News: 1710459306

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Forget TikTok – Chinese spies want to steal IP by backdooring digital locks

(2024/03/15)


There's another Chinese-manufactured product – joining the likes of TikTok, cars and semiconductors – that poses a national security risk to Americans: electronic locks, such as those used in safes.

In a letter to National Counterintelligence and Security Center (NSCS) director Michael Casey, US senator Ron Wyden (D-OR) urged the White House threat-intel arm to sound the alarm on commercial safes and locks. He also accused the Feds of intentionally keeping American businesses in the dark about the data-security risk to trade secrets and other sensitive IP while "quietly protecting government agencies from it."

NSCS spokesperon Dean Boyd told The Register "We've received the senator's letter and are reviewing it."

[1]

Most commercially available safes include manufacturer reset codes for their locks to help consumers if they lose or forget the code they set. However, government agencies and law enforcement can [2]request access to these codes – usually via a warrant or subpoena, and ostensibly to help investigate a crime or address some sort of national security concern.

[3]

[4]

"It would be one thing if these backdoors were only available to US government agencies, but they are not," Wyden [5]wrote [PDF].

We should point out that privacy advocates beg to differ, and aren't fans of Uncle Sam using backdoors to snoop on Americans – but that's not Wyden's concern at the moment.

[6]

"These backdoor codes can be exploited by foreign adversaries to steal sensitive information that US businesses store in safes, such as trade secrets and other intellectual property," Wyden warned.

This, he added, is especially risky when it comes to Chinese-made electronic safe locks – such as those manufactured by SECURAM Systems, a major seller of electronic safe locks sold in the US.

"Although DoD has informed my office that the company's products are not approved for US government use, its low-cost products have enabled the firm to dominate the consumer-focused portion of the market," Wyden wrote, noting that SECURAM's website confirms its products include manufacturer reset codes.

[7]

"As a China-headquartered company, SECURAM is of course obligated to follow Chinese law, including the requirement to cooperate with secret demands for surveillance assistance," Wyden continued. "Consequently, SECURAM could be forced to share codes with the Chinese government that would enable surreptitious or clandestine access to the safes used by US businesses."

SECURAM did not immediately respond to The Register 's request for comment.

[8]Uncle Sam tells nosy nations to keep their hands off Americans' personal data

[9]Congress told how Chinese goons plan to incite 'societal chaos' in the US

[10]Former US Treasury Secretary Steve Mnuchin thinking about buying TikTok

[11]White House goes to court, not Congress, to renew warrantless spy powers

The US Department of Defense (DoD) is well aware of the issue, according to Wyden, who cites a November 8 email from the DoD calling manufacturer reset codes a security threat.

But while the DoD prohibits government agencies using these locks, it doesn't want the American public to even know they exist, the letter alleges:

DoD also provided my staff with the attached white paper on December 15, 2023, revealing that US government standards for approved locks do not explicitly reference these backdoor codes in order to avoid tipping off the public to their existence. In short, the government has opted to keep the public in the dark about this vulnerability, after quietly protecting government agencies from it.

The Department of Defense did not respond to The Register 's inquiries.

In light of this "espionage threat posed by foreign spies," Wyden wants to see the NCSC update its educational materials with recommendations that businesses use locks that also meet US government security standards – and presumably without backdoor codes.

But, he cautioned, people can't do this if they don't even know about the problem in the first place: "US businesses cannot protect their valuable intellectual property, and consequently, America's global economic edge, from foreign espionage if they are kept in the dark about vulnerabilities in the safe locks they use." ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfPV6BEIf6kVi0iAxoNdrgAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.nytimes.com/2023/09/08/business/liberty-safe-codes.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfPV6BEIf6kVi0iAxoNdrgAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfPV6BEIf6kVi0iAxoNdrgAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.wyden.senate.gov/imo/media/doc/Wyden%20letter%20to%20NCSC%20on%20lock%20backdoors.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfPV6BEIf6kVi0iAxoNdrgAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfPV6BEIf6kVi0iAxoNdrgAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/02/28/white_house_sensitive_data/

[9] https://www.theregister.com/2024/02/01/china_attack_warning/

[10] https://www.theregister.com/2024/03/14/tiktok_mnuchin/

[11] https://www.theregister.com/2024/02/29/fisa_section_702_wyden/

[12] https://whitepapers.theregister.com/



Ah, Physical Security

An_Old_Dog

As for the government/police using a backdoor (default codes, reset codes, etc.) on a citizen-of-its-country's device: if they've gotten a proper warrant for it, then sure, that's okay.

As for the existance of backdoors in locks, electronic or otherwise: boo, hiss, that's bad, because the "secret" info, like hydrogen, inevitably escapes. At that point, the end-user is fucked.

If you want true security, you have to design and build it yourself, or perhaps have a trusted friend with the skills do so for you. Traditional lock/safe-making corporations such as Chubb, Schlage, Mosler, Diebold*, etc., are not within my "circle of trust." YMMV.

*Yes, the same Diebold who also is the maker of proven-flawed voting machines. "It's not who votes that counts. It's who counts the votes." -- attributed to Stalin.

Re: Ah, Physical Security

veti

If you design and build your own security, unless you're a world-leading expert in security, it won't be secure. Indeed, unless you're in the top 1% of security engineers it probably won't even pretend to work at all.

I have no problem with the government (or anyone else) having a digital means to, metaphorically, kick down a locked door. They've always had that ability anyway, I think it's foolish to try to take it away from them. But I make the proviso, when they do so, it should be obvious that they've done so - there should be some equivalent of a kicked-in door lying in the space to tell everyone, immediately, what's happened.

So if the manufacturer's code has the effect of resetting the passcode to "000000" or whatever, I'm fine with it. It's only really nefarious if you can undo the change and set the whole thing back to its previous configuration, to make it look as if nothing has happened.

Fudd's First Law of Opposition:
Push something hard enough and it will fall over.