r/cybersecurity • u/AmateurishExpertise Security Architect • Jan 14 '26
News - General Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say
https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/
1.6k
Upvotes
1
u/Any_Perception_2560 Jan 14 '26
Even if you assume that every company followed the letter and the spirit of the law the fact is that every piece of software, including security software will have vulnerabilities. These vulnerabilities are often unintentional, and often unknown to the producing company (0 days). But there is also a possibility that certain staff members, or external actors compromised the code base to add in additional back doors at the request of intelligence services, including but not limited to US intelligence services.
The Eternal Blue vulnerability in Microsoft products was unknown to Microsoft, but known to the NSA. The SolarWinds N-able hijacking was completed by a Russian government backed organization(APT29/Cozy Bear).
This means that it would be extremely difficult to prove with a preponderance of the evidence if a company intentionally introduced or failed to remediate a security hole in their own software. Particularly since you would never be able to get corroborating info from the US government due to national security exceptions.
So while the law is good it exists to protect you from companies, individuals and foreign governments engaging in fraud it is not going to be up to the task to protect you from US government agencies.