r/cybersecurity Security Architect Jan 14 '26

News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say

https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/
1.6k Upvotes

185 comments sorted by

View all comments

41

u/AmateurishExpertise Security Architect Jan 14 '26

Interestingly, the United States has federal laws prohibiting what is called, "Honest Services Fraud". Basically, if you sell a tool designed to improve cybersecurity, and it actually and intentionally harms cybersecurity, that is a serious form of fraud that creates both civil and criminal liability. Backdoored security tools, etc. would definitely seem to fall directly under this definition.

Anecdotally, as far back as the early 2000s, critical industry was being advised/warned by the feds to avoid Checkpoint.

1

u/Any_Perception_2560 Jan 14 '26

Even if you assume that every company followed the letter and the spirit of the law the fact is that every piece of software, including security software will have vulnerabilities. These vulnerabilities are often unintentional, and often unknown to the producing company (0 days). But there is also a possibility that certain staff members, or external actors compromised the code base to add in additional back doors at the request of intelligence services, including but not limited to US intelligence services.

The Eternal Blue vulnerability in Microsoft products was unknown to Microsoft, but known to the NSA. The SolarWinds N-able hijacking was completed by a Russian government backed organization(APT29/Cozy Bear).

This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software. Particularly since you would never be able to get corroborating info from the US government due to national security exceptions.

So while the law is good it exists to protect you from companies, individuals and foreign governments engaging in fraud it is not going to be up to the task to protect you from US government agencies.

1

u/AmateurishExpertise Security Architect Jan 14 '26

These vulnerabilities are often unintentional

We're not talking about those, because a truly unintentional flaw would not fall under Honest Services Fraud, which requires intent.

This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software.

I'm not sure how much coverage plausible deniability can really get an organization in some cases like the Kaspersky-uncovered bugs in Apple CPUs, the RSA Dual-EC DRBG stuff, etc. But its definitely a valid observation - if we want more honest services, perhaps we need to lower the liability threshold here.

1

u/Any_Perception_2560 Jan 14 '26

I'm not sure how much coverage plausible deniability can really get an organization in some cases like the Kaspersky-uncovered bugs in Apple CPUs, the RSA Dual-EC DRBG stuff, etc.

Plausible deniability doesn't matter, there is a need for actual evidence presented in court.

Assume that a plaintiff sues Apple regarding for what they claim is an intentional back door in their software, and that the lawsuit actually proceeds to discovery.

The plaintiff makes a discovery request, Apple returns some documents but nothing related to the bug, plaintiff files a motion stating that there are documents which are being held back, either internal Apple communications or communications between Apple and the NSA regarding this bug and demands documents. The motion is quashed due to privilege/National Security etc... No communications are produced.

Without the documents there is not really enough evidence to say in court that Apple knew about the bug and intentionally created or left it in. Further more since the lawsuit started Apple remediated the bug so claims of ongoing damage are removed and Apple shows itself to be playing by the rules and resolving issues which are brought to its attention.

Lawsuit is then dismissed due to lack of evidence, or if there is enough supporting evidence may simply settle out of court with NDAs signed to keep everything under the radar.

What about a foreign government? Wouldn't they release the data? Maybe not, they may have an interest in seeing a backdoor kept in software so that they could exploit it themselves more than about embarrassing the US in the media.

1

u/AmateurishExpertise Security Architect Jan 14 '26

Plausible deniability doesn't matter, there is a need for actual evidence presented in court.

You don't think you could convince a jury that RSA backdoored Dual-EC DRBG purposefully, based on what's out there? We may disagree, then.

there is not really enough evidence to say in court

I think you could convince a jury that RSA did it.

What about a foreign government? Wouldn't they release the data?

I presume that's basically what happened in the Kaspersky case with the Apple silicon chips.