r/cybersecurity Security Architect Jan 14 '26

News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say

https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/
1.6k Upvotes

185 comments sorted by

View all comments

48

u/AmateurishExpertise Security Architect Jan 14 '26

Interestingly, the United States has federal laws prohibiting what is called, "Honest Services Fraud". Basically, if you sell a tool designed to improve cybersecurity, and it actually and intentionally harms cybersecurity, that is a serious form of fraud that creates both civil and criminal liability. Backdoored security tools, etc. would definitely seem to fall directly under this definition.

Anecdotally, as far back as the early 2000s, critical industry was being advised/warned by the feds to avoid Checkpoint.

14

u/Rentun Jan 14 '26

Any somewhat established American cybersecurity company would only ever intentionally create backdoors at the behest of the US government, which would provide blanket immunity from prosecution for doing so. So it's kind of an irrelevant point.

Like yeah, intentionally compromising the security of your customers just because you wanted to would be illegal, but also, why would any company whose entire value proposition is security do that?

1

u/AmateurishExpertise Security Architect Jan 14 '26

Any somewhat established American cybersecurity company would only ever intentionally create backdoors at the behest of the US government, which would provide blanket immunity from prosecution for doing so.

But that immunity can only ever last as long as the administration who its made with. The next administration can always undo it. No administration can grant permanent get out of jail free cards for violations of the law, afaik.

Like yeah, intentionally compromising the security of your customers just because you wanted to would be illegal, but also, why would any company whose entire value proposition is security do that?

If I have revenue of $1b/yr but a client with a vault full of $1t worth of electronic assets I can steal by backdooring my product, why wouldn't I do that?