Live data from Hacker News

FCC Bans Authorizations for Devices That Pose National Security Threat

fcc.gov

91–100 of 242 posts

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#91

While I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning…

>How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port?

Nothing so sophisticated is required. Look at the sheer number of "default credential" and "static credential" for a whole variety of products:

https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Cisco+crede...

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#92

While I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning…

“I learned it from you dad”…

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#93

While I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning…

Huawei singlehandedly destroyed Canada's Nortel Networks through espionage and sabotage. The CIA did an analysis and discovered that Huawei was dumping wireless equipment to small wireless providers in areas around US military basis at a loss. At the very least, the ability to disrupt communication of those military bases were easily achievable.

> The CIA did an analysis

I had my doubts, but not after the CIA said it's true.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#94

While I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning…

Your argument sounds like deflection and elementary school logic. If Cisco has problems, that should also be dealt with. But because Cisco has problems doesn't mean that Huawei shouldn't be dealt with. In Western cultures, we have the notion of "Two wrongs don't make a right." This is a classic Chinese government talking point. "Don't look at what we're doing. Look over there, instead!" For decades it's been using th…

> Your argument sounds like deflection and elementary school logic.

A pessimistic and frankly rude reading of my comment.

Cisco also has it's equipment manufactured outside of the united states, making them susceptible to similar backdooring without x-raying every board produced.

> But because Cisco has problems doesn't mean that Huawei shouldn't be dealt with.

Cisco is not getting banned by the FCC - so the comparison is moot.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#95

While I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning…

it is probably paranoia but not improbable. they have direct control of these companies and can totally do this. others like the US would have to go less direct routes for these things.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#97

While I have no doubt than basically anything from China is probably backdoored (and to the fault of western countries outsourcing manufacturing for cheap labour), what exactly has Huawei done? How do we know that the Cisco equipment also isn't backdoored and if I send a few malformed TCP packets it opens up its control plane on the receiving port? Compared to the last few decades, it seems like a strong hand banning…

Huawei singlehandedly destroyed Canada's Nortel Networks through espionage and sabotage. The CIA did an analysis and discovered that Huawei was dumping wireless equipment to small wireless providers in areas around US military basis at a loss. At the very least, the ability to disrupt communication of those military bases were easily achievable.

Nortel networks haven't been around for nearly a decade. I've seen lots of news about 5G/Huaewi and 'core networks' only in the recent years in western countries (UK/US mainly). However, I haven't seen anything published that really reflects new risks/major backdoored products.

I wouldn't 100% trust anything built in China, but there must be some reason people are only taking action now? Unless it's just "better late than never" response after years of this.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#98
post #72

Earlier quoted context omitted.

well, yes and no. Amazon most definitely has a counterfeit/stolen goods problem that they are deliberately (from outside perspectives) not doing anything about. however, if a "legit" vendor is selling devices that does not meet local regulations and it is known by the seller this is true, then the seller has blame as well.

And also the seller cannot just say "oopsie I didn't know". Well, they must make an effort to "know your customer", instead of "better not ask".

I think there is/should be a grace period though. If a retailer is provided goods by a vendor where the vendor knows their products are illegitimate, it is possible for the retailer to be unaware. However, once it becomes known that the vendor is selling illegitimate products, it is up to the retailer to then remove those items. Most major retailers have agreements/contracts with these vendors that say they must buy back any merchandise unable to be sold. This would be a normal way of handling things. Once this avenue is not pursued and the retailer continues to sell the product, then the retailer is no longer innocent.

Re: FCC Bans Authorizations for Devices That Pose National Security Threat

#99
They seem to make a special case of modules by those brands, for example 4G or 5G modems that are contained in other manufacturers appliances, and these days employ self contained operating systems in theory perfectly capable of moving information back and forth without any intervention, or even knowledge, from the device employing them (cellphone, IoT device, industrial appliance, vehicle etc). The problem is: how do they certify them without obtaining the firmware source code along all the original design data?
Post reply on HN