Slashdot Mirror


Under Pressure, Western Tech Firms Including Cisco and IBM Bow To Russian Demands To Share Cyber Secrets (reuters.com)

An anonymous reader shares a Reuters report: Western technology companies, including Cisco, IBM and SAP, are acceding to demands by Moscow for access to closely guarded product security secrets, at a time when Russia has been accused of a growing number of cyber attacks on the West, a Reuters investigation has found. Russian authorities are asking Western tech companies to allow them to review source code for security products such as firewalls, anti-virus applications and software containing encryption before permitting the products to be imported and sold in the country. The requests, which have increased since 2014, are ostensibly done to ensure foreign spy agencies have not hidden any "backdoors" that would allow them to burrow into Russian systems. But those inspections also provide the Russians an opportunity to find vulnerabilities in the products' source code -- instructions that control the basic operations of computer equipment -- current and former U.S. officials and security experts said. [...] In addition to IBM, Cisco and Germany's SAP, Hewlett Packard Enterprise Co and McAfee have also allowed Russia to conduct source code reviews of their products, according to people familiar with the companies' interactions with Moscow and Russian regulatory records.

111 comments

  1. I'd want to know, too. by Frosty+Piss · · Score: 5, Insightful

    These are reasonable requests and fit perfictly within the Open Source paradigm. So what's the issue?

    Oh, yeah it's Russia...

    --
    If you want news from today, you have to come back tomorrow.
    1. Re:I'd want to know, too. by Anonymous Coward · · Score: 1

      And the cybercrime mafia that they work with.

    2. Re:I'd want to know, too. by rmandevi · · Score: 5, Insightful

      If they're sharing the code with everybody, that's good engineering practice. This raises the possibility that a White Hat will discover a bug and report it to the vendor, who can then close the hole.

      If they're sharing it with only Russia, this puts them in a privileged position to exploit those bugs without reporting them. Clearly, this increases the odds of a breach. This isn't because it's Russia, either; sharing with any one entity, unless you absolutely trust them to report all the flaws they find, causes the same problem.

      --
      People who live in glass houses shouldn't walk and text.
    3. Re:I'd want to know, too. by ShanghaiBill · · Score: 4, Insightful

      These are reasonable requests and fit perfectly within the Open Source paradigm. So what's the issue?

      The Open Source paradigm is that with many eyes all bugs are shallow. But in this case, there are not many eyes, only a few Russian eyes, and those eyes are at least potentially hostile.

      If they want to give the Russians access, it would be wise to also give more source access to friendly eyes, such as Western security experts, along with some bug bounties to incentivise them.

    4. Re:I'd want to know, too. by Frosty+Piss · · Score: 5, Insightful

      If they want to give the Russians access, it would be wise to also give more source access to friendly eyes, such as Western security experts, along with some bug bounties to incentivise them.

      Who says they haven't? My guess is the NSA has looked at the code...

      --
      If you want news from today, you have to come back tomorrow.
    5. Re: I'd want to know, too. by Anonymous Coward · · Score: 3, Insightful

      Do you honestly think that US agencies don't have access to the source code of US products? I can't imagine the department of defense running Cisco routers without inspecting the source code at first. Can you imagine US agencies running Chinese products and wouldn't it be reasonable to ask them to disclose their source code before you buy from them ?

      I mean Cisco don't HAVE to sell to Russia and Russia doesn't have to buy their stuff. They can go for Huwaweii instead and I am pretty sure they will get the source for that,

    6. Re: I'd want to know, too. by Frosty+Piss · · Score: 0

      I mean Cisco don't HAVE to sell to Russia and Russia doesn't have to buy their stuff.

      Corporations like Cisco do not have an allegiance except to the dollar.

      How about a Hitler analogy: If Hitler were alive and a rising star in Germany today Cisco would be all over it providing the infrastructure for the IoT computer network for the ovens...

      --
      If you want news from today, you have to come back tomorrow.
    7. Re:I'd want to know, too. by Anonymous Coward · · Score: 1

      BWAAAHHHAAA. They HAVE given the US and other supposedly 'friendly eyes' access. Hell, we KNOW the CIA had some Cisco routers diverted to have spyware installed on them. The problem here is your definition of 'friendly eyes'. You're assuming WE'RE the 'good guys' and 'our side' would do nothing wrong if given that access. How may times does the NSA & CIA have to get caught with their hands in the cookie jar before people wake up to the fact that these agencies are NOT our 'friends'.

      They may work for us but they are NOT working 'on our behalf'. WannaCry would never have happened if the CIA had disclosed the vulnerability to MS as a 'good actor' would. Instead the CIA keeps the world in the dark & when it gets out (it was inevitable) then the world blames a 'hacker' instead of the real culprit, the CIA.

    8. Re: I'd want to know, too. by Anonymous Coward · · Score: 0

      Well, I guess you can that to the Chinese in ten years or so, then let them decide whatever you have a "Hitler" in power ...

    9. Re:I'd want to know, too. by ShanghaiBill · · Score: 2, Interesting

      Who says they haven't? My guess is the NSA has looked at the code...

      The NSA doesn't report bugs and vulnerabilities back to the tech company.

      If I had a choice of disclosing my source code to either the Russians or the NSA, I would pick the Russians.

    10. Re:I'd want to know, too. by Anonymous Coward · · Score: 0, Insightful

      So anyway, how's the pay for being a russian shill ?

    11. Re:I'd want to know, too. by Anonymous Coward · · Score: 0

      Wouldn't this fall under the Munitions Act or whatever like encryption?

    12. Re:I'd want to know, too. by sl3xd · · Score: 1

      Yeah, I'd go with neither - agencies from both nations are going to do the same thing, for the same reasons.

      --
      -- Sometimes you have to turn the lights off in order to see.
    13. Re: I'd want to know, too. by ShanghaiBill · · Score: 2

      Do you honestly think that US agencies don't have access to the source code of US products?

      Do you honestly think that these agencies are "friendly eyes"?

    14. Re:I'd want to know, too. by WheezyJoe · · Score: 1, Insightful

      Truly. If they're sharing them with Russia, they should share with EVERYONE - draw an open-source license.

      IBM et al. are biting the bullet because they want to sell to the Russian market... perhaps because if they don't, someone else will and make lots of oil-soaked rubles and countless Russian intangibles. But if they give away these "secrets" to the Russians, we can pretty much assume such secrets are in the wild, perhaps immediately handed to the teams of patriotic but not-at-all-affiliated with the government Russians (wink, wink) who are taking down Ukrane's power grid. The point of keeping them secret is so that other people won't copy what you've done and sell it and compete with you. But for sure that's exactly what the Russians will do with this... build their own so they don't have to give up their oil rubles to Western companies. And there's no guarantee the Russians won't sell what they've learned to the Chinese (or any other highest bidder), who will be happy to pass it on to some half-state-owned conglomerate to build their own equipment for 1/1000 of what the Western companies would sell for.

      The only people NOT getting in on the source code is the open-source community who might do something good with it, like find bugs.

      Put short, if you're going to have to open your code to Russia to sell to Russia, draw an open-source license first. If you can't afford the open-source community to see and copy your code, you damn well can't afford the Russians to do it.

      Me, if I want to purchase "secure" equipment from these companies, I damn-well want to make they're products that have NOT been sold and opened-up to the Russians, or for my money such equipment is de-facto NON-secure. Should have some kind of NOT OPENED TO RUSSIANS certification or something.

      --
      Take it easy, Charlie, I've got an Angle...
    15. Re:I'd want to know, too. by WheezyJoe · · Score: 1, Insightful

      The NSA doesn't report bugs and vulnerabilities back to the tech company.

      If I had a choice of disclosing my source code to either the Russians or the NSA, I would pick the Russians.

      Be careful what you wish for. The NSA may bust your neighbor for hoarding bomb-making material, or fink you to the FBI for your 15-year collection of kiddy-pr0n. The Russians, OTOH, will cut the power to your town on the hottest day of the year, brick the machine in the hospital that's keeping you alive, make your bank account disappear, make ships, drones and planes crash into each other, and turn your home router into a trove of kiddy-pr0n while finking you out to the FBI, and even rig media and election machines to put a failing businessman turned reality-TV show host into the White House. Why? For a laugh at our expense (what else is there to do fun in Russia?), and to show Big Boss Putin what they can do in hopes of catching a few scraps from his table.

      It ain't a great choice, nor do I have it, but I'll take the NSA, thank you.

      --
      Take it easy, Charlie, I've got an Angle...
    16. Re: I'd want to know, too. by Anonymous Coward · · Score: 0

      And it's not open source ------

    17. Re: I'd want to know, too. by Anonymous Coward · · Score: 0

      Besides that, if the NSA is aware of any particular vulnerabilities, and if they keep their ear to the ground, they should at least get an idea of a developing cyber attack, and warn the vendor well in advance.

    18. Re: I'd want to know, too. by Anonymous Coward · · Score: 0

      Poor American companies, forced to give all their secrets to the bad Russians, just to be able to have enough bread for their kids ... bad Russia, bad. Where's this world going, it was so much better when our empire was untouchable.

    19. Re:I'd want to know, too. by unixisc · · Score: 1

      Since China has been stealing not only our IP but also doing identity theft on Americans, it's hardly fair to let them have a monopoly on that. I fully support Russia horning in on the action. But they should give us land in Siberia for the privilege

    20. Re:I'd want to know, too. by Anonymous Coward · · Score: 0

      So once again greed over all else. The vendors should have told them to go pound sand and develop their own shit. They have the resources.

    21. Re:I'd want to know, too. by Anonymous Coward · · Score: 0, Insightful

      Yeah, sure thing. Until 'white hats' start dying mysteriously of polonium poisoning.

    22. Re:I'd want to know, too. by OrangeTide · · Score: 2

      If I had a choice of disclosing my source code to either the Russians or the NSA, I would pick the Russians.

      I strongly disagree, I say this having worked at Cisco when Russian companies were building and selling clones of Cisco gear, and firmware updates with hacked licenses.

      --
      “Common sense is not so common.” — Voltaire
    23. Re:I'd want to know, too. by roman_mir · · Score: 1

      The Open Source paradigm is that with many eyes all bugs are shallow. But in this case, there are not many eyes, only a few Russian eyes, and those eyes are at least potentially hostile.

      - not only these are 'not many eyes', these are very *specific* eyes looking at the code.

      The code is not given to just anybody in Russia, it's provided to the government, which hires people specifically to break into systems. This does not reduce security problems, it increases them.

      Of-course I believe that NSA, (and by extention CIA, FBI, DHS, etc.) also have seen this code and the same exact problem applies there as well.

    24. Re:I'd want to know, too. by Anonymous Coward · · Score: 0

      As a business, you can go with 'neither'. But then, no sales in Russia because they just banned your product.

      If you want to sell sw in Russia, you put up with their audits. (There can be no backdoors, or at least none unknown to them. They are not stupid.) If you want to sell gps products, they had better support glonass too. They care for their own.

    25. Re:I'd want to know, too. by Anonymous Coward · · Score: 0

      You are being naive. What's the incentive for white hats to go looking vs the incentive for sponsored black hats?

    26. Re: I'd want to know, too. by Anonymous Coward · · Score: 0

      LOL how naive.

      The NSA hoard vulns for later use. They don't disclose the good stuff.

    27. Re:I'd want to know, too. by Anonymous Coward · · Score: 0

      and those eyes are at least potentially hostile.

      that's the purpose, or you just want cheers and kudos for your "well written" software?
      They have the incentive to spot vulnerabilities, they don't care about money.

    28. Re:I'd want to know, too. by RabidReindeer · · Score: 1

      Because the items in question are presumably not Open Source, they're

      closely guarded product security secrets

      Meaning that the open-source support community hasn't had a chance to vet these resources for either accidental security holes, deliberate back doors, or weak spots that this quarter's budget didn't allow fixing.

      So an unfriendly power can see things that the American public cannot see, giving them an advantage in terms of exploits and exploit counter-measures.

    29. Re: I'd want to know, too. by Anonymous Coward · · Score: 0

      How about a Hitler analogy: If Hitler were alive and a rising star in Germany today Cisco would be all over it providing the infrastructure for the IoT computer network for the ovens...

      If Hitler were alive and a rising star in Germany today, IBM would... oh shit.

    30. Re:I'd want to know, too. by Anonymous Coward · · Score: 0

      Who says they haven't? My guess is the NSA has looked at the code...

      He said friendly eyes.

    31. Re:I'd want to know, too. by Tom · · Score: 1

      only a few Russian eyes, and those eyes are at least potentially hostile.

      That is exactly why they want to see the source code. Because they are considered hostile, which makes it highly likely that those security products are being fitted with backdoors.

      It shows they're not complete idiots.

      If you want to know if something is a bullshit and you are the victim of propaganda, simply reverse the roles. If big Russian IT companies, known for working closely with the Russian government, would sell security products to the USA, how would you judge that the US government asks to see the source code for security reasons?

      --
      Assorted stuff I do sometimes: Lemuria.org
    32. Re:I'd want to know, too. by Tom · · Score: 2

      If they're sharing it with only Russia,

      What makes you think the US or other western governments didn't ask for the source code and had it inspected?

      --
      Assorted stuff I do sometimes: Lemuria.org
  2. Fake red scare by Anonymous Coward · · Score: 0, Offtopic

    The "Russia hacked the election" narrative is DNC/MSM political fiction. The rest of the world isn't paying any attention and it's business as usual.

    1. Re:Fake red scare by AutodidactLabrat · · Score: 1, Interesting

      Well, except for the DAILY new information supporting the Trump - Putin - Hacker - Election axis, yes, that means everyone NOT in the Faux "News" moonbat directory.
      Daily
      With former FBI, NSA and CIA directors acknowledging the One Party Promoting Hacks

    2. Re:Fake red scare by PopeRatzo · · Score: 1

      The "Russia hacked the election" narrative is DNC/MSM political fiction.

      You might want to mention that to President Trump and current Homeland Security officials. He seems to think it was real. Also, to those left-wing Democratic operatives over at Voice of America.

      "At a separate hearing, a current Homeland Security official, Jeanette Manfra, told the Senate Intelligence Committee that the agency has evidence that Russia targeted election-related systems in 21 of the 50 U.S. states. Johnson said 36 states accepted help from the federal government in trying to blunt the Russian efforts, even as many states rejected federal oversight of their state-run election operations."

      https://www.voanews.com/a/trum...

      --
      You are welcome on my lawn.
    3. Re:Fake red scare by Anonymous Coward · · Score: 0

      I think its about time the canard of "political fiction" is put to rest. There is enough evidence of Russia attempting to hack the election. There is also data on specific methods used, signature attacks that have been narrowed down to individuals or teams (mostly based on evidence from Ukraine which has dealt with a horrendous stream of assaults ever since they dared to defy Putin) and all this is in the open. We have no idea what the NSA or the FBI have which maybe far more sophisticated or detailed than what we see from private researchers. To stick your head in the sand and pretend that there is no Russian intervention is at best stupid and at worst somewhat treasonous.
      Note that this is distinctly different from whether Trump and his merry and colluded with the russians; at present all we have is conjecture - at least in public domain. If there is direct evidence of collusion, we have a serious problem. At present is is highly circumstantial.

    4. Re:Fake red scare by unixisc · · Score: 1, Troll

      WHAT evidence? Wikileaks is hardly evidence that the Russians tried to interfere. If anything, Dem administrations - both Clinton & Obama - tried interfering in foreign elections, such as Israel's.

    5. Re:Fake red scare by Anonymous Coward · · Score: 0, Informative

      HURR DURR Trump make 'murrika GREAT again! Freind Trump bring back rocks-that-make-fire! Trump boldly grab woman right in pussy like REAL man! HERP DERP

      You Trumpites are fucking retarded. Seriously check your tap water for lead contamination. Are you from Flint Michigan or something? Be sure to enjoy your boy (and I do mean BOY, he's no man, he's an overgrown piece of shit 13 year old) getting thrown in Leavenworth for treason. We should round up all of you sub-100 IQ types that voted for that fat faggot and put you in a camp somewhere so you won't cause any more trouble. Fucking autists.

    6. Re:Fake red scare by subk · · Score: 0

      No, you shut the fuck up beau. Why don't you go find some more faggot ass Microsoft stories to post.

      --
      Now, if you'll excuse me, I have backups to corrupt.
    7. Re:Fake red scare by phantomfive · · Score: 2

      everyone NOT in the Faux "News" moonbat directory.

      What news source isn't in the moonbat directory right now? They've all gone off the deep end as far as I can tell.

      --
      "First they came for the slanderers and i said nothing."
    8. Re:Fake red scare by Zontar+The+Mindless · · Score: 1

      Maybe you should find a better way to waste your time than responding to an obvious ringer?

      (ProTip: Posts from real Slashdot editor accounts are badged with the Slashdot logo.)

      --
      Il n'y a pas de Planet B.
    9. Re:Fake red scare by Anonymous Coward · · Score: 0

      skiped a pill?

      go clubbing ITS FRIDAY YEEEEEE

    10. Re:Fake red scare by Anonymous Coward · · Score: 0

      That's what the Russians want you think. Seed doubt.

    11. Re:Fake red scare by AutodidactLabrat · · Score: 1

      That's what TRUMP wants you to think, prevent Democratic elections!

  3. Code audits shouldn't be suspicious by Hentes · · Score: 3, Interesting

    They should be standard procedure by every authority dealing with security sensitive systems.

  4. I soviet russia the source code opens you by paulatz · · Score: 1

    This story is the best reply to all those who claim that closed source offers intrinsically better security than open source: close source code is only closed for you.

    --
    this post contain no useful information, no need to mod it down
    1. Re:I soviet russia the source code opens you by Aighearach · · Score: 1

      In Soviet Russia, code repository forks you!

      Incidentally, this is why my next router is going to be a generic linux SBC and not an appliance.

  5. they are just catching up with the times by Anonymous Coward · · Score: 0

    American agencies have been doing this for decades now, but its apparently a story when the Russians do it...

    Capcha: stench

  6. solution :-) by Anonymous Coward · · Score: 0

    There is very easy solution to this - open source the proprietary code :-)

  7. Many governments do this by Arzaboa · · Score: 1

    US Government does this. China does this. Others do. I'm only surprised they didn't start sooner.

    1. Re:Many governments do this by AHuxley · · Score: 2

      Companies that wanted to sell to the US gov often show their code in full too.

      --
      Domestic spying is now "Benign Information Gathering"
  8. Fair is fair by Anonymous Coward · · Score: 0

    It is to be expected that the US agencies have had access to the source code for years, so it is not unreasonable for other countries to want to review the code too. As long as it is a technical review (and not cover for corporate espionage) this could be a good thing to help make everyone feel more comfortable (if the Russians buy the devices after reviewing the code, it is unlikely that they saw lots of backdoors).

  9. Pot, meet Kettle by Anonymous Coward · · Score: 0, Funny

    I'm glad the US, British and western governments never do such things. /s

    1. Re:Pot, meet Kettle by Anonymous Coward · · Score: 0

      I'm glad the US, British and western governments never do such things. /s

      Of course they do not. Why would they need to? It is them who design and manufacture the hardware and/or the code that goes with it.

  10. A headline you'll never see... by mnemotronic · · Score: 2
    A headline you'll never see...

    Western technology companies, including Cisco, IBM and SAP, are acceding to demands by concerned citizens in many countries for access to closely guarded product security secrets

    Weird that the companies value making a buck today over the possibility that a hostile foreign power could undermine the security of their products tomorrow. I see it as these companies throwing everyone who depends on these systems under the bus.

    --
    The Russians have won. They have made the world a cesspool of distrust, greed, fear and hate.
    1. Re:A headline you'll never see... by zlives · · Score: 1

      a hostile foreign power would maybe matter to a national company, multinationals have no conflict except lack of growth.

    2. Re:A headline you'll never see... by Anonymous Coward · · Score: 0

      A headline you'll never see...

      Western technology companies, including Cisco, IBM and SAP, are acceding to demands by concerned citizens in many countries for access to closely guarded product security secrets

      Weird that the companies value making a buck today over the possibility that a hostile foreign power could undermine the security of their products tomorrow. I see it as these companies throwing everyone who depends on these systems under the bus.

      I work for one of those companies in that list and have been a part of an on-site visit by the foreign government entities. Its done in a VERY controlled manner. Unless somebody has a photographic memory that can memorize the entire product design, AND, over 1 million lines of code all in their head - yeah, good luck with pulling off a security exploit.

      Try changing the name of the country reviewing source code to "Canada". Tell me if you opinion changes. I can promise you the on-site controls in place absolutely do not.

    3. Re:A headline you'll never see... by mnemotronic · · Score: 1

      I work for one of those companies in that list and have been a part of an on-site visit by the foreign government entities. Its done in a VERY controlled manner.

      Under the conditions you describe I can see how it would be difficult to duplicate the source code, or glean much in the way of useful information

      to ensure foreign spy agencies have not hidden any "backdoors" that would allow them to burrow into Russian systems.

      . Personally, I couldn't sit down, scan over 1 million lines of code and spot any backdoors, but somebody obviously can.

      I didn't catch where the reviews you were part of were conducted. The article says reviews were done in a "clean room" and mentions Echelon, a Moscow-based technology testing company. Normally I'd be a little skeptical, but I guess when Echelon says "clean" they really mean it.


      {sarcasm=on}
      Hang on a sec, someone on the phone wants to sell me a bridge in St. Petersburg for a really reasonable price. I can't let this offer pass.

      --
      The Russians have won. They have made the world a cesspool of distrust, greed, fear and hate.
  11. This is the absolute best effect of Trump elected by SuperKendall · · Score: 2

    Before, no-one would have cared about Russia at all. Many openly mocked Romney years ago for saying Russia was still a threat...

    Now Russia actually concerns people, not just on the right anymore but also the left. FINALLY we have some agreement that we need to be more cautious with security around Russia and that they are a major player in security breaches.

    Mind you, the left has probably gone overboard on the Russia concern, but they are way closer to the correct degree of paranoia than they once were even if they overshot.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  12. Greed will destroy the west by Anonymous Coward · · Score: 1

    "We will hang the capitalists with the rope that they sell us."

    W.I. Lenin

    1. Re:Greed will destroy the west by unixisc · · Score: 1

      Russia != USSR

  13. Re:This is a test by Anonymous Coward · · Score: 0

    Sorry, Google won't let me search social security numbers. Who does that one belong to?

  14. "Ostensibly"? by Anonymous Coward · · Score: 0

    "are ostensibly done to ensure foreign spy agencies have not hidden any "backdoors""

    "Ostensibly"? The US government has a verified history of sneaking malicious items into commercial electronics, The Cisco Routher fiasco, the Iraq printer chips, the printer watermarks are just few of the more well known ones. Foreign governments have good reason to be wary of US computer hardware/software.

  15. I just hope ... by CaptainDork · · Score: 1

    ... the Russians let me know if my Cisco router is a piece of shit.

    --
    It little behooves the best of us to comment on the rest of us.
  16. The USA should ... by CaptainDork · · Score: 1

    ... certainly be doing the same for IoT.

    --
    It little behooves the best of us to comment on the rest of us.
    1. Re:The USA should ... by sl3xd · · Score: 1

      Regulation in this administration/congress/senate? Why don't you just go punch out God while you're at it?

      --
      -- Sometimes you have to turn the lights off in order to see.
    2. Re:The USA should ... by CaptainDork · · Score: 1

      I'd rather tip a unicorn.

      --
      It little behooves the best of us to comment on the rest of us.
  17. And Why are we saying "yes"? by evolutionary · · Score: 2

    Okay, do we really want business with Russia so badly we are going to potentially exposure ourselves so freely? Wonder how Trump is enjoying this.

    --
    "Imagination is more important than knowledge" - Einstein
  18. Anything for money by tatman · · Score: 1

    Sadly, its that simple.

    --
    I've always said English was my second language. Had Romeo and Juliet been written in C, I might have understood it.
  19. Whose Problem is This, Really? by TommyNelson · · Score: 1

    Well, its not as if Cisco and Co are obliged to reveal their code. They choose to agree to the demand so as to be able to sell their products there. So that is just plain commercial interest - nothing inherently wrong there.

    On a political level the adversary has a chance to spot and exploit possible flaws in said code to do Bad Things... different pair of shoes, isn't it, Donald.

  20. Importing crypto to Russia requires two licenses. by tlambert · · Score: 1

    Importing crypto to Russia requires two licenses.

    One from their equivalent of the State Department, and one from their equivalent of the NSA.

    The NSA part stopped granting licenses a while back, which is why the Chromebook crypto development group was disbanded in Moscow (and most of them ended up moving West to Finland, and started working on the same code again).

    You weren't allowed to import or export computers with TPM hardware.

    Hard to work on Chromebooks when you can't get Chromebooks.

  21. What about export controls? by drew_kime · · Score: 1

    I thought there were export controls on security/encryption software, specifically to prevent this technology from falling into the hands of international rivals.

    --
    Nope, no sig
    1. Re:What about export controls? by TechyImmigrant · · Score: 1

      I thought there were export controls on security/encryption software, specifically to prevent this technology from falling into the hands of international rivals.

      You file paperwork with the government and get permission, per product. This is normal.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    2. Re:What about export controls? by unixisc · · Score: 1

      The world is probably pretty even on this. Like the OpenBSD project is Canadian, not American, and their stuff is pretty much open. Chances are that not only do the Russians & Chinese have the latest & greatest, but even our Muslim enemies do. Export controls won't do a thing

    3. Re:What about export controls? by gweihir · · Score: 1

      These always were BS. What would happen today is that they would just build their own equivalents not much later.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  22. It's Sales FFS by Anonymous Coward · · Score: 0

    I work making security products for a big company. Not one of those listed in TFS, but you use their products.

    Yes we share design details and source code with governments and other big customers, under NDA. It's normal practice. They need a reason to trust the product. We want to sell it to them. The value is not in the source code. It's in the trust that customers have in the product.

    We aren't acceding to demands. Someone sends an email. We pull in a lawyer who does the NDAs (if we don't already have one) and than have a couple of meetings to find out what they are after and to go over the design and code.

    A nice thing about governments is that they are usually well informed customers. They have experts who can ask difficult and pertinent questions that help in understanding your own designs from a security perspective.

    There is nothing new here. Move along.
       

    1. Re:It's Sales FFS by Rick+Schumann · · Score: 1

      How effective is having a foreign government, potentially hostile to your country, sign an NDA, so far as preventing them from using knowledge of that source code to mount attacks targeting your specific products?

  23. Re:Importing crypto to Russia requires two license by unixisc · · Score: 1

    What's there to stop the Russians from creating Chromebook VMs? That's easy to do on standard, more powerful computers. They can then work on those VMs.

  24. Re:This is a test by Anonymous Coward · · Score: 0

    whats with all these ^9 numbers, are you fucking kids? god damned millenials.

  25. Re:This is the absolute best effect of Trump elect by nnet · · Score: 4, Insightful

    McCarthy wasn't always wrong. What goes around comes around. Welcome to the New Cold War, same as the Old Cold War.

  26. This is why it is so stupid ... by Alain+Williams · · Score: 3, Insightful

    of the likes of GCHQ and the NSA to hoard vulnerabilities that they find. The Russians, and likely other ''bad guys'', are probably going to find the same set of vulnerabilities.

    If they really wanted to do their job of protecting us they would tell the vendor and we would all be a lot safer.

    1. Re:This is why it is so stupid ... by gweihir · · Score: 1

      Indeed. And even of the others do not get the source code, these reviews can be done on lower level as well. Just a bit more expensive.

      Incidentally, for most purposes, the NSA and the GCHQ must be classified as "bad guys" these days.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  27. Re:Importing crypto to Russia requires two license by OrangeTide · · Score: 1

    Because a VM isn't real hardware and you miss out on a lot of platform issues when you never run your software on the real platform.

    --
    “Common sense is not so common.” — Voltaire
  28. Re: This is the absolute best effect of Trump elec by SuperKendall · · Score: 1

    Yeah like you are going to do any business in Russia without going through the Russian Mafia to some degree - who cares?? The Russian Mafia is old news compared to Russian Government. Get a new hobby as yours is driving you CRAY CRAY.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  29. collusion by Anonymous Coward · · Score: 0

    The NSA already knows about the vulnerabilities and refuses to tell the U.S. companies about them.

  30. As Lenin wrote... by Anonymous Coward · · Score: 0

    They [capitalists] will furnish credits which will serve us for the support of the Communist Party in their countries and, by supplying us materials and technical equipment which we lack, will restore our military industry necessary for our future attacks against our suppliers. To put it in other words, they will work on the preparation of their own suicide.

  31. Maybe do produce products with bad code then? by gweihir · · Score: 1

    And these reviews are nothing to fear. Cone to think of it, maybe have such reviews of your products done independently and regularly anyways?

    I can see nothing bad here, the Russians are doing it right.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    1. Re:Maybe do produce products with bad code then? by gweihir · · Score: 1

      That should have been "do not" in the title...

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  32. *American Tech Firms by Anonymous Coward · · Score: 0

    Don't throw all of us into one pot.

    I see you choosing geological areas however convenient. Fuck that.

  33. We have Top Men working on it. Top Men. by Anonymous Coward · · Score: 0

    > Well, except for the DAILY new information supporting the Trump - Putin - Hacker - Election axis, yes

    Highly placed anonymous intelligence sources from the Obama administration, as well as seventeen US intelligence agencies, tell me that all of that information was fabricated out of thin air by people making up quotes. While I was not able to analyze the servers myself, the reports I was shown have given me high confidence that it's pure hokum. If you doubt me, I will be happy to supply some memos that I wrote which confirm that my version of the story is accurate.

    So who are you to discount all of these intelligence agencies?

  34. Re: This is the absolute best effect of Trump ele by Anonymous Coward · · Score: 0

    "The Russian Mafia is old news compared to Russian Government"

    There's a big overlap between them.

  35. Re:This is the absolute best effect of Trump elect by Anonymous Coward · · Score: 0

    Many openly mocked Romney years ago for saying Russia was still a threat...

    No, we mocked him for his outdated response which was to act like Reagan did, or possibly Nixon, or even Eisenhower.

    Notice how Romney frittered around about "bomber gaps" and "battleships in mothballs" instead of actual problems with Russia.

    Fuck, old Mittens probably agreed with them on assaulting homosexuals. I'd give a 50% chance he didn't even realized WE were the ones who invaded Afghanistan.

  36. Re:This is the absolute best effect of Trump elect by geek · · Score: 0

    McCarthy thought there were about 20 to 30 Russian spies working int he US government. When the USSR fell and their files opened up we learned they had closer to 300 spies in extremely high places in the government.

    McCarthy wasn't just right, he was actually less paranoid than he should have been. Yet today, despite all the proof to the contrary leftists still use his name like he was the boogeyman, all because Hollywood got exposed as the anti-American shit stains they were/are.

  37. Re:This is the absolute best effect of Trump elect by Anonymous Coward · · Score: 0

    Somebody's upset that McCarthy wasn't able to find the spies, just randomly attacking people like the drunken boor he was.

    Go ahead, though, claim Hollywood was exposed as anti-American, and make yourself a proud example of everything that was wrong with McCarthy.

  38. wow, misleading headline by Tom · · Score: 1

    What a misleading headline, wow.

    Yes, you would want to see the source code of security products, especially if they are made in a country that constantly paints you as its #1 cyber enemy and that is known for having its secret services work closely with its IT companies. If the Kremlin had hired me for consulting, getting the source code and carefully inspecting it would've definitely been on the list of things I'd recommend.

    What's next? "Russian authorities enforce self-bondage laws on all citizens, requiring the use of seatbelts" ?

    --
    Assorted stuff I do sometimes: Lemuria.org
  39. Re:This is the absolute best effect of Trump elect by Tom · · Score: 2

    How much of the Cold War do you think was created by people believing and/or wanting to have a Cold War?

    McCarthy certainly caused many of the things he was afraid of to happen. For example, communists within the USA went underground due to his prosecutions. Before him, communism was simply another political option, like the Green party is today.

    --
    Assorted stuff I do sometimes: Lemuria.org
  40. Re:This is the absolute best effect of Trump elect by geek · · Score: 0

    Every single person McCarthy exposed was later proven to be a Russian spy. Every. Single. One.

  41. Re:Importing crypto to Russia requires two license by unixisc · · Score: 1

    I'd get the point if you're talking about hardware that's very different from the host hardware. Like if you were talking about a Solaris/SPARC VM on a Windows Server. But in the case of Chromebooks, the hardware is a feature subset of the host: it's usually an Atom based netbook running ChromeOS. So the hardware should be rather trivial to duplicate on the VM, even if the OS is very different.

  42. Re:Importing crypto to Russia requires two license by tlambert · · Score: 1

    If you can do a TPM in a VM, it's strong cryptography.

    Which you are not allowed to have without a license from two agencies in Russia.

    It's also a waste of time, when you have actual hardware available, but you are not allowed to take it into or out of the country.

    If the things will never be allowed to be sold in Russia, why pay a Russian team to work on something that's never going to impact their market? How can they be expected to come up with clever or innovative new things, when all they have is their imagination about how they might be used, rather than actually using them themselves?

    But seriously: if you could build software TPMs that are as useful and secure as a hardware TPM, why would you ever buy a hardware TPM again?

  43. Re:Importing crypto to Russia requires two license by tlambert · · Score: 1

    Except the TPM, of course. And the Cellular modem. And the camera controller. And the PMU.

    An emulator isn't the same as a simulator.