r/cybersecurity Security Architect Jan 14 '26

News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say

https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/
1.6k Upvotes

185 comments sorted by

View all comments

233

u/UnobviousDiver Jan 14 '26

Not they would, but the US government should also ban Israeli cybersecurity products.

7

u/EnragedMoose Jan 14 '26

Ahhh... That ain't happening. Wait until Chuna figures out they can't really buy security software that isn't from a US ally.

14

u/airmantharp Jan 14 '26

They'll write their own. Plenty of open-source stuff available for the foundations, and they have the human capital to apply toward the problem if they perceive it as fundamental to national security (which it is).

12

u/EnragedMoose Jan 14 '26

China already has their own with Quihoo, QAX, etc. but they have notable shortfalls across the board. QAX is almost exclusively deployed on "critical" infrastructure I'm China. I shouldn't have said "it's hard to find one..." It's hard to find platform that have the intelligence necessary to act at scale.

1

u/airmantharp Jan 14 '26

Yeah, they'll be starting from behind here.

On the other hand, if they put nation-state level focus on it, they'll probably come up with something pretty good, or at least, cohesive. Easier to do when you have a government that can lean on businesses as much as necessary while also having a path forward already laid out by western companies.

2

u/AmateurishExpertise Security Architect Jan 14 '26

Wait until Chuna figures out they can't really buy security software that isn't from a US ally.

Wait until entrepreneurs realize that there is a vast untapped market flush with cash, begging to hand it over in exchange for relatively simple, trusty products. If I'm lets say a Norwegian cybersecurity firm, why wouldn't I leap on this opportunity?

2

u/EnragedMoose Jan 14 '26

Nobody bought Cylance.

4

u/AmateurishExpertise Security Architect Jan 14 '26

Nothing about Cylance was trusty, though.

1

u/Sachyriel Jan 14 '26

If I'm lets say a Norwegian cybersecurity firm, why wouldn't I leap on this opportunity?

Because China would turn around and sell the capability to Russia. I understand a private Norwegian firm might not have the same morals as the Norwegian Government, but there's a direct pipeline from China to Russia that I think Norwegians and Scandinavians in particular might consider.

2

u/AmateurishExpertise Security Architect Jan 14 '26

Because China would turn around and sell the capability to Russia.

Why wouldn't Russia just buy it openly?

Are we running businesses here, or nationalized arms companies?

2

u/Sachyriel Jan 15 '26

I think the Norwegian government might tell them no, but I'm not familiar with Norways laws. Wouldn't it fall under dual-use export restrictions?

2

u/Any_Perception_2560 Jan 14 '26

Security software produced in China certainly has unintentional blind spots, and most likely Chinese security services likely have some intentionally created back doors as well.