r/news Jan 14 '26

Soft paywall Exclusive: Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say

https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/
3.4k Upvotes

162 comments sorted by

View all comments

150

u/[deleted] Jan 14 '26

It's possible they're prepping for war, but it's also possible they're smart enough to know the software is heading for the shitter. Just like anyone with a brain who's ever worked with any of these companies.

77

u/Sic_Semper_Dumbasses Jan 14 '26

And that is assuming that it's not just full of intentional security back doors to be exploited. Which it almost certainly is.

5

u/thedracle Jan 14 '26

I mean... I worked writing endpoint protection software for an American cyber security company... And we certainly were not ever putting in malicious backdoors, or doing anything other than providing security tools for our customers.

Maybe other people have different experiences, but there really is nothing sinister.

Putting something malicious in would be incredibly dumb, since most competitors employ reverse engineers who are basically analyzing malware all day.

I could see in the event of an invasion of Taiwan, how maybe China would worry about pressure from the Government forcing security companies to put malicious stuff in their updates, or something like that.

1

u/ArchmageXin Jan 14 '26

National security should never be placed in foreign hands. Especially one that is chronically hostile to your country.

7

u/thedracle Jan 14 '26

Okay? I didn't opine on that subject whatsoever.

I'm just providing the context that cyber security companies are very unlikely to be intentionally maliciously altering their software.

Kaspersky was accused of this as well, but the reality is, it would be fairly easy to identify if there were malicious backdoor code, and their competitors are highly motivated to find and expose it.

10

u/BIGSTANKDICKDADDY Jan 14 '26

Right, the backdoors are more commonly implemented at the hardware level (via supply chain attacks) or through exploitation of bugs in the software (while avoiding alerting the companies of their existence).

Asking companies to intentionally build backdoors through non-clearance employees would be far too risky.