Live data from Hacker News

The Clean Network – United States Department of State

state.gov

161–170 of 412 posts

Re: The Clean Network – United States Department of State

#161

Earlier quoted context omitted.

I laughed, but also ... yes? As a lover of liberty I would much rather just my own government (by which I am ostensibly represented) have the ability to infringe on that liberty than 2 governments. I would want to support regulations that protect myself and neighbors from the influence of those other infringers, no?

Your own government also has more tools to use against you. You'll pass through your own border more frequently, you're more available to be arrested, harassed by LE, etc. How about as a lover of liberty, _nobody_ snoops on our data?

Of course you are correct, but the tools available to other governments still concern me greatly. Are we actually presently capable of making sure nobody snoops on our data? If so then I agree it is a better solution. But is it not better to use an imperfect plan which is implementable than wait for a perfect plan (if such a thing exists for cyber-security) to become implementable when a threat is present?

Re: The Clean Network – United States Department of State

#162

Earlier quoted context omitted.

The actions required to shut out that second attacker are blunt tools that impinge upon your personal freedom far beyond their stated purpose. And since you still have that primary attacker, then you still have to defend against them anyway. The proper solutions to protect us from "China" are the same as the solutions to protect us from NSA - E2E encryption, P2P communication, decentralized namespaces, and making dat…

Can we realistically implement these in the near future? Will this not function as a stop-gap in the meantime while we do work on your (better) solution?

Yes they can be implemented, when there is necessity. The tech industry has been coasting on commercial surveillance to fund centralized solutions, relying on consumers not looking too hard behind the curtain. I'd say that overall fiction is what is really collapsing here.

I don't see how it's possible to answer whether this will "function". None of the simplistic actions stated in the press release address any of the actual threats - hence everyone is filling in their own imagined technical specifics. This is basically another "series of tubes" moment, with politicians not understanding that while they can control the physical wires, they cannot control the emergent complexity of communications happening over the wires.

Re: The Clean Network – United States Department of State

#163
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

Why has no one actually provided evidence of a single backdoor in the replies? The top reply is currently some anecdote that while interesting does not answer the question at all.

Surely we can be less shitty about answering the OP’s question. As a start, it sounds like at some point there were unsecured Telnet servers in some Huawei devices: https://www.theregister.com/2019/04/30/huawei_enterprise_rou... It’s not entirely satisfying evidence because the Register believes it was legitimately for diagnostics. They also point out that there were comparable “backdoors” in Cisco equipment: https://www.theregister.com/2019/05/02/cisco_vulnerabilities...

If anyone replies with an example of an actual unambiguous Huawei backdoor for which there isn’t a corresponding Cisco “backdoor” I’ll be happy to buy them a coffee. But why are so many of the replies to the parent comment just pure noise?

Re: The Clean Network – United States Department of State

#164

Earlier quoted context omitted.

Can we realistically implement these in the near future? Will this not function as a stop-gap in the meantime while we do work on your (better) solution?

Yes they can be implemented, when there is necessity. The tech industry has been coasting on commercial surveillance to fund centralized solutions, relying on consumers not looking too hard behind the curtain. I'd say that overall fiction is what is really collapsing here. I don't see how it's possible to answer whether this will "function". None of the simplistic actions stated in the press release address any of th…

Is it really another "series of tubes moment"? Is it not true that a system crucial to the majority of economic, social, and political(!) activity in this country ought not to be running on hardware/software known to be designed/manufactured by what has proven to be a "malign actor"?

Re: The Clean Network – United States Department of State

#165

This really comes off as a hastily prepared political dig against China, when there are in addition so many other actors and countries trying to take advantage of poor security. The JPEGed giant logo at the top doesn't help... Other observations: -- "Remove untrusted applications from US mobile app stores": so, this would call for even tighter control by Apple, Google, over its app distribution and monopolies? -- Cle…

> The JPEGed giant logo It's almost like they ran it through jpegify.me on purpose as a joke, but really it's just another sign of the US's government technical incompetence.

Or, the government employee tasked with putting this thing up did it intentionally as a subtle form of protest.

Re: The Clean Network – United States Department of State

#166
post #80

I have the same feeling about this as I did the announcement of the "Department of Homeland Security". The name sounded Soviet in origin, with only the exchange of "Homeland" in place of "Motherland". It reminded me of things my family had taught me didn't happen in the United States. "We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbo…

> It is my impression that modern companies that care about security assume that all networks are compromised and act accordingly.

I think more to the point, Google et al assume that all networks are compromised by state level actors. As in NSA. As in the people who wrote this "Clean" policy.

Re: The Clean Network – United States Department of State

#167
post #84
post #62

This is disgusting. Anybody working at an American firm that's supporting this initiative should be ashamed. Anybody working on this project is actively contributing to the destruction of international trust and cooperation. I am beyond disgusted at my government. This Republican administration has been an unprecedented disaster on every front.

How would you suggest we limit the surveillance and active attacks on American infrastructure by the Chinese government? They show no signs of letting up and/or respecting how America works in the slightest.

Easy, USA can invest in open hardware/software. It would destroy Intel/AMD but who cares, national security is more important, no?

Re: The Clean Network – United States Department of State

#168
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

I grew up in Ottawa, Nortel HQ, and had lots of friends with parents working at Nortel. That's a town that does not buy a lot of Huawei.

What kept happening, from the perspective of people who worked there that I've talked to, was that Nortel would do heavy R&D investments and then a few months later Huawei would be selling identical hardware with zero R&D budget- for lower cost, naturally. It took Nortel years to finally figure out their network was highly compromised, likely by the PLA[0]. The PLA would steal industrial secrets and hand them to companies owned or controlled by the Chinese government, like Huawei.

One fellow I met at a wedding party once told me how he had actually read Huawei source code that included Nortel copyright notices. It was a joke by the end. Everyone knew.

As for as being an arm of the PRC, Huawei claims they're owned by their employees Trade Union. But Trade Unions in China, by law, are highly controlled and managed by the party. You can't have a trade union that isn't highly associated with the Communist Party. Huawei counter these arguments by saying it's very complex- but provide no evidence to the contrary.[1]

[0]https://en.wikipedia.org/wiki/Criticism_of_Huawei#Nortel

[1]https://en.wikipedia.org/wiki/Criticism_of_Huawei#Opaque_own...

Re: The Clean Network – United States Department of State

#169
post #62

This is disgusting. Anybody working at an American firm that's supporting this initiative should be ashamed. Anybody working on this project is actively contributing to the destruction of international trust and cooperation. I am beyond disgusted at my government. This Republican administration has been an unprecedented disaster on every front.

Biden is going to be 110% behind this too. I don't have the slightest idea of why you'd think otherwise. People have been playing nice with China for the last few decades hoping they'd change and it hasn't happened maybe a different approach is needed.

Re: The Clean Network – United States Department of State

#170
post #84

Earlier quoted context omitted.

How would you suggest we limit the surveillance and active attacks on American infrastructure by the Chinese government? They show no signs of letting up and/or respecting how America works in the slightest.

Easy, USA can invest in open hardware/software. It would destroy Intel/AMD but who cares, national security is more important, no?

Ok that helps the issue in issue in 20-30+ years (develop the tech, start mass production, replace all old hardware with it) what can we do in this decade?
Post reply on HN