Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices.

Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence.

You're not going to convince me that a foreign state actor pressuring a company to include a backdoor wouldn't disguise it as a "whoopsie, our crap code lol" as opposed to adding in the open with a disclaimer on it.

It's all closed source firmware. Even the GPL packages from most consumer router vendors are loaded with binary blobs. Tell me I should trust it.



Are you saying that other manufacturers don't do this?


If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable. Not so with China.

(That is not to say that the FCC change will move the needle on the underlying issue of router security; as some of the ancestor comments have said, lax security practices are common industry-wide, irrespective of country of development/manufacture.)


The Snowden leak showed that Cisco routers had been altered to enable surveillance [1]. Whether or not the manufacturer is complicit, or how the alteration is performed is ultimately irrelevant to the end user. Ultimately, the only people that got in legal trouble for this were Snowden and people who provided service to him.

[1]: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...


Actually it's entirely relevant how, in the context of this conversation.

Here, we're discussing product as shipped, not product intercepted and modified. We're discussing if products are shipped secure or not.

The Snowden disclosures are important, but not relevant in this case.


It is absolutely relevant. It is completely within the realm of feasibility that a foreign nation state would pressure a manufacturer in their jurisdiction to include a backdoor, or simply insert it themselves. Routers are in every home and office in the country, and can be leveraged for immense attacks. It’s a hugely attractive target, and it’s a reasonable security policy to try to limit our exposure to this threat. And it would absolutely make sense for adversaries to avoid buying U.S. made routers for exactly the same reason. Unfortunately this administration is generating more adversaries by the day.


I think you're responding to the wrong comment, or missing the nuance above.

Having state actors redirecting products after shipping, without telling the company or the client it's happening, and installing backdoors, has nothing at all to do with backdoors from manufacturers.


You seem to have missed this part:

>a foreign nation state would pressure a manufacturer in their jurisdiction to include a backdoor

That absolutely is about jurisdiction and is a much bigger, more scalable attack than intercepting and installing implants. More to the point, it can be done at _any time_ not just the initial ship.


In as I was specifically not talking about that, and even said so, no.. it's not relevant.


My point is that the US did alter homemade products for export, and that the only people litigated against were the whistleblower and/or companies providing service to him.

> If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable.

With that context added, my point is that the US judicial system would never litigate against e.g. Cisco if they were involved. The issue is not the relation between the state and Cisco, it's the relation between the US justice system and the US national security apparatus that prevents any such litigation to happen.


> legal avenues exist to hold those manufacturers accountable

Maybe in theory. I think the practical chance of enforcing anything meaningful through those legal avenues against a US manufacturer is not meaningfully higher than the chance of doing so against a Chinese manufacturer, so it doesn't make sense to treat them differently on these grounds.


When was the last time American intelligence agencies were held accountable?

Literally your own Congress is not even allowed to review their budget! Not that any US politician even WANTS to know.


> legal avenues exist to hold those manufacturers accountable

Oh, sweet summer child. Disclaiming these possible avenues of liability is the main goal of clickwrap "terms of service".


Are you asking me if I have the master list of naughty and nice router manufacturers?

No, I don't have it but you may check with Santa Claus.


What was the company, and what did they inject?



That's only proof of the vulnerability. Where's the proof of it being misused by the vendor?


Sure, but this also bans pretty much all routers made by American companies too, since they're not fully assembled in the US. So I'm not sure that explanation fits.


And I have evidence of domestic devices being intentionally nerfed, backdoors added on purpose, backdoors added by hackers, AND backdoors secretly added by the government itself.

Banning foreign-made devices will not stop any of that.


And who hasn't seen American software companies where crap security practices are later leveraged by the same company to run exploits? It's of course always phrased in Orwellian terms of business practices, terms of service, "security", etc but we can still call a spade a spade.


One dog's exploit is another's Clippy. I've certainly seen companies downgrade security generally when they deploy (and enable by default) new features. Start with web browsers. Ads in software you paid for. Always on app telemetry. Cloud backups. Cloud-compute assisted "desktop" tools. Sorry, out of time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: