> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices.
Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence.
You're not going to convince me that a foreign state actor pressuring a company to include a backdoor wouldn't disguise it as a "whoopsie, our crap code lol" as opposed to adding in the open with a disclaimer on it.
It's all closed source firmware. Even the GPL packages from most consumer router vendors are loaded with binary blobs. Tell me I should trust it.
If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable. Not so with China.
(That is not to say that the FCC change will move the needle on the underlying issue of router security; as some of the ancestor comments have said, lax security practices are common industry-wide, irrespective of country of development/manufacture.)
The Snowden leak showed that Cisco routers had been altered to enable surveillance [1]. Whether or not the manufacturer is complicit, or how the alteration is performed is ultimately irrelevant to the end user. Ultimately, the only people that got in legal trouble for this were Snowden and people who provided service to him.
It is absolutely relevant. It is completely within the realm of feasibility that a foreign nation state would pressure a manufacturer in their jurisdiction to include a backdoor, or simply insert it themselves. Routers are in every home and office in the country, and can be leveraged for immense attacks. It’s a hugely attractive target, and it’s a reasonable security policy to try to limit our exposure to this threat. And it would absolutely make sense for adversaries to avoid buying U.S. made routers for exactly the same reason. Unfortunately this administration is generating more adversaries by the day.
I think you're responding to the wrong comment, or missing the nuance above.
Having state actors redirecting products after shipping, without telling the company or the client it's happening, and installing backdoors, has nothing at all to do with backdoors from manufacturers.
>a foreign nation state would pressure a manufacturer in their jurisdiction to include a backdoor
That absolutely is about jurisdiction and is a much bigger, more scalable attack than intercepting and installing implants. More to the point, it can be done at _any time_ not just the initial ship.
My point is that the US did alter homemade products for export, and that the only people litigated against were the whistleblower and/or companies providing service to him.
> If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable.
With that context added, my point is that the US judicial system would never litigate against e.g. Cisco if they were involved. The issue is not the relation between the state and Cisco, it's the relation between the US justice system and the US national security apparatus that prevents any such litigation to happen.
> legal avenues exist to hold those manufacturers accountable
Maybe in theory. I think the practical chance of enforcing anything meaningful through those legal avenues against a US manufacturer is not meaningfully higher than the chance of doing so against a Chinese manufacturer, so it doesn't make sense to treat them differently on these grounds.
Sure, but this also bans pretty much all routers made by American companies too, since they're not fully assembled in the US. So I'm not sure that explanation fits.
And I have evidence of domestic devices being intentionally nerfed, backdoors added on purpose, backdoors added by hackers, AND backdoors secretly added by the government itself.
Banning foreign-made devices will not stop any of that.
And who hasn't seen American software companies where crap security practices are later leveraged by the same company to run exploits? It's of course always phrased in Orwellian terms of business practices, terms of service, "security", etc but we can still call a spade a spade.
One dog's exploit is another's Clippy. I've certainly seen companies downgrade security generally when they deploy (and enable by default) new features. Start with web browsers. Ads in software you paid for. Always on app telemetry. Cloud backups. Cloud-compute assisted "desktop" tools. Sorry, out of time.
Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence.
You're not going to convince me that a foreign state actor pressuring a company to include a backdoor wouldn't disguise it as a "whoopsie, our crap code lol" as opposed to adding in the open with a disclaimer on it.
It's all closed source firmware. Even the GPL packages from most consumer router vendors are loaded with binary blobs. Tell me I should trust it.