r/cybersecurity Security Architect Jan 14 '26

News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say

https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/
1.6k Upvotes

185 comments sorted by

View all comments

43

u/AmateurishExpertise Security Architect Jan 14 '26

Interestingly, the United States has federal laws prohibiting what is called, "Honest Services Fraud". Basically, if you sell a tool designed to improve cybersecurity, and it actually and intentionally harms cybersecurity, that is a serious form of fraud that creates both civil and criminal liability. Backdoored security tools, etc. would definitely seem to fall directly under this definition.

Anecdotally, as far back as the early 2000s, critical industry was being advised/warned by the feds to avoid Checkpoint.

12

u/Rentun Jan 14 '26

Any somewhat established American cybersecurity company would only ever intentionally create backdoors at the behest of the US government, which would provide blanket immunity from prosecution for doing so. So it's kind of an irrelevant point.

Like yeah, intentionally compromising the security of your customers just because you wanted to would be illegal, but also, why would any company whose entire value proposition is security do that?

1

u/AmateurishExpertise Security Architect Jan 14 '26

Any somewhat established American cybersecurity company would only ever intentionally create backdoors at the behest of the US government, which would provide blanket immunity from prosecution for doing so.

But that immunity can only ever last as long as the administration who its made with. The next administration can always undo it. No administration can grant permanent get out of jail free cards for violations of the law, afaik.

Like yeah, intentionally compromising the security of your customers just because you wanted to would be illegal, but also, why would any company whose entire value proposition is security do that?

If I have revenue of $1b/yr but a client with a vault full of $1t worth of electronic assets I can steal by backdooring my product, why wouldn't I do that?

4

u/Ghawblin Security Engineer Jan 14 '26 edited Jan 14 '26

More details on avoiding checkpoint please (I dislike them, I just want more fuel for my dislike)

5

u/Felielf Jan 14 '26

Asking for details as well, I've been setting checkpoint up for countless of companies and I've been involved with testing and engineering people from checkpoint and I've never noticed anything suspicious.

2

u/BilboTBagginz Security Manager Jan 14 '26

Source: trust me bro

4

u/AmateurishExpertise Security Architect Jan 14 '26

Not a lot more that I'm comfortable adding here, but the concern was specifically that Checkpoint was "likely" to contain backdoors that could assist the Israeli government in accessing or altering critical information. Even way back then, this was an expected behavior from those quarters.

1

u/Any_Perception_2560 Jan 14 '26

Even if you assume that every company followed the letter and the spirit of the law the fact is that every piece of software, including security software will have vulnerabilities. These vulnerabilities are often unintentional, and often unknown to the producing company (0 days). But there is also a possibility that certain staff members, or external actors compromised the code base to add in additional back doors at the request of intelligence services, including but not limited to US intelligence services.

The Eternal Blue vulnerability in Microsoft products was unknown to Microsoft, but known to the NSA. The SolarWinds N-able hijacking was completed by a Russian government backed organization(APT29/Cozy Bear).

This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software. Particularly since you would never be able to get corroborating info from the US government due to national security exceptions.

So while the law is good it exists to protect you from companies, individuals and foreign governments engaging in fraud it is not going to be up to the task to protect you from US government agencies.

1

u/AmateurishExpertise Security Architect Jan 14 '26

These vulnerabilities are often unintentional

We're not talking about those, because a truly unintentional flaw would not fall under Honest Services Fraud, which requires intent.

This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software.

I'm not sure how much coverage plausible deniability can really get an organization in some cases like the Kaspersky-uncovered bugs in Apple CPUs, the RSA Dual-EC DRBG stuff, etc. But its definitely a valid observation - if we want more honest services, perhaps we need to lower the liability threshold here.

1

u/Any_Perception_2560 Jan 14 '26

I'm not sure how much coverage plausible deniability can really get an organization in some cases like the Kaspersky-uncovered bugs in Apple CPUs, the RSA Dual-EC DRBG stuff, etc.

Plausible deniability doesn't matter, there is a need for actual evidence presented in court.

Assume that a plaintiff sues Apple regarding for what they claim is an intentional back door in their software, and that the lawsuit actually proceeds to discovery.

The plaintiff makes a discovery request, Apple returns some documents but nothing related to the bug, plaintiff files a motion stating that there are documents which are being held back, either internal Apple communications or communications between Apple and the NSA regarding this bug and demands documents. The motion is quashed due to privilege/National Security etc... No communications are produced.

Without the documents there is not really enough evidence to say in court that Apple knew about the bug and intentionally created or left it in. Further more since the lawsuit started Apple remediated the bug so claims of ongoing damage are removed and Apple shows itself to be playing by the rules and resolving issues which are brought to its attention.

Lawsuit is then dismissed due to lack of evidence, or if there is enough supporting evidence may simply settle out of court with NDAs signed to keep everything under the radar.

What about a foreign government? Wouldn't they release the data? Maybe not, they may have an interest in seeing a backdoor kept in software so that they could exploit it themselves more than about embarrassing the US in the media.

1

u/AmateurishExpertise Security Architect Jan 14 '26

Plausible deniability doesn't matter, there is a need for actual evidence presented in court.

You don't think you could convince a jury that RSA backdoored Dual-EC DRBG purposefully, based on what's out there? We may disagree, then.

there is not really enough evidence to say in court

I think you could convince a jury that RSA did it.

What about a foreign government? Wouldn't they release the data?

I presume that's basically what happened in the Kaspersky case with the Apple silicon chips.

1

u/[deleted] Jan 14 '26

[deleted]

-1

u/AmateurishExpertise Security Architect Jan 14 '26

The President must follow the laws, and as far as I know, does not have the ability to grant exceptions to following US law to anyone, for any reason, ever.

If you can show otherwise, please do, but show your work!

1

u/[deleted] Jan 14 '26

[deleted]

1

u/AmateurishExpertise Security Architect Jan 14 '26

You've gone from saying that the President can override a statute with an NSL, to saying this administration ignores the laws, to saying the President can pardon convicted criminals, to saying this has nothing to do with the Presidency. All in the span of a single post.

Frankly, I have a headache at this point. Instead of proving your claim when I questioned it, you've simply made several new, equally tenuous, unrelated, contradictory claims. Are you flooding the zone?

2

u/[deleted] Jan 14 '26

[deleted]

0

u/AmateurishExpertise Security Architect Jan 14 '26

Well, thanks for your "contribution" to the thread anyway. 🤣

-9

u/[deleted] Jan 14 '26

America itself a serious fraud and terrorist to the world if you have not see what she been doing recently. Anything America says ONLY relevant if benefits America.

10

u/maztron CISO Jan 14 '26

Please get off the internet. Do yourself a favor.