Remix.run Logo
LoganDark 15 hours ago

This makes me wonder if we've ever had any evidence that "onshore manufacturing" prevents or even lessens foreign backdoors or security vulnerabilities. Honestly, to me it seems like onshore manufacturers are generally far more clueless than they have any right to be, so it's highly unlikely that they could both write materially better code and act as any meaningful barrier to internal compromise.

hn_submit 13 hours ago | parent | next [-]

Apple is a case in point. It designs and engineers everything and stringently checks that its Chinese ODMs aren't quietly swapping in cheaper inferior parts or alter its software. I therefore assume Apple products are safe even though they're manufactured in China.

But the fact is that most Western manufacturers are too lazy to develop things themselves and merely slap their label on a Chinese designed and manufactured product. This means that the Chinese could slip in anything in the hard/software which creates a huge security liability.

LoganDark 12 hours ago | parent [-]

> Apple is a case in point. It designs and engineers everything and stringently checks that its Chinese ODMs aren't quietly swapping in cheaper inferior parts or alter its software. I therefore assume Apple products are safe even though they're manufactured in China.

Absolutely. I trust Apple a lot more than I trust almost any other company. Maybe Valve is up there as well.

> But the fact is that most Western manufacturers are too lazy to develop things themselves and merely slap their label on a Chinese designed and manufactured product. This means that the Chinese could slip in anything in the hard/software which creates a huge security liability.

Well, the problem here would be a Chinese entity being required to create a US entity, which often just ends up with the US entity inheriting everything, including the slips, from the Chinese entity.

cingraa 15 hours ago | parent | prev [-]

"foreign backdoors" and "security vulnerabilities". Both are an worn-out excuse, not some real concern.

Gaslighting as a policy.

LoganDark 13 hours ago | parent | next [-]

I'm sure most people who've ever said it were not talking about actual cases, only decoy reasons to get people worried about it and justify actions about it. But both things do exist: foreign backdoors (https://www.youtube.com/watch?v=lA8WuXDXfcI) and security vulnerabilities (too many router, smart TV, streaming box etc. botnets to count). Not to mention the backdoors and security vulnerabilities that aren't foreign (e.g. Tesla vehicles).

But I think both such things talked about in this announcement are complete bullshit, yes

fhub 14 hours ago | parent | prev [-]

[dead]