Live data from Hacker News

US says it can prove Huawei has backdoor access to mobile-phone networks

arstechnica.com

171–180 of 296 posts

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#171

Earlier quoted context omitted.

I don’t really understand comments like this. US has lots of problems but we do have the semblance of rule of law. We do have the notion of transparency and you do not get sent to a labor camp if you have political views antithetical to the state. The Chinese can and do simply disappear people without the semblance of due process. Their history also is one of ethnic cleansing as the Han people have pushed out or marg…

The US is better in terms of handling its own citizens compared to China but they are much worse in terms of international affairs. Consider https://en.wikipedia.org/wiki/United_States_involvement_in_r... or the bombing of civilians in middle east with killer drones.

Let's check back in a few decades and see if this still holds true. I suspect the current disparity is due the US holding the title of unchecked global super power for the past century while China is still getting up to speed. What happens when Belt & Road initiatives start to be expropriated by radical populist governments in the 2040's?

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#172

Note: The following might be considered off-topic. On the otherhand, there might be something nefarious in the SMS network. I found something strange that affects SMS in Canada. You can send the lower case text "secure communication", but it will never be recieved by the recipient. I am not sure if this behavior is reproducible outside of Canada. It might be a software defect, or perhaps there is something capturing…

I just tried. Successful delivery.

from: Freedom Mobile to: Freedom Mobile Location: Ontario

Mobile data: off Wifi: off

Side note: So cool to see so many Canadians on here! If requested I can send SMS to USA numbers.

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#173

Earlier quoted context omitted.

I have never corresponded with a Uighur, and certainly never on topics that are sensitive for the Chinese state. Have you?

I don't see any reason why I would be afforded any more legal protections than they give to their own citizens, do you?

If you're not in their jurisdiction, or neighboring jurisdictions (I've heard some rumors of events in e.g. Vietnam), they're not going to do anything to you. USA cannot make the same claim.

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#174

Note: The following might be considered off-topic. On the otherhand, there might be something nefarious in the SMS network. I found something strange that affects SMS in Canada. You can send the lower case text "secure communication", but it will never be recieved by the recipient. I am not sure if this behavior is reproducible outside of Canada. It might be a software defect, or perhaps there is something capturing…

> I found something strange that affects SMS in Canada. You can send the lower case text "secure communication", but it will never be recieved by the recipient.

This reminds me of how, until just a few years ago (as late as 2016), people were wondering why you couldn't tweet the phrase "Get better".

It turned out that you can't tweet any phrase that begins with "Get" because... you guessed it, posting tweets from the web interface still shared backend code with the SMS-based system[0]. So it would interpret "Get foo" as an API request to fetch tweets, not a tweet itself.

[0] Twitter was originally designed to work on dumbphones! You could text your tweet to 40404 and it would post for you, or you could fetch tweets by saying "GET chimeracoder" and it would fetch the latest tweets from user @chimeracoder.

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#175

Earlier quoted context omitted.

I have never corresponded with a Uighur, and certainly never on topics that are sensitive for the Chinese state. Have you?

I don't see any reason why I would be afforded any more legal protections than they give to their own citizens, do you?

I would assume I am afforded less legal protections than a Chinese citizen!

But here's the thing: with the platonic ideal of "civil liberties" in mind that might bother me, but practically speaking? Chinese legal protections or threats have no bearing on me. None whatsoever.

I don't have a secret clearance. I don't know anyone who does. I don't know anything of significant value to the Chinese state that they couldn't use their existing sources to steal. My "deepest darkest secrets", at worst, would get me in trouble with my local government. They're not enough of a lever to make me an agent of China.

If, however, the information that could get me in trouble with my local government made it to my local government? That might be more of a concern for me.

Do you see why I might not care in the slightest what China knows about me, while simultaneously caring a great deal what my local government knows?

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#176
I like to post this whenever huawei backdoor gets mentioned.

RDG is the author of masscan

https://blog.erratasec.com/2014/03/we-may-have-witnessed-nsa...

tl;dr they watched someone login with a huawei tech support account from mainland china.

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#177

Note: The following might be considered off-topic. On the otherhand, there might be something nefarious in the SMS network. I found something strange that affects SMS in Canada. You can send the lower case text "secure communication", but it will never be recieved by the recipient. I am not sure if this behavior is reproducible outside of Canada. It might be a software defect, or perhaps there is something capturing…

I found that an international SMS containing the entire text for a Wells Fargo SMS 2-factor code from the US to the UK doesn't deliver. Found that interesting.

I could get it to deliver US to US, though.

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#178
post #122

China's intelligence law requires people or companies to spy when asked. >“request relevant organs, organisations, and citizens provide necessary support, assistance, and cooperation”. According to Article 16, intelligence officials “may enter relevant restricted areas and venues; may learn from and question relevant institutions, organisations, and individuals; and may read or collect relevant files, materials or it…

Isn't this also pretty much the case with American companies? The only difference is that they need a warrant (which should be pretty easy to get). Anyway, there is a new bill trying to kill e2ee in America https://news.ycombinator.com/item?id=22202110

Yes and no.

There are some specific carve-outs for telecom companies that their networks must have the ability to tap into specific traffic when a government agency comes knocking with a warrant.

But, as you point out, backdoor-free e2e encryption is not yet illegal, and the US gov't can't force e.g. Apple to put a backdoor in iMessage or in iOS's device encryption.

I expect that this is not the case in China; if the CCP tells a company to do something, anything, to allow them to spy on their users, they do it, or they get destroyed.

Bills like the EARN IT Act scare the hell out of me, but at least there's a process by which it becomes law, and we can affect that process and (hopefully) kill it. That's just not possible in China.

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#179
post #6

Earlier quoted context omitted.

This is one of those "if X has access, so does everyone else" and rule makers still don't seem to grasp it.

"Because I can log into my sshd, so can everyone else"...? We are not talking about weak crypto here (though AFAIK 5G crypto is designed to be decidedly not E2E), but rather access to the data processed by these systems. There is no particular reason why granting e.g. the NSA access to a stream of CDRs would immediately give others access.

If you're able to retrieve the private key, then yes, you're able to generate a working public key. If they even use a (pre-generated) private key. Often, passwords are even hard-coded in "firmware".

Re: US says it can prove Huawei has backdoor access to mobile-phone networks

#180

Earlier quoted context omitted.

Judging by the number of wars it started in the last century... it's definitely the American.

I don’t really understand comments like this. US has lots of problems but we do have the semblance of rule of law. We do have the notion of transparency and you do not get sent to a labor camp if you have political views antithetical to the state. The Chinese can and do simply disappear people without the semblance of due process. Their history also is one of ethnic cleansing as the Han people have pushed out or marg…

The US also has a history of ethnic cleansing, is the originator of the concentration camp, has more people imprisoned than any other state in history, has black sites where police disappear people to (Chicago police department famously) as well as federal agencies doing the same, selectively prosecutes poor and minorities at disproportionate rates in terms of crimes committed and the magnitude of those crimes, and on and on. The difference is the US pretends none of this is true. The transparency and rule of law quoted is an illusion.
Post reply on HN