Slashdot Mirror


The Trouble With Bringing Your Business Laptop To China

snydeq writes "A growing trend faces business executives traveling to China: government or industry spooks stealing data from their laptops and installing spyware. 'While you were out to dinner that first night, someone entered your room (often a nominal hotel staffer), carefully examined the contents of your laptop, and installed spyware on the computer — without your having a clue. The result? Exposure of information, including customer data, product development documentation, countless emails, and other proprietary information of value to competitors and foreign governments. Perhaps even, thanks to the spyware, there's an ongoing infection in your corporate network that continually phones home key secrets for months or years afterward.'"

13 of 402 comments (clear)

  1. encryption by Anonymous Coward · · Score: 5, Insightful

    Why doesn't your business mandate HDD encryption?

    China isn't the only place this goes on...

    1. Re:encryption by homer_ca · · Score: 5, Informative

      A hardware keylogger inline with the keyboard cable takes care of that. It only means they'll have to break in twice instead of once.

    2. Re:encryption by Vegan+Cyclist · · Score: 5, Funny

      As a vegan it's probably more like every 16hrs. ;)

  2. Re:That's only one of the problems by DragonWriter · · Score: 5, Informative

    Considering these laptops are for the most part manufactured in China anyway, how does bringing them back there in anyway give China access to any "controlled technology" they don't already have?

    Controlled technology includes software as well as hardware.

  3. throw away laptops by lophophore · · Score: 5, Interesting

    Any serious exec is going to use a throw-away laptop for travelling to China. A $400 special will keep you online abroad, and then it can be destroyed as a business expense. Cheap insurance against hacking.

    --
    there are 3 kinds of people:
    * those who can count
    * those who can't
    1. Re:throw away laptops by Anonymous Coward · · Score: 5, Interesting

      Yup, that's how we deal with it. We're frequently in China to do software and hardware testing at our facilities (I work for a large US transportation company), and we have "China laptops". These are encrypted machines that are specifically loaded with the bare minimum stuff we need when we leave and immediately blown away when we get back. Installation of anything beyond the bare minimum (which is pretty much Win7 and VS2005) is strictly disallowed. Source is kept on a separate, encrypted sd card which is not to be kept in the machine, but even then it's just not that interesting. It's all internal source for package sort controllers and such, and we don't even have the ability to check code back in from these machines. It's purely for debugging and sending problem reports back home.

      There's a big sticker on them that even says "China laptop, do not connect to corporate network"

    2. Re:throw away laptops by swillden · · Score: 5, Informative

      ChromeOS encrypts all user data by default, automatically verifies the integrity of all software during startup, and reverts to a known-good version in the event any compromise is discovered. Boot verification is based on code and data stored in ROM, so subverting it requires modifying the hardware. Run-time compromise must be done by leveraging web-style attacks (cross-site scripting, etc.) and can normally only achieve what web-style attacks can achieve which is access to data from other sites, etc. In the event deeper compromise is achieved, it's lost as soon as the device is restarted, until the user visits the malicious web site again.

      Use a Chromebook, connect only to trusted sites and only over SSL, and you become an extremely hard target for compromise. Little if any of your data is actually stored on the device, what is cached on it is encrypted. When you get home, reboot and you're very, very likely to have a trustworthy system again. Do a factory reset and it's guaranteed to be clean (barring hardware hacks), since all data will be gone, and any modified code will be detected by the verified boot process. And, as a last resort, you only paid $200 for the thing, so if you fear hardware hacks, just chuck it and buy a new one. It's unlikely to add more than about 5% to the cost of your trip.

      http://www.chromium.org/chromium-os/chromiumos-design-docs/security-overview

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  4. Re:Industrial espionage by hendridm · · Score: 5, Interesting

    I've surprised by many of the countries on your list.

    Can you give some examples of what you've observed that we non-travelers might find surprising/interesting?

  5. Re:Or Windows '98 by RabidReindeer · · Score: 5, Funny

    How about Windows 95 with Microsoft Bob?

    I think that's a violation of the Geneva Convention.

  6. Encryption: Not allowed by jabberwock · · Score: 5, Informative

    From The New York Times in February:

    Both China and Russia prohibit travelers from entering the country with encrypted devices unless they have government permission.

  7. troll them by Lehk228 · · Score: 5, Funny

    Troll like a pro, carry lots and lots of "super sekrit" docs in a poorly truecrypted volume (password on a sticky note under the mouse)

    gigabytes and gigabytes of detailed looking prototype data from your projects that failed due to a fatal and truly unsolvable flaw, but fudge the data and info to mask the unsolvable part

    bonus points for anything that will cost them 100 million to fail to reproduce
    more bonus points at the billion, 10 billions and 100 billion level

    cold fusion, hot fusion, electric vehicle, atomic reactors, there must be trillions of dollars worth of hopelessly flawed design proposals kicking around collecting dust in company archives. -- Put them to good^H^H^H^HLulzy use

    --
    Snowden and Manning are heroes.
  8. Re:Industrial espionage by RocketRabbit · · Score: 5, Funny

    I'm sure your lack of experience in capital letters and their proper usage increases the public's perceived veracity in your experience with this subject.

  9. Re:Shred of Evidence by Man+On+Pink+Corner · · Score: 5, Informative

    US export law is no joking matter. It is impossible to exaggerate how goofy the rules are, and how much trouble you can get in for violating them. It doesn't matter if you're a hacker in a basement or a Fortune 100 defense contractor -- you do not want to mess around with these people.

    Some examples of the evidence you're asking for.

    More here. I think my favorite is the veterinary supply wholesaler in Waukee, Iowa who was fined $250,000 for sixteen unlicensed exports of cattle prods to Mexico.