Live data from Hacker News

The Clean Network – United States Department of State

state.gov

31–40 of 412 posts

Re: The Clean Network – United States Department of State

#31

Isn't it ridiculously easy to set up attacks from within a "clean" network? It probably does increase costs marginally (you have to fly people to "clean" countries, set up ISP access with third parties, etc) but are there any public estimates how much it does that vs the increased costs to run this network? I would think it's marginal. Seeing the partner list this seems like more of a ploy by telecoms to attack tech…

There's a bunch of different measures discussed, but they all seem to remove some attack surface that we have seen exploited.

Securing the routers and network cables removes the means for man in the middle attacks (or at least makes them preventable with router security). Not connecting to telecos does the same (because of bgp highjacking and the like).

Removing chinese apps and not storing data on Chinese servers makes decreases the amount of data that can be extracted from large portions of the population by the CCP. E.g. preventing the "who knows who" graph from leaking wholesale (even if individual nodes can still be investigated via other means).

This doesn't fix all security problems, but it removes some of China's current advantages in cyberwarfare.

Not putting apps in Chinese app stores and devices looks to be an outlier in that it's a form of sanction (in response to human rights abuses) rather than a defensive measure.

Re: The Clean Network – United States Department of State

#32

Isn't it ridiculously easy to set up attacks from within a "clean" network? It probably does increase costs marginally (you have to fly people to "clean" countries, set up ISP access with third parties, etc) but are there any public estimates how much it does that vs the increased costs to run this network? I would think it's marginal. Seeing the partner list this seems like more of a ploy by telecoms to attack tech…

No, this is propaganda by the current admin who's succeeding step by step to create a tyrannical position that has control-censorship abilities like the CCP et al.

This information has already been had by hackers (e.g. Equifax) and/or people from within US companies doing corporate sabotage to steal trade secrets from within a company, etc.

Re: The Clean Network – United States Department of State

#33
post #17

Earlier quoted context omitted.

84 more days till election... fingers & toes crossed

Many municipalities have no-justification-needed absentee voting (vote-by-mail by any other name) which can be dropped off often weeks before in-person voting occurs. Likewise many places have early in-person voting. 1. Check your voter registration. 2. Register to vote if you need to and it's still open for registration in your state. 3. VOTE as soon as you can. If you're voting absentee then drop off your ballot ea…

The key this year is to _personally drop off your ballot_ at an official drop point rather than mailing it in. USPS can and will deprioritize mail in ballots for the fall elections.

Re: The Clean Network – United States Department of State

#35

The question I think this is an answer to is how you can have a reasonable expectation of freedom and privacy while sharing an internet with a CCP who has militarized their technology sector as a means to facilitate colonial expansion. I'm no fan of anyone involved, but we should accept that the Internet as we may have known it has been compromised by exogenous governance structures and their gatekeepers in service o…

Is it the devil we know though? Until the talks about TikTok started, I assumed nothing like this could ever happen in this country.

Re: The Clean Network – United States Department of State

#36

Isn't it ridiculously easy to set up attacks from within a "clean" network? It probably does increase costs marginally (you have to fly people to "clean" countries, set up ISP access with third parties, etc) but are there any public estimates how much it does that vs the increased costs to run this network? I would think it's marginal. Seeing the partner list this seems like more of a ploy by telecoms to attack tech…

Some of the companies listed in the photo are only companies that do not (or have never) used Huawei equipment in their network infrastructure.

For instance, Rogers (Canadian telecom company) hasn't released any statements [as far as I'm aware—to date] following Pompeo's announcement. They've been set up to use Ericcson for their 5G rollout for several years.

It's misleading on the part of whoever drafted the document.

Re: The Clean Network – United States Department of State

#37
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

There’s such a long list of this stuff from various companies. It’s not hard to research this at all.

In terms of an anecdotal evidence... My father used to work for molex, one of his biggest complaints were fixing the molds after they were sent to Chinese factories. They would try to deconstruct them and couldn’t put them back together (this was the 90’s, early 2000’s). So they would be shipped back to the US operations to fix.

Eventually, he ended up spending years training up Chinese to replace him (my father, in China). Molex moved much of its tool making shop to China and shut down most US tool and die making operations.

Anyway, China has people who are trained, on factory floors, who are there to reverse engineer processes.

This has been known for decades, companies don’t really seem to care or know (I guess that’s possible as they are outsourcing manufacturing).

I have no doubt this is designed across all their industries and systems. It’s in their interest to do this.

EDIT: I want to point out, there’s no longer a need for China to reverse engineer. US companies ship the designs straight to China. This is probably why we’ve seen China catch up so fast. We trained their workforce and now provide them all the IP before we build it.

Re: The Clean Network – United States Department of State

#38
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

https://www.politico.eu/article/huawei-germany-court-case-pr...

Of specific concern is a 2017 intelligence law that obliges companies to "support, assist and cooperate with state intelligence services in accordance with the law, and maintain secret all knowledge on the national intelligence services." Another is China's cybersecurity law, which contains similar requirements.

https://www.bloomberg.com/news/articles/2019-04-30/vodafone-...

Vodafone asked Huawei to remove backdoors in home internet routers in 2011 and received assurances from the supplier that the issues were fixed, but further testing revealed that the security vulnerabilities remained, the documents show. Vodafone also identified backdoors in parts of its fixed-access network known as optical service nodes, which are responsible for transporting internet traffic over optical fibers, and other parts called broadband network gateways, which handle subscriber authentication and access to the internet, the people said. The people asked not to be identified because the matter was confidential.

Re: The Clean Network – United States Department of State

#39
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

It doesn't matter whether there's good evidence or not. The risk potential is there and that is what most of this is based on.
Post reply on HN