Slashdot Mirror


Huawei Laptop 'Backdoor' Flaw Raises Concerns (bbc.com)

A flaw in Huawei Matebook laptops, found by Microsoft researchers, could have been used to take control of machines. From a report: The "sophisticated flaw" had probably been introduced at the manufacturing stage, one expert told BBC News. Huawei is under increasing scrutiny around the world over how closely it is tied to the Chinese government. The company, which denies any collusion with Beijing, corrected the flaw after it was notified about it in January. Prof Alan Woodward, a computer security expert based at Surrey University, told BBC News the flaw had the hallmarks of a "backdoor" created by the US's National Security Agency to spy on the computers of targets. That tool was leaked online and has been used by a wide variety of hackers, including those who are state-sponsored and criminal gangs. "It was introduced at the manufacture stage but the path by which it came to be there is unknown and the fact that it looks like an exploit that is linked to the NSA doesn't mean anything," Prof Woodward said.

95 comments

  1. Why is anyone buying anything from this company? by Rick+Schumann · · Score: 4, Interesting

    Seriously, WHY? Seems clear as day to me that everything they're producing is compromised in one way or another.

  2. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 0, Troll

    What does Cisco have to do with this?

  3. Re:Why is anyone buying anything from this company by ZorinLynx · · Score: 5, Insightful

    We should probably consider ANY hardware manufactured in a country with an uber-authoritarian, paranoid government to be suspect.

    How closely does Apple scrutinize iPhones coming out of Foxconn, I wonder?

  4. If they are so sophisticated... by SuperKendall · · Score: 1

    If the company was really sophisticated, why would they name a product the "Matebook".

    Talk about something that's never likely to be used by anyone serious...

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re: If they are so sophisticated... by Anonymous Coward · · Score: 0

      They have plenty of serious products. C'est La Vie.

    2. Re:If they are so sophisticated... by Anonymous Coward · · Score: 0

      Maybe they are targetting users with no mates?

    3. Re:If they are so sophisticated... by Anonymous Coward · · Score: 0

      You make an excellent point. Although it is said that the tradition of staffing Marketing departments with stupid cunts originated in the USA .......

    4. Re:If they are so sophisticated... by Anonymous Coward · · Score: 0

      If the company was really sophisticated, why would they name a product the "Matebook". [...]

      To remind ET of the concept of opposing genders. ET's got more important tasks to complete.

    5. Re:If they are so sophisticated... by Anonymous Coward · · Score: 0

      Checkbook Matebook

    6. Re:If they are so sophisticated... by AHuxley · · Score: 1

      Looks over to Lifebook.

      --
      Domestic spying is now "Benign Information Gathering"
    7. Re:If they are so sophisticated... by Anonymous Coward · · Score: 0

      Or as the recently release McDonalds Laptop is called, the McBook. Dumbest name ever, amirite?!

  5. Because they have done nothing wrong and are #1 by Anonymous Coward · · Score: 0, Funny

    Because they are the most popular and growing server, smartphone, and network infrastructure company in the world, with the best engineering in the world, and they have never had a provable security issue. I trust them to be 100% secure, because every allegation at them always has a [citation needed] by it.

    1. Re:Because they have done nothing wrong and are #1 by Anonymous Coward · · Score: 1

      ".. never had a provable security issue.." So you didn't even read the TFS title? Of course they have. Multiple. As documented here in slashdot and everywhere else. But you don't care 'cause you're just a shill (probably too stupid to be a paid one) trolling for social media points back home.

  6. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    umm.. EVERYTHING is compromised these days, regardless of where and how - and the compromising parties aren't able to keep that info secure so other parties know of them.

    all you're doing is choosing what flavor of compromise - and even then - compromises during manufacture aren't necessarily attributable to the most obvious party.

  7. Re:Why is anyone buying anything from this company by WankerWeasel · · Score: 5, Insightful

    Curious why you single out Apple when Samsung, Nokia, Dell, Sharp, Google, Amazon, Sony, and everyone else have their stuff made by Foxconn too. All of these companies go over their devices thoroughly as they know any security issue could have HUGE negative repercussions for them.

  8. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0, Troll

    I'm buying their stuff because I believe them over the hypocritical US government. Oh and also because it's a good value.

  9. My understanding by Anonymous Coward · · Score: 0

    Is they write really crappy software and they themselves don't know what it does at times, let alone jabber across the interwebs after hours.

    1. Re: My understanding by Anonymous Coward · · Score: 0

      A dirty little secret of all software companies. Often they forget what a piece of code does from time to time. The best companies remember what their code does and use creativity in marketing to introduce bugs.

  10. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    Wow, way to expose yourself as the ignorant, untravelled hometown mook that you are. Foxconn is a Taiwanese company. Taiwan does not have an authoritarian, paranoid government.

    Frankly, I would be more concerned about what the United States government is meddling with.

  11. Why would anyone support this company anymore by Anonymous Coward · · Score: 1

    Seriously, them and the Chinese government are so in-bed, that the government is putting increasing pressure on Canada with imaginary claim like Canola being infested with pest and retrial a Canadian just to give him the death penalty right after the whole thing with Huawei's CFO started by request of the US. Among other things.

    1. Re:Why would anyone support this company anymore by Anonymous Coward · · Score: 0

      that's how communism works, the corporation is not wholly owned by shareholders, the state plays an ownership role as well.

  12. Just your reminder: by Anonymous Coward · · Score: 1

    As a PSA, please remember that Trump overrode the various national intelligence agencies' concerns and removed sanctions on Huawei.

    1. Re:Just your reminder: by Narcocide · · Score: 1

      Wait, what now? Wasn't it his idea to sanction them in the first place?

    2. Re:Just your reminder: by Anonymous Coward · · Score: 0

      Whatever "bad" is today, Trump did.

      Orange Man Bad.

      The end.

  13. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    > How closely does Apple scrutinize iPhones coming out of Foxconn, I wonder?

    totally.

  14. communism by Anonymous Coward · · Score: 0

    every corporation in a communist country has a government official on staff

  15. You think the Chinese are the worst data thieves? by Anonymous Coward · · Score: 0

    I couldn't give a fuck about the Russians or the Chinese. There is another nation that is far, far worse.

    Enjoy.

  16. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 0

    How do you know this? We donâ(TM)t see articles like this about Cisco.

  17. Why would anybody not in the Chinese army... by Anonymous Coward · · Score: 0

    buy a laptop from the Chinese army?

    I'm totally baffled by anybody who claims to be educated and who accepts the Chinese government's own public declarations that they are a communist country, and who can easily discover that the country has made its leader a leader-for-life --- but who then denies that Huawei is part of the government of China and, by virtue of the very basic definitions of that system, integrally related to the army of China [and, of course also the spy services thereof].

    There's no independent court system there, no written constitution guaranteeing rights that the government cannot violate on a whim, and no legal right for any "business" to exist there without ties to the government.

    Reality is not an opinion; reality is an objective thing.

    1. Re: Why would anybody not in the Chinese army... by Anonymous Coward · · Score: 0

      No shit. Jesus Christ, Huawei could execute people in front of their business and there would still be fuckwads here defending it. These assholes have to be Chinese defense ministry actors.

    2. Re: Why would anybody not in the Chinese army... by Anonymous Coward · · Score: 1

      Or we just don't care about your silly government's little delusions and temper tantrums.

      But keep that tinfoil hat on. You might need it to protect you from the secret mind scanners that Mexicans agents are rumoured to be using against your shithole country.

  18. Re:Why is anyone buying anything from this company by Narcocide · · Score: 3, Insightful

    This is a weird thing to me, because at first actually it seemed like it was much ado about nothing, which was actually more suspicious than this highly predictable revelation. However, I still don't know if there's any way to tell who is backdooring these devices, only that it is now clear Huawei can't protect their supply chain any better than anyone else.

  19. serious question by Narcocide · · Score: 1

    What about a Commodore 64?

  20. Re: Why is anyone buying anything from this compan by Narcocide · · Score: 1

    We do though. We just haven't as recently.

  21. Re:Why is anyone buying anything from this company by Ol+Olsoc · · Score: 2

    Curious why you single out Apple when Samsung, Nokia, Dell, Sharp, Google, Amazon, Sony, and everyone else have their stuff made by Foxconn too. All of these companies go over their devices thoroughly as they know any security issue could have HUGE negative repercussions for them.

    Nothing to be curious about. When Slashdotters hate Apple, anything is fodder for for their angst and anger. The fact that other companies use FoxConn is irrelevant.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  22. Let me guess by drinkypoo · · Score: 4, Funny

    A flaw in Huawei Matebook laptops, found by Microsoft researchers, could have been used to take control of machines.

    Windows 10?

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  23. Re:Why is anyone buying anything from this company by Cmdln+Daco · · Score: 2

    Also, lots of slashdotters hate Apple.

    We've done so for a long, long time.

    It isn't angst or anger, btw. It's an understanding of what kind of company Apple has been for a long time.

  24. Re:Why is anyone buying anything from this company by Rick+Schumann · · Score: 1

    I would hope they load all their own firmware all the way down to bare metal and not let any 3rd-party company have anything to do with it.

  25. surprise by guygo · · Score: 1

    Gee, what a surprise...

    1. Re:surprise by e432776 · · Score: 1

      I know, right? I am starting to think this company is not very reliable!

  26. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    Yeah, and how did the NSA get their software on their computers?

  27. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    Which government has the power to completely fuck up your life?

    The answer to that question is usually the government of the country that you live in. I don't live in the US, China, or Russia myself, yet it is my home country that has by far the most power over me.

  28. Re:Why is anyone buying anything from this company by e432776 · · Score: 1

    Price? Looks just like an offering from another computer company named after fruit, but costs much less.

    At least that is my guess.

  29. Re: Why is anyone buying anything from this compa by Anonymous Coward · · Score: 1

    LOL
    Facts.

  30. spyware by Anonymous Coward · · Score: 4, Insightful

    If you are honest, it comes down to which governments will you make it easy to spy on you. Telecoms are backdooring/MITM cells anyway, so no advantages there.

    What about PC and tablets?
    Windows, Android, Apple? The US already has your shit.
    Huawei, etc? China does too.
    Russia's backward economy doesn't actually make electronics products worth importing anywhere else, but they have decent software skills, hence Kaspersky.
    Europe's got a few things...Airbus?, but no real marquee stuff in tech. RIP Nokia, which is now basically an Android subcontractor.

    If you live in China, and aren't politically active or ambitious, absolutely get a Huwei and save a 20% up to a hundred bucks vs a Nokia with equivalent specs.

    If Russia already has your data, sure, go ahead and run Kaspersky to keep the Chinese out. Might be good for Russian aligned Linux users too.

    But here is the real, practical deal:
    If you use what 99% of other people use (aka not Gentoo) the US can get your stuff pretty easily.

    So it comes down to what companies ALSO get your data. Running office and chrome on your mac book? Apple, MS and Google all have your stuff. Hell even without chrome all your Gmail friends each gave their half of shit to Google anyway.

    The US has my stuff. MS has my stuff. But Google doesn't and apple doesn't. Beat I can do. And even Google or Apple will get my phone stuff in a year when WinPhone is dead dead. What am I going to do? Not use a smartphone? Live like an animal on a cave? F that.

    The US has been the most trustworthy of the admittedly low bar set by China, Russia and the US. Even with #orangemanbad stuff, the US is only dropping towards the other two. I'd love for some other empire to exist and be better, but right now, the obnoxious bumbling America is still better than the other two bidders.

  31. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    If you read a bit of the summary you'd realize the experts are pointing at the NSA rather than the Chinese.

  32. Re:Why is anyone buying anything from this company by Ol+Olsoc · · Score: 1

    Also, lots of slashdotters hate Apple.

    We've done so for a long, long time.

    It isn't angst or anger, btw. It's an understanding of what kind of company Apple has been for a long time.

    Sure it is. I've used Apples and Windows and before that MS-DOS for a long time. Your idea that you have some understanding of Apple's special evil merely shows you don't have an understanding of everyone elses.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  33. Re:Why is anyone buying anything from this company by AHuxley · · Score: 1

    Free trade.
    The US and Uk "have" to accept equal and tech trade products from China.
    Thats how its getting in to the USA and EU.

    --
    Domestic spying is now "Benign Information Gathering"
  34. GAIUS BALTAR! by grep+-v+'.*'+* · · Score: 1

    Would you please quit playing around? We've got work to do.

    --
    If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  35. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 0

    Apple is US company that has devices manufactured in China that are approved. Also well known and liked by many idiots that talk privacy.

  36. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    Hilarious; when the researchers are from Microsoft.

  37. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    +1 on that; US government is among the most hypocritical.

  38. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 0

    This conversation really needs to shift to who you prefer to be spied on by.

    Chinese companies keep being accused of being compromised. It is a reasonable assumption and most likely true.

    US companies have proven to be comprised. See the Snowdon files, or if you like case in point, Cisco: https://www.tomshardware.com/news/cisco-backdoor-hardcoded-accounts-software,37480.html

  39. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 1

    If you've used MS DOS, then you should be able to remember when Slashdot was for Linux enthusiasts. Then you should also remember that MS was the root of all evil in those days. Then you should also know that Apple and Google are today's Microsoft, in Slashdot world.

  40. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 0

    Foxconn plants are in mainland China, you ignorant person. Chinese territory = Chinese laws and rules.

  41. Re:Why is anyone buying anything from this company by Megol · · Score: 1

    Normally I'd expect such an opinion to be based on facts and not fear-mongering produced without proof. Here we are served an article without technical data, without any actual information at all but the speculation of some unknown person (to me at least) in combination with scary words from an obviously nontechnical writer. No links, no description of the exploit, no reason to actually believe the unknown person.

  42. I think I just sharted. by Anonymous Coward · · Score: 0

    Sorry

    1. Re: I think I just sharted. by Anonymous Coward · · Score: 0

      No kidding? Me too!

  43. Re:Why is anyone buying anything from this company by serviscope_minor · · Score: 1

    Sure it is. I've used Apples and Windows and before that MS-DOS for a long time. Your idea that you have some understanding of Apple's special evil merely shows you don't have an understanding of everyone elses.

    I have a special place in my heart just for hating Apple. For you see they basically hate developers and are determined to make lives miserable for everyone who actually wants to do things professionally.

    They won't let you compile on other machines and they won't sell decent servers.

    There's a special place in hell for Apple, this hell to be precise http://smbc-comics.com/comic/p...

    Plus their adverts are insufferable pretentious.

    --
    SJW n. One who posts facts.
  44. Re:Why is anyone buying anything from this company by gravewax · · Score: 1

    and which company is producing anything that is not compromised in some way? this is the reality of the highly complex integrated world we live in. Consumers won't pay the price that would be required for true verification and security that would guarantee no compromises.

  45. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    450 advertisers on smbc? And you have to opt-out of every single one?????

    (sniff) Bye bye smbc. :( I will miss you or at least find them on a mirror/blog that doesn't have your trackers.

  46. Re:Why is anyone buying anything from this company by thegarbz · · Score: 1

    We should probably consider ANY hardware manufactured in a country with an uber-authoritarian, paranoid government to be suspect.

    Given how we actively know the NSA has sought exactly these kinds of back doors you can just remove all adjectives and say:

    "We should probably consider ANY hardware manufactured in a country with a government to be suspect."

  47. Not everything is made in Japan by DrYak · · Score: 2

    Samsung {...} Sony, and everyone else have their stuff made by Foxconn too.

    Not every single company manufactures its stuff exclusively in China.
    For example, Sony still manufactures in Japan.
    (And Samsung obviously manufactures a lot in South Korea)

    Those non-China-made products include their smartphones (and other high-tech, hi-priced gadgets), they'll prefer outsourcing less sensitive accessories (wall wart charger).

    disclaimer: both of my latest two smartphones are Japan-made Sony Xperias. Though I still flashed an entirely different OS (not Android) on them.
    So it's not *China*'s spyware you're going to find installed in there.

    --
    "Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
  48. Re: Why is anyone buying anything from this compan by houghi · · Score: 1

    They go over it and send it back if their root exploit doesn't work. Thanks Sony.

    --
    Don't fight for your country, if your country does not fight for you.
  49. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    And when you write

    everything they're producing is compromised in one way or another

    Are you referring to american companies, that introduce back-doors for the NSA?

  50. Re:Why is anyone buying anything from this company by Highdude702 · · Score: 2

    That tool was leaked online and has been used by a wide variety of hackers, including those who are state-sponsored and criminal gangs. "It was introduced at the manufacture stage but the path by which it came to be there is unknown and the fact that it looks like an exploit that is linked to the NSA doesn't mean anything," Prof Woodward said.

    And if you comprehend the summary, it says everybody now uses it because it was leaked. And they insinuate that its not the NSA, I assume because it was found.

  51. Re:Why is anyone buying anything from this company by Ol+Olsoc · · Score: 1

    I have a special place in my heart just for hating Apple. For you see they basically hate developers and are determined to make lives miserable for everyone who actually wants to do things professionally.

    I've written a tiny little bit for iOS. Just different rules. But if you wanna hate, by all means have at it.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  52. clarification and link to the security advisory by nimbius · · Score: 4, Interesting

    Pathetic that slashdot has gotten to this point, but the original article has no link to any meaningful information.
    in summary:

    - this is an exploit in a windows program written by huawei called pcmanager.
    - Dell, HP, and even Lenovo have had security bugs in their software as well. The fact that this is a huawei bug means every news outlet gets to ratched up the terror factor for clicks.
    - googling the name Alan Woodward returns the exact same article title at nearly 2 dozen news sites, but nothing meaningful about the guy outside of his singular report.
    https://www.huawei.com/en/psir...

    --
    Good people go to bed earlier.
  53. Re: Why is anyone buying anything from this compan by Ol+Olsoc · · Score: 1

    If you've used MS DOS, then you should be able to remember when Slashdot was for Linux enthusiasts. Then you should also remember that MS was the root of all evil in those days. Then you should also know that Apple and Google are today's Microsoft, in Slashdot world.

    Well, I wasn't on Slashdot until some time in the early Y2K's. By that time Applehate was well established.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  54. Re:Why is anyone buying anything from this company by XXongo · · Score: 2

    If you read the summary you'd realize that the experts said that they have no idea who put the backdoor in.

  55. Re:US or China? by XXongo · · Score: 1

    It's amusing to see all the whataboutism on /., but, really, although the U.S. has problems, it's nothing compared to mainland China.
    https://www.nbcnews.com/news/china/disappearances-forced-confessions-china-targets-dissent-n505046
    https://www.vox.com/2018/8/15/17684226/uighur-china-camps-united-nations
    https://en.wikipedia.org/wiki/Human_rights_in_China
    https://freedomhouse.org/blog/china-s-quiet-drive-normalize-repression
    https://www.theguardian.com/world/2017/jul/17/chinas-growing-intolerance-for-dissent-will-come-at-a-high-price

  56. Re:Why is anyone buying anything from this company by XXongo · · Score: 1

    We should probably consider ANY hardware manufactured in a country with an uber-authoritarian, paranoid government to be suspect.

    If you credit Wired, the problem isn't that Huwei is compromised by the Chinese government (although it probably is. Their government holds very tight control over everything.).

    The problem is that their software QC is slipshod.

    From https://www.wired.com/story/huawei-threat-isnt-backdoors-its-bugs/:
    "Though the geopolitical discourse has gotten heated, the report concluded that the flaws in Huawei's code are related to "basic engineering competence and cyber security hygiene" and could be exploited by anyone."

  57. Still IMPERSONATING me JEALOUS "Lil' Jowie"? by Anonymous Coward · · Score: 0

    MacOS model's not done: Stop IMPERSONATING me lying & proof portfilter err's can't happen https://news.slashdot.org/comm... in my work!

    u IMPERSONATE me & also ADMIT u have a /. acct & STALK me by UNIDENTIFIABLE ac https://hardware.slashdot.org/... - YOU got ISSUES.

    That's "best ya got"?

    u WISH u were ME (as ur POOR imitation = the sincerest form of flattery) WASTING ur life STALKING me by UNIDENTIFIABLE anon OR IMPERSONATING me!

    APK

    P.S.=> I BLOW U AWAY https://tech.slashdot.org/comm... + https://it.slashdot.org/commen... + https://yro.slashdot.org/comme...

  58. Re:Why is anyone buying anything from this company by AmiMoJo · · Score: 1

    What's the point of inspecting your products when they arrive from the Chinese factory when your own government just intercepts them during shipment to customers/vendors and installs malware? The US was caught red handed doing that, and pretty much nothing has been done about it.

    Also security issues have no repercussions for any of these big tech companies. Dozens of celebrities' private photos were stolen from Apple's servers, didn't touch their stock price. Sony deliberately installed malware on people's computers, and hardly anyone even heard of it at the time.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  59. Re:Why is anyone buying anything from this company by DavidHumus · · Score: 2

    Did you notice the part in the summary that states that this flaw looks like an NSA backdoor?

  60. But Dell, HP, Apple backdoors do not raise concern by Anonymous Coward · · Score: 0

    Why is that? It's funny how they are all given a pass, in particular Apple who ignore all reports and have been on record with waiting as much as 10 months before they finally fix the security holes. The security hole in this driver was patched very quickly.

    But hey keep fooling yourself.

  61. Re:Why is anyone buying anything from this company by AmiMoJo · · Score: 1

    Probably just a garden variety fuck-up. Like when Apple accidentally published the private signing key for their battery firmware, allowing anyone to create a malicious update that permanently backdoored the machine and could not be removed without tearing the laptop apart. Or the infamous GOTO FAIL bug.

    Or how about Intel's Management Engine flaws, which similarly allow an attacker to permanently pwn the machine?

    Maybe they were all NSA implants into the codebase. The GOTO FAIL one looks particularly suspicious. But there is also a high probability that they are just human error.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  62. Re:Why is anyone buying anything from this company by drinkypoo · · Score: 1

    Dozens of celebrities' private photos were stolen from Apple's servers, didn't touch their stock price.

    That's because it wasn't Apple's fault. Those celebrities were using bad passwords.

    Sony deliberately installed malware on people's computers, and hardly anyone even heard of it at the time.

    That was a bit more puzzling. I feel like a lot of nerds didn't do their job on that one, and make their non-nerd friends understand the repercussions.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  63. Re: Why is anyone buying anything from this compan by Galactic+Dominator · · Score: 1

    Correct. We did have a similar to Huawei exploit from Intel in the not too distant past. Difference is 'Mericans want to crucify Huawei because 'Merica.

    --
    brandelf -t FreeBSD /brain
  64. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    You are more concerned about the US government than the Chinese government.

    Absolutely.

    Talk about ignorant. Or you are a Chinese or Russian plant.

    How many countries have you lived in (one year or more)? Have you lived in both the United States and China? I have, among six other countries.

    The problem with Americans, is they make up shit about other places as if they know those places when they probably haven't even left their place of birth. Try travelling, kid. It'll open your eyes and make you not so prejudiced and bigoted.

  65. Re: Why is anyone buying anything from this compan by Anonymous Coward · · Score: 0

    Still a Taiwanese company, so it's pretty silly to think they aren't going to be inspecting their own products.

    Have you ever been there? Taiwan is not Chinese territory, you ignorant little boy.

  66. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    Gotta love how someone tried to mod this as a troll. It's OK to talk all the shit you want about other countries, but when the flaws in the USA are pointed out, it's suddenly trolling. LOL.

    The United States is one of the WORST countries I have ever lived in. Americans believe that they have rights, but when compared to other places, it's just an illusion. The USA is one of the least free countries I have ever been to where one can be prosecuted for anything and must undergo religious indoctrination in order to deal with the legal system or government.

  67. Re:Why is anyone buying anything from this company by Anonymous Coward · · Score: 0

    The most logical conclusion is that the USA NSA put it there. It is unquestionably their creation, so that is the most accurate conclusion.

    I bet the "leak" was on purpose after the NSA planted their backdoor code into loads of computers and devices and they only "leaked" it so they could lie and claim innocence. "We made the backdoor, but it was only for...uh...research! Yeah, research! We never used it and some commie Chinese spy infiltrated our super-duper, top notch intelligence organisation, stole our code and leaked it....yeah, that's the ticket!"

    Sorry, I ain't buying it.

  68. Re:huh? by Anonymous Coward · · Score: 0

    I don't give a shit what you or your government say. I have no reason to trust you.

  69. Running Intel? by Anonymous Coward · · Score: 0

    Your OS doesn't matter. ME can spy from below your platform visibility.

    ME network access is disabled? Look for TPM, sound card/gpu firmware/microcode, and cpu microcode exploits. Unless you are running registered memory, rowhammer is still a concern even if all the 'new' DDR4 mitigations work acceptably on unbuffered memory.

    Even if none of those work, the SPI flash used since one generation after SPI flash became standard has a SERIOUS flaw. The chips write protect pin ONLY works if a software command is sent to write protect it after power on. If a piece of software can power glitch the chip to reset without resetting the whole system the write protect goes away. The PCH on Intel hardware added a memory region masking function to work around that, but it in turn is part of the suspect hardware platform.

    AMD, ARM, Cisco, Huawei, Oracle/Fujitsu SPARC, even IBM and their PowerPC (although a lot more transparent than the aforementioned.) None of these are really trustworthy. With every passing day one more piece of hardware requires proprietary or signed firmware. Many are part of a DRM solution, usually to the customer's detriment. Some even allow remote surveillance or software updates.

    Top to bottom, modern hardware is untrustworthy and insecure. In order to secure it, we effectively need to start from the ground up. Without the backing of major corporations or wealthy individuals, this means taking a step back on performance and efficiency, to ~2003 era hardware. As the main guy at Parallax can tell you, masks for the propeller 2 chip were ~200k USD on that process, meaning a larger cpu might be in the million dollar range, which is entirely doable given dedicated crowdfunding efforts. If you can tolerate Pentium 3 bus speeds, there are FPGAs today with partially or fully open toolchains (iCE40, ECP5, and there was Spartan 2 work at one time.) Those FPGAs are just wide enough and fast enough to run a channel of SDRAM or a PCI/AGP bus, both of which should be patent free now. Given the benefit of 20 years of engineering and research, some of which may not be patented, unlike newer bus designs and display technologies, building a platform sufficient for day to day productivity and digital security, utilizing modern storage and peripheral devices at reduced speeds is possible. A Pentium 3 with a 5TB hard drive, a 500mb/s SSD, and a PCI to PCI express bridge plugged into a dedicated 32 bit 66mhz PCI slot would give more than enough performance for Gigabit Ethernet, access to modern PCIe graphics cards (at reduced performance), and most of the other conveniences of modern technology. Registered SDRAM dimms supporting 1 or 2GB apiece are possible, allowing up to 8GB off a single SDRAM channel (Up to 1 Gigabyte per second peak bandwidth.)

    Compared to the 40+GB/s of a modern system or the 1TB/s of HBM based solutions, it won't be anything special. But having a socketed processor, socketed memory, and a patent free bus, plus the ability to reconfigure the memory controller or i/o hub if functionality or security can be improved would be a huge coup for the individual security conscious user.

    This is the only way forward where we can claw our control back from our corporate and government overlords. Choose to stride differently, or walk lockstep into the new world order!

    1. Re:Running Intel? by Anonymous Coward · · Score: 0

      Those FPGAs are just wide enough and fast enough to run a channel of SDRAM or a PCI/AGP bus, both of which should be patent free now. Given the benefit of 20 years of engineering and research, some of which may not be patented, unlike newer bus designs and display technologies, building a platform sufficient for day to day productivity and digital security, utilizing modern storage and peripheral devices at reduced speeds is possible. A Pentium 3 with a 5TB hard drive, a 500mb/s SSD, and a PCI to PCI express bridge plugged into a dedicated 32 bit 66mhz PCI slot would give more than enough performance for Gigabit Ethernet, access to modern PCIe graphics cards (at reduced performance),

      A better and equally expensive option is Amiga Reloaded plus Vampire V4 plus PCI control board (to allow the Amiga system the use of PCI cards)

  70. Why so irrational and emotional? by Anonymous Coward · · Score: 0

    You have ranted and raved, yet offered not a single coherent, logical, rational argument.

    Are you on the payroll of Huawei?

    I ask, not in the way anti-trumpers ask if any opponent is a Russian, but as a genuine question about why this topic seems to make you so angry and/or irrational while seemingly involving no rational reasoning. If you would make any simple, logical argument for your attacks on the previous posts there would at least be some apparent reasoning involved.

  71. Re:Why is anyone buying anything from this company by serviscope_minor · · Score: 1

    I've written a tiny little bit for iOS. Just different rules.

    A tiny bit, quite. Try developing an actual product. It's really hard to do CI remotely well when you can't get anything approaching decent servers. For android it's trivial: just spin up a bunch of VMs on your cloud or local platform of choice running any of the usual systems.

    For apple: fuck you.

    --
    SJW n. One who posts facts.
  72. Re:Why is anyone buying anything from this company by ZorinLynx · · Score: 1

    Actually I'm an Apple user and enjoy their products.

    I used them as an example because they're one of the largest companies with extremely popular products that most people trust, yet are made in China.