

The US Navy, NATO, and NASA Are Using a Shady Chinese Company's Encryption Chips
source link: https://it.slashdot.org/story/23/06/16/2330235/the-us-navy-nato-and-nasa-are-using-a-shady-chinese-companys-encryption-chips
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

The US Navy, NATO, and NASA Are Using a Shady Chinese Company's Encryption Chipsbinspamdupenotthebestofftopicslownewsdaystalestupid freshfunnyinsightfulinterestingmaybe offtopicflamebaittrollredundantoverrated insightfulinterestinginformativefunnyunderrated descriptive typodupeerror
Yet nearly two years later, Hualan -- and in particular its subsidiary known as Initio, a company originally headquartered in Taiwan that it acquired in 2016 -- still supplies encryption microcontroller chips to Western manufacturers of encrypted hard drives, including several that list as customers on their websites Western governments' aerospace, military, and intelligence agencies: NASA, NATO, and the US and UK militaries. Federal procurement records show that US government agencies from the Federal Aviation Administration to the Drug Enforcement Administration to the US Navy have bought encrypted hard drives that use the chips, too. The disconnect between the Commerce Department's warnings and Western government customers means that chips sold by Hualan's subsidiary have ended up deep inside sensitive Western information networks, perhaps due to the ambiguity of their Initio branding and its Taiwanese origin prior to 2016. The chip vendor's Chinese ownership has raised fears among security researchers and China-focused national security analysts that they could have a hidden backdoor that would allow China's government to stealthily decrypt Western agencies' secrets. And while no such backdoor has been found, security researchers warn that if one did exist, it would be virtually impossible to detect it.
"If a company is on the Entity List with a specific warning like this one, it's because the US government says this company is actively supporting another country's military development," says Dakota Cary, a China-focused research fellow at the Atlantic Council, a Washington, DC-based think tank. "It's saying you should not be purchasing from them, not just because the money you're spending is going to a company that will use those proceeds in the furtherance of another country's military objectives, but because you can't trust the product." [...] The mere fact that so many Western government agencies are buying products that include chips sold by the subsidiary of a company on the Commerce Department's trade restrictions list points to the complexities of navigating the computing hardware supply chain, says the Atlantic Council's Cary. "At minimum, it's a real oversight. Organizations that should be prioritizing this level of security are apparently not able to do so, or are making mistakes that have allowed for these products to get into their environments," he says. "It seems very significant. And it's probably not a one-off mistake."
Recommend
-
5
Don’t be shady, deploy your JavaScript source maps JavaScript source code minification is a beneficial tool for reducing download file sizes. However, the resulting obfuscation makes the code difficult to read, and reduces tr...
-
7
In this ProductTank Exeter talk, Paul Boag, Founding Partner of ...
-
10
What does the word “shady” mean? The word “shady”, as commonly used by people, is used to describe people or things that are questionable or seem unreliable and suspicious. The word can be used to describe people, businesses...
-
4
www is prepended to invalid urls like '.de' and '.com' and thereby can redirect to shady websitesThanks for reporting this. What happens is Firefox treats .de as a valid domain name and tries to load it. That fails, so...
-
7
Shady Marketing Tactics That Will Hurt Your Business Full Stack Radio
-
9
Artificial truth archives | latest
-
6
Chip choices — US lawmakers warn Apple on using Chinese group’s chips in new iPhone Cupertino accused of "playing with fire" if it buys data storage components from YMTC.
-
4
US Navy Hit by Chinese Hacking Campaign, R...
-
0
red alert — The US Navy, NATO, and NASA are using a shady Chinese company’s encryption chips US government warns encryption chipmaker Hualan has suspicious ties to China’s...
-
5
Wednesday, 07 February 2024 10:00 Chinese company set to make 5nm chips this year: report Featured By Sam Varghese
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK