Live data from Hacker News

The Clean Network – United States Department of State

state.gov

101–110 of 412 posts

Re: The Clean Network – United States Department of State

#101
post #16

Has anyone published the evidence of Huawei being an "arm of the PRC surveillance state"? I've seen a lot of claims and a lot of out-of-court-settled lawsuits, but nothing really showing that they're using their devices or software infrastructure for surveillance.

There’s such a long list of this stuff from various companies. It’s not hard to research this at all. In terms of an anecdotal evidence... My father used to work for molex, one of his biggest complaints were fixing the molds after they were sent to Chinese factories. They would try to deconstruct them and couldn’t put them back together (this was the 90’s, early 2000’s). So they would be shipped back to the US operat…

That Molex story is great. Can only imagine how much magic is in some of those molds... trying to think through many molex connectors in terms of relief angles, tolerances, and manufacturability boggles the mind.

Re: The Clean Network – United States Department of State

#102
post #67

Earlier quoted context omitted.

Building something like tiktok covertly is orders of magnitude harder than building it openly in China.

Why? Copy cats are normal, everybody copies things that are successful in other countries. How do you assure that the company that creates a new app "out of the blue" isn't secretly funded by China? Require a background check and federal approval before an app can be downloaded more than 1000 times?

You can't move around the many millions of dollars in advertising without the government being aware of it. Good old fashioned investigative work and arrest of anyone knowingly contributing to wirefraud is sufficient to stop clandestine apps from growing to the size of tiktok.

Sort of like how the CFO of Huawei is currently in jail.

Creating orwellian straw man arguments is not a productive method of conversation. Please stop.

Re: The Clean Network – United States Department of State

#103
post #98
post #90

Earlier quoted context omitted.

> Furthermore, State is a decade or more behind the game. It is my impression that modern companies that care about security assume that all networks are compromised and act accordingly. Unfortunately far from true. There's a small percentage who have the resource to run this kind of ops. Don't look at FAANG on how security is in companies, they're outliers by far.

State's 2020 budget is $52B. It has direct-collaboration access to DOD and NIST. We should expect our national-security infrastructure to be more resilient than commercial infrastructure, not less.

Hmm, absolutely.

However, the infrastructure and scenario may be wildly different from your average (modern) big tech company.

There's always the notion that your national infrastructure needs the security applied as an afterthought, VS maybe more careful planning and less heavy "legacy" dragging them down in the tech companies.

Re: The Clean Network – United States Department of State

#104
post #42
post #19

Earlier quoted context omitted.

The election may already be "decided" through fraudulent means with the USPS being captured. Trump's USPS' Postmaster General replacement, along with who recently fired 23 USPS executives: "Lawmakers Demand Removal of Postmaster General DeJoy Over 'Nefarious' Efforts to Destroy the Postal Service and 'Aid Trump Reelection'" - https://www.reddit.com/r/politics/comments/i71z41/lawmakers_...

This shouldn't be downvoted - it's relevant to hackers here because the executive branch found an effective way to hack the electoral process. Socio-political engineering at its finest!

I concur, I just wish we weren't living in it.

Re: The Clean Network – United States Department of State

#105
post #80

I have the same feeling about this as I did the announcement of the "Department of Homeland Security". The name sounded Soviet in origin, with only the exchange of "Homeland" in place of "Motherland". It reminded me of things my family had taught me didn't happen in the United States. "We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbo…

> It is my impression that modern companies that care about security assume that all networks are compromised and act accordingly. See https://cloud.google.com/beyondcorp as an example.

No, you assume the network can be compromised like any other device in the system. You still defend the network and add in layers of access control. Employees of Google still use VPNs to connect into sensitive networks.

With the prevalence of 0-days and demonstration of usage by nation-state actors, you have to have multiple layers of defense to try to have any reasonable chance of preventing a compromise.

Re: The Clean Network – United States Department of State

#106
post #40

What is a better way to prevent mass IP theft the CCP is doing?

Simple, stop outsourcing manufacturing to China. Companies regularly get contracts which require an IP transfer in return for cheap mass labor. Of course there's IP which is stolen, but that's the cost of doing business when manufacturing at home has been shuttered.

But, wouldn't this need to be enforced by the government? How else are companies going to agree to stop outsourcing manufacturing to China? And if you agree that the correct solution involves government regulation, then what specifically about this plan doesn't accomplish your preferred outcome of "stop outsourcing manufacturing to China"? I may be naive but I also fail to see exactly how this plan is bad. Do you not feel the Chinese government is using technology to undermine the US, or that this isn't actually a legitimate and compelling issue of national defense?

Re: The Clean Network – United States Department of State

#107

Earlier quoted context omitted.

it swings back when we invent new protocols - which is to say it never swings back. From traditional publishing to radio to tv to the internet to gentrification once the bastards get control you gotta make the next thing.

This isn't just protocols, though. At least to me it sounds like an announcement that they plan to "cut the lines" to countries that don't adhere to the standards of the current American administration. A new protocol won't allow you to communicate with people in the United States if you're on a "blacklisted" comms company's network.

Well that's not how the Internet works. Perhaps they can blacklist prefixes from being accepted by American ISPs, but as long as ISPs peer with any ISPs from outside of the country, those advertisements will be coming in.

Re: The Clean Network – United States Department of State

#108
post #80

I have the same feeling about this as I did the announcement of the "Department of Homeland Security". The name sounded Soviet in origin, with only the exchange of "Homeland" in place of "Motherland". It reminded me of things my family had taught me didn't happen in the United States. "We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbo…

Yes. It is ridiculous how closely the language sounds to that of a dictatorial regime. The language is just so.. cringy. When I first read, I genuinely could not believe it was not onion or some weird caricature.

Re: The Clean Network – United States Department of State

#109
post #80

I have the same feeling about this as I did the announcement of the "Department of Homeland Security". The name sounded Soviet in origin, with only the exchange of "Homeland" in place of "Motherland". It reminded me of things my family had taught me didn't happen in the United States. "We call on all freedom-loving nations and companies to join the Clean Network." is a sentence straight out of an authoritarian playbo…

To be honest they are forcing a "National Internet" in Iran, and the language in this document just reminded me of that. Huh.

Re: The Clean Network – United States Department of State

#110
This really comes off as a hastily prepared political dig against China, when there are in addition so many other actors and countries trying to take advantage of poor security. The JPEGed giant logo at the top doesn't help...

Other observations:

-- "Remove untrusted applications from US mobile app stores": so, this would call for even tighter control by Apple, Google, over its app distribution and monopolies?

-- Clean Apps: "Prevent untrusted PRC OEMs from installing trusted apps on their apps store... should remove apps to ensure they are not partnering with a human rights abuser." Umm, seriously, we're going to open this can of worms?

Edit to add a last thought:

I have yet to understand or read a coherent description about how we do not have the technical ability to protect against eavesdropping/etc regardless of who owns the physical hardware. Why is CCP-owned infrastructure uniquely susceptible to this? If we can't protect our transmissions with encryption, secure data storage techniques, what does it matter that the equipment is supplied by China? What unusual attack do they get access to by owning or manufacturing the equipment?

Post reply on HN