Earlier quoted context omitted.
Would this help shape policy in some way or are you just curious as a technologist? I don’t really need to know, as a long time infosec practitioner I have a fertile imagination for the shenanigans they could be up to.
Of course it will help shape policy, AND I want to know, as a technologist! How can we know what standard to apply in our work when we don’t know which standard has been broken?! As a fellow infosec practitioner who works at one of the world’s biggest security companies, I don’t want to leave it up to imagination, I want to know exactly what the wrongdoing is, because my job may depend on it in the future!
* hardware
* deep backdoors in radio chips
* physical supply chain TM goes here
* etc etc
* software * we can audit and monitor this easier
* etc
There is a lot to read between the lines, but it is guess work based on supply chain advisories and high level behaviors of govt entities on both sides and our community is good at missing the forest for the trees on this speculative thinking. I think also there is the possibility of minimal actual wrong doing. It could just be entirely political. Ahh well, I guess I have seen enough of this over the years that I accept there is stuff we will never learn about.