Krypteia (Greek: κρυπτεία / krupteía, from κρυπτός / kruptós, “hidden, secret things”) Gonzo INFOSEC Blogger Doctor of Divinity ULC

X

Huawei, Cisco, Nokia, Alcatel, ZTE… Commonality? Everything Is Made in China:

There are a couple of stories going around that are claiming that Huawei, the maker of many telco products has pre-pwn’ed their hardware with architecture flaws in the chips themselves or, alternatively, created deliberate software/firmware flaws that could allow takeover. The spawn of this seems (at least this go round) is due to a Defcon presentation this July that showed how easy it was to overtake certain lower end routers made by the company. Now, this would just be chalked up usually to lackadaisical programming on the part of any other company, but, since this is a Chinese company, then of course, it’s a nefarious plot to overtake the world!

*puts on neru jacket and puts cigarette in mouth, holds white cat* MWAHAHAHAHAHA

The realities though, are somewhat different in the real world, outside of the one where the media goes off half cocked on an idea that will generate copy for them and drive  traffic to their sites. The real story here lies between the xenophobic lines and I think that actually The Economist does the best job of level headed reporting about this story, what there is of it that is. No, the real story is that EVERYTHING is made in China now, and to say that just one company, a Chinese owned company is the arbiter of our digital doom for merely being “Chinese” is akin to “Driving while black”

This is not to say though, that some espionage hasn’t come out of our pals at Huawei, nor for that matter ZTE, as wholly owned Chinese companies with ties to individuals in the PRC and PLA. No my friends, this too can be called into question and I for one would take a close look at the players and their motives to understand who they are and what they may be doing now and then in the way of digital espionage. Clearly in the case of Huawei there are accounts of outright theft of IP being used to generate their hardware/software to gain a foothold to start (see article in the Economist, link provided above) No friends, I would put it to you now, at this very moment, that there is no grand plan to backdoor every phone or telco device by either of these companies that I am privy to, in fact, the people I know, have said (from the MIL side that is) that they do indeed check all of the chip sets and systems that go into secure areas or missile systems and there, to date, has been no large effort to subvert those systems en masse. There have been instances where systems had bad chips and there have been instances where some have been, shall we say circumspect, but overall, no “Chinese invasion plan” has been detected.

… And after all.. If there were… Would we not have a moratorium on buying from them per the government if it were the case?

Who’s on the Board at Huawei and ZTE? *cough* PRC Ties Anyone?

So, Ren Zhengfei was a member (is) of the PLA (Peoples Liberation Army) and the stellar rise of Huawei can be somewhat tracked to those ties. This though does not mean that the PLA runs the show right? One wonders though who else in the echelon is/was also PLA right? As for ZTE, at the time of this posts being written, I could not locate solid backgrounds on all the members however, the bio of the company plainly shows their connection with the PLA  So, there you have it, both have ties to the People’s Liberation Army, but when you think about it, it’s China! If you did not have affiliation with the PLA, it usually meant you were in some gulag or other, so, your mileage may vary.

Suffice to say, that every company in China (born of it) will likely have connections to the PLA because that is their base. Does this mean that they all are bent on overtaking the US with bogus chips or pre-pwned hardware? Not necessarily.. Though, I for one would be checking that shit.. Wouldn’t you? Meanwhile, the US government has seen fit (ok, congress critters really) to look into both companies over allegations of spying. Which I think is prudent, and not just from this knuckle headed idea that everything is pre-pwned but instead, by proxy of their affiliations, their buy outs, and their cutout companies that do business to steal others IP.

Aye, there’s the rub…

Does this mean I think the Congress Critters will get to the bottom of things?

Fuck no!

But they will have a good time trying while endeavoring not to be too xenophobic.

Supply Chains and Their Subversion:

Meanwhile, back to the pre-pwned chips, routers, phones, and everything else that Dr. Cyberlove is pimping as the latest in cyber-warfare-douchery. Look, frankly, if you were going to be China or a company thereof owned by or beholden to, then you would want to futz with the supply chain now and again. I mean, who wouldn’t right? If you were one of the pre-eminent purveyors of prodcts of this ilk, then you would have ample opportunity to mess with the supply chain! There would be no need to just go all in and backdoor everything right? I mean, where’s the sense people? Lull your targets into complacency and then hit them with some bad hardware where it counts ok?

So, if you were to ask me, and really, no one has, and frankly *small tear in corner of eye* I’m hurt you all haven’t, I’d say that perhaps there are more than one way to skin this digital cat. First off, look at the notion that everything is made in China now. Why? Because its CHEAP! Cheap labor, cheap facilities, and no taxes etc. You get all the benefits that help your bottom line as say CISCO, and no down side financially! No pesky unions and more black in your balance sheet no? Ok, so there are issues of potentially having software or hardware embedded in your stuff because you were paying attention to every piece, but sure, you get more MONEY!

“mo money mo money mo money”

Ok lets back up a bit there.. So, no, not everything made on site necessarily has been tampered with. In fact, there is a HUGE grey market as well for this tech and of course since this shit is all now made IN China, and the plans are in their hands, they can reverse R&D things as well. Say they get a piece off the line at the end, paid for through a front company, and then pwn it and re-sell it to the US government?

Ooooh, now there’s a notion huh? Just Google for stories of grey market chip sets for missiles and you will see where bad grade stuff has been put into actual systems meant for use and failed. Yeah.. it’s happening and has been for some time. Some of these companies are just in it for the money and the con, others are fronts for the MSS. So,as I said, there are many ways this can play out. Frankly, I have more respect for the Chinese than to believe these half baked ideas of a full on frontal assault on  us by products made by ZTE or Huawei for public consumption.

Trust But Verify:

So, where does that leave us? It leaves us at the point where we should be. Any systems we buy for anything important, be they telco/infrastructure/gov/mil should be lot checked and assured that they are what they claim to be. This does go on today in any areas where sensitive data resides (mil and gov at least) Public side though, well, many do not have the wherewithal to do that. However, once again, I say that no one can be sure of any hardware they buy right? I mean, even if it is made in the US, it could also be parted out from other sources, or tampered with right?

Trust but verify… If it’s important then test your stuff. Insure that it not only works, but that it also is not blatantly hiding extra chip sets on the board right? The same goes for any company that you are going to do deals with. Do your homework and see what they are all about before you do it. This is just common sense to me, but then again it seems that the general populace is clueless I guess. Do the leg work and if you feel hinky about anything, don’t buy from them. The same goes for hardware you might buy from an intermediary or “grey market”

After all, as they say in the con game biz.. “If it’s too good to be true, then it probably isn’t” We, the US, have unfortunately set ourselves up in a “pay less” mindset that has ha the military buying cheap hardware for missile systems that in the end, failed to launch. Do you want to have the same happen to your router or other hardware that your company relies on? Never mind the whole espionage thing…

Trust but verify.

Xenophobia Will Not Help:

In the end, I just have to say that the xenophobia going on over the Chinese is getting out of hand. Yes, they spy on us and they steal A LOT of our IP, but, so do other countries. They are not the Fu Manchu character out of the old movies nor are they Charlie Chan either. This is a country that surely wants to be a superpower, if not THE superpower. They do have agenda’s but, they are not omniscient…

We just have to work smarter and be better players at the game of ‘Go’

So far, well, we are not so good and its time to learn..

K.

Continue reading here: 

Huawei and Cyber Espionage, A Question of Trust but Verify

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.