Live data from Hacker News

Lenovo: Companies working in China may have to install local backdoors

theinquirer.net

81–90 of 90 posts

Re: Lenovo: Companies working in China may have to install local backdoors

#81
post #76
post #64

Earlier quoted context omitted.

iCloud in China has been hosted by a local licencee for a while. People who care about privacy are at least aware that the backend is no longer secure. While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time be…

My brain's being a bit pedantic/dense about wording, so I want to clarify - are you saying that Windows 10 builds destined for Chinese governmental use are shipped to China in source form?

No. The source code is shipped to a system integrator based in China, vetted by both parties and under strict NDA, who then edit the code with required changes, compile and ship the binary to government users.

MS have, for a long time, allowed major customers to audit Windows source code on site but they are still forbidden from making copies. The whole setup is meant to avoid shipping source code directly.

Re: Lenovo: Companies working in China may have to install local backdoors

#82
post #67
post #64

Earlier quoted context omitted.

iCloud in China has been hosted by a local licencee for a while. People who care about privacy are at least aware that the backend is no longer secure. While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time be…

How do I, as a US citizen, know that Apple isn't replicating my data to this Chinese datacenter? I know you will say "you have to trust them", but therein lies the problem. There is no way for consumers to verify anything about their data.

Short answer is we will never know for sure. There is no reason or incentive for Apple to duplicate your data and it certainly breaches an assortment of data protection laws. Nevertheless you data is always one error away from being sent all over the world. Recall the incident when Cloudflare leaked an unknown amount of information to the public, looks like they have suffered very little repercussion given the scope of the leak.

https://blog.cloudflare.com/incident-report-on-memory-leak-c...

Re: Lenovo: Companies working in China may have to install local backdoors

#83
post #75

Earlier quoted context omitted.

The ban on the export of cryptography strikes me as a great example of the US Government misunderstanding technology - I don't see how it's remotely possible for a ban on exporting ideas to affect bad actors in any way.

This is an example of you misunderstanding the US Government's motives for labeling crypto as a non-exportable weapon. ;) If they had been able to keep it up, they would have. Unfortunately for them, practicality won over here once it began to threaten corporate profits.

And this is an example of a meta-misunderstanding that the motives for labeling crypto as non-exportable with clamorous pleas for backdoors to get the public frightened and then finally reassuringly concede to overwhelming defeat with the eventuality of the practical vision held by academia, industry, and especially prescient revolutionary anarchist-libertarians for ironclad strength of a ubiquitous crypto primitive monoculture praised for its open standards detailing specifically its applicability for hierarchical control, designed by a completely unbiased select group of security researchers whose proposals are judged to consensus, tweaked to optimal security parameters for the benefit of all with lovingly chosen constants that couldn't possibly be related to undisclosed attacks the previous standards that were replaced suffered from requiring update once a few undesirables got wind, who rightly espouse a fundamental belief in the professional exclusivity of implementation and analysis while making sure to mentor the next generation in extensive confidence with complexity conjectures based on buried assumptions, gently redirecting their pupils towards the future away from the glaring history of churned systems, compromised research, and perverse financial/legal/social incentives of keeping the ball rolling gently, are not just two sides of the same coin.

Re: Lenovo: Companies working in China may have to install local backdoors

#84

Meanwhile in the US we also have a long history of monitoring internet traffic, installing backdoors and allowing private third-parties to filter what we see online. Where do we get off critiquing the PRC? We should clean our own house first.

Last I checked, in the EU or the USA you don't disappear in the middle of the night never to be seen again because you are: -follower of different religion -saying the word "democracy" -critisizing a politician/the government so yes, first things first.

I'm trying to be as objective as possible. I've never been to China, but I've been to other communist country and the truth is I saw a lot of happy citizens there. While we can sit here and criticize other countries all day, but does it really matter if their own people are living happily there? We can argue and fight all day for the best policies, best technologies, best business ideas, etc. but at the end of the day what everyone is really looking for is just happiness. You can have the most money in the world and still be miserable, our world is already full of those people.

Re: Lenovo: Companies working in China may have to install local backdoors

#85
post #81
post #76

Earlier quoted context omitted.

My brain's being a bit pedantic/dense about wording, so I want to clarify - are you saying that Windows 10 builds destined for Chinese governmental use are shipped to China in source form?

No. The source code is shipped to a system integrator based in China, vetted by both parties and under strict NDA, who then edit the code with required changes, compile and ship the binary to government users. MS have, for a long time, allowed major customers to audit Windows source code on site but they are still forbidden from making copies. The whole setup is meant to avoid shipping source code directly.

Why does Microsoft not make those changes themselves? Does the Chinese government not want them to know what changes they want?

Re: Lenovo: Companies working in China may have to install local backdoors

#86
post #68
post #54

Earlier quoted context omitted.

> As China vies for world hegemony China is not going to export their political system beyond the HK and Taiwan, unlike the US. > the country intervening in most foreign elections is the United States with 81 interventions, from 1946 to 2000

You forget China's intervention in the Korean War/North Korea. They've also annexed Tibet and killed/arrested dissidents since the 50s. It's a case of which is the lesser evil. US's style of "imposing" democracy (and toppling it and replacing the government with puppets when it become socialist and/or unfavorable for US corporations) or Chinese totalitarianism.

> You forget China's intervention in the Korean War/North Korea.

Unlike the USA? So if China came along bombing the shit out of mexico, you'd expect the US to sit on their hands?

> They've also annexed Tibet

Annexed is hardly the right word. Tibet was part of China for centuries, they regained power after a brief period of independence. It's well within reasonable to disapprove of that, but putting it like China just conquered that totally different country that it had no relations with before is just wrong.

Same with Taiwan. To China it's a province where the government has been taken over by separatists, so why should they just give it up? Western media conveniently never mentions this so again in the minds of people Taiwan is just this country that has existed forever and is now attacked by the evil Chinese. Just pull up a list of countries which do and don't regard Taiwan as its own sovereign country and not part of China.

Re: Lenovo: Companies working in China may have to install local backdoors

#87

Earlier quoted context omitted.

More likely that the schematics will contain backdoors, that aren't easily understood to be backdoors. EDIT: have - contains

It could conceivably be done even below the schematic level, though I'm not sure how much room modern processes have for this sort of thing now that we're talking about how many atoms wide a transistor is. I've been told that there was a period of a few years in which a kind of "copy protection" proliferated in IC layouts. The layouts would be tweaked to exploit quirks of the originating company's fabrication process…

The lower a level, the easier to add a backdoor, the harder to audit. To add the backdoor to the handwritten assembly code is much easier than to do this with (reasonably clean style) C, and both are easier than add it to Standard ML or Haskell code. The same is true with verified formal hardware description specifications, Verilog and lithographic mask.

So the path toward trustworthy computing, besides cheap fabs, is higher level tools, projects like Kami and CakeML, proof checking, automatic verification and synthesis.

Re: Lenovo: Companies working in China may have to install local backdoors

#88
post #58

This is not unique to China. New Zealand has the TICSA requirement that network operators must provide intercept capabilities to security agencies, and all network operator designs must be approved by security agencies before deployment. I would imagine other five eyes countries have or soon will have similar requirements.

Wasn't there this announcement recently that the Five Eyes was "asking" vendors to provide backdoors voluntarily, or else?

And all the governments engaging in this kind of behavior are at the same time giving each other excuses, "because every one else is doing it, too". So if China does this, you can be sure other countries will point to China's example and require their own backdoors. Let's just hope all those backdoors are mutually incompatible.

Re: Lenovo: Companies working in China may have to install local backdoors

#89
post #81
post #76

Earlier quoted context omitted.

My brain's being a bit pedantic/dense about wording, so I want to clarify - are you saying that Windows 10 builds destined for Chinese governmental use are shipped to China in source form?

No. The source code is shipped to a system integrator based in China, vetted by both parties and under strict NDA, who then edit the code with required changes, compile and ship the binary to government users. MS have, for a long time, allowed major customers to audit Windows source code on site but they are still forbidden from making copies. The whole setup is meant to avoid shipping source code directly.

Thanks for the insight.

I'm guessing the on-site/NDA combination is intended to prevent another Mainsoft (and all the other leaks...) from happening.

I wonder if I stand a chance of turning up a copy of Chinese-governmental Windows 10. Would be awesome.

Re: Lenovo: Companies working in China may have to install local backdoors

#90
post #85
post #81

Earlier quoted context omitted.

No. The source code is shipped to a system integrator based in China, vetted by both parties and under strict NDA, who then edit the code with required changes, compile and ship the binary to government users. MS have, for a long time, allowed major customers to audit Windows source code on site but they are still forbidden from making copies. The whole setup is meant to avoid shipping source code directly.

Why does Microsoft not make those changes themselves? Does the Chinese government not want them to know what changes they want?

Well, obviously politics, burden of blame, and plausible deniability, and all that. Microsoft never made the changes themselves, they've no real idea what happened, they just sat in a corner of the room and glanced at the devs' screens once in a while to make sure they didn't look like they were stealing anything.
Post reply on HN