Live data from Hacker News

The Clean Network – United States Department of State

state.gov

271–280 of 412 posts

Re: The Clean Network – United States Department of State

#271
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

There is the story about a man who invented a way to coat glass with diamonds. He was negotiating to sell his invention to Huawei when they shipped one of his samples to China even though he instructed them not to because it was export controlled technology. The reason it is export controlled is that such an invention has applications in military laser weapons. I am summarizing from memory but you can read this article to learn more.

https://www.bloomberg.com/news/features/2019-02-04/huawei-st...

Re: The Clean Network – United States Department of State

#272
post #145

Earlier quoted context omitted.

The Chinese has shown no interest in co-operating with the world. They are an enemy. What’s wrong with keeping them out of our internet when they have their own? To put it another way; this is like allowing your enemy to design and manfacture your military jets.

The Chinese government has shown no interest in cooperating with many western governments . Even though the Chinese government is, in some ways, an “enemy”, most of the 1.5 billion people living in China are not. We should be interested in what the people have to say and I’m sure the people of China are interested in what we have to say, too. We should be building connections amongst the people, not walls. I’d even s…

> We should be building connections amongst the people, not walls.

Do you think that it's really up to us? We weren't the ones who set up the Great Firewall. We have been trying to "build walls" for the past 30 years and it has gotten us nowhere. I get that people like to say things that evoke "positivity" or to feel good about themselves but there needs to be some semblance of reality if we really want to progress.

Re: The Clean Network – United States Department of State

#273

If you're not already familiar with the history of labeling immigrants (particularly non-European immigrants) as unclean or dirty, I'd urge you to read up. This article seems to be a good start: https://journals.openedition.org/transtexts/1011 In short, calling this a "clean" network continues a long history of racist and xenophobic language in the U.S.

Europeans got it too, Irish, Italians, Germans (post WW1 and 2), pretty much the "last ones" to the party get crapped on.

Yes. I don't think its repeated usage in this way diminishes my point, however. In all of these contexts it's been used to put down foreigners or immigrants.

Re: The Clean Network – United States Department of State

#274
post #269
post #80

I have the same feeling about this as I did the announcement of the "Department of Homeland Security". The name sounded Soviet in origin, with only the exchange of "Homeland" in place of "Motherland". It reminded me of things my family had taught me didn't happen in the United States. "We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbo…

Yep. This "Clean Network" BS reminds me of the "Golden Shield" project (official name of the project that China's firewall is part of). Not something I'd expect from the US.

If the Clean Network lasts even so much as a few months as an infrastructure with a non-trivial amount of activity, it will be a fascinating time capsule. It will reflect a very strange kind of culture and bizarre set of national security assumptions and political constraints.

When we look back at the archive.org copies of Clean Net, it will be like visiting a bizarre short lived theme park.

Re: The Clean Network – United States Department of State

#275
post #80

I have the same feeling about this as I did the announcement of the "Department of Homeland Security". The name sounded Soviet in origin, with only the exchange of "Homeland" in place of "Motherland". It reminded me of things my family had taught me didn't happen in the United States. "We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbo…

Just read in the news this morning that the intelligence community acknowledges China has a steak in Biden being put in the Oval Office and Russia has a steak in Trump staying put. Interesting that Russia's name was not in this piece anywhere...

s/steak/stake medium rare and well done puns are omitted

Re: The Clean Network – United States Department of State

#276

Earlier quoted context omitted.

> What unusual attack do they get access to by owning or manufacturing the equipment? It is incredibly easy to add almost undetectable backdoors to hardware, particularly inside ICs. Here's one particularly clever attack described by security researchers at U of Michigan, but there are many: https://www.wired.com/2016/06/demonically-clever-backdoor-hi...

How would a hardware vulnerability on router equipment handling traffic compromise data flowing over that router which has already been encrypted properly at the source/destination?

Your comment that I responded to was referring to smart phones (ie, multiple references to "apps" and "mobile") and now you're bringing up "routers"?

Did you mean to do this? Because if not, it's what's called a bailey-and-motte fallacy. You've stated a very controversial, hard-to-defend position (what difference does compromised hardware make to a user's security?), mentioned it in a context where it would make a huge difference (smartphones), and now you've brought up a very specific scenario and context that is more reasonable (although still not as much as you appear to think).

Again, your original question was "What unusual attack do they get access to by owning or manufacturing the equipment?". Your original post made no reference to routers or switches.

To answer that original question explicitly, having a many types of hardware exploits on end-user equipment is game over - full access to all your data and communications on that device.

Edit: And regarding compromised routers, from https://www.welivesecurity.com/2019/01/17/new-years-resoluti..., here's a list of things that a hacked router could do to you, many of which would be of interest to nation-state attacker targeting a person or organization:

- redirect you to a web page that phishes for your credentials,

- dupe you into installing malware-laced versions of legit software,

- be hijacked to conduct man-in-the-middle attacks (MitM) on what you would believe are secure and encrypted connections,

- be corralled into a botnet in order to launch DDoS attacks against websites or even against aspects of the internet’s infrastructure,

- be co-opted as an on-ramp to attacks at other devices within your network,

- be used to spy on you via Internet-of-Things (IoT) devices,

- be compromised with malware such as VPNFilter, or, as another threat du jour, be misused for covert cryptocurrency mining.

Edit 2: And unless a website is only available via HTTPS, the end user is using an extension like HTTPS Everywhere, or the user carefully types in `https` as the URL protocol, then the end user is still vulnerable to SSL strip from a compromised router.

Re: The Clean Network – United States Department of State

#277
post #145

Earlier quoted context omitted.

The Chinese has shown no interest in co-operating with the world. They are an enemy. What’s wrong with keeping them out of our internet when they have their own? To put it another way; this is like allowing your enemy to design and manfacture your military jets.

The Chinese government has shown no interest in cooperating with many western governments . Even though the Chinese government is, in some ways, an “enemy”, most of the 1.5 billion people living in China are not. We should be interested in what the people have to say and I’m sure the people of China are interested in what we have to say, too. We should be building connections amongst the people, not walls. I’d even s…

>there’s just the internet.

It is, unfortunately, a new field of warfare.

I like to think I'm the most free speech loving, liberal progressive in any room I walk into. But I think the wild west of the internet that existed in the 90s and early 2000s that leant itself to idealistic visions of what the internet could be is not what we have today.

You can't build bridges that are then used against you for espionage, theft of intellectual property, disinformation, tracking and abducting political dissidents, and infiltrating critical national security infrastructure, and then point at that and say "this is free speech!" And if there's no room to acknowledge that in your understanding of how the modern internet works in reality, then I don't know that we're operating from a similar understanding of reality.

Re: The Clean Network – United States Department of State

#278
post #238

Earlier quoted context omitted.

The US is not a democracy for the vast majority of Americans. It is an oligarchy posing as a democracy.

Nearly every affluent liberal democracy on the planet qualifies as an oligarchy by the premise that gets floated about the US. Similarly qualified: Britain, Australia, Canada, France, Germany, Spain, Japan, South Korea, Switzerland, Sweden, Norway, Ireland, Iceland. Have you looked at how many billionaires there are in Sweden and Norway? Oligarchy. Sweden has considerably more billionaires per capita than the US does…

You're so close to getting the point

Re: The Clean Network – United States Department of State

#280
post #201
post #199

Earlier quoted context omitted.

We actually don’t know that the US has gathered the largest database of sensitive information. Only that it used to gather a lot before Snowden.

I'd bet a lot of money that the NSA didn't just turn off their servers and sit their twiddling their thumbs after the Snowden leaks.

That's an unfair caricature. The steelman version of that argument is that China has likely amassed a more robust global surveillance database (to the extent that that's even the right word to use) than the U.S.
Post reply on HN