US Department of Homeland Security warns American business not to use Chinese tech or let data behind the Great Firewall
- Reference: 1608703270
- News link: https://www.theregister.co.uk/2020/12/23/dhs_warns_us_businesses_dont_use_china_tech/
- Source link:
The fifteen-page [1]“Data Security Business Advisory” [PDF] opens by warning “Businesses expose themselves and their customers to heightened risk when they share sensitive data with firms located in the PRC, or use equipment and software developed by firms with an ownership nexus in the PRC.”
Among the risks mentioned are “theft of trade secrets, of intellectual property, and of other confidential business information; violations of U.S. export control laws; violations of U.S. privacy laws; breaches of contractual provisions and terms of service; security and privacy risks to customers and employees; risk of PRC surveillance and tracking of regime critics; and reputational harm to U.S. businesses.”
The document argues that China’s 2017 National Intelligence Law is a primary source of risk, as it “compels all PRC firms and entities to support, assist, and cooperate with the PRC intelligence services, creating a legal obligation for those entities to turn over data collected abroad and domestically to the PRC.”
China’s new Data Security Law, due to come into force in 2021, also gets a lashing on grounds that it offers China’s government further surveillance powers and will “force foreign markets to remain open to Chinese data services providers.”
Fitness tracker data could be matched with property tax records and “further leveraged to identify names and family members.”
The document also says China’s new encryption law compels key-sharing.
The Department therefore advises American businesses that any data they hold in Chinese data centres won’t be secure, Chinese-designed hardware has backdoors, and joint ventures with Chinese firms will see third-party data shared around.
Made-in-China mobile apps such as TikTok aren’t safe, the advice adds, while even fitness trackers are a risk because the location data they collect could be harvested by the Communist Party, matched with property tax records and “further leveraged to identify names and family members”
Once it’s done scaring readers, the document suggests businesses “should minimize the amount of at-risk data being stored and used in the PRC or in places accessible by PRC authorities” and “acquire a thorough understanding of the ownership of data service providers, location of data infrastructure, and any tangential foreign business relationships and significant foreign investors.”
If businesses can find one, the document recommends finding an alternative and trustworthy supplier. Which may not be easy given that we know the United States National Security Agency has tapped gear made by US companies, while Russia is suspected of having close to God-mode access to big American companies thanks to flaws at [2]SolarWinds and [3]FireEye .
The document tells IT operators to “IT ensure proper segmentation of their network infrastructure from any external software use” (see SolarWinds and FireEye above). And all businesses are told to brush up their cybersecurity skills (see SolarWinds and FireEye above).
None of the advice is silly, but it lacks detail on how to figure out if a supplier has a Huawei router lurking on a rack somewhere, or how to determine if a business relationship draws you into the PRC’s legal orbit.
At least it does recommend ongoing due diligence. Which probably means lawyers and security consultants should be busy. The Register expects the latter will start mentioning the DHS document in their marketing before too long. ®
Get our [4]Tech Resources
[1] https://www.dhs.gov/sites/default/files/publications/20_1222_data-security-business-advisory.pdf
[2] https://www.theregister.com/2020/12/18/solarwinds_nnsa_microsoft_cisa/
[3] https://www.theregister.com/2020/12/09/fireeye_tools_hacked/
[4] https://whitepapers.theregister.com/
As Mad as a Hatter Determined to Fail Spectacularly in an Epic Display of Hubristic Self-Harm ‽ .
Well, I'm sure to not be the only voice to ask if the United States Department of Homeland Security's (DHS) fifteen-page [1]“Data Security Business Advisory” [PDF] is irrefutable proof positive Uncle Sam has slipped into the deep and dark desponds which server paranoid schizophrenia as fodder and feed to try and protect a rotten body riddled to excess with its wares?
So much for that ages old stalwart adage of competition being the lifeblood of open free markets and business enterprise ..... although the markets have been rigged forever since whenever it was realised by an arrogant, never ever thought we'd be found out few, fickle fantasies only require silent obedient labour and ignorant worker bees can be easily capitalised with public debt and fancy printed paper as a currency for massive private profit and colossal population captivation and willing engagement ....... Effective Practical Capture and Remote Virtual Enslavement.
That is not to say that such is not a great plan, for its elegant and attractive simplicity is a joy to behold and admire, the problem and shame is that it is administered and exercised so abysmally by executive elites not up to the tasks required of the future as future directors/present producers.
It is easily fixed though with a radical change needed resulting in the engagement of Future Greater Grand Task Masters. Such is certainly the most wise and surely simplest of any available option if one wants to escape the crushing destructive defeats and ignominious increasingly rapid annihilations that competing against or opposing them deliver out of the blue, totally unexpected and with one completely unprepared for the consequences resulting in such ill-conceived actions.
[1] https://www.dhs.gov/sites/default/files/publications/20_1222_data-security-business-advisory.pdf
Mandatory backdoors, key sharing, and data harvesting are evil? Indeed. Now put your foot where your mouth is and stop demanding the very same at home.
Pot, meet kettle. Nice to meet you. Kettle, meet pot. Nice to meet you too.
Pot and kettle, please be very wary when you meet wok.
What's yours is ours
And we don't want to share it with China or anyone else.
Re: What's yours is ours
"...violations of U.S. privacy laws;"
Do they have any?
On a similar subject
I got a very interesting letter from the DGSI ( [1]Direction Générale de la Sécurité Intérieure ) warning about the risks of using clouds outside EU. Very enlightening.
[1] https://en.wikipedia.org/wiki/General_Directorate_for_Internal_Security
Surely
That also means Apple kit. Whats to say no chips are secretly added to their kit.