Live data from Hacker News

Lenovo: Companies working in China may have to install local backdoors

theinquirer.net

51–60 of 90 posts

Re: Lenovo: Companies working in China may have to install local backdoors

#51
Interesting choice of language there:

"we don't put in backdoors [...] we follow the ethics"

but then

"if there are countries that want to have access [...] you provide what they're asking"

No, Mr. YY, it's you who's providing what "they" are asking, and that makes you evil, not me. ("Them" too, naturally.)

Re: Lenovo: Companies working in China may have to install local backdoors

#52
post #33

Earlier quoted context omitted.

But your mini-fab might be backdoored and create chips with backdoors.

That's harder thing to do on every iteration down to the first principles. So in theory you maybe could do the hammer, which is made so as to specifically clog nails with a deviation of 5.2 degrees to the left, which leads to the light bulbs distortions in the chip designer room which eventually leads to particular backdoor in the chip he designed - but this is really hard.

Isn't this just the physical manifestation of "Trusting Trust" - the seminal paper on backdooring compilers?

It might be difficult, but who really inspects their own prints at a 100-micron resolution?

https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7... - there's plenty of HN discussions to be found too.

Re: Lenovo: Companies working in China may have to install local backdoors

#53

I miss the early 90s and 2000s when governments were still struggling to understand what the internet was, rather than trying to control it.

Did that time ever really exist? https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... I also remember writing some (naive) crypto tools as a kid and I had to report it to permit re-export from the US. Also, the DMCA is from the nineties: https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

I remember the US federal govt. hired around 20 Unix sysadmins around 1984-1985 to monitor/archive IRC and newsfeeds (pre-WWW.)

Re: Lenovo: Companies working in China may have to install local backdoors

#54
post #49

Meanwhile in the US we also have a long history of monitoring internet traffic, installing backdoors and allowing private third-parties to filter what we see online. Where do we get off critiquing the PRC? We should clean our own house first.

We do, but this is at a different, unprecedented scaled. As China vies for world hegemony, our future may look very bleak if China's Orwellian views are imposed at a global level.

> As China vies for world hegemony

China is not going to export their political system beyond the HK and Taiwan, unlike the US.

> the country intervening in most foreign elections is the United States with 81 interventions, from 1946 to 2000

Re: Lenovo: Companies working in China may have to install local backdoors

#55

I miss the early 90s and 2000s when governments were still struggling to understand what the internet was, rather than trying to control it.

What? This was never the case. Especially china.

The internet was born from a Department of Defense project (ARPANET). The british, french, etc governments were also early internet players. Every major power understood the internet.

It's why china in the 90s/00s decided to create their own internet companies. It's why we have alibaba, baidu, tencent, etc. The same thing with russia. The same thing with south korea and japan.

Re: Lenovo: Companies working in China may have to install local backdoors

#56
post #33

Earlier quoted context omitted.

That's harder thing to do on every iteration down to the first principles. So in theory you maybe could do the hammer, which is made so as to specifically clog nails with a deviation of 5.2 degrees to the left, which leads to the light bulbs distortions in the chip designer room which eventually leads to particular backdoor in the chip he designed - but this is really hard.

Isn't this just the physical manifestation of "Trusting Trust" - the seminal paper on backdooring compilers? It might be difficult, but who really inspects their own prints at a 100-micron resolution? https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7... - there's plenty of HN discussions to be found too.

That's why we are talking about cheap small mini-fabs instead of just placing the order to any Chinese fab. The mini-fabs would use open-source community-driven software which is easy to audit for backdoors. That's not easy, but the trend is toward that, for sure - e.g. pick and place systems driven by OpenPNP is a step in this direction.

Re: Lenovo: Companies working in China may have to install local backdoors

#57
post #33

Earlier quoted context omitted.

That's harder thing to do on every iteration down to the first principles. So in theory you maybe could do the hammer, which is made so as to specifically clog nails with a deviation of 5.2 degrees to the left, which leads to the light bulbs distortions in the chip designer room which eventually leads to particular backdoor in the chip he designed - but this is really hard.

Isn't this just the physical manifestation of "Trusting Trust" - the seminal paper on backdooring compilers? It might be difficult, but who really inspects their own prints at a 100-micron resolution? https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7... - there's plenty of HN discussions to be found too.

The example in Trusting Trust was a very specific case: he modified the C compiler to replace a known bit of code in the login program. Along those same lines, you could possibly set up your minifab such that it inserts a backdoor into a particular RISC-V implementation. However, if I sat down and made my own chip, how would the fab figure out how to insert a backdoor? If you have code which can analyze a processor layout and seamlessly insert a backdoor, please come forward and collect your Turing Award.

Re: Lenovo: Companies working in China may have to install local backdoors

#58
This is not unique to China. New Zealand has the TICSA requirement that network operators must provide intercept capabilities to security agencies, and all network operator designs must be approved by security agencies before deployment.

I would imagine other five eyes countries have or soon will have similar requirements.

Re: Lenovo: Companies working in China may have to install local backdoors

#59

Earlier quoted context omitted.

Last I checked, in the EU or the USA you don't disappear in the middle of the night never to be seen again because you are: -follower of different religion -saying the word "democracy" -critisizing a politician/the government so yes, first things first.

Really, does HN deserve that kind of idiotic post? You can walk around China an say "democracy" all day. You think they don't report on eg elections in the US on TV there? People in China complain about the government and laws all day. There is a lot wrong with China that they deserve to be called out for, but what's your goal with a post like that? Show the world that you don't have a clue about anything besides tec…

True. It would be a more accurate post if it listed "having a watch set to the wrong time zone" instead (mentioned in the HRW report).

It is unfortunate that there is a lot of misinformation about China out there. Winnie the Pooh isn't banned. The social credit system apparently isn't like how it's commonly reported in the West. But I also chafe at the suggestion that China is little worse than the US on these points. There are few countries on earth that have more control over their population and shape the way they think than China.

https://www.hrw.org/report/2018/09/09/eradicating-ideologica...

Post reply on HN