Live data from Hacker News

Lenovo: Companies working in China may have to install local backdoors

theinquirer.net

71–80 of 90 posts

Re: Lenovo: Companies working in China may have to install local backdoors

#71
This is gravely concerning to me.

Privacy is a fundamental human right, and it's needed to fight unjust laws and practice civil disobedience in a safe and comfortable way.

If we had today's surveillance capabilities in the 70's, it would have been impossible for the LGBTQ community to achieve the societal acceptance they now have!

We need a fully open-source hardware ecosystem (with downloadable component blueprints, 3D-printing machines and local co-ops or gumtree-like marketplaces for obtaining free hardware), to bring much-needed democratisation to our society like the Internet did at the software / information access level.

We need a Linux of hardware.

Re: Lenovo: Companies working in China may have to install local backdoors

#73

This is gravely concerning to me. Privacy is a fundamental human right, and it's needed to fight unjust laws and practice civil disobedience in a safe and comfortable way. If we had today's surveillance capabilities in the 70's, it would have been impossible for the LGBTQ community to achieve the societal acceptance they now have! We need a fully open-source hardware ecosystem (with downloadable component blueprints,…

Please support librecores. It's a small start. I think one thing we are missing is a Stallman of hardware. Some who is loud, willing to take a stand, and who has enough technical chops to back it all up.

Re: Lenovo: Companies working in China may have to install local backdoors

#74

I miss the early 90s and 2000s when governments were still struggling to understand what the internet was, rather than trying to control it.

Did that time ever really exist? https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... I also remember writing some (naive) crypto tools as a kid and I had to report it to permit re-export from the US. Also, the DMCA is from the nineties: https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

The ban on the export of cryptography strikes me as a great example of the US Government misunderstanding technology - I don't see how it's remotely possible for a ban on exporting ideas to affect bad actors in any way.

Re: Lenovo: Companies working in China may have to install local backdoors

#75

Earlier quoted context omitted.

Did that time ever really exist? https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... I also remember writing some (naive) crypto tools as a kid and I had to report it to permit re-export from the US. Also, the DMCA is from the nineties: https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

The ban on the export of cryptography strikes me as a great example of the US Government misunderstanding technology - I don't see how it's remotely possible for a ban on exporting ideas to affect bad actors in any way.

This is an example of you misunderstanding the US Government's motives for labeling crypto as a non-exportable weapon. ;)

If they had been able to keep it up, they would have. Unfortunately for them, practicality won over here once it began to threaten corporate profits.

Re: Lenovo: Companies working in China may have to install local backdoors

#76
post #64

> Does Lenovo put backdoors in if the Chinese government asks? > "If they want backdoors globally? We don't provide them. If they want a backdoor in China, let's just say that every multinational in China does the same thing. Even though not a direct answer, close enough. One could only hope to get a similar statement from Apple wrt iCloud so we aren't left with assumptions about lack of privacy.

iCloud in China has been hosted by a local licencee for a while. People who care about privacy are at least aware that the backend is no longer secure. While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time be…

My brain's being a bit pedantic/dense about wording, so I want to clarify - are you saying that Windows 10 builds destined for Chinese governmental use are shipped to China in source form?

Re: Lenovo: Companies working in China may have to install local backdoors

#77
post #9

Earlier quoted context omitted.

Companies that don't sell physical goods don't have much choice too. > A prototype search engine that Google is designing to meet the scrutiny of Chinese officials links users’ phone numbers to the searches they perform > This report adds to earlier news, also broken by The Intercept about the search engine, codenamed “Dragonfly,” which eliminates from results a number of terms and topics, like freedom and democracy.…

I think they have plenty of choice. They can say "no", tell these regressive regimes to go to hell, and simply not manufacture/sell their product there, where-ever "there" may be.

> They can say "no", tell these regressive regimes

The US has made pretty similar demands from Google and Twitter and Facebook not too long ago, in the context of "Russian election interference" and even before that on the basis of "terrorist radicalization".

The big difference here is that if the US demands it, it becomes the de-facto global standard. The results of this are subtle, but creeping. [0]

At this point, the aforementioned three are subcontracting a whole little industry of "content moderators" in places like Manila in the Philippines. Where hundreds of people do nothing but "moderate" social media content, they literally "okay" or "delete" videos and pictures on social media.

French channel ARTE made a really interesting, and quite creepy, documentary about it called "The Cleaners" [1]. Sadly it's only been available in French/German, and has been depublished by now, but an English version was shown at Sundance, so that should exist.

[0] https://motherboard.vice.com/en_us/article/wnxdv5/the-artist...

[1]https://www.arte.tv/de/videos/069881-000-A/im-schatten-der-n...

Re: Lenovo: Companies working in China may have to install local backdoors

#78
post #67
post #64

Earlier quoted context omitted.

iCloud in China has been hosted by a local licencee for a while. People who care about privacy are at least aware that the backend is no longer secure. While we are on the topic, Windows 10 binary for Chinese government contracts are compiled by a third party company based in China so certain features could be added/removed at code level without directly giving away the source code. It may only be a matter of time be…

How do I, as a US citizen, know that Apple isn't replicating my data to this Chinese datacenter? I know you will say "you have to trust them", but therein lies the problem. There is no way for consumers to verify anything about their data.

On another note, if I get my data on the Chinese datacenter, does this mean my country's government is unable to extract this information from Apple?

If they send a notice to Apple for my data, will Apple refer them to China instead?

Re: Lenovo: Companies working in China may have to install local backdoors

#79

Meanwhile in the US we also have a long history of monitoring internet traffic, installing backdoors and allowing private third-parties to filter what we see online. Where do we get off critiquing the PRC? We should clean our own house first.

Last I checked, in the EU or the USA you don't disappear in the middle of the night never to be seen again because you are: -follower of different religion -saying the word "democracy" -critisizing a politician/the government so yes, first things first.

> In 2014, former CIA and NSA director Michael Hayden said in a public debate, “We kill people based on metadata.”

> According to multiple reports and leaks, death-by-metadata could be triggered, without even knowing the target’s name, if too many derogatory checks appear on their profile.

> “Armed military aged males” exhibiting suspicious behavior in the wrong place can become targets, as can someone “seen to be giving out orders.” Such mathematics-based assassinations have come to be known as “signature strikes.”

Source: https://www.rollingstone.com/politics/politics-features/how-...

Re: Lenovo: Companies working in China may have to install local backdoors

#80

Earlier quoted context omitted.

But your mini-fab might be backdoored and create chips with backdoors.

More likely that the schematics will contain backdoors, that aren't easily understood to be backdoors. EDIT: have - contains

It could conceivably be done even below the schematic level, though I'm not sure how much room modern processes have for this sort of thing now that we're talking about how many atoms wide a transistor is. I've been told that there was a period of a few years in which a kind of "copy protection" proliferated in IC layouts. The layouts would be tweaked to exploit quirks of the originating company's fabrication process (e.g. a pattern might look like a diode but actually function as a resistor when fabricated), and this would sabotage attempts by other companies to clone the chip (at the time, Japanese and Soviet clones were major concerns).
Post reply on HN