Until the Chinese government penalizes these Chinese companies for these insecure practices, they'll continue to be sold as is. China doesn't need to care about Chinese made products sold for export apparently.
Why single out the Chinese government? No government anywhere cares about defective software. "Engineering" is certainly not the correct term to apply to this industry.
Yeah. I subscribe to a mailing list from a data security company that sends me a summary of breaches, daily. I know it is in their interest to keep me worried. But they aren’t making these stories up.
To be fair, in many (maybe all?) of those cases, those companies faced consequences. I highly doubt this company is going to face any consequence for this data breach.
AT&T was fined $177 million for one data breach, which represents 12 hours of revenue, and $13 million for the other, which represents 54 minutes of revenue. "Consequences". Right.
You can brush that $177M fine aside but I'm almost certain that none of the Chinese companies above with these security vulnerabilities will pay even $1 in fines.
Because they didn't cause harm to 100 million people. The headline is a blatant lie. Nobody was hacked, the reporter hired a pentester to pentest a product. Is it a good thing that it's insecure, obviously not. But obviously this is going to be a legal non-event compared to leaking PII for 100m people, regardless of nationality of companies involved, when leaking PII for 100m people is already slap-on-the-wrist territory. There are also countless insecure American hardware products on the market that also don't result in litigation because the scale is not national news-worthy.
Do US markets (Amazon) hold any responsibility for what shady companies and their insecure products they enable to sell here, I wonder? Does our government, for import?
I see an opportunity for an import hurdle masquerading as a security compliance mark on all Chinese imports.
I doubt it will be implemented as there are no western cheap gadget industries left to lobby for it, and the big players would prefer the fud of buy cheap be tracked.
China doesn't need to care about Chinese made products sold for export apparently.
Wait until you hear about this American car companies that makes vehicles so unsafe, they intentionally lock themselves down tight in an accident so the emergency services can't get people out of them, and presumably just have to sit there and burn to death with their rescuers half a metre away.
This is perfectly legal under US law. There are no safety regulations.
Comments
Until the Chinese government penalizes these Chinese companies for these insecure practices, they'll continue to be sold as is. China doesn't need to care about Chinese made products sold for export apparently.
Why single out the Chinese government? No government anywhere cares about defective software. "Engineering" is certainly not the correct term to apply to this industry.
[1] Yahoo loses all of their 3 billion account credentials https://www.sec.gov/Archives/edgar/data/732712/0000732712170...
[2] Equifax loses PII of 150 million Americans, including their SSNs https://www.ftc.gov/enforcement/refunds/equifax-data-breach-...
[3] AT&T loses SSNs of 73 million customers https://about.att.com/story/2024/addressing-data-set-release...
[4] AT&T loses phone call/texting metadata of 110 million customers https://www.sec.gov/Archives/edgar/data/732717/0000732717240...
[5] Change Healthcare loses medical records of 200 million Americans https://www.hhs.gov/hipaa/for-professionals/special-topics/c...
To someone not drinking your nationalist kool-aid, it looks rather preposterous to make this about the Chinese bogeyman.
Yeah. I subscribe to a mailing list from a data security company that sends me a summary of breaches, daily. I know it is in their interest to keep me worried. But they aren’t making these stories up.
Yes, which is I am so bullish into having this industry getting liability like everywhere else.
Cybersecurity laws are a good start, however thanks to lobbying it will still take decades.
To be fair, in many (maybe all?) of those cases, those companies faced consequences. I highly doubt this company is going to face any consequence for this data breach.
AT&T was fined $177 million for one data breach, which represents 12 hours of revenue, and $13 million for the other, which represents 54 minutes of revenue. "Consequences". Right.
You can brush that $177M fine aside but I'm almost certain that none of the Chinese companies above with these security vulnerabilities will pay even $1 in fines.
Because they didn't cause harm to 100 million people. The headline is a blatant lie. Nobody was hacked, the reporter hired a pentester to pentest a product. Is it a good thing that it's insecure, obviously not. But obviously this is going to be a legal non-event compared to leaking PII for 100m people, regardless of nationality of companies involved, when leaking PII for 100m people is already slap-on-the-wrist territory. There are also countless insecure American hardware products on the market that also don't result in litigation because the scale is not national news-worthy.
It's only going to get so much worse. Most companies right now are dropping all the standards they still had to ship AI slop code as fast as possible.
Do US markets (Amazon) hold any responsibility for what shady companies and their insecure products they enable to sell here, I wonder? Does our government, for import?
I'm not sure this is uniquely a China problem
Cheap electronics with terrible software? Maybe not unique, but they dominate the market.
We could sure go a long way if China would start.
I see an opportunity for an import hurdle masquerading as a security compliance mark on all Chinese imports.
I doubt it will be implemented as there are no western cheap gadget industries left to lobby for it, and the big players would prefer the fud of buy cheap be tracked.
Wait until you hear about this American car companies that makes vehicles so unsafe, they intentionally lock themselves down tight in an accident so the emergency services can't get people out of them, and presumably just have to sit there and burn to death with their rescuers half a metre away.
This is perfectly legal under US law. There are no safety regulations.