It's going to be entertaining to watch my Fortune 250 figure out how to work with this.
We make big, expensive, technical things that have a lot of very-closely-held software on them. One current, big, internal effort is to encrypt the code on the controller, so that people can't dump it, or at least not modify it. What's going to happen when the Chinese government demands to escrow the signing keys for any product sold in their country? I fully expect that they will be handed over. That's pretty much a given. But what if they go further and demand to escrow the source code? That would get really interesting, really fast, for many reasons.
Also, how will they continue to block Skype chat history in the US, based on dodgy interpretations of SOX and related laws, yet allow the Chinese government full access to all the logs? What happens when the CEO chats in China, or someone chats at him from China? I suppose it will be Microsoft to the rescue here, with a giant tick-box in the Skype FOR BUSINESS admin panel for "segregate retention policy based on CHINA," which is precisely the sort of thing that continues to make them the big bucks. All of these hosted infrastructure pieces, like Office365 and GSuite, are going to need huge exceptions built into them. (Maybe they already do, and I'm just ignorant.)
> One current, big, internal effort is to encrypt the code on the controller, so that people can't dump it, or at least not modify it.
Do you think you can do it? This is what the industry has abandoned more than a decade ago. DRM keys from efuses leak, credit card protected flash getting copied, "physically uncopyable" security elements have few POCs against them shown
No, I don't believe we have any special insight here. I expect any effort will eventually be circumvented, as all such things are. I mean, if Yahoo! can't protect their user database, and Apple can't categorically guard against iPhone cracks, who do we think we are? But I also must admit, with a heavy heart, that we must undertake the effort, in order to ameliorate our legal vulnerability against what a customer might do with a modified product.
You sound knowledgable about this field. Do you have any links to further reading on this?
> But I also must admit, with a heavy heart, that we must undertake the effort, in order to ameliorate our legal vulnerability against what a customer might do with a modified product.
Wait, wait? Is there actually precedence for this? Sure seems obvious to me that once the product has been modified by someone other than the manufacturer, it's no longer the same product. If the NOS in my car explodes when I'm racing Vin Diesel, I can't think a judge would hold Ford liable.
I've asked a well-placed internal person that very question, myself. I think it's clear that once you break the thing, you get to keep both pieces, no questions asked. But internal senior management groupthink is that there's enough weakness against such litigation that we're willing to further burden an already-straining engineering design & build process with this new requirement. Make of that what you will. I have not studied actual case law on the topic, because no one cares to hear a contrary opinion on this. Maybe that would be a good question to put to the CEO at one of the "town halls" he's so fond of holding...
The case law on that topic is against it, for what it's worth, but hard to find because it's such a silly argument no one really tries it. They probably think what they do as an excuse to implement DRM and maintain some control over their platform.
If you look at gun mods you might get somewhere. These do actually fail in ways that harm people as they're made to contain explosions. Has the user of a modified device ever been able to sue? No.
For all software the government itself uses, yes, but the article is detailing a law in China that gives them the ability to just take ALL data (and source code) unilaterally if it exists anywhere within the border.
So China is publicly announcing that it's deploying what the Five Eyes have deployed in democratic countries under the cover of darkness across the world (while lying to their citizens, who have a constitutional right to know)?
IllogicalLogic, these discussions have more value when we focus on the topic at hand, not devolve into whataboutism. Your comparison is both a mischaracterization and off-topic.
Not whataboutism, if the case can be made that 350 million people need protection then the case can more easily be made for 1.3 billion people.
Wikileaks also showed us that US agencies were engaged in industrial espionage, stealing German/French industrial technology using the Five Eyes tools and giving it to GE & friends ...
The problem is, my more "reality-based" framing destroys the "China is uniquely evil" narrative that western media/gov is pushing everywhere for primarily economic reasons.
We should simply persecute anyone finds issues with this software to the full extent of the law. A culture of fear around security research is the most effective culture.
Why? What's "good" about it? What if you don't want to? Should you be forced to, just because a government chose your software? On what grounds? Are there any bad things that could come out of this, aside from the obvious use of coercion and infringements of individual rights?
You just used the word "should". That implies the philosophical concept of morality. What makes you think that you're more qualified to set the rules above any individual they might affect? Let him who is without sin cast the first stone.
We make big, expensive, technical things that have a lot of very-closely-held software on them. One current, big, internal effort is to encrypt the code on the controller, so that people can't dump it, or at least not modify it. What's going to happen when the Chinese government demands to escrow the signing keys for any product sold in their country? I fully expect that they will be handed over. That's pretty much a given. But what if they go further and demand to escrow the source code? That would get really interesting, really fast, for many reasons.
Also, how will they continue to block Skype chat history in the US, based on dodgy interpretations of SOX and related laws, yet allow the Chinese government full access to all the logs? What happens when the CEO chats in China, or someone chats at him from China? I suppose it will be Microsoft to the rescue here, with a giant tick-box in the Skype FOR BUSINESS admin panel for "segregate retention policy based on CHINA," which is precisely the sort of thing that continues to make them the big bucks. All of these hosted infrastructure pieces, like Office365 and GSuite, are going to need huge exceptions built into them. (Maybe they already do, and I'm just ignorant.)