US 'dropped the ball' on security by going it alone claims Huawei US CSO
- Reference: 1628208783
- News link: https://www.theregister.co.uk/2021/08/06/cso_huawei_us/
- Source link:
"The US has fundamentally dropped the ball when it comes to participation in global security standards," Purdy told The Register . "We need really strong standards and the US should be a major player."
Instead of working with China and other technologically sophisticated nations, the US under the Trump administration took a confrontational stance. Huawei, a China-based global telecom conglomerate, suffered during this period and the mistrust laid bare during those years lingers.
[1]
So it's perhaps not surprising that Purdy, as an executive with the company's US subsidiary, believes the US made the wrong move by erecting trade barriers and shunning Huawei.
[2]
[3]
"I don't think the US realizes it, but I think the US made a colossal mistake in imposing the export controls to basically drive China to accelerate the chance when they'll create an alternative to what the semiconductors in the US can do," he said.
But Purdy is more focused on advocating for cooperation than assessing the effect of trade barriers on China's tech sector. He went so far as to describe an encounter at a security conference last year where he asked a top US intelligence official about the possibility of agency personnel visiting Huawei facilities to evaluate security practices. The official replied that the agency does not have the authority to do so because Huawei is not a US company tied to the US defense industrial base.
[4]
Citing discussions with other security professionals to the effect that you have two choices – develop a security protocol that eliminates the advantage nation states have for intelligence gathering or accept that you're not really going to have security – Purdy said he disagreed.
"I don't believe that," he said. "Nation states – US and China in particular, Israel and a couple others – are going to have the ability to spy, all around the world."
"But I think we need to learn some lessons and it looks like the Biden administration is taking some steps in the right direction from the recent attacks on SolarWinds, Microsoft Exchange, and to a lesser extent the ransomware attacks. They all show the vulnerability of everything."
[5]
These attacks, though attributed to nation states, he said, involved trusted suppliers, so the old assumptions no longer work.
[6]Huawei to America: You're not taking cyber-security seriously until you let China vouch for us
[7]Huawei says its latest flagship smartphones lack 5G, blames US sanctions
[8]Money can't buy you love: Huawei continues to throw fistfuls of dollars at US lobbying efforts
[9]UK.gov's Huawei watchdog says firm made 'no overall improvement' on firmware security but won't say why
Purdy argues that trust doesn't need to be assumed. "Something I've really emphasized is the trust-no-one approach," he said. "[We should be] working on developing a zero-trust architecture and zero-trust principles so it's not just about the perimeter."
And if trust isn't a given, Purdy suggests we can at least have enough transparency to make informed decisions.
"How can you make it possible to know whether or not a company is doing the right thing?" he said. "You can't just use an approach like [the Trump administration did with] WeChat and TikTok. ...Ownership and control assertions by the head of a company aren't the answer. You need to test. You need to have independent conformance and you need visibility to know whether the company is doing the right thing. ...You also need much greater accountability."
Purdy said he sees the US tiptoeing toward greater accountability, at least for critical infrastructure.
"We need to move from the old UN cyber-norms of conduct to incorporate some of the things China has recommended in the [10]China Global Initiative on Data Security from 2020," he said.
Purdy imagines that might take the form of mutual trust agreements between governments, so companies in the US, China, or wherever can operate from a common set of assumptions, with penalties for broken promises similar to those contemplated for privacy violations by Europe's GDPR.
He points to the way Germany oversees the relationship between telecom operators and suppliers as an example of how to proceed. "The operators are responsible for these suppliers that are part of their supply chain to make sure they know what the suppliers are doing," he explained.
"You need a special visibility between operators and suppliers, much greater than we've had in the past, so you have an objective way to know whether the suppliers are doing what they're supposed to be doing.
"I think we need to move toward a system where there's greater visibility and transparency, and much greater accountability, because we really have not been big on accountability in the United States at all and it's really been a mistake," he concluded. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQyz969Qth@KCNlvtA8BKwAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQyz969Qth@KCNlvtA8BKwAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQyz969Qth@KCNlvtA8BKwAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQyz969Qth@KCNlvtA8BKwAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQyz969Qth@KCNlvtA8BKwAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/02/huawei_security_advice_to_usa/
[7] https://www.theregister.com/2021/07/29/huawei_announces_its_latest_flagship/
[8] https://www.theregister.com/2021/07/21/huawei_us_lobbying/
[9] https://www.theregister.com/2021/07/20/huawei_hcsec_oversight_report_muted_criticism/
[10] https://www.fmprc.gov.cn/mfa_eng/zxxx_662805/t1812951.shtml
[11] https://whitepapers.theregister.com/
Maybe backdoor less?
The USA shouldn't be involved in any way in security because all it does is backdoor stuff.
Look at Certs, any certification authority can issue a fake cert for any site. Who designed that? An f-ing crackhead? But, you say the fake cert would be spotted..... and along come CDN networks who can individually target fake certs that will never get spotted, effectively backdooring any security they offered.
All they ever do is backdoor security. If there's a security standard that comes out with government involvement the government's contribution was a backdoor.
Yesterday, Zinc Network popped up again, (UK Foreign office's fake NGO) Adam and his crappy "here we found 350 fake Chinese propaganda accounts, using (insert implausible data mining/language analysis explanation incapable of searching low level noise like that) and 'exposed' how China is obsessed with propaganda, mostly against Steven Bannon. Honest China is totally anti-Bannon so you should listen to whatever racist crap Bannon spews...here look at all these cartoons we, er they drew about Bannon, the guys a legend, you should worship him because China totally did this". Sure Adam, sure they did, and sure they are obsessed with Steve Bannon as much you are, and sure you *didn't* just put up 350 fake accounts from other fake FCO NGOs, then find them again. I ToTALLy BeLIEVe that.
Do I trust a government that runs propaganda operations attacking encryption and the privacy right with funded fake NGOs to protect security and privacy? Propaganda aimed and read almost exclusively by its own people? *DOMESTIC* propaganda? Domestic propaganda driving domestic laws to undermine security and spy on their own country? F**K NO!
Those certs you backdoored, they also certify software downloads, and the source of the software, so you've backdoored every piece of kit with your f**ing backdoors. All *your* hi-tech all compromized, by *you*. Undermined by *you*.
Well done, now to make things secure, every piece of US kit should be ripped out, and every US CDN have its contract cancelled, because you f**kers and you're backdoors.
/rant
Zero trust security. The privacy right in a nutshell.
Re: Maybe backdoor less?
You know it is blasphemy to criticise the land of the free and say anything good about the evil CCP to all the Trump/GOP and flag waving loonies.
Re: Maybe backdoor less?
I'm pissed off at this, as you can tell.
Shanghai stock exchange, I'm seeing fake injected DNS packets, blocked CSS files, a routing via Kansas, yet the entry point in China Telecom routes via Hong Kong and is twice as fast. Not the exception, a lot of their financial sites are getting this crap. Fake crap to give the impression of failure and disuade inward investment.
CDN networks that are simply government fronts. Certs that should never exist, ever, out in the wild.
It's economic warfare, and I'm pretty sure USA didn't declare war against China yet Huawei are just one of the attacks going on.
I see the propaganda from yesterday, go digging into it, and find a rent-a-desk network of UK government funded NGOs run by ex diplomats and security guys. Last I looked, the privacy right is written into the UK constitution, and they attack it, with taxpayer funding. Attacking UK rights.
Fake NGO1: "sending kids back to war zones is unpopular.... lets turn it into meme to hide what we're doing...."
Fake NGO2: "how about 'people smuggling', *smuggling* is *bad*, and we focus it on the mythical baddies and away from the victims we're victimizing..."
Fake NGO1: "that's good but can we get a terrorism or drug reference in there to help with the demonization...."
Fake NGO2: "I know how about 'human trafficking'... it removes the 'people' part so Brits no longer indentify with them as people, and it sounds like *drug*-trafficking for the demonization".
Fake NGO1: "Brillitant! Now we're no longer sending people back to be killed in war zones, we're tackling 'HUMAN TRAFFICKING'!"
Fake NGO2: "NGO1, can I ask a question.... we're doing political propaganda with taxpayer money, while pretending to be concerned about the subjects we're pushing.... are we the baddies? Are we the baddies NGO1? Are we? Are we the baddies?"
Fake NGO1: "No, I ask Goebbels our ethicist and he says its totally fine, as long as we don't tell anyone what we're doing and hide it behind a bunch of front companies and rent-a-desk mailing addresses".
Re: Maybe backdoor less?
The whole Internet is one massive backdoor. That's how it was designed - by academics, not governments - and all attempts to secure it are like trying to make water run uphill, except that no-one is prepared to pay for the pumps.
As to Zinc Network, it's a weird but perfectly legit organisation. And I can't find any trace, either on Google News or Zinc's own website, of the story you reference. If the goal is to influence people, you'd think they'd want to publicise it - at least a bit?
Oh, shut up.
Covering up for your parent company by throwing stones is not a good idea.