It wouldn't be very secret if it was published on the internet. It's definitely a credible concern given the level of control China demands of companies operating in the country. The US also essentially has backdoors into most communication, and possibly phones as well, so it's not that crazy for China to also have them.
China is also very aggressive in hacking into companies. Even if they didn't have a custom backdoor, them finding a way in and essentially banning Huawei from fixing it, is another option.
It's secret like Area 51 is secret. We know it's there, we know the government is doing something with it, but we don't know fully what, when, why, or how.
I don't think the US Govt backdoors phones anymore ... mostly because they don't need to. They find other ways to get the information, like warrantless surveillance of Google and Apple notification servers.
The other reason I don't think it happens is that there are just too many security researchers trying to find exploits and backdoors. Also it's pretty well known that any backdoor can be used against you. The NSA has an interest in domestic phones being secure.
Granted, international models might have some alterations/backdoors... Even then, that would be egg on the face that they don't really need if they got caught with a backdoor that applied only to international phones.
The backdoors the NSA uses are known vulnerabilities, 0days, USB drops, all the normal hacker tools... and if it's a target of sensitive enough in nature, maybe a warrant requiring Apple Update/Windows Update/whoever or whatever device needs spied on, to deliver a payload to that specific machine.
They're definitely grabbing analytics and statistics. But so is AT&T, Verizon, T-Mobile, Apple, Amazon, Samsung, Google, Microsoft.
If the Chinese government asked any of those other companies to give them all the data they have on you in particular, They probably tell them to get bent.
But if the US government told them to do it, they would comply and then have a gag order slapped against them to keep them from telling you it happened.
Huawei is beholden to the Chinese government. So it works kind of in the opposite way.
If the Chinese government asked any of those other companies to give them all the data they have on you in particular, They probably tell them to get bent.
More likely they’ll send an invoice. They’re already selling your data to them. (And everyone else.)
If you work in a field with sensitive data (financial, healthcare, technology, politics) you don't get a phone designed by a China-government owned company.
Most of Lenovo’s rootkit fiascos are due to lack of vetting bundleware providers though; Huawei is actually unlikely to have a backdoor in their phones. Their 5G infrastructure on the other hand is known to have at least two different potential backdoors designed in such a way that they may just be a chain of unfortunate vulnerabilities. Or not.
So far, all of Huawei's found potential backdoors turned out to be them being extremely terrible at writing secure software or developing secure operating procedures.
That's how you write a backdoor in 2023 "oops... Guess I made a mistake again"
Probably, but iPhones and Android have them for the Five Eyes and anyone else who is willing to pay/push for laws to make it happen. All you do with a phone is pick your poison, do you want China to spy on you, or America, the UK, or some other government or company who then sells it to the highest bidder.
Any cell phone, dumb or smart, is a tracking device. The smarter it is, the better it is as snooping on you. Doesn't matter how or where the phone's hardware is made, it's going to track you without consent. You just need to ask "Am I worried about China or am I worried about another government?" to even "If the backdoor is big enough, can third parties get me too as I walk by on the street?"
yea phones constantly ping something so at least the network operator can map out where it has been with good accuracy if you become person of interest
The network operator will naturally have a log of the nearest cell tower to your phone as you move around and each entry there gives an (almost, but not quite in heavilly built places because line of sight obstructions and signal bounces) circular area within which that phone was at that time (not absolutelly sure about the tower measuring and keeping logs of radiowave power levels, but if it does that circular area can be further improved to something like a torus), and the higher the density of cell towers around the phone (i.e. in cities) the smaller the areas and hence the higher location precision.
Also, at least in the US, it's possible to get the operator to triangulate the phone's position using multiple towers to get a much more precise location, which is how law enforcement (and who knows who else) can find people via their phones.
Even the dumbest of mobile phones can be tracked this way.
On the same vein, do wo know if Intel Management Engine is a NSA backdoor?
I keep hearing about the potential of it beeing a back door, but haven't heard an exploit using it roaming about the interwebs
It's not known to be a backdoor, but it's a juicy attack surface that customers are largely ignorant of and provides little consumer benefit. If I were an NSA employee and my boss handed me a blank check to develop a preboot exploit for Intel PCs, I'd start with IME.
It doesn't matter if it's a Huawei or some American phone, China, USA and others will spy on you no matter what phone you choose only the means differ. If you buy a Huawei china will have backdoors in your phone and the USA will buy all your info and if you get an American phone the USA will have backdoors and china will buy the data.
Also I find the focus on china kinda weird. I ultimately don't want anyone stealing my data, not even the USA. Just like china the USA has been involved in mass surveillance and a lot of war crimes. For example American soldiers have been found guilty of rapping and killing children. From Wikipedia (United States war crimes > war on terror > Iraq war):
On 12 March 2006, a 14-year-old Iraqi girl named Abeer Qassim Hamza al-Janabi was raped and subsequently murdered along with her 34-year-old mother Fakhriyah Taha Muhasen, 45-year-old father Qassim Hamza Raheem, and 6-year-old sister Hadeel Qassim Hamza al-Janabi.
After all of that I want to ask you one question, do you really want the USA sterling your data? Also what you answer that question with doesn't matter since both china and the USA will be stealing your data no matter if you want it or which phone you buy.
As a final note I should maybe mention that I'm not American if you haven't figured that out yet. Also please don't accuse me of spreading Chinese propaganda. I'm advocating against the USA and the CIA, not for china.
Also sorry for being so political in a kind of not that political thread.
But it sounds like you are advocating for china. Look how much you wrote about another country when someone asked specifically about china and a Chinese phone manufactured in china.
top 50 comments