusting trust. Or using toy computers.
But maybe the hardware world is not have to be this way and this way only.
> No part of Kami need be trusted beside the formalization of low-level (Verilog-style) circuit descriptions; all other aspects have end-to-end correctness proofs checked by Coq. Hardware designs are broken into separately verified modules, reasoned about with a novel take on labeled transition systems. Furthermore, Coq provides a natural and expressive platform for metaprogramming, or building verified circuit generators, as for a memory caching system autogenerated for a particular shape of cache hierarchy, or a CPU generated given a number of concurrent cores as input.
> We have been developing a candidate official formal specification for RISC-V, which stands a good shot at being ratified soon as such by the RISC-V Foundation. The spec now includes virtual memory and is able to pass all the official RISC-V machine-code tests that aren't marked as specific to particular extensions. We should be able to boot Linux on the specification soon, running as a simulator.
> A verified processor exists providing all that functionality, though we are still working on debugging the specification, since the current version isn't quite able to boot an operating system (so the specification must be out-of-synch with software expectations somehow).
Re: Lenovo: Companies working in China may have to install local backdoors
#67> Does Lenovo put backdoors in if the Chinese government asks? > "If they want backdoors globally? We don't provide them. If they want a backdoor in China, let's just say that every multinational in China does the same thing. Even though not a direct answer, close enough. One could only hope to get a similar statement from Apple wrt iCloud so we aren't left with assumptions about lack of privacy.
iCloud in China has been hosted by a local licencee for a while. People who care about privacy are at least aware that the backend is no longer secure. While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time be…
I know you will say "you have to trust them", but therein lies the problem. There is no way for consumers to verify anything about their data.
Re: Lenovo: Companies working in China may have to install local backdoors
#68Earlier quoted context omitted.
We do, but this is at a different, unprecedented scaled. As China vies for world hegemony, our future may look very bleak if China's Orwellian views are imposed at a global level.
> As China vies for world hegemony China is not going to export their political system beyond the HK and Taiwan, unlike the US. > the country intervening in most foreign elections is the United States with 81 interventions, from 1946 to 2000
It's a case of which is the lesser evil. US's style of "imposing" democracy (and toppling it and replacing the government with puppets when it become socialist and/or unfavorable for US corporations) or Chinese totalitarianism.
Re: Lenovo: Companies working in China may have to install local backdoors
#69Earlier quoted context omitted.
iCloud in China has been hosted by a local licencee for a while. People who care about privacy are at least aware that the backend is no longer secure. While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time be…
How do I, as a US citizen, know that Apple isn't replicating my data to this Chinese datacenter? I know you will say "you have to trust them", but therein lies the problem. There is no way for consumers to verify anything about their data.
Re: Lenovo: Companies working in China may have to install local backdoors
#70Earlier quoted context omitted.
"made my own chip" You are aware that making a chip with any reasonable processing power either requires using existing designs, or teams of hundreds of people for several years, yes? You're back to trusting trust. Or using toy computers.
In the traditional world of raw Verilog, gate-level tuning, verification systems with millions of lines of code and all that, that's true. By the way, those hundreds of people will need a bunch of million dollar tools, hardware and software. And a lawyers dealing with the license and patents, if you are going to sell your chips - and of course you are going to sell your chips in traditional hardware world, except you…
At some point, you have to trust somebody - "build from first principles" is really only available for extremely well-funded players.
Also: "the specification must be out-of-synch with software expectations somehow". I see the hardware world hasn't changed at all :)