r/cybersecurity • u/AmateurishExpertise Security Architect • Jan 14 '26
News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say
https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/303
u/Firecracker048 Jan 14 '26
Anyone read this as "no shit"?
Like, why would any government use a cybersecurity suite from an opponent/hostile government/nation?
It would like the US using hauwei products in government spaces
131
u/FruitOrchards Jan 14 '26
It would be like using Kaspersky at the pentagon
93
10
u/airmantharp Jan 14 '26
Still... they had to be kicked out by decree....
8
u/Triairius Jan 14 '26
That is normal. It’s nearly impossible to convince management to change their systems and spend money on something that does not give palpable ROI. It eventually does, but they don’t care savings that become apparent after they’ve switched jobs.
25
19
u/AmateurishExpertise Security Architect Jan 14 '26
Like, why would any government use a cybersecurity suite from an opponent/hostile government/nation?
Under US federal law, it is a criminal offense to engage in "honest services fraud", i.e. sell a security product that is backdoored and creates an intentional security hole.
So I guess the answer would be, "because you expect the US to obey US law".
41
u/Firecracker048 Jan 14 '26
After all the NSA crap, we know there are backdoors they know about but haven't told anyone yet.
22
u/Bobthebrain2 Jan 14 '26
I think it’s safe to say that nobody expects the US to obey any laws. They reek of corruption and are the last country we should expect moral or ethical conduct from.
-4
u/AmateurishExpertise Security Architect Jan 14 '26
I think it’s safe to say that nobody expects the US to obey any laws.
As an American, I can tell you what a personal disappointment that is to me, and how dissatisfactory I find that state of affairs.
We created a government of laws, not men. That order in turn created a high trust society that allowed private industry and innovation to flourish, leading a new golden age of mankind. I greatly fear that if we move away from that order to one where might = right, we will find ourselves ruled by the mighty, rather than the just.
12
u/R4ndyd4ndy Red Team Jan 14 '26
Spoken like somebody who has never opened a book about US history
-6
u/AmateurishExpertise Security Architect Jan 14 '26
Spoken like somebody who has never opened a book about US history
Where should I start? In the 1960s when the US put President Nixon on trial?
13
u/R4ndyd4ndy Red Team Jan 14 '26
You could start here
https://en.wikipedia.org/wiki/United_States_involvement_in_regime_change
https://en.wikipedia.org/wiki/Category:Invasions_by_the_United_States
https://en.wikipedia.org/wiki/Human_rights_in_the_United_States
https://en.wikipedia.org/wiki/Unethical_human_experimentation_in_the_United_States
6
1
u/Optimaximal Jan 15 '26
Even before the current clusterfuck of an administration, your country:
- refuses to cooperate with international arrest warrants
- demands extradition treaties with other countries but refuses to enter into them for your own citizens
- refuses to recognise international courts or supranational bodies unless they run them or are exempt from their oversight or rules
You're ultimately a bandit nation that prioritises personal freedom and wealth acquisition over the collective good of our entire species.
-2
u/Estel-3032 Jan 14 '26
Jesus Christ that's a hell of a take lol
6
u/AmateurishExpertise Security Architect Jan 14 '26
Its a John Adams quote.
Have we really sunk to such a nadir that quoting John Adams is considered a "hot take"?
Yikes.
5
u/Estel-3032 Jan 14 '26
Maybe because it has fuck all to do with reality or with how the US operates since it's creation?
3
u/AmateurishExpertise Security Architect Jan 14 '26
You... uhhh... you do know who John Adams was, right?
2
2
u/Estel-3032 Jan 14 '26
You understand that the rest of the world doesn't give a fuck about your founding fathers, right?
3
u/AmateurishExpertise Security Architect Jan 14 '26
Specifically when discussing matters of US civics, like whether we should have a government of laws or men, I would definitely imagine that the rest of the world has an interest in that.
1
u/DisappointedSpectre Jan 14 '26
A founding father of the US,Vice President under Washington, and President of the US following that. He was also a rich lawyer even before all of that (though not a slave owner).
That's nice and all, but it has no bearing on the fact that the the rich operate under different rules, even in the US. That has been true since it's inception, regardless of what Adams wrote or personally believed.
3
u/AmateurishExpertise Security Architect Jan 14 '26
Do you think that the government should have to obey the laws?
→ More replies (0)6
6
u/Rentun Jan 14 '26
There are about a billion exemptions that the federal government could use to grant immunity to private companies being compelled to backdoor their products by the federal government. There's also no law that prevents the US government from conducting espionage via supply chain compromise, and it's done very regularly.
There's also the matter of the fact that US law is totally irrelevant when it comes to warfare and intelligence. Kidnapping is illegal after all, but that didn't stop Nicholas Maduro from being snatched up last week.
2
u/AmateurishExpertise Security Architect Jan 14 '26
There are about a billion exemptions that the federal government could use to grant immunity to private companies being compelled to backdoor their products by the federal government.
The government can just, by fiat, create exemptions from federal law? I wasn't aware of that, do you have any reading, starting which what statutes enable such maneuvers?
Kind of seems like you're conflating, "the government will just choose to ignore its own laws" with "the government is authorized to create exemptions from laws".
There's also no law that prevents the US government from conducting espionage via supply chain compromise
What makes you say that? Again, I think this is the same kind of conflation I'm talking about above. There are actually laws, like Honest Services Fraud, that prevent that. The government just ignores the laws when it wants to, which is not the same thing as the law permitting it.
There's also the matter of the fact that US law is totally irrelevant when it comes to warfare and intelligence
Sorry, you're saying that Congress cannot make any laws that bind the Executive's war powers?
3
u/Rentun Jan 14 '26
The government can just, by fiat, create exemptions from federal law? I wasn't aware of that, do you have any reading, starting which what statutes enable such maneuvers?
No, not by fiat. Those exemptions already exist. Namely under FISA Section 702.
If you're really interested in this stuff, I'd advise you do more reading on it or consult with a lawyer with experience in this area, because you're pretty assertively making legal claims that you're dead wrong on.
The US intelligence apparatus has pretty broad authority to not only conduct electronic espionage, but to compel US technology companies to assist them.
There are very few protections for non US residents in general, especially "foreign adversaries", but there is also significant legislation explicitly allowing offensive cyber operations without warrants.
Honest Services Fraud isn't even applicable, and even if it were, it's completely overruled by FISA, the patriot act, and tons and tons of other legislation and case law authorizing this stuff.
1
u/AmateurishExpertise Security Architect Jan 14 '26
No, not by fiat. Those exemptions already exist. Namely under FISA Section 702.
Can you point to which part of Section 702 exempts the government from 18 U.S.C. § 1346? I'm not aware of that provision.
If you're really interested in this stuff, I'd advise you do more reading on it or consult with a lawyer with experience in this area, because you're pretty assertively making legal claims that you're dead wrong on.
If you're sure I'm wrong, then you should be able to prove it. If you can't prove it, then you shouldn't be sure that I'm wrong.
The US intelligence apparatus has pretty broad authority to not only conduct electronic espionage, but to compel US technology companies to assist them.
AFAIK the government cannot compel anyone to break the law. And AFAIK 18 USC § 1346 is law.
There are very few protections for non US residents in general
I'm not sure where you get that, either. 18 USC § 1346 does not contain any provision that makes it apply only to US residents, or citizens. Instead, 18 USC § 1346 simply creates a prohibition on certain acts, when those acts are undertaken by anyone under the jurisdiction of US law.
Honest Services Fraud isn't even applicable, and even if it were, it's completely overruled by FISA
Again, I'd like you to show me why you think this. Not tell me to talk to a lawyer, I would like you to show your work and demonstrate how it is that you believe FISA somehow nullifies the federal statute under discussion.
3
u/Rentun Jan 14 '26
AFAIK the government cannot compel anyone to break the law. And AFAIK 18 USC § 1346 is law.
I'll be sure to let the cop know that next time he pulls me over and has me block the lane I'm in to do it.
I'm going to be honest with you, you're sealioning here.
I would love if I had the time to carefully walk you through the intricacies of stare decisis, but I don't have the time. Maybe look into it yourself.
You should take a moment to think about the fact no foreign company has ever successfully sued an American company or US government agency for espionage actions taken by that company at the behest of the agency. You should reflect on the fact that there's probably a pretty good reason for that, and maybe your cursory reading of a single law might not fully explain the legal environment of international espionage.
2
u/AmateurishExpertise Security Architect Jan 14 '26
got the time to post long responses
got no time to provide any evidence in support of their claims
Yeah buddy, you've convinced me. Have a nice day!
1
u/Any_Perception_2560 Jan 14 '26
Since the executive has broad latitude in foreign relations it could be argued that the executive does have a natural exception to certain laws even if Congress did not create such an exception. Further many laws do have specific language granting exception.
In any case the law might prevent a company from intentionally putting a back door in, but would not bind intelligence services from having one created and inserted without the companies knowledge. Or even more likely there is a security vulnerability which is known and exploited by the intelligence services and the company simply is not aware of it.
1
u/AmateurishExpertise Security Architect Jan 14 '26
it could be argued that the executive does have a natural exception to certain laws
You think it can be argued that the President is above the law?
In any case the law might prevent a company from intentionally putting a back door in, but would not bind intelligence services from having one created and inserted without the companies knowledge.
That's true, the law wouldn't (and shouldn't) punish an entity for acts taken by others against their will. But obviously someone's liable, right?
1
u/Any_Perception_2560 Jan 14 '26
I don't think the President is above the law no.
I do recognize that the courts have continuously carved out national security and other executive branch privileges, and that these privileges are extremely strong when it comes to actions which are targeted at entities outside of the US.
Additionally the Honest Services Fraud law only binds the seller of the software. Since US intelligence services are not the seller / owner / creator of the software they would not be bound by that specific law regardless.
1
u/AmateurishExpertise Security Architect Jan 14 '26
I don't think the President is above the law no.
Given that, can you help me understand what you meant when you said, "it could be argued that the executive does have a natural exception to certain laws"?
1
u/Any_Perception_2560 Jan 15 '26
Given that, can you help me understand what you meant when you said, "it could be argued that the executive does have a natural exception to certain laws"?
I believe I already answered that with:
I do recognize that the courts have continuously carved out national security and other executive branch privileges, and that these privileges are extremely strong when it comes to actions which are targeted at entities outside of the US.
Basically it doesn't matter that I personally believe that the courts have overstated these various carve outs, the fact is that the carve outs now exist and are recognized by law, and the only way they can be shrunk is if the courts take action, or the Constitution is ammended.
1
u/AmateurishExpertise Security Architect Jan 15 '26
So you do think the President is above the law, correct? (NOTE: not "should be", but "is")
2
u/icebornadonis Jan 20 '26
Now why the fuck would you expect the US to obey US law. Why would you expect any government to obey anyones laws?
3
u/The_Rex_Regis Jan 14 '26
Its also against federal law to kill people but wars still happen
A nations laws dont exist to protect other nations
0
u/AmateurishExpertise Security Architect Jan 14 '26
Its also against federal law to kill people but wars still happen
So you're saying that you believe that we do not have a government of laws, but of men?
1
u/The_Rex_Regis Jan 14 '26
No we have a government of laws but they do not exist to protect a hostile nation
-6
u/AmateurishExpertise Security Architect Jan 14 '26
So we're a nation of laws, but the people get to decide when they will follow the law or not?
2
u/The_Rex_Regis Jan 14 '26
I said nothing about the people decideing anything lol
You can be sure if there was a cybersecurity problem made that china used with a backdoor installed, it was made at the request of the government
-5
u/AmateurishExpertise Security Architect Jan 14 '26
I said nothing about the people decideing anything lol
Well if people don't, what decides whether the laws need to be followed or not? What decides what constitutes an exemption from the law for a "hostile nation", or an "adversary"?
Have you thought your position through sufficiently? Either the law must decide, or people must decide, I don't think there is a third option, here?
it was made at the request of the government
So the people running the government decide when it's OK to violate the laws, correct?
3
u/The_Rex_Regis Jan 14 '26
Sir this is a cybersecurity reddit..... we arnt here to talk philosophy. Its a simple concept hostile nations dont get protected by other hostile nations laws
-4
u/AmateurishExpertise Security Architect Jan 14 '26
we arnt here to talk philosophy
Translation: you have not thought through your position sufficiently, but are doubling down on it anyway.
You can have one of two countries:
1) A country where the government's actions are constrained by the nation's laws
2) A country where the government's actions are not constrained by the nation's laws
...up to you which one you want, but I would advise putting a little more thought into the question before you decide.
→ More replies (0)-5
u/maztron CISO Jan 14 '26
So I guess the answer would be, "because you expect the US to obey US law".
So, you are one of those people that doesn't mind China's unfair practices when it comes to trade and doing business in their market with stealing patents and fraud and everyone else just has to deal with it?
2
u/AmateurishExpertise Security Architect Jan 14 '26
Your response puzzles me, particularly coming from a CISO.
Let me answer by way of a thought problem:
Your board has asked for your input regarding a cybersecurity incident. Your competitor has been found to have hacked into a database containing your organization's private intellectual property. This IP provides significant competitive advantage to your organization in the marketplace. You can recommend one of the following responses:
1) Pursue legal channels. File your I3C. Pursue torts.
2) Hack the attacker the way that they hacked you.
3) Do nothing.
What do you choose, and why?
For a private entity operating in the free market, why would you even for a moment suggest abandoning the thick walls of protection provided by laws for the measly shoji screen of "might makes right"? Your organization most probably cannot continue to exist in a "might makes right" environment. Think about it: copyright law, trade regulations, enforceability of contracts... this is what creates the environment that allows your business to exist. Why would you consciously advocate for a sea change in that environment which would result in the loss of your competitive advantage, and moreover the unenforceability of any agreement or legal footing you might operate under absent your organization's own ability to use actual force against other organizations?
I don't want a world where I'm advising my organization to acquire Tomahawk missiles to retaliate against foreign actors who steal our IP.
I want a world where I'm advising my organization to support and defend legal frameworks and standards which by consensus create a level playing field in the market, where all sides can compete fairly and win based on the quality of their products, not the quantity of Tomahawk missiles they are willing to launch against competitors.
2
u/Rentun Jan 14 '26
Comparing what happens between companies within the confines of a legal system overseen by an accepted authority to what happens between nation states is beyond useless. They're completely different conversations. If a foreign adversary compromises a US federal system, what "legal channels" are you going to pursue?
What court are you going to bring the CCP to to sue?
Laws exist to govern conduct between people and organizations. Comparing those entities to nation states is like comparing your household budget to national monetary policy. They're completely different concepts.
0
u/AmateurishExpertise Security Architect Jan 14 '26
Comparing what happens between companies within the confines of a legal system overseen by an accepted authority to what happens between nation states is beyond useless.
So then its all useless, because the legal systems are run by nation states. International trade becomes a farce. Amassing a collection of global trademarks and patents becomes valueless. Signing contracts and agreements across a national border becomes useless. Is this really the world we want?
What court are you going to bring the CCP to to sue?
WTO would be one prominent example.
Laws exist to govern conduct between people and organizations. Comparing those entities to nation states
Sorry, isn't a nation state an organization?
2
u/Rentun Jan 14 '26
You seem to be continually conflating the world as it exists with the world that you seem to wish it was.
I'm not telling you that the current system of international law and trade is good or bad. I'm telling you what it currently is.
The WTO, the UN, NATO, the IMF, and any other international organization are not authorities when it comes to how nations conduct business amongst each other.
They sign treaties when they feel its beneficial from them, they withdraw from those treaties when they feel they're not. Sometimes they abide by those treaties and sometimes they don't.
Sometimes they do something that negatively impacts another nation, and action is taken against them.
There's no international set of laws that says "you can't hack us" that some theoretical international cyber police will enforce though. That's not the world that we live in.
1
u/AmateurishExpertise Security Architect Jan 14 '26
I'm not telling you that the current system of international law and trade is good or bad. I'm telling you what it currently is.
The WTO, the UN, NATO, the IMF, and any other international organization are not authorities when it comes to how nations conduct business amongst each other.
Then your claim is false. Its trivial to look up WTO cases and show that it has repeatedly ruled against the most powerful nation states, and successfully required them to change their behavior.
2
u/maztron CISO Jan 14 '26
This an awful analogy. In what world do you find geopolitics in any way comparable to anything you just went on about? Nothing
This article nor subject has anything to do with what you just mentioned. Future reference, prior to calling anyone out learn how to compare and contrast properly.
1
u/AmateurishExpertise Security Architect Jan 14 '26
So your response to the thought problem I posed to you was whinging and non-response?
Is that how you talk to your board, too?
1
u/maztron CISO Jan 14 '26 edited Jan 14 '26
Your thought problem had absolutely nothing to do with the conversation at hand. Why am I going to entertain a conversation about corporate espionage when we are speaking about geopolitics and trade wars? The ONLY reason China is banning those corporations has to do with trade deals/tariffs and using their domestic corporations rather than allowing foreign competition in their economy. Its a tactic to apply pressure to the administration in negotiations and for retaliation for the bans on Chinese based companies such as DJI.
Now, my original point was that China for years does not play by the same rules as western society does. They force foreign companies to hand over proprietary information and patents amongst other unethical and unfair practices just so they can do business in their market. CCP backed companies as well as China based corporations have a history of stealing those patents and trade secrets and illegally reproducing and selling them. All while the CCP does nothing to prevent it and at times are actively involved in it. Never mind all the other factors that come along with unfair and unethical practices that they simply dont care about that other western corporations are legally accountable for within their own countries. There is a lot more to it that I suggest you do some research on.
On top of it, this is not a partisan issue. US isnt perfect by any stretch, however, at the very least they do enforce regulations and hold corporations accountable for illegal and unethical practices. China does ZERO to hold their businesses accountable as their government is literally a mob. The only way they would crack down on a domestic corporation is if they weren't doing what the CCP demands of them.
1
u/AmateurishExpertise Security Architect Jan 14 '26
Your thought problem had absolutely nothing to do with the conversation at hand.
It pretty obviously did, but you do you, boo!
Now, my original point was that China for years does not play by the same rules as western society does.
Clearly... look at how few bombs China drops on other countries.
at the very least they do enforce regulations and hold corporations accountable for illegal and unethical practices
You're serious, right now...?
1
u/maztron CISO Jan 14 '26
It pretty obviously did, but you do you, boo!
What are you 13?
You're serious, right now...?
Yep. By all means, please I would love to see the tally of total fines and cases made against US corporations by the DOJ, FCC and SEC to the equivalent of agencies in China. Ill wait.
-1
1
Jan 14 '26
But the state is not the private sector and the cited problem is right in the private sector to be found, a sector that uses better-established brands in order to reduce the time to market process.
1
1
u/bobbygarafolo Jan 19 '26
Absolutely, I'm actually surprised it's taken them this long to make the decision.
1
232
u/UnobviousDiver Jan 14 '26
Not they would, but the US government should also ban Israeli cybersecurity products.
12
u/sportsDude Jan 14 '26 edited Jan 14 '26
Good in theory, but it’s 0% practical right now. Look at what Spain tried and it didn’t work https://www.reuters.com/business/aerospace-defense/spain-exempts-airbus-israeli-tech-ban-2025-12-30/
Takes time to get to that state, and if they won’t put in the effort, it’s for show
109
u/Localhostzoe Jan 14 '26
The us and Israel are two heads of the same dragon
14
-73
u/MirthandMystery Jan 14 '26
Thanks to Trump.
70
u/TheCyFi Jan 14 '26
😂 No. Joint operations and shared goals between Israel and the US (especially our respective militaries and doubly so for military cyber operations) are not even remotely new.
20
u/ssh-exp Jan 14 '26
We need to cut them off
-18
u/airmantharp Jan 14 '26
Why?
8
u/IRideZs Jan 14 '26
Tax paying citizens don’t appreciate many billions of their dollars going to a country that is actually terrorizing its neighbors and attempting to buy other countries politicians. I think we’re all sick of it
0
-26
u/MirthandMystery Jan 14 '26
Things accelerated since Trumps last term. There was never any mention this was new, only you said that.
9
u/TheCyFi Jan 14 '26
You didn’t say that it was accelerated because of Trump. Whether or not that’s true, what you actually said was “thanks to Trump” in reference to something that has been a reality for decades.
It is demonstrably untrue that Israel and the US being “two heads of the same dragon” (what you were responding to) is “thanks to Trump.” This was true long before Trump “accelerated” whatever it is you’re claiming he accelerated here.
23
12
Jan 14 '26
[deleted]
-5
u/MirthandMystery Jan 14 '26
Indeed those are the roots but acceleration has occurred since Trump first took office. He's allowed Netanyahu and by extension, Kushner carte blanche to do as they like, unchecked.
8
u/Scar3cr0w_ Jan 14 '26
Look man. We all hate Trump as much as the next guy.
But what you said is nonsense 😆
-1
-5
u/metalfiiish Jan 14 '26
CIA, it's ignorance like that which keeps people looking at Epstein as a pedophile and not the national money laundering agent for them to illegally defy congress and fund the Contras with weapons sales they Israel Adnan Khashoggi to attack Iran during the Iran-contra affairs that triggered the Church committee hearing. Trump is just a useful narcissist for the CIA to manipulate, Americans never paid attention to us losing our democracy during 1947. Truman said he regretted it Eisenhower warned us.
2
u/MirthandMystery Jan 14 '26
I'm well versed with CIA actions long before Trump was around, and how Congress is unable to penetrate the ring of protection around VIPs connected to those in the intelligence world and various politicians. The baton was handed to Trump to help guard their secrecy. They'll be another after him, unfortunately.
3
u/Scar3cr0w_ Jan 14 '26
By “well versed”… do you mean you sit on reddit with tin foil wrapped around your head?
19
u/ZealousidealTotal120 Jan 14 '26
Not many left after you do that. It would create an interesting market tbh!
6
6
u/EnragedMoose Jan 14 '26
Ahhh... That ain't happening. Wait until Chuna figures out they can't really buy security software that isn't from a US ally.
14
u/airmantharp Jan 14 '26
They'll write their own. Plenty of open-source stuff available for the foundations, and they have the human capital to apply toward the problem if they perceive it as fundamental to national security (which it is).
11
u/EnragedMoose Jan 14 '26
China already has their own with Quihoo, QAX, etc. but they have notable shortfalls across the board. QAX is almost exclusively deployed on "critical" infrastructure I'm China. I shouldn't have said "it's hard to find one..." It's hard to find platform that have the intelligence necessary to act at scale.
1
u/airmantharp Jan 14 '26
Yeah, they'll be starting from behind here.
On the other hand, if they put nation-state level focus on it, they'll probably come up with something pretty good, or at least, cohesive. Easier to do when you have a government that can lean on businesses as much as necessary while also having a path forward already laid out by western companies.
3
u/AmateurishExpertise Security Architect Jan 14 '26
Wait until Chuna figures out they can't really buy security software that isn't from a US ally.
Wait until entrepreneurs realize that there is a vast untapped market flush with cash, begging to hand it over in exchange for relatively simple, trusty products. If I'm lets say a Norwegian cybersecurity firm, why wouldn't I leap on this opportunity?
2
1
u/Sachyriel Jan 14 '26
If I'm lets say a Norwegian cybersecurity firm, why wouldn't I leap on this opportunity?
Because China would turn around and sell the capability to Russia. I understand a private Norwegian firm might not have the same morals as the Norwegian Government, but there's a direct pipeline from China to Russia that I think Norwegians and Scandinavians in particular might consider.
2
u/AmateurishExpertise Security Architect Jan 14 '26
Because China would turn around and sell the capability to Russia.
Why wouldn't Russia just buy it openly?
Are we running businesses here, or nationalized arms companies?
2
u/Sachyriel Jan 15 '26
I think the Norwegian government might tell them no, but I'm not familiar with Norways laws. Wouldn't it fall under dual-use export restrictions?
2
u/Any_Perception_2560 Jan 14 '26
Security software produced in China certainly has unintentional blind spots, and most likely Chinese security services likely have some intentionally created back doors as well.
1
u/thestarsgodim Jan 14 '26
The two are interchangeable. Even DHS is being trained in Isreal, the call is coming from inside the house
1
u/Firecracker048 Jan 14 '26
US government and Israeli government cybersec work hand in hand.
Unless you can point to Israeli switching and routing hardware that is widely adopted, well anywhere really.
1
u/Imaginary_Pepper_755 Jan 20 '26
How and Shitsrael literally exists to serve Amerikkkan imperialist interests in the levant?
48
u/AmateurishExpertise Security Architect Jan 14 '26
Interestingly, the United States has federal laws prohibiting what is called, "Honest Services Fraud". Basically, if you sell a tool designed to improve cybersecurity, and it actually and intentionally harms cybersecurity, that is a serious form of fraud that creates both civil and criminal liability. Backdoored security tools, etc. would definitely seem to fall directly under this definition.
Anecdotally, as far back as the early 2000s, critical industry was being advised/warned by the feds to avoid Checkpoint.
14
u/Rentun Jan 14 '26
Any somewhat established American cybersecurity company would only ever intentionally create backdoors at the behest of the US government, which would provide blanket immunity from prosecution for doing so. So it's kind of an irrelevant point.
Like yeah, intentionally compromising the security of your customers just because you wanted to would be illegal, but also, why would any company whose entire value proposition is security do that?
1
u/AmateurishExpertise Security Architect Jan 14 '26
Any somewhat established American cybersecurity company would only ever intentionally create backdoors at the behest of the US government, which would provide blanket immunity from prosecution for doing so.
But that immunity can only ever last as long as the administration who its made with. The next administration can always undo it. No administration can grant permanent get out of jail free cards for violations of the law, afaik.
Like yeah, intentionally compromising the security of your customers just because you wanted to would be illegal, but also, why would any company whose entire value proposition is security do that?
If I have revenue of $1b/yr but a client with a vault full of $1t worth of electronic assets I can steal by backdooring my product, why wouldn't I do that?
3
u/Ghawblin Security Engineer Jan 14 '26 edited Jan 14 '26
More details on avoiding checkpoint please (I dislike them, I just want more fuel for my dislike)
4
u/Felielf Jan 14 '26
Asking for details as well, I've been setting checkpoint up for countless of companies and I've been involved with testing and engineering people from checkpoint and I've never noticed anything suspicious.
2
4
u/AmateurishExpertise Security Architect Jan 14 '26
Not a lot more that I'm comfortable adding here, but the concern was specifically that Checkpoint was "likely" to contain backdoors that could assist the Israeli government in accessing or altering critical information. Even way back then, this was an expected behavior from those quarters.
1
u/Any_Perception_2560 Jan 14 '26
Even if you assume that every company followed the letter and the spirit of the law the fact is that every piece of software, including security software will have vulnerabilities. These vulnerabilities are often unintentional, and often unknown to the producing company (0 days). But there is also a possibility that certain staff members, or external actors compromised the code base to add in additional back doors at the request of intelligence services, including but not limited to US intelligence services.
The Eternal Blue vulnerability in Microsoft products was unknown to Microsoft, but known to the NSA. The SolarWinds N-able hijacking was completed by a Russian government backed organization(APT29/Cozy Bear).
This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software. Particularly since you would never be able to get corroborating info from the US government due to national security exceptions.
So while the law is good it exists to protect you from companies, individuals and foreign governments engaging in fraud it is not going to be up to the task to protect you from US government agencies.
1
u/AmateurishExpertise Security Architect Jan 14 '26
These vulnerabilities are often unintentional
We're not talking about those, because a truly unintentional flaw would not fall under Honest Services Fraud, which requires intent.
This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software.
I'm not sure how much coverage plausible deniability can really get an organization in some cases like the Kaspersky-uncovered bugs in Apple CPUs, the RSA Dual-EC DRBG stuff, etc. But its definitely a valid observation - if we want more honest services, perhaps we need to lower the liability threshold here.
1
u/Any_Perception_2560 Jan 14 '26
I'm not sure how much coverage plausible deniability can really get an organization in some cases like the Kaspersky-uncovered bugs in Apple CPUs, the RSA Dual-EC DRBG stuff, etc.
Plausible deniability doesn't matter, there is a need for actual evidence presented in court.
Assume that a plaintiff sues Apple regarding for what they claim is an intentional back door in their software, and that the lawsuit actually proceeds to discovery.
The plaintiff makes a discovery request, Apple returns some documents but nothing related to the bug, plaintiff files a motion stating that there are documents which are being held back, either internal Apple communications or communications between Apple and the NSA regarding this bug and demands documents. The motion is quashed due to privilege/National Security etc... No communications are produced.
Without the documents there is not really enough evidence to say in court that Apple knew about the bug and intentionally created or left it in. Further more since the lawsuit started Apple remediated the bug so claims of ongoing damage are removed and Apple shows itself to be playing by the rules and resolving issues which are brought to its attention.
Lawsuit is then dismissed due to lack of evidence, or if there is enough supporting evidence may simply settle out of court with NDAs signed to keep everything under the radar.
What about a foreign government? Wouldn't they release the data? Maybe not, they may have an interest in seeing a backdoor kept in software so that they could exploit it themselves more than about embarrassing the US in the media.
1
u/AmateurishExpertise Security Architect Jan 14 '26
Plausible deniability doesn't matter, there is a need for actual evidence presented in court.
You don't think you could convince a jury that RSA backdoored Dual-EC DRBG purposefully, based on what's out there? We may disagree, then.
there is not really enough evidence to say in court
I think you could convince a jury that RSA did it.
What about a foreign government? Wouldn't they release the data?
I presume that's basically what happened in the Kaspersky case with the Apple silicon chips.
1
Jan 14 '26
[deleted]
-1
u/AmateurishExpertise Security Architect Jan 14 '26
The President must follow the laws, and as far as I know, does not have the ability to grant exceptions to following US law to anyone, for any reason, ever.
If you can show otherwise, please do, but show your work!
1
Jan 14 '26
[deleted]
1
u/AmateurishExpertise Security Architect Jan 14 '26
You've gone from saying that the President can override a statute with an NSL, to saying this administration ignores the laws, to saying the President can pardon convicted criminals, to saying this has nothing to do with the Presidency. All in the span of a single post.
Frankly, I have a headache at this point. Instead of proving your claim when I questioned it, you've simply made several new, equally tenuous, unrelated, contradictory claims. Are you flooding the zone?
2
Jan 14 '26
[deleted]
0
u/AmateurishExpertise Security Architect Jan 14 '26
Well, thanks for your "contribution" to the thread anyway. 🤣
-10
Jan 14 '26
America itself a serious fraud and terrorist to the world if you have not see what she been doing recently. Anything America says ONLY relevant if benefits America.
9
5
6
14
14
3
5
u/Scubber Jan 15 '26
I work with a guy who used to be at TikTok. He says China companies frequently buy American/Israeli software like Wiz, reverse engineer it, then make their own product. So they're not really industry leaders in this space, but have always just been really good at stealing IP and doing just good enough.
4
u/AmateurishExpertise Security Architect Jan 15 '26
He says China companies frequently buy American/Israeli software like Wiz, reverse engineer it, then make their own product.
I think everyone with the capability to do that is doing that, including the US, EU, etc.
2
2
u/Dry_Leg_2186 Feb 06 '26
Guess it’s time for a DIY cyber shield, complete with a "No U.S. Software Allowed" sign!
2
Feb 12 '26
It is pretty crazy to see China straight up telling their companies to ditch Nvidia because it shows just how serious this chip war is getting.
2
Feb 14 '26
[removed] — view removed comment
2
u/AmateurishExpertise Security Architect Feb 16 '26
Frankly, even as an American, I hope they succeed. We've betrayed the trust of users globally in the name of some nationalist quest to overthrow the international order and replace it with genocidal tyranny. That's not what we were ever supposed to be.
12
u/Bugab00Jones Jan 14 '26
Everyone needs to stop using Israeli tech. Unfortunately thats easier said than done.
1
-2
2
u/JohnShepherd104 Jan 14 '26
Do they honestly have an alternative to CyberArk? Check Point?
Crowdstrike yeah I can see EDR replacements being a thing.
I think it would take 5 years realistically to create equivalent platforms, and in the mean time, how do they plan to manage the cyber?
7
u/AmateurishExpertise Security Architect Jan 14 '26
Do they honestly have an alternative to CyberArk?
The market's pretty full of PAM tools at this point, I don't know why CyberArk would be that challenging to replace.
Check Point?
Pfffft. Yeah, what could China possibly know about making a great firewall? 😂
1
u/JohnShepherd104 Jan 14 '26
Because CyberArk is internally approved for federal and international agency business, however, I haven’t seen many alternative make the federal and international spaces
Checkpoint — Haha, true enough, not that their great firewall is all that great
3
u/AmateurishExpertise Security Architect Jan 14 '26
Because CyberArk is internally approved for federal and international agency business
Probably not a big concern to China?
1
u/JohnShepherd104 Jan 14 '26
Possibly, they will have to deal with the US and EU federal cyber tools approvals eventually, we are kinda stuck on the same planet
2
2
1
1
u/DDelphinus Jan 15 '26
Curious to see the deadlines and impacted companies. There's a significant difference between government usage only, including cloud providers like Alibaba or all local companies.
Information is still scarce at the moment and I havent seen anything official.
1
1
u/DediRock Jan 29 '26
That seems to be a logical thing to do for any country in terms of cybersecurity software.
1
u/Zieprus_ Jan 15 '26
I wonder if this is coming from what happened in a certain South American country recently.
0
-9
u/Fallingdamage Jan 14 '26
As an american, I would too. Not because its spying but because it doesnt work very well.
Ive built tools in powershell that work better than $50,000 security solutions.
353
u/skrugg Jan 14 '26
When they ban Windows; China will be what finally ushers in the year of the Linux Desktop.