Remix.run Logo
szatkus 4 hours ago

MediaTek is a Taiwanese company. Xiaomi could put any backdoor that the government tell them to install and TSMC won't be able to catch that.

linkregister 3 hours ago | parent | next [-]

I'm unaware of any actual hardware backdoors introduced by primary manufacturers in practice, especially those installed in Xiaomi hardware.

There are accounts of interdiction and post-manufacturing compromises, such as those revealed in the Snowden leaks (2013) and most recently by reporting about the Israeli security services' sabotage of Hezbollah pagers and 2-way radios. These projects didn't expose primary manufacturers to the reputational and legal risk of association.

Until there's evidence of backdoors implanted by these companies, it's better to adopt a "trust but verify" approach and use standard layered security practices to detect intrusion. Conventional network intrusion and insider threat campaigns carry less risk of failure and are simpler and cheaper to execute.

szatkus 43 minutes ago | parent | next [-]

I'm only aware of some software backdoors in Chinese devices, but times when you could've reverse engineered a chip with microscope are long gone. If there are any it would be really difficult to find them.

codersfocus 3 hours ago | parent | prev | next [-]

Intel management engine

antonvs 2 hours ago | parent [-]

“It’s not a vulnerability, it’s a feature!”

sundbry 3 hours ago | parent | prev | next [-]

[flagged]

RiverCrochet 3 hours ago | parent | next [-]

Get off the short bus twin. CPU backdoors do no good unless there is cooperation with network driver code or the CPU itself has full operating system with a full network stack.

Intel's ME comes really close to that, but I don't think Intel's ME has drivers for every possible NIC and bus a NIC can appear on in its little Minix. So, just put a Broadcom NIC in a PCIe slot and leave the Intel onboard NIC empty, or LAN facing only.

Xiaomi may get Chinese 4G/5G baseband chip manufacturers to put in backdoors in Chinese phones, but they're not needed - the Chinese government pretty much already has total control of its Internet. For other countries, how are they going to make Qualcomm provide something undocumented CPU instructions can access.

qmr 3 hours ago | parent | prev | next [-]

You can refute their statement without personal attacks.

Not knowing a thing makes someone uninformed, not retarded.

linkregister 3 hours ago | parent | prev [-]

My retardation status is unrelated to my statement. You assert there are top secret register values but without any evidence beyond your most recent psilocybin trip.

The existence of undocumented hardware behavior isn't proof of anything.

theteapot 2 hours ago | parent | prev [-]

Everyone relax. This guy on the Internet is unaware of any.

Dylan16807 2 hours ago | parent [-]

And are you aware of any? If nobody can find evidence then it's probably not a widespread risk.

Dah00n 4 hours ago | parent | prev | next [-]

Do you say the same about Intel, Amd, etc. or is it only big bad China?

InTheArena 3 hours ago | parent | next [-]

There's been 40 years of documented push back when western governments try to backdoor things - starting with clipper. Pushback is not always successful - but it's far more transparent then China.

linkregister 3 hours ago | parent | next [-]

Are there any documented cases of backdoors being present in Chinese hardware at time of manufacturing?

hedora 3 hours ago | parent | next [-]

Probably, but you are asking the wrong question: Is it legal to produce non-backdoored networked devices or services in China?

The answer to that question in the US is within epsilon of “no” thanks to the cloud act.

Europe and China have passed similar laws. However, China has a reputation for passing laws then selectively enforcing them. Maybe if you get on the right side of the right party member, the answer might still be “Yes” there.

Anyway, the next question to ask is: Who would I rather backdoor my device?

I doubt the Chinese government cares much about me, and unless I vacation there it’s an international incident if they, say, hack my car and murder me by aiming it at a tree at 95mph, like the CIA apparently does now:

https://www.motor1.com/news/138679/wikileaks-claim-cia-hack-...

Of course, the US government banned cars from China. Presumably this is because they do not have the mandated remote murder network port open, or, if they do, the US doesn’t have the necessary permissions to access it.

bryant 3 hours ago | parent | prev [-]

Two just this year, CVE-2026-66747 and CVE-2026-11405.

linkregister 3 hours ago | parent [-]

Those are both great examples. I think this doesn't obliterate my point, though it weakens it. The manufacturer in CVE-2026-11405 is already out of business, and the one in CVE-2026-66747 is unlikely to continue as a going concern.

Would Xiaomi or the CCP accept the reputational and legal risk of getting caught with a backdoor? Recall the CCP considered the arrest of the Huawei executive in Canada as an offense against itself.

holoduke 3 hours ago | parent | prev [-]

Too many propoganda leads to expressions like yours. Sorry your story has zero foundation and is fox news quality.

hedora 3 hours ago | parent [-]

Like a stopped clock, Fox News is right once or twice a day.

For instance election tampering in the US is a well-documented thing: However it almost always favors republicans in districts with electronic voting machines that do not generate paper trails.

As for the person you are replying to, their claims have been documented by most media outlets, places like wikileaks, and their claims are backed by US legal requirements to backdoor stuff (like the US Cloud act).

szatkus 38 minutes ago | parent | prev [-]

My opinion about Trump is as bad as the next guy's, but we still have better relation with the USA than with China. And it's not like we have much choice.

BiteCode_dev 4 hours ago | parent | prev | next [-]

There are already American backdoors on intel and AMD chips everywhere, we call them ME and PSP. Switching to chinese tech won't make it worse.

Now, if the EU would start make to make chips that have no subsystem to screw me over, that would be something.

graemep 3 hours ago | parent | next [-]

> Now, if the EU would start make to make chips that have no subsystem to screw me over, that would be something.

Why would they not do the same? They are very pro-surveillance for a start.

tensor 3 hours ago | parent [-]

Hopefully the same pushback that has so far stopped the worst of chat control would help. But even if not having more western alternatives would be very welcome. If you're in the US it may not resonate with you, but as a Canadian currently reading ongoing rhetoric about being annexed by the US I'd love to have options if things continue to go south with the status quo.

eigenform 44 minutes ago | parent | prev [-]

It's good to be skeptical about how we implement the idea of a "root of trust" in these machines, but matter-of-factly characterizing ME and PSP as "backdoor" is misleading and not useful.

well_ackshually 3 hours ago | parent | prev [-]

TSMC doesn't care what you put in your CPUs. Apple could tell them they want to build a CPU where 90% of the transistor footprint is for a new CIA Engine that takes pictures of your feet every three seconds to trace where you've been from the smell and TSMC's response would be "how many wafers do you want?".