Live data from Hacker News

Huawei Says It Would Offer Access To Its Source Code

securityweek.com

21–28 of 28 posts

Re: Huawei Says It Would Offer Access To Its Source Code

#21

Let's not forget: Aliyun OS is an admitted illegal closed-source Linux fork (And likely an Android ripoff). Perhaps China should comply with basic U.S. law if they want to sell things here.

Aliyun is derived from the Android Open Source Project (AOSP). In intent and execution, it is much the same as OPhone, which is another Android-derived OS used in China.

Neither one violates licensing terms for AOSP.

There are many devices that make use of AOSP for a wide range of purposes, from the well-known Amazon Kindle, which competes with Android, to in-vehicle systems you might never know run AOSP.

If you look at the Open Handset Alliance membership, you will find several that either sell OPhone devices, or develop and integrate OPhone system software. And yet Google objects to none of that. Curious, no?

Re: Huawei Says It Would Offer Access To Its Source Code

#22
post #4

Let's not forget: Aliyun OS is an admitted illegal closed-source Linux fork (And likely an Android ripoff). Perhaps China should comply with basic U.S. law if they want to sell things here.

The point is that you can't judge a company solely on where they are from and that simply because of the company's origin to not only state concern, but to actually completely ruin their reputation by issuing serious concerns about possible spying activities, before having analyzed the products in suspicion, is just wrong. That is btw exactly what you are doing. Aliyun OS is illegal, so Huawei has to suffer? This is…

I guess at some points I can judge a company based on where it's from, especially with the political system in China.

Re: Huawei Says It Would Offer Access To Its Source Code

#23
post #5

Earlier quoted context omitted.

Huawei wants to enter US market -> spying suspicions Huawei makes source code open -> all they want is free bug fixing Is that really fair? Note: Have you even read the article? They say they would make the source code available for official governmental institutions to analyze it if they wanted, they don't say anything about making it completely open-source!

Making the source code open doesn't help unless you can flash the devices, since you have no guarantee the source code is what's on the devices. Plus, if the backdoors are in hardware (say the hardware AES implementation has a small key scheduling "bug" or something) , not software, source code wouldn't help.

Exactly. And any update feature, which is typically built into most networking products, could enable a backdoor to be installed at a later date. Could be clean now, but doesn't mean always!

Re: Huawei Says It Would Offer Access To Its Source Code

#24
post #11
post #8

Has anyone compared Ericssons tech with Huawei? Honest question. I feel like if you're setting up infrastructure, take it from the countries that does it the best. Ericsson is Swedish and _THE_ first country to roll out with 4G (around my parents place, even).

The technology isn't really relevant. Sure, organizations with unlimited budget would probably choose some other vendor than Huawei. But that really doesn't include most mobile operators in the world. And then what starts mattering is that Ericsson or NSN charges twice as much for the same capacity. Or that Huawei is willing to give financing on good terms (including on parts of the network supplied by other vendors)…

I beg the differ. It is very relevant if you want proper infrastructure with reliability and speed.

3G sucks in Singapore, but the 4g is amazing. Ericsson is in charge of the 4g infrastructure here. It's not fully done, but for me it feels like island wide coverage.

http://www.techinasia.com/wake-disastrous-rainstorm-beijing-...

Re: Huawei Says It Would Offer Access To Its Source Code

#25
post #5
post #3

Yes, and get all the bugs they want to fix fixed for free, is it not? And leave open those they deem worth leaving.

Huawei wants to enter US market -> spying suspicions Huawei makes source code open -> all they want is free bug fixing Is that really fair? Note: Have you even read the article? They say they would make the source code available for official governmental institutions to analyze it if they wanted, they don't say anything about making it completely open-source!

Neither did I say so: if the US tells them 'this does not comply for this & that' there they go: free counseling....

Yes I do not trust them. A.T.a.l.l.

Have you even taken a look at the crappy code they ship their routers with? Take your time

http://conference.hackinthebox.org/hitbsecconf2012kul/materi...

Re: Huawei Says It Would Offer Access To Its Source Code

#26
post #11
post #8

Has anyone compared Ericssons tech with Huawei? Honest question. I feel like if you're setting up infrastructure, take it from the countries that does it the best. Ericsson is Swedish and _THE_ first country to roll out with 4G (around my parents place, even).

The technology isn't really relevant. Sure, organizations with unlimited budget would probably choose some other vendor than Huawei. But that really doesn't include most mobile operators in the world. And then what starts mattering is that Ericsson or NSN charges twice as much for the same capacity. Or that Huawei is willing to give financing on good terms (including on parts of the network supplied by other vendors)…

[deleted]

Re: Huawei Says It Would Offer Access To Its Source Code

#27

Earlier quoted context omitted.

I see a flaw here. How would we know that the source code made available to US officials is the actual code built and shipped on their devices? They could be showing officials 'cleaned' code, and then ship different code with spyware/malware baked in. The only way to really trust the code is if an end user can download the source, review it, build it, and install it on their device.

I see a flaw in your flaw. 1st) small chance that spying features are implemented that a paranoid analyzing by US officials wouldn't have revealed* (or that the US would have said the products are good, while still having reasonable concerns about potential spying) 2nd) i don't know how they would give their source code to government officials but i guess it's fair to assume that it can be done in private and trustin…

Nice try, Huawei PR
Post reply on HN