Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's going to be entertaining to watch my Fortune 250 figure out how to work with this.

We make big, expensive, technical things that have a lot of very-closely-held software on them. One current, big, internal effort is to encrypt the code on the controller, so that people can't dump it, or at least not modify it. What's going to happen when the Chinese government demands to escrow the signing keys for any product sold in their country? I fully expect that they will be handed over. That's pretty much a given. But what if they go further and demand to escrow the source code? That would get really interesting, really fast, for many reasons.

Also, how will they continue to block Skype chat history in the US, based on dodgy interpretations of SOX and related laws, yet allow the Chinese government full access to all the logs? What happens when the CEO chats in China, or someone chats at him from China? I suppose it will be Microsoft to the rescue here, with a giant tick-box in the Skype FOR BUSINESS admin panel for "segregate retention policy based on CHINA," which is precisely the sort of thing that continues to make them the big bucks. All of these hosted infrastructure pieces, like Office365 and GSuite, are going to need huge exceptions built into them. (Maybe they already do, and I'm just ignorant.)



> One current, big, internal effort is to encrypt the code on the controller, so that people can't dump it, or at least not modify it.

Do you work for John Deere?

Wouldn't it be funny if abusive behavior by the Chinese government ends up undermining abusive behavior by large corporations?


> undermining

Subsuming is more likely.


> Do you work for John Deere?

So close... ;-)


> So close... ;-)

Must be Case IH then.


Or VW. ;)


In some way it is genius, US ban 28 Chinese companies because of surveillance, now everybody has to support surveillance by law, apply the rule now ..


> One current, big, internal effort is to encrypt the code on the controller, so that people can't dump it, or at least not modify it.

Do you think you can do it? This is what the industry has abandoned more than a decade ago. DRM keys from efuses leak, credit card protected flash getting copied, "physically uncopyable" security elements have few POCs against them shown


No, I don't believe we have any special insight here. I expect any effort will eventually be circumvented, as all such things are. I mean, if Yahoo! can't protect their user database, and Apple can't categorically guard against iPhone cracks, who do we think we are? But I also must admit, with a heavy heart, that we must undertake the effort, in order to ameliorate our legal vulnerability against what a customer might do with a modified product.

You sound knowledgable about this field. Do you have any links to further reading on this?


> But I also must admit, with a heavy heart, that we must undertake the effort, in order to ameliorate our legal vulnerability against what a customer might do with a modified product.

Wait, wait? Is there actually precedence for this? Sure seems obvious to me that once the product has been modified by someone other than the manufacturer, it's no longer the same product. If the NOS in my car explodes when I'm racing Vin Diesel, I can't think a judge would hold Ford liable.


I've asked a well-placed internal person that very question, myself. I think it's clear that once you break the thing, you get to keep both pieces, no questions asked. But internal senior management groupthink is that there's enough weakness against such litigation that we're willing to further burden an already-straining engineering design & build process with this new requirement. Make of that what you will. I have not studied actual case law on the topic, because no one cares to hear a contrary opinion on this. Maybe that would be a good question to put to the CEO at one of the "town halls" he's so fond of holding...


The case law on that topic is against it, for what it's worth, but hard to find because it's such a silly argument no one really tries it. They probably think what they do as an excuse to implement DRM and maintain some control over their platform.

If you look at gun mods you might get somewhere. These do actually fail in ways that harm people as they're made to contain explosions. Has the user of a modified device ever been able to sue? No.


I actually think it would be a good thing if governments required access to the source code for all software that they use.


For all software the government itself uses, yes, but the article is detailing a law in China that gives them the ability to just take ALL data (and source code) unilaterally if it exists anywhere within the border.


So China is publicly announcing that it's deploying what the Five Eyes have deployed in democratic countries under the cover of darkness across the world (while lying to their citizens, who have a constitutional right to know)?

Points for transparency.


Factually incorrect. None of the Five Eyes do any sort of mass decryption even remotely similar to what is mentioned in the article.


You have proof that no mass decryption (or attempts) occur/have occurred?

I'm not as optimistic. History shows human nature tends to work as we expect when US economic/security interests are involved...

https://wikileaks.org/nsa-france/selectors.html https://wikileaks.org/nsa-germany/selectors.html https://wikileaks.org/nsa-japan/selectors.html


IllogicalLogic, these discussions have more value when we focus on the topic at hand, not devolve into whataboutism. Your comparison is both a mischaracterization and off-topic.


I don't see any mischaracterization since Five Eyes was for exactly the same purpose.


Not whataboutism, if the case can be made that 350 million people need protection then the case can more easily be made for 1.3 billion people.

Wikileaks also showed us that US agencies were engaged in industrial espionage, stealing German/French industrial technology using the Five Eyes tools and giving it to GE & friends ...

The problem is, my more "reality-based" framing destroys the "China is uniquely evil" narrative that western media/gov is pushing everywhere for primarily economic reasons.


I'd go further and extend that to "every citizen has access to the source code of all software their governments use".


The government already has enough crippling inefficiency, but yeah let’s throw a grenade onto all the software they ever wanted to use.


We should simply persecute anyone finds issues with this software to the full extent of the law. A culture of fear around security research is the most effective culture.


For software developed by / for government this is already the case in some countries..


Other side: The US doesn't even publish software paid for by tax payers, or the a lot of the FDA information also paid for by citizens.


Why? What's "good" about it? What if you don't want to? Should you be forced to, just because a government chose your software? On what grounds? Are there any bad things that could come out of this, aside from the obvious use of coercion and infringements of individual rights?


> What if you don't want to?

Then your software should be excluded from gov purchase. You'd be ok to keep selling to non-gov places though.


You just used the word "should". That implies the philosophical concept of morality. What makes you think that you're more qualified to set the rules above any individual they might affect? Let him who is without sin cast the first stone.


> That implies the philosophical concept of morality.

Not seeing how it could even possibly be considered philosophical, but okay...

And sure thing.

Consider that me casting said first stone... :)


Their unofficial policy is to provide the source code to local competitors. They can just rebrand, and compete. Happens all the time now.


Read access, or write access? ;)


Write the software onto the controllers in Taiwan at least.


That's why there's a hong kong you know.


Not for long




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: