A Thought on Huawei

John Hemmings made some interesting and critical points about the “security” (my metaphoric quotes) of Huawei equipment.  In doing so, he cited a study by Finite State, a cyber-security organization that looks deeply into the Internet of Things and resulting vulnerabilities—an IoT of which Huawei is aiming to be a central part (as well as a central part of national communications and defense systems and of governments).  Finite State’s analysis investigated “more than 1.5 million files embedded in 9,936 firmware images supporting 558 different products within [Huawei’s] enterprise networking product lines.”

Hemmings’ points center on these:

  • In virtually all categories we studied, we found Huawei devices to be less secure than comparable devices from other vendors.
  • On average, Huawei devices had 102 known vulnerabilities inside their firmware, primarily due to the use of vulnerable open-source and third-party components.
  • Out of all the firmware images analyzed, 55% had at least one potential backdoor.
  • On dozens of occasions, Huawei engineers disguised known unsafe functions (such as memcpy) as the “safe” version (memcpy_s) by creating wrapper functions with the “safe” name but none of the safety checks.
  • Across 356 firmware images, there are several million calls into unsafe functions. Huawei engineers choose the “safe” option of these functions less than 17% of the time, despite the fact that these functions improve security and have existed for over a decade.
  • Huawei devices had…2-8x more potential 0-day vulnerabilities than the other devices.
  • Vulnerabilities in both the routers and the fixed access network remained beyond 2012 and were also present in Vodafone’s businesses in the U.K., Germany, Spain and Portugal.

Those vulnerabilities? Given how enthusiastically Huawei’s representatives tout the superiority of their equipment, and given that fourth bullet, I suggest that those vulnerabilities also are known to Huawei’s men and put there deliberately.

And that last bullet: Vodafone had identified those “vulnerabilities” to Huawei in 2011 and received assurances from Huawei that they’d be removed.  Those security holes remained far past 2012.  And still remain as far as I can tell.

This is why Huawei has no legitimate place in any organization outside of the People’s Republic of China, nor should it have access to any technology of any nation or business outside of the PRC.

But Huawei’s CEO, Ren Zhengfei, and CFO, Meng Wanzhou, and men of the PRC’s government, like President Xi Jinping, deny all of this. And Ren is an honorable man; So are they all, all honorable men.

A Continued Power Grab

The People’s Republic of China objects to the sale of defensive weapons to the Republic of China.

China will sanction US firms that participate in arms sales to Taiwan [The Wall Street Journal‘s conflation of the island with the nation that sits on the island], after Washington approved sales of $2.2 billion in tanks, missiles and related military hardware, Beijing said.

The PRC’s Foreign Ministry has justified the threat with this:

the arms sales “harmed China’s sovereignty and national security”

Of course, it does no harm to the PRC’ sovereignty to sell weapons to a sovereign nation.  Of course it does no harm to the PRC’s national security to sell defensive weapons to a sovereign nation that’s so much smaller than the PRC.

All the sale does is increase a sovereign nation’s ability to defend itself against the aggression, the threats of invasion, which the PRC has so repeatedly leveled against that sovereign nation.  If the PRC has no such aggressive intent, it has nothing to fear from the sale.

The PRC’s moves would be nonsensical, did they not amount to such a cynical and naked and continued grab for power.

Joe Biden’s Foreign Policy

Last Thursday, Progressive-Democratic Party Presidential candidate Joe Biden laid out his foreign policy paradigm.  The gist of his policy is this:

[The] overarching purpose of our foreign policy, I believe, must be to defend and advance our security, prosperity, and democratic values that the United States stands for.

And

I would remind the world that we are the United States of America and we do not coddle dictators. The United States of America gives hate no safe harbor.

And he’ll

make it my mission to restore American leadership….

In fine, Biden’s foreign policy is to Make America Great Again.

The Cost of a Celebration

President Donald Trump held America’s Independence Day celebration with a Salute to America, centered at the Lincoln Memorial.

Together, we are part of one of the greatest stories ever told—the story of America.  Today, just as it did 243 years ago, the future of American Freedom rests on the shoulders of men and women willing to defend it.

Just to pick out a couple of things: The Wall Street Journal cited “Democrats” complaining about

the use of military hardware for a traditionally nonpartisan celebration.

Because defending our nation’s existence and celebrating those who do that defense isn’t nonpartisan.  Sure.

And this one:

The Pentagon has said it wouldn’t have cost estimates until next week at the earliest.

I have some estimates now—not on the costs of the military units’ performances, but on those costs unique to their participation in the Salute to America celebration.

The aircraft—and their pilots—used consisted of

B-2 stealth bomber
F-35 Joint Strike Fighter
F-22 Raptor
F/A-18 Hornet
Air Force One
Marine One

Their cost that’s unique to the celebration is a good approximation of zero.  Those sorties flown—every single one of them—count as nav currency sorties and formation-keeping currency sorties, and they are a direct substitute for sorties that otherwise would have to be flown as part of any pilot’s currency training.  Furthermore, the fuel and maintenance resulting from the sorties also are already accounted for in those required currency sorties.

M1 Abrams tanks
M2 Bradley Fighting Vehicles

Here, the costs will be somewhat incremental, but some—the transport part—will count for existing currency requirements, similarly to the aircraft costs.

The incremental costs just aren’t that great.

A Whole Year

That’s how close Iran is to getting a nuclear weapon.  The Wall Street Journal‘s subheadline tells the tale.

Tehran exceeded a key limit in the 2015 deal but experts say that it is only a small step and that it would take Tehran at least a year to make a weapon

That’s how far away from nuclear armament Iran would have been under the JCPOA on that deal’s expiration.  After all,

The 2015 deal was structured to make sure that Iran would take a year to amass enough material for a weapon if it chose to break the accord.

A whole year.