U.S. Warns Of Spy Dangers Of Chinese-Made Drones
101–110 of 165 posts
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#102I'm not sure they understand how bug bounties are supposed to work...
https://arstechnica.com/information-technology/2017/11/dji-l...
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#103Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…
This is exacerbated by the very poor levels of security in these devices in general: DEF CON 23 - Robinson and Mitchell - Knocking my neighbors kids cruddy drone offline
https://www.youtube.com/watch?v=5CzURm7OpAA
However, to put things into perspective, purpose built security cameras -- even expensive ones from well reputed industry brands -- have had similar very poor levels of very poor security for many years.
https://www.youtube.com/watch?v=B8DjTcANBx0
It's not really a problem of drones. It's a problem with the poor levels of security in consumer devices in general. It's "as if" the situation has been engineered to let bad actors do lots of spying.
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#104"We're not being paranoid" No, but the amount of suggestive "Might" "Could" etc titles/articles now out there shows a whole other picture. China is now the new enemy. And everybody must know apparently. Even respectable news outlets can't resist the temptation of completely unfounded copying of the American media machine. I'm not stating China is so innocent, but sorry there is only one country in the world systemati…
Your premise is clearly wrong.
NATO bombed Libya. Every member of NATO is guilty. There are 29 nations in NATO. Here they are:
Belgium, Canada, Denmark, France, Iceland, Italy, Luxembourg, the Netherlands, Norway, Portugal, the United Kingdom the United States, Greece, Turkey, Germany, Spain, Czech, Hungary, Poland, Bulgaria, Estonia, Latvia, Lithuania, Romania, Slovakia, Slovenia, Albania, Croatia, and Montenegro.
Those nations are all very happy to have the US as their superpower shield to be pointed at a target when it's convenient (see the recent past: Kosovo; the US rapidly stopped a genocide the Europeans couldn't or wouldn't deal with in their own backyard).
France aggressively lobbied the US to stay in the military conflict in Syria. In fact, Macron's lobbying is the only thing that kept the US involved as long as it was.
South Korea and Japan are mostly happy every day that the US has its military present - and nuclear shield - to protect them from China and North Korea.
Besides that, Russia was quite happy to put its military to use in Syria for its self-interest.
When it comes to spying, the five eyes are all obviously guilty. Beyond that, every country of consequence spies to the extent it's able to. The European powers are all guilty of it.
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#105World: We're not being paranoid. US drones kill innocent civilians around the world. They're really beating the drum on China. Be intensely suspicious. China is a trading partner that does some shitty things (e.g. in Xinjiang province), but the nation focused on world domination is the one right here.
You're comparing apples and oranges. US drones aren't doing fully autonomous killing, they're killing through policies of leaders you help elect. That's the apples. The oranges is tech we purchase (drones in particular) having backdoors. Why do you think these two are comparable?
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#106Isn't this the US's fault for letting manufacturing move to China in the 1980-present? Any large global migration of industry will have this same threat eventually.
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#107Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…
> These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). Isn't that the purpose? To fuel the trade tensions for the home team. Don't expect truth in trade wars...
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#108Earlier quoted context omitted.
> start communicating over the 5G backbone 5G operates at OSI layer 1 (and maybe has some impact on layer 2). I've never heard of any aspect of it changing higher layers, which is where the concerns about control come in. Is there something I'm missing? If not, 5G has nothing to do with application-level control (eg: controlling a drone's movements, intercepting a camera feed, etc). We'll still use TCP/IP, HTTPS, and…
That's not what I was suggesting at all. If you control the cell infrastructure you absolutely can put cellular capabilities into products that aren't explicitly advertised. That would be a bigger risk for surveillance tech. Your complaint ignores my original statement about controlling both components (cellular and device). There is no need to tamper with someone else's TLS-secured communications or anything, you ca…
However I still don't think 5G is an important factor here. If you control both ends at a higher layer of the stack (eg, it's your own software connecting to your own servers) you can do whatever you'd like. If you have OTA software updates, you can do whatever you like at any point in the future. If this channel is properly secured with TLS no one can intercept or fake it, and if you want, you can design the devices so it won't work without this connectivity present (see: most cloud-based "smart home" devices on the market today).
> If you control the cell infrastructure you absolutely can put cellular capabilities into products that aren't explicitly advertised. That would be a bigger risk for surveillance tech.
So many devices already have internet connectivity built-in, and if money is not a concern you can already incorporate a GSM modem and pay for a link to the existing cellular networks -- it's not like AT&T (or whoever) is going to care what you are doing with the connection, so long as you're paying for it. You can also use other short-range radio links.
I'll grant you that 5G introduces the possibility to have this link without AT&T's knowledge -- at least assuming they don't have the ability to also detect the traffic coming out the tower's uplink. The big downside of this attack vector, aside from the immense cost and complexity of building this into 5G carrier equipment and all these devices, is if detected and blocked at the uplink all that effort is suddenly for nothing.
Basically, the 5G-specific attack vector is expensive and brittle, and thus pretty unlikely. The attack vector at application level is easy and cheap (no hardware-related costs), gets you almost all the same capabilities, and in many cases can be done today on existing in-field products with OTA software updates.
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#109Earlier quoted context omitted.
Lenovo does nothing more than assemblying, and their acts on PC can be easily identified.
No, assembling means more security risks, as it could temper more parts. However, trump saying that Huawei could be part of the trade deal means banning Chinese companies has nothing to do with security. The US didn’t go after Lenovo simply because assembling isn’t a high value add process and doesn’t threat US tech leadership. Huawei got banned because its tech is too advanced.
I don't think that's a certain conclusion. Huawei has been caught with their hand in the cookie jar. For example, [1] a neutral expert found that Huawei copied Cisco's code.
[1] https://blogs.cisco.com/news/huawei-and-ciscos-source-code-c...
Re: U.S. Warns Of Spy Dangers Of Chinese-Made Drones
#110Why not publish a specific threat? These vague "The Chinese are up to something but we cannot reveal what" isn't really helpful, particularly given the current trade tensions (and political motivations e.g. "bring jobs home"). I'm not really "siding" with the Chinese, they may be up to something, but the US has really done themselves a great deal of damage when their own allies don't really believe them. Just publish…
The following is a contrived analogy, admittedly not a great one, to illustrate why I suspect they can't give specifics.
Imagine if you have a gigantic elephant standing near a village. It's so big that you can only see one of the following, depending on where you stand: a trunk that can suck people up, legs that can smash, a tail that can create a wind that tosses people about. Three people are standing in different places to see each of these: Alice (trunk), Bob (legs), and Charlie (tail - poor Charlie). Someone comes running into the village and leaves an anonymous note saying a huge being is a threat and it is going to smash houses.
Except the villagers, if they can figure out who was standing where and what they could see, can tell who left the anonymous note. It was Bob, who could see the legs.
Giving the specifics they know about a threat reveals what they know, and what they don't know, and reveals how they might have gotten the information.