• humanspiral@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    Motherboards/routers (these are motherboards too) require very careful inspection, specifically if bios chip is unusual, or extra chip connected to bios. There is concern trolling over routers because Huawei is best in world. There is no concern about Motherboards, because only Taiwan is the competitor to China. The point is that inspections instead of baseless hysteria over origin is the right policy.

    • Aceticon@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      It’s not a question of concern, it’s a question of what’s technically possible.

      It’s technically possible to ship a motherboard with spyware capabilities in the BIOS.

      • humanspiral@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        There are experts, even stupid fat american ones, who could confirm the existence of such spyware capabilities.

        • Aceticon@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 hours ago

          Yeah, well, when was the last time common people and business paid attention to IT Security experts BEFORE their systems were broken into?!

          Also, who would pay the people with the necessary expertise to decompile all BIOS of all motherboard shipments (if at all possible, in this day and age when a lot of shit is encrypted with the keys inside a TPM module)?

          I mean, just go at it another way - notice how thousands of pager sent to Lebanon were altered by the Israelis and nobody were aware of it until the Israelis made them explode.

          In this day and age it’s pretty straightforward to just alter the software for some shipments and not others or add a weakness (like both Intel and AMD CPUs have) that can be used as a backdoor by software that’s installed remotely (for example, pushed as a Windows update, something which certain American 3 letter agencies can most certainly do since the have the power to demand the signing keys from MS).

          There are huge numbers of vectors for spyware to end up in certain computers that start with subtly backdooring the hardware itself.

          • humanspiral@lemmy.ca
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 hour ago

            when was the last time common people and business paid attention to IT Security experts BEFORE their systems were broken into?!

            You/America can be worried about spyware from China. So the US makes an inspection department, like it has for food and drugs, that certifies there is no spyware. That is a completely different approach than fabricating spyware hysteria, and then forcing everyone to believe it.

            • Aceticon@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              1 hour ago

              I think that at least when it comes to America it’s more than widely proven that they have an insanely large digital spying infrastructure (not just the 4-eyes stuff but also all that the NSA does, a lot of which having been revealed by Snowden) and even very openly laws such as the Patriot Act and the Cloud Act that let them force American companies to spy for them.

              No “hysteria” necessary to conclude that America will do whatever it takes to spy on everybody (both internally and internationally).