Skip to content

Comment on Spy agencies ban Lenovo PCs on security groundsparent

Comments

How can Dell check for back doors when the entire design and manufacturing process is done by Chinese subcontractors? That makes no sense..

Through testing, just like the governments did to discover alleged backdoors in Lenovo chips. Did you read the article before you posted multiple times criticizing it?

The ban was introduced in the mid-2000s after intensive laboratory testing of its equipment allegedly documented “back-door” hardware and “firmware” vulnerabilities in Lenovo chips.

Do they check every machine? From TFA:

  > A technology expert at the ­Washington-based Brookings ­In­stitution, Professor John Villasenor, said the globalisation of the semi-conductor market has “made it not only possible but inevitable that chips that have been intentionally and maliciously altered to contain hidden ‘Trojan’ circuitry will be inserted into the supply chain.
So we aren't necessarily talking about every single machine being back-doored. My point is that Dell and HP aren't necessarily any more secure just because they're American companies. The home-country of the company whose badge is on the machine is pretty much meaningless in a globalized world.

The article also contains some suggestion that this was motivated by rivalry in addition to security, so there's that as well.

I see such back doors as less of a problem for the general public than it is for intelligence agencies because because even a single malicious device could result in a major security breach and so randomized testing mightn't be as effective. If trying to snoop on the general public on an ongoing basis though then it would be hard to avoid randomized testing (presuming someone is actually doing such testing).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.