Live data from Hacker News

U.S. Warns Of Spy Dangers Of Chinese-Made Drones

npr.org

21–30 of 165 posts

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#21
post #14

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

Let's assume that they're encrypting the payload before sending it back home and we've broken their encryption techniques. You don't think it would do a lot of harm to publish detailed analyses letting them know we've broken their encryption?

You could publish a white paper demonstrating that "unknown" data is being sent and look at the code/device that is sending it (since they're in the US). There's no need to even break encryption if you have the sending device.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#22
post #14

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

Let's assume that they're encrypting the payload before sending it back home and we've broken their encryption techniques. You don't think it would do a lot of harm to publish detailed analyses letting them know we've broken their encryption?

Yeah, that's similar to how we can't let Saddam know that we know where his giant WMD factories and storage facilities are, so you just have to take our word for it...

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#23

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

Well, the specific concern is that all new tech ships with OTA update capability. Infrastructure should probably never have this in the first place for a variety of reasons, but it does and it will because the of huge cost savings it can enable. When the Chinese government can tightly control the companies under it, and those companies control the OTA update, then nothing produced by those companies can ever be consi…

>> The same could absolutely be said about US made products being used in countries that the USA is adversarial against

Such as, itself.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#24

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

> Just publish technical information. It isn't hard. It would do huge damage to the Chinese and reinforce the US's whole argument.

I doubt that it would damage China. The existence of the threat is already well publicized.

I think that U.S. intelligence does not talk about specific threats because the attack vectors would probably misunderstood and underestimated by the general public. There would inevitably be pushback like "Gee, we have to give up our drones just because of X?!"

The consequences from these types of events aren't felt immediately, and many people perceive that as being equivalent to no consequences at all.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#26
post #14

Earlier quoted context omitted.

Let's assume that they're encrypting the payload before sending it back home and we've broken their encryption techniques. You don't think it would do a lot of harm to publish detailed analyses letting them know we've broken their encryption?

Yeah, that's similar to how we can't let Saddam know that we know where his giant WMD factories and storage facilities are, so you just have to take our word for it...

I don't know how old you were at the time of 9/11 - but there were loud, public voices in the Intelligence Community telling everyone that the WMD situation was fabricated. To the point the only person claiming there were WMDs was Cheney and his inner circle, which is why both the Democrats and our international partners had to be brow beaten into supporting the invasion of Iraq.

To claim these two situations are the same is a very, very large stretch.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#27

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

Well, the specific concern is that all new tech ships with OTA update capability. Infrastructure should probably never have this in the first place for a variety of reasons, but it does and it will because the of huge cost savings it can enable. When the Chinese government can tightly control the companies under it, and those companies control the OTA update, then nothing produced by those companies can ever be consi…

I don't see how the trade war fixes the possible security issue caused by a potential OTA update in a potential conflict, a solution would be to make illegal OTA updates for critical hardware and software without getting the update reviewed. So military or other important things would buy only products that are reviewed and with updates that are signed by the government.

Or even simpler have this hardware and software setup to only get OTA updates and commands only from central command.

This feels so hypocritical considering that many PC around the world run CPUs that have Intel ME or equivalent and there is no media coverage of known backdoors in CPUs(I know technically it is a fully featured remote management feature that had some bugs in the past but Intel assures us that there are no more critical bugs and for sure no intentional bugs and this enterprise feature is also included in all CPUs not only in enterprise ones)

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#28
post #5

Earlier quoted context omitted.

A government also can and should prioritize amongst multiple simultaneous priorities.

They do. That's why governments have different departments (DHS and DOT in this case) and associated, prioritized budgets.

No I am talking about more directly. As an obvious example, in wartime everything goes to support the defense of the nation and is shifted to support that goal.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#29
post #9

Security researchers in the field have been talking about this for several years. DJI absolutely dominates the consumer/pro UAV market so this is a real issue. Source: I had a UAV related startup several years ago and got to know some of the security folks.

> I had a UAV related startup several years ago and got to know some of the security folks.

Oh, excellent, you are confirming that 'spying' issue is real and you seem to be the one who can give us some real insight - can you provide names of "the security folks", maybe some links to their research where we all could see proof for all these claims?

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#30

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

> Just publish technical information. It isn't hard. It would do huge damage to the Chinese and reinforce the US's whole argument. I doubt that it would damage China. The existence of the threat is already well publicized. I think that U.S. intelligence does not talk about specific threats because the attack vectors would probably misunderstood and underestimated by the general public. There would inevitably be pushb…

This has nothing to do with convincing the general public. The US is struggling to convince their own allies that the threat is real, and definitely haven't convinced the technical community they need to stop buying e.g. Huawei hardware.

> The existence of the threat is already well publicized.

Parroting the same vague "there's a threat, but the threat is secret so we cannot tell you about it" isn't well publishing anything. It is bordering on fear mongering. A well publicized threat would be a series of white papers describing in technical terms the weaknesses/backdoors/etc in Chinese manufactured hardware.

Post reply on HN