Live data from Hacker News

U.S. Warns Of Spy Dangers Of Chinese-Made Drones

npr.org

51–60 of 165 posts

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#51

Earlier quoted context omitted.

> Just publish technical information. It isn't hard. It would do huge damage to the Chinese and reinforce the US's whole argument. I doubt that it would damage China. The existence of the threat is already well publicized. I think that U.S. intelligence does not talk about specific threats because the attack vectors would probably misunderstood and underestimated by the general public. There would inevitably be pushb…

This has nothing to do with convincing the general public. The US is struggling to convince their own allies that the threat is real, and definitely haven't convinced the technical community they need to stop buying e.g. Huawei hardware. > The existence of the threat is already well publicized. Parroting the same vague "there's a threat, but the threat is secret so we cannot tell you about it" isn't well publishing a…

No allies doubt the Chinese engage in hacking and other forms of digital espionage. Do other nations need a white paper detailing our weapons systems to believe in our capability? The world doesn’t owe you proof of anything and government intelligence agencies know more than you. Sorry but nobody is going to give you a white paper.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#52

Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…

Microsoft did such a write up about a laptop.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#53

Earlier quoted context omitted.

Well, the specific concern is that all new tech ships with OTA update capability. Infrastructure should probably never have this in the first place for a variety of reasons, but it does and it will because the of huge cost savings it can enable. When the Chinese government can tightly control the companies under it, and those companies control the OTA update, then nothing produced by those companies can ever be consi…

I don't see how the trade war fixes the possible security issue caused by a potential OTA update in a potential conflict, a solution would be to make illegal OTA updates for critical hardware and software without getting the update reviewed. So military or other important things would buy only products that are reviewed and with updates that are signed by the government. Or even simpler have this hardware and softwar…

The trade war won't fix issues with OTA as a vulnerability. It is useful for the US to point it out to tip things in their favor so it gets a lot of coverage.

I also agree with you that the solution to OTA updates is tight control, but that isn't realistic either. They are talking about drones in the article. These are devices bought and run by companies that build infrastructure in the US but are not directly related to the government. They want OTA because it has legitimate benefits in worker time and cost savings and helps keep their "fleet" running with all the latest features.

Now, an example attack might be an OTA update for the drone controller to shunt mapping data back to home base in China to give them high quality military maps of infrastructure for attack planning. The attack might be unrealistic, but the spying threat isn't. Alternatively, if car autopilot takes off, imagine the economic damage an OTA attack could do that causes 30% of the traffic in the US to just stop. To prevent this sort of attack, you would have to review ALL code coming out of China since you can't directly hold them responsible after the fact when they are out of your sovereign jurisdiction. The kind of dedicated and educated workforce required to code check all firmware/software updates for such huge classes of consumer products is just not going to happen and it can only get worse.

Intel ME is an abomination, but it's also well known and gets a lot of coverage. It's just not in the mainstream news right this minute.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#55
post #45

Earlier quoted context omitted.

We're talking national security. I hope nobody is running a Xiaomi robot vacuum at a sensitive or classified site, or any other brand of robot vacuum for that matter... There's a difference between individual invasions of privacy and national security. There's definitely Chinese apps that invade your privacy. There's also Western apps that do too. The question is of national security however.

Observing private homes can help select your targets. By observing the inside of the home you may learn if the owner has access to secrets (national security or commercial), what kind and what level. From where you can switch to traditional methods. My 2c.

It gives you the layout of homes, it doesn't allow you to observe their occupants. It is a spinning laser.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#56

Earlier quoted context omitted.

Well, the specific concern is that all new tech ships with OTA update capability. Infrastructure should probably never have this in the first place for a variety of reasons, but it does and it will because the of huge cost savings it can enable. When the Chinese government can tightly control the companies under it, and those companies control the OTA update, then nothing produced by those companies can ever be consi…

I don't see how the trade war fixes the possible security issue caused by a potential OTA update in a potential conflict, a solution would be to make illegal OTA updates for critical hardware and software without getting the update reviewed. So military or other important things would buy only products that are reviewed and with updates that are signed by the government. Or even simpler have this hardware and softwar…

The trade war -- if done right -- would supposedly force China to make some real concessions if they want the trade war to end. For instance, they almost agreed to end the forced tech transfers from US to Chinese companies, but then they changed their minds, which seems to be what actually prompted the recent tariff raise to 25%.

I understand not "making the economic situation worse", but sometimes things have to get worse before they get better. Obama had "good relationship with China" and China trampled all over American companies because of it, pretty much making up whatever demands they wanted if those companies wanted to do business there. Plus, even before the trade war, car imports had 25% tariffs in China, and I think 0-5% in the U.S. for the reverse.

It reminds me of when Google was "open" with the Gmail and GChat APIs, and then Facebook abused it to get all of Gmail's contacts through the mass-invite feature, while Google couldn't do the same with Facebook contacts.

Similarly, Microsoft was working on adding GChat support to Skype - but the reverse (Skype in GChat) wasn't possible. This example illustrates pretty well why you can't always be "open to everyone, no matter what", when some can become hyper-aggressive in exploiting what you have to offer when being so open, but not paying it back in any form.

I believe I also read a recent comment about RISC-V developers giving the Chinese the could shoulder in collaborations, because Chinese developers tend to "take take take" and not contribute anything back, ever.

I even see it all the time with people praising Samsung, etc for "innovating more than Google", forgetting the fact that 95% of the OS is Google's work.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#57
World: We're not being paranoid. US drones kill innocent civilians around the world.

They're really beating the drum on China. Be intensely suspicious. China is a trading partner that does some shitty things (e.g. in Xinjiang province), but the nation focused on world domination is the one right here.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#58
> "The Communist Party of China now has in their law the ability to interfere and take information from virtually every Chinese company,"

I think that not only the Communist Party of China but all the political systems around the world have the ability to demand lawful access to information from virtually every company that is supposed to comply with their laws.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#59
post #15

"I'm not being paranoid", said every paranoid ever

The fact you are paranoid does not mean they are not after you.

But makes it more likely that you'd be seeing stuff that isn't there. And stating one is not paranoid does not convey any kind of useful information since the most paranoid are usually the ones who will be more convinced they aren't. Case in point, I don't know if US is being paranoid on this or not and I couldn't care less. I was just pointing out the general case of how ironic it is for someone to argue that they are not being paranoid.

Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones

#60

Earlier quoted context omitted.

> Just publish technical information. It isn't hard. It would do huge damage to the Chinese and reinforce the US's whole argument. I doubt that it would damage China. The existence of the threat is already well publicized. I think that U.S. intelligence does not talk about specific threats because the attack vectors would probably misunderstood and underestimated by the general public. There would inevitably be pushb…

This has nothing to do with convincing the general public. The US is struggling to convince their own allies that the threat is real, and definitely haven't convinced the technical community they need to stop buying e.g. Huawei hardware. > The existence of the threat is already well publicized. Parroting the same vague "there's a threat, but the threat is secret so we cannot tell you about it" isn't well publishing a…

You don't need a whitepaper to say "Any device with over-the-air updates (or server-side processing) controlled by a Chinese company can receive anytime new software (thus a payload) controlled by the Chinese intelligence services".

This is what's implied.

Post reply on HN