Cisco’s Attempt to Dodge Responsibility for Facilitating Human Rights Abuses(eff.org)
eff.org
Cisco’s Attempt to Dodge Responsibility for Facilitating Human Rights Abuses
https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-dodge-responsibility-facilitating-human-rights-abuses-export
15 comments
I think the term is "criminal".
It's not criminal. It could and should be outlawed, but hasn't been.
> It could and should be outlawed, but hasn't been.
I respect your opinion greatly. Why do you disagree with the EFF's assertion that Cisco's actions violate the Alien Tort Statue (the "ATS") [1]?
If Cisco knew, or should have reasonably known, that the technologies they were developing for the Chinese government would be used in contravention of the United Nations Convention Against Torture [2], which the U.S. ratified and would thus be covered under the ATS, then it would seem like this would fall under "aiding and abetting.
[1] https://www.law.cornell.edu/uscode/text/28/1350 28 U.S.C. § 1350
[2] https://en.wikipedia.org/wiki/United_Nations_Convention_agai...
I respect your opinion greatly. Why do you disagree with the EFF's assertion that Cisco's actions violate the Alien Tort Statue (the "ATS") [1]?
If Cisco knew, or should have reasonably known, that the technologies they were developing for the Chinese government would be used in contravention of the United Nations Convention Against Torture [2], which the U.S. ratified and would thus be covered under the ATS, then it would seem like this would fall under "aiding and abetting.
[1] https://www.law.cornell.edu/uscode/text/28/1350 28 U.S.C. § 1350
[2] https://en.wikipedia.org/wiki/United_Nations_Convention_agai...
I agree with the EFF. The Alien Tort Statute recognizes civil claims. They should lose the civil trial.
Separately, we should pass a federal law outlawing the knowing sale of technology for the purpose of persecuting groups of people based on their race/ethnicity/religion. Once that law exists, it will be a crime to do what Cisco did, and I'll be happy about that.
Until then, discussing what Cisco did as "criminal" is dangerous. It should be harder to stretch our existing laws to make criminal cases, not easier.
Separately, we should pass a federal law outlawing the knowing sale of technology for the purpose of persecuting groups of people based on their race/ethnicity/religion. Once that law exists, it will be a crime to do what Cisco did, and I'll be happy about that.
Until then, discussing what Cisco did as "criminal" is dangerous. It should be harder to stretch our existing laws to make criminal cases, not easier.
> we should pass a federal law outlawing the knowing sale of technology for the purpose of persecuting groups of people based on their race/ethnicity/religion.
If it had any teeth, such a law would do serious damage to the US arms exports industry.
If it had any teeth, such a law would do serious damage to the US arms exports industry.
Once that law exists, it will be a crime to do what Cisco did, and I'll be happy about that.
Until then, discussing what Cisco did as "criminal" is dangerous. It should be harder to stretch our existing laws to make criminal cases, not easier.
Are you at all familiar with the current U.S. laws and how they are effectively applied? Does RICO ring any bells? Al Capone vs. IRS, perhaps?This sort of thing has been illegal for a while, so long as you're not considered too powerful to prosecute...
> > It's not criminal. It could and should be outlawed, but hasn't been.
>
> I respect your opinion greatly.
FWIW tptacek INAL, AFAIKConspiracy to commit murder/torture is indeed illegal.
Words mean things. When you draw wild connections like these, you endorse the notion that society should be governed by the moral feelings of citizens and not by laws. That may feel good in the moment, but I guarantee you that in the long run, it's people like you and I who will suffer the most if that worldview prevails.
Conspiracy to assist the unethical law enforcement operations of another country is not, in fact, a crime in the US. I wish it were. But to be guilty of a crime, it has to be a crime when you commit it. It doesn't work retroactively --- that's one of the first safeguards against despotism the founders came up with.
Conspiracy to assist the unethical law enforcement operations of another country is not, in fact, a crime in the US. I wish it were. But to be guilty of a crime, it has to be a crime when you commit it. It doesn't work retroactively --- that's one of the first safeguards against despotism the founders came up with.
It's not a wild connection; conspiracy in the US to aid murder/torture abroad is currently a violation of US law.
Couching it in "unethical law enforcement operations" doesn't really change the fact of the matter, does it?
Couching it in "unethical law enforcement operations" doesn't really change the fact of the matter, does it?
I'm assuming you're trying to convince the rest of the thread, and not me. I think what Cisco did here was repellant and that they richly deserve to lose the civil suit against them, but I also thinking trying to twist criminal law to specifically target the villain of the moment is a terrible idea that will backfire, badly.
We have laws against paying bribes, even when they are lawyered into legal-ishness in a foreign country.
It is far from clear-cut that when US corporations assist regimes where the US officially has serious problems with their human rights record, that laws against torture and other human rights violations would not apply to those enabling and assisting those violations. Some law enforcement operations are not merely unethical, or "different" from those that are legal here.
It is far from clear-cut that when US corporations assist regimes where the US officially has serious problems with their human rights record, that laws against torture and other human rights violations would not apply to those enabling and assisting those violations. Some law enforcement operations are not merely unethical, or "different" from those that are legal here.
What's your point? Selling surveillance equipment to China doesn't violate the FCPA.
Are you arguing that we should pass another act, like the FCPA, that criminalizes the knowing and deliberate sale of technologies that will be used to harm people in violation of the UDHR? I'm right there with you.
Are you arguing that we should pass another act, like the FCPA, that criminalizes the knowing and deliberate sale of technologies that will be used to harm people in violation of the UDHR? I'm right there with you.
You are that sure there are no ITAR bad guys using the GFW to find dissindents.
What's an "ITAR bad guy"?
There is a list of individuals and organizations you can't sell to directly or indirectly.
Ah, that makes sense. But now we're talking about crimes that are more or less unrelated to what EFF is accusing them of.
The general accusation is that the GFW is part of China's security apparatus and that there are enough legal restrictions on selling the tools of oppression that Cisco should not have done it, even if they got away with it. Any cursory DD on who might use the GFW, and for what, would result in backing off selling it. They didn't want to look. It is very difficult to see Cisco being regulatorily and possibly criminally in the clear on building the GFW. It is directly analogous to selling the batons with which to beat protesters and being shocked, shocked! when it happens.
Don't forget that China has a "50-cent army": http://www.rfa.org/english/news/china/propaganda-03122014184...
And the "Citizen Score": https://www.aclu.org/blog/free-future/chinas-nightmarish-cit...
Which is aking of FB/GOOG collecting metadata of your activities and having "paid likes", but being used in a more specific and direct way.
Which is aking of FB/GOOG collecting metadata of your activities and having "paid likes", but being used in a more specific and direct way.
If they're doing this for China, what do you figure they've been doing for the US government?
You mean apart from the fact that the US Government doesn't operate a "Great Firewall of the United States"?
No, but what if there is some sort of NSA backdoor? I have no evidence of one, but if they're willing to build special hardware for another country's secret police, why not?
That's a legit question. If you'll design software specifically to help China persecute a religion, it's hard to imagine pushing back too hard on a lawful request from your own government.
Walls are so passé. Panopticons have been the modern way to keep people in check since sometime back in the 18th/19th Century in Europe. After all, when you have nothing to hide, you are nothing to fear...
You're suggesting that there are straightforward comparisons to be drawn between the Communist Party of China and the United States Government?
That sounds like something that's especially fun to argue on an Internet message board and not all that illuminating anywhere else.
That sounds like something that's especially fun to argue on an Internet message board and not all that illuminating anywhere else.
Just a moment ago you argued that China is a nation of laws and Cisco didn't break them, so they are not criminals. Now you question the ability to make "straightforward comparisons." Which is it? Or are we getting at the essence of American exceptionalism here?
I did not claim that China is a nation of laws. But even if I had, I still wouldn't understand this objection. Could you try to make it clearer?
> You mean apart from the fact that the US Government doesn't operate a "Great Firewall of the United States"?
So, basically you're saying that even though Cisco has shown a willingess to work with a corrupt government in China, that willingness to work with corruption does not translate to the US, simply because the US doesn't run a 'great firewall'?
So, basically you're saying that even though Cisco has shown a willingess to work with a corrupt government in China, that willingness to work with corruption does not translate to the US, simply because the US doesn't run a 'great firewall'?
The NSA would rather collect data ;)
But there is some blocking. It's mostly been DNS poisoning, against "piracy" and such. I don't recall specifics, but at times there have been sites that were reachable with IP addresses, but not using public DNS servers. There have been, for example, Firefox plug-ins with hard-coded lookups.
But there is some blocking. It's mostly been DNS poisoning, against "piracy" and such. I don't recall specifics, but at times there have been sites that were reachable with IP addresses, but not using public DNS servers. There have been, for example, Firefox plug-ins with hard-coded lookups.
Doesn't it? It is just transparent and the traffic shaping is self enforced.
No, it doesn't.
I sincerely thank you for pushing back on all the crap in this particular thread. HN seems to have devolved in to "well the world SHOULD work the way I want it to" recently, and you're doing sterling work here being the voice of reason.
You ate correct of course. Five eyes is not a firewall. Tapping into fibre optics, spying on civilian satellite communications, and keeping tabs on everyone's phone calls, emails and web browsing s not a firewall either.
But it is an invalid comparison snce it isn't the GFW that is gettng people killed, it's the packet inspection and traffic monitoring.
But it is an invalid comparison snce it isn't the GFW that is gettng people killed, it's the packet inspection and traffic monitoring.
That's not a firewall any more than a river is a damn.
Of course, there are many much more subtle and effective ways to stifle free speech and human rights than a big firewall which can easily be circumvented with a VPN. MITM attacks, botnet troll armies, astroturfing, etc. etc. Good luck finding proof of that though.
"I can't find proof of this, therefore it must be happening" is very popular message board logic.
> "I can't find proof of this, therefore it must be happening" is very popular message board logic.
It's also not what they said, at all. If anything, you could say they argued it might be happening because it's more effective.
From seeing the things people and companies do openly, from marketing to politics, I see no reason to believe that moral qualms is what would keep them from doing more. And while I don't know about MITM attacks, that seems like something that would be done on an individual basis; as for astroturfing and "troll armies", the logic is rather "if it makes sense, works, is cheap, has been reported on multiple times, then yeah, it's probably happening", at least for me, can't speak for the other poster.
And is anyone honestly debating that
> there are many much more subtle and effective ways to stifle free speech and human rights than a big firewall
is true? Because refuting a straw man is not the same thing.
And here too I'm sure I could find reading material if required, I'm sure. From the candid beginnings of marketing and public relations to all sorts of musings, short stories and probably even Star Trek episodes about how a prison you can see, one you know you're in, is much less insidious and effective than one where you think you're free, where you never try the door or don't even realize there is one. I remember a short story in my 8th grade textbook or something that was about a prison without walls. You can say and do what you want, sure, and you think you came up with what you want all by yourself, too, it's just you didn't. That's the general idea.
Walls, like murder, are just very crude tools, they are not the zenith of oppression and exploitation. If you see huge concentrations of power, skepticism is always warranted. How could there be smoke without fire? It doesn't prove anything, sure, and even if I could prove that "there has to be a fire", then that doesn't make any wild fantasies about the nature of it correct. But still, to muse about causes one can't prove (yet) seems a lot less foolish than to for example say "oh look, a huge blob of smiling friendly power, it just has to be everything it says on the tin". I'd rather be wrong about something I investigated for the right reasons, than guess right by sheer dumb luck.
But personally I prefer to think of useful ways that would also nip some fires in the bud anyway. I don't need to know if we are being manipulated, I know critical thought is required and I know group think can be dangerous even when not manipulated, which it is so readily. So why not catch one real and one potential bird with one stone that is obligatory? I don't know how much of a problem global warming is, but I know that renewable energies are a good idea regardless, at "worst" we simply get to use fossil fuels for more plastic and fertilizer rather than burning them. I don't know how many people the planet can sustain, but I know something that needs to grow to not collapse cannot work on a finite planet, and that we need to rethink that at least until we get out of the solar system and split up into a gazillion humanities that will do whatever. I don't need to know if someone is trying to guess my password, I simply generate a long random one anyway. And so on.
Likewise, I don't know if there will ever be the kind of oppressive societies here and where you are that were the norm throughout history and are still plentiful in the world, and I can't prove the exact levels of fuckery we are under right now, much less my idle suspicion that the West might fall get phased out in favour of the Chinese model -- but I still strive to be the best and most free I can be. Certain things should not be a response to pressure from the outside, they should be growing anyway. If there is nothing on the outside trying to opppress, everybody is happy. If there is, it gets to pop, and everybody who matters is happy. Win/win?
It's also not what they said, at all. If anything, you could say they argued it might be happening because it's more effective.
From seeing the things people and companies do openly, from marketing to politics, I see no reason to believe that moral qualms is what would keep them from doing more. And while I don't know about MITM attacks, that seems like something that would be done on an individual basis; as for astroturfing and "troll armies", the logic is rather "if it makes sense, works, is cheap, has been reported on multiple times, then yeah, it's probably happening", at least for me, can't speak for the other poster.
And is anyone honestly debating that
> there are many much more subtle and effective ways to stifle free speech and human rights than a big firewall
is true? Because refuting a straw man is not the same thing.
And here too I'm sure I could find reading material if required, I'm sure. From the candid beginnings of marketing and public relations to all sorts of musings, short stories and probably even Star Trek episodes about how a prison you can see, one you know you're in, is much less insidious and effective than one where you think you're free, where you never try the door or don't even realize there is one. I remember a short story in my 8th grade textbook or something that was about a prison without walls. You can say and do what you want, sure, and you think you came up with what you want all by yourself, too, it's just you didn't. That's the general idea.
Walls, like murder, are just very crude tools, they are not the zenith of oppression and exploitation. If you see huge concentrations of power, skepticism is always warranted. How could there be smoke without fire? It doesn't prove anything, sure, and even if I could prove that "there has to be a fire", then that doesn't make any wild fantasies about the nature of it correct. But still, to muse about causes one can't prove (yet) seems a lot less foolish than to for example say "oh look, a huge blob of smiling friendly power, it just has to be everything it says on the tin". I'd rather be wrong about something I investigated for the right reasons, than guess right by sheer dumb luck.
But personally I prefer to think of useful ways that would also nip some fires in the bud anyway. I don't need to know if we are being manipulated, I know critical thought is required and I know group think can be dangerous even when not manipulated, which it is so readily. So why not catch one real and one potential bird with one stone that is obligatory? I don't know how much of a problem global warming is, but I know that renewable energies are a good idea regardless, at "worst" we simply get to use fossil fuels for more plastic and fertilizer rather than burning them. I don't know how many people the planet can sustain, but I know something that needs to grow to not collapse cannot work on a finite planet, and that we need to rethink that at least until we get out of the solar system and split up into a gazillion humanities that will do whatever. I don't need to know if someone is trying to guess my password, I simply generate a long random one anyway. And so on.
Likewise, I don't know if there will ever be the kind of oppressive societies here and where you are that were the norm throughout history and are still plentiful in the world, and I can't prove the exact levels of fuckery we are under right now, much less my idle suspicion that the West might fall get phased out in favour of the Chinese model -- but I still strive to be the best and most free I can be. Certain things should not be a response to pressure from the outside, they should be growing anyway. If there is nothing on the outside trying to opppress, everybody is happy. If there is, it gets to pop, and everybody who matters is happy. Win/win?
As are appeals to authority. i.e.:
"I can't find proof of this, therefore it must not be happening
Let me ask you this, what precisely would suffice as proof, in your opinion, of such activities?
On the internet, maybe there really is no such thing as undeniable "proof" that anyone did anything, considering how easy it is to fabricate evidence. [1]
[1]https://news.ycombinator.com/item?id=11440594
Let me ask you this, what precisely would suffice as proof, in your opinion, of such activities?
On the internet, maybe there really is no such thing as undeniable "proof" that anyone did anything, considering how easy it is to fabricate evidence. [1]
[1]https://news.ycombinator.com/item?id=11440594
Pointing out that you've presented no evidence for an argument is not an "appeal to authority".
>Argument from ignorance (from Latin: argumentum ad ignorantiam), also known as appeal to ignorance (in which ignorance represents "a lack of contrary evidence"), is a fallacy in informal logic. It asserts that a proposition is true because it has not yet been proven false (or vice versa). This represents a type of false dichotomy in that it excludes a third option, which is that: there may have been an insufficient investigation, and therefore there is insufficient information to prove the proposition be either true or false.
https://en.wikipedia.org/wiki/Argument_from_ignorance
Open and shut case, Johnson!
https://en.wikipedia.org/wiki/Argument_from_ignorance
Open and shut case, Johnson!
If anyone here could be reasonably construed as arguing from ignorance it'd be you.
You said that "there are many much more subtle and effective ways to stifle free speech and human rights than a big firewall," such as "MITM attacks, botnet troll armies, astroturfing, etc. etc."
If you're not asserting that such techniques are being deployed, then ok. But if you are, and follow that up with "Good luck finding proof of that though," as though that's a perfectly reasonable excuse for not being able to back up what you're alleging, then you are yourself asserting "a proposition is true because it has not yet been proven false."
You said that "there are many much more subtle and effective ways to stifle free speech and human rights than a big firewall," such as "MITM attacks, botnet troll armies, astroturfing, etc. etc."
If you're not asserting that such techniques are being deployed, then ok. But if you are, and follow that up with "Good luck finding proof of that though," as though that's a perfectly reasonable excuse for not being able to back up what you're alleging, then you are yourself asserting "a proposition is true because it has not yet been proven false."
Of course such attacks are being deployed, but by whom and for what purpose?
Here is an example of one such attack, which the researchers called "Censorship 2.0".
https://www.reddit.com/r/netsec/comments/38wl43/we_used_sock...
See also:
https://en.wikipedia.org/wiki/Hacking_Team#Use_by_repressive...
Here is an example of one such attack, which the researchers called "Censorship 2.0".
https://www.reddit.com/r/netsec/comments/38wl43/we_used_sock...
See also:
https://en.wikipedia.org/wiki/Hacking_Team#Use_by_repressive...
Aaand it's off the front page.
http://i.imgur.com/FQNYhED.png
Isn't that interesting? The story above this one is roughly as old, has half the upvotes, and more comments. The one just below it is a lot older, and has a lot more comments than upvotes. Conspiracy? No, just the audience I guess, but all the same: QED.
> Unpopular ideas can be silenced, and inconvenient facts kept dark, without the need for any official ban. Anyone who has lived long in a foreign country will know of instances of sensational items of news — things which on their own merits would get the big headlines-being kept right out of the British press, not because the Government intervened but because of a general tacit agreement that ‘it wouldn’t do’ to mention that particular fact. So far as the daily newspapers go, this is easy to understand. The British press is extremely centralised, and most of it is owned by wealthy men who have every motive to be dishonest on certain important topics. But the same kind of veiled censorship also operates in books and periodicals, as well as in plays, films and radio. At any given moment there is an orthodoxy, a body of ideas which it is assumed that all right-thinking people will accept without question. It is not exactly forbidden to say this, that or the other, but it is ‘not done’ to say it, just as in mid-Victorian times it was ‘not done’ to mention trousers in the presence of a lady. Anyone who challenges the prevailing orthodoxy finds himself silenced with surprising effectiveness. A genuinely unfashionable opinion is almost never given a fair hearing, either in the popular press or in the highbrow periodicals.
http://orwell.ru/library/novels/Animal_Farm/english/efp_go
http://i.imgur.com/FQNYhED.png
Isn't that interesting? The story above this one is roughly as old, has half the upvotes, and more comments. The one just below it is a lot older, and has a lot more comments than upvotes. Conspiracy? No, just the audience I guess, but all the same: QED.
> Unpopular ideas can be silenced, and inconvenient facts kept dark, without the need for any official ban. Anyone who has lived long in a foreign country will know of instances of sensational items of news — things which on their own merits would get the big headlines-being kept right out of the British press, not because the Government intervened but because of a general tacit agreement that ‘it wouldn’t do’ to mention that particular fact. So far as the daily newspapers go, this is easy to understand. The British press is extremely centralised, and most of it is owned by wealthy men who have every motive to be dishonest on certain important topics. But the same kind of veiled censorship also operates in books and periodicals, as well as in plays, films and radio. At any given moment there is an orthodoxy, a body of ideas which it is assumed that all right-thinking people will accept without question. It is not exactly forbidden to say this, that or the other, but it is ‘not done’ to say it, just as in mid-Victorian times it was ‘not done’ to mention trousers in the presence of a lady. Anyone who challenges the prevailing orthodoxy finds himself silenced with surprising effectiveness. A genuinely unfashionable opinion is almost never given a fair hearing, either in the popular press or in the highbrow periodicals.
http://orwell.ru/library/novels/Animal_Farm/english/efp_go
This story was on the front page for hours today.
Not the first time this has happened to me:
https://news.ycombinator.com/item?id=11109985
https://news.ycombinator.com/item?id=11109985
No, we only have the NSA that can archive days (weeks?) worth of the United States internet traffic, seamlessly MITM 0days, or tons of other frightening things...
I guess a transparent firewall is not a firewall?
I guess a transparent firewall is not a firewall?
We don't have anything like a "transparent firewall", either.
Unless you are fully aware of NSA activities, you cannot be sure of that statement.
Here's an excerpt from Cisco: [0]“Traditionally, a firewall is a routed hop and acts as a default gateway for hosts that connect to one of its screened subnets. A transparent firewall, on the other hand, is a Layer 2 firewall that acts like a "bump in the wire," or a "stealth firewall," and is not seen as a router hop to connected devices.”
I dunno if our disagreement is about the semantics of what a "transparent firewall" is, but the NSA has been shown to filter a majority of the traffic that traverses the USA, so your statements that the USA has nothing like the GFW seems a bit off...
[0]: http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/conf...
Here's an excerpt from Cisco: [0]“Traditionally, a firewall is a routed hop and acts as a default gateway for hosts that connect to one of its screened subnets. A transparent firewall, on the other hand, is a Layer 2 firewall that acts like a "bump in the wire," or a "stealth firewall," and is not seen as a router hop to connected devices.”
I dunno if our disagreement is about the semantics of what a "transparent firewall" is, but the NSA has been shown to filter a majority of the traffic that traverses the USA, so your statements that the USA has nothing like the GFW seems a bit off...
[0]: http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/conf...
The NSA "filters" a majority of the traffic that traverses the USA? What site can't I get to because of those filters?
A massive wall with a gate in it that allows everyone through is still a wall.
Everyone going through that gate can be monitored, recorded, held for questioning, etc.
And jumping out of the metaphor, every packet passing through the gate can be copied and stored for later.
Everyone going through that gate can be monitored, recorded, held for questioning, etc.
And jumping out of the metaphor, every packet passing through the gate can be copied and stored for later.
I guess my criticism is that stopping communication (GFW) and monitoring communication (NSA) are very similar, therefore we do have our own GFW.
What the US does is not even remotely similar to what the GFW does.
And, by the way, the idea that you can trivially evade the GFW using a VPN? That's an extremely dangerous assumption.
And, by the way, the idea that you can trivially evade the GFW using a VPN? That's an extremely dangerous assumption.
I see monitoring and blocking to be part of the same machine. We apparently disagree. :)
>And, by the way, the idea that you can trivially evade the GFW using a VPN? That's an extremely dangerous assumption.
I think that part of your reply was meant for someone else. (I agree with the part I quoted.)
>And, by the way, the idea that you can trivially evade the GFW using a VPN? That's an extremely dangerous assumption.
I think that part of your reply was meant for someone else. (I agree with the part I quoted.)
I think a big problem with your argument is your assumption that the US government does, or even can, monitor to the same degree that China does. The amount of interconnections and peering between networks makes this near impossible in practice in the US. If they could, there would have been no need for them to try to tap directly into Google's datacenter-to-datacenter lines. The internet is a mesh, not a star. Monitoring can get far by picking the largest entities and trying to insert themselves at those points, but there's plenty of traffic that goes directly between entities that isn't monitored. This works for monitoring, because it's passive, but once we're talking about a firewall and something is blocked, traffic will just shift to routes that aren't blocked if they exist. The GFW is a firewall because they actually have control of all the routes.
Cisco created the "lawful intercept" protocol for routers, for starters...which of course can now be used by hackers as well.
https://tools.ietf.org/html/rfc3924
https://www.blackhat.com/presentations/bh-dc-10/Cross_Tom/Bl...
https://tools.ietf.org/html/rfc3924
https://www.blackhat.com/presentations/bh-dc-10/Cross_Tom/Bl...
> Cisco created the "lawful intercept" protocol...
That's not correct, csco _implemented_ lawful-intercept, the protocol is an integral part of 3gpp spec I.e. All companies playing in the epc/telecom market would most likely support this e.g Ericsson, Nokia (nsn), Alcatel-lucent etc etc
That's not correct, csco _implemented_ lawful-intercept, the protocol is an integral part of 3gpp spec I.e. All companies playing in the epc/telecom market would most likely support this e.g Ericsson, Nokia (nsn), Alcatel-lucent etc etc
[deleted]
Those people who helped increase the quarterly earnings at the time by selling this tech to the Chinese government must've felt pretty proud of themselves.
Has anyone heard of similar abuses by Juniper Networks?
I'd focus more towards the merchant silicon of Marvell/Broadcom/Fulcrum
if somebody wants to sue a layer 2 ethernet fabric chip maker they're insane. any asshole can use a switch to do any sort of terrible thing with their nation's internet infrastructure.
it's like suing intel because they made the 1GbE NIC in a server seized for kiddie porn.
it's like suing intel because they made the 1GbE NIC in a server seized for kiddie porn.
Not if they backdoored it for money to aid nation-states in I.P. theft or murder of innocents. I'm not saying I recall above companies doing that. Just that it's one legit reason among many to sue or bring charges against a telecoms, semiconductor company. And we know more than one vendor that previously did exactly that.
[deleted]
Show me any documentation whatsoever that proves a pure layer 2 Ethernet switch has been put on a test network and observed (via packet capture on its upstream) sending data home.
It's not the switch itself. It's the I.P. in the switches. And you've narrowed the situation enough to ensure nobody could meet your criteria unless representing the most wreckless spies on Earth.
Note: One fun fact of layer 2 Ethernet is it's insecure enough by itself that many just tap straight into the lines somewhere. Led to development of MACsec standard.
Note: One fun fact of layer 2 Ethernet is it's insecure enough by itself that many just tap straight into the lines somewhere. Led to development of MACsec standard.
Not at all. "Put a suspicious device on an internet connection, let it run, and capture all packets to see where it phones home" is a fairly basic process.
The connectors in TAO catalog use RF to make that impossible without unusual spectrum analyzers. I did that, too. Another trick is covert channels to make it invisible in network traffic. Covert channel analysis is mandated in high assurance specs but almost nobody does it.
Anyway, you're not going to see a switch subverted by pro's in action. They won't blow that cover. They'll use it to facilitate a normal attack and plant evidence it came through a normal vector. That's how subversion works at pro level.
Anyway, you're not going to see a switch subverted by pro's in action. They won't blow that cover. They'll use it to facilitate a normal attack and plant evidence it came through a normal vector. That's how subversion works at pro level.
[deleted]
It's disturbing that I didn't even know Cisco was involved until now.
What's your intended meaning?
A combination of feeling guilty that I haven't been paying more attention to unethical things that US companies do abroad and being disappointed that this wasn't bigger news.
So it's wrong to abuse, humiliate, and torture someone in the United States but if you do it elsewhere it's ok?
Oh wait...
Oh wait...
We detached this subthread from https://news.ycombinator.com/item?id=11529845 and marked it off-topic.
this case is about selling an internet filter.
It would not be wrong, as in illegal or subject to any civil penalty, if Cisco sold that internet filter to the United States' agencies.
so that highlights the delicious irony in your retort
It would not be wrong, as in illegal or subject to any civil penalty, if Cisco sold that internet filter to the United States' agencies.
so that highlights the delicious irony in your retort
First, they built special hardware to target a specific group that is internationally known to be a frequent target of oppression. So that's going beyond what they normally provide.
Second, if you're selling something to a known person, and you have a good reason to know what they're going to do with it. And let's be clear, Cisco totally knew what they were going to be used for in this case. Then you're an accessory.
Second, if you're selling something to a known person, and you have a good reason to know what they're going to do with it. And let's be clear, Cisco totally knew what they were going to be used for in this case. Then you're an accessory.
| First, they built special hardware to target a specific group
Is that stated as a fact in the case? I didn't find anything that makes that suggestion.
Is that stated as a fact in the case? I didn't find anything that makes that suggestion.
The article explicitly says, "Cisco built a special Falun Gong module into the Golden Shield".
Reading the abstract of brief, it looks like "built" is being used to me "specifically sold and configured hardware." So it's not necessarily some special asic, but rather machines configured specifically to target and identify Falun Gong members. Anyway, in the 21st century, the line between hardware and software that runs on dedicated hardware is pretty ill defined.
Reading the abstract of brief, it looks like "built" is being used to me "specifically sold and configured hardware." So it's not necessarily some special asic, but rather machines configured specifically to target and identify Falun Gong members. Anyway, in the 21st century, the line between hardware and software that runs on dedicated hardware is pretty ill defined.
I'd encourage you to do more than read an article written by a party with a vested interest, and critically read the linked legal submission.
When reading such a court document, remember it is written by a lawyer (or team of laywers) with the intent (explicit or otherwise) of conflating many ideas.
Creative naming of artefacts, systems, roles, organisations, etc. are all employed to paint a picture - the most vivid, influential, negative picture possible - whilst still being technically factually.
Critical reading of the submission, filtering for technical details suggests that yes, there was indeed integration into existing networks (obviously), and existing databases/systems of record, maybe related to Falun Gong, but frankly the majority of the technical data looks like a description of any intercept network - whether for troubleshooting, traffic analysis, or lawful intercept.
When reading such a court document, remember it is written by a lawyer (or team of laywers) with the intent (explicit or otherwise) of conflating many ideas.
Creative naming of artefacts, systems, roles, organisations, etc. are all employed to paint a picture - the most vivid, influential, negative picture possible - whilst still being technically factually.
Critical reading of the submission, filtering for technical details suggests that yes, there was indeed integration into existing networks (obviously), and existing databases/systems of record, maybe related to Falun Gong, but frankly the majority of the technical data looks like a description of any intercept network - whether for troubleshooting, traffic analysis, or lawful intercept.
and they also would not be subject to any civil remedy if they sold such thing to a US agency.
the only thing I responded to.
the only thing I responded to.
PhasmaFelis(3)
MichaelGG(5)
Well boo hoo, Google is trafficking in human information, Facebook is trafficking in human information, FourSquare remnants are trafficking in human information, all realizing Orwell's sweaty nightmares. But a company that is affecting someone overseas, and not it's own citizens, is in the wrong?
Find me a specific incident perpetrated by GOOG/FB that has directly facilitated human rights abuses. This is not an accusation of a vague misuse of information. This is a direct action by the company that they knew would facilitate torture, etc.
That's their business model - people are their product. That's how they make money. That's the only way they make money. They sell people to advertisers. What's not wrong with that?
"Sell[ing] people to advertisers" != "sell[ing] people to an oppressive regime."
That's one way to look at it. But Chinese view US regime as oppressive, and any opinion to the contrary would result in the downvote fairies of the 50-cent army slashing your karma to oblivion, in a similar way I lost about 25 points on this post.
Wat? Nothing you've said above or below would incite the ire of 50¢A. If anything they would upvote you.
Google has an intimate relationship with the State Department and the Department of Defense. At one point they created a "tool" to track defections from Syria[0][1], and encourage civil war, meaning they are at least in part responsible for the violence there.
They also censored Benghazi related video on Youtube at the request of the State Department, which, while not really an "abuse of human rights," and only a temporary block, still amounts to propaganda and censorship.
[0]https://wikileaks.org/clinton-emails/emailid/12166#efmAMoAbj
[1]http://www.breitbart.com/tech/2016/03/22/leaked-clinton-emai...
They also censored Benghazi related video on Youtube at the request of the State Department, which, while not really an "abuse of human rights," and only a temporary block, still amounts to propaganda and censorship.
[0]https://wikileaks.org/clinton-emails/emailid/12166#efmAMoAbj
[1]http://www.breitbart.com/tech/2016/03/22/leaked-clinton-emai...
> Cisco’s attempt to try to leverage the Wassenaar discussions into legal immunity for itself is unfounded and should fail.
More like attempts to get a civil penalty in the United States for business in another country should fail
More like attempts to get a civil penalty in the United States for business in another country should fail
The US is entitled to use its leverage to effect cultural change abroad. One way we do that is combat foreign corruption by holding American companies accountable when they engage in fraud abroad. We also hold Americans who participate in sex with minors in foreign countries accountable. This is in the same vein.
Why not? Seems like there is lots of precedent for it: https://en.wikipedia.org/wiki/Alien_Tort_Statute
Also, do you think it matters that one of the plaintiffs is a US citizen?
Also, do you think it matters that one of the plaintiffs is a US citizen?
Yes.
As a US citizen, you can be held responsible for violating certain US laws outside the United States. Why would this be different?
Indeed. This is just a business selling a product someone wanted. Cisco is a multinational company; it makes no more sense to hold them to US law for products sold in China then to hold a Chinese company to US law for products sold in China.
You can say the exact same thing about bribing overseas officials, and yet we have the FCPA.
It's been said better up at the top now, but my point was exactly that: if we want to prevent this specific scenario, we need a law that says "company that does business in the US must not do Y", rather than saying "Y is illegal here, so lets sue company that does business in the US for doing Y elsewhere."
and yet, I feel the same way about the FCPA
bring it up when I run for office
bring it up when I run for office
I don't understand the objection. It's not like you suddenly lose all benefits and protections of US citizenship when you step over the border. If you don't want to follow these laws, move your company and renounce your citizenship. If you're not willing to do that then you need to follow the rules.
If you would like to talk about the FCPA, I never mentioned my objection.
The objection is that it undermines competitiveness in corrupt business environments. Business environments that are inherently corrupt whether the US entity participates or not. Kickbacks are a way of doing business in many jurisdictions, and then the US government levies a charge against you that is solved with: YOU GUESSED IT, ANOTHER KICKBACK. But its okay because the SEC and DOJ call it a settlement.
A totally unnecessary law that is enforced at the discretion of the administration.
The objection is that it undermines competitiveness in corrupt business environments. Business environments that are inherently corrupt whether the US entity participates or not. Kickbacks are a way of doing business in many jurisdictions, and then the US government levies a charge against you that is solved with: YOU GUESSED IT, ANOTHER KICKBACK. But its okay because the SEC and DOJ call it a settlement.
A totally unnecessary law that is enforced at the discretion of the administration.
I understand your point about lawsuit settlements being useless and hypocritical, but your main point about competitiveness is obviously not really relevant. There are tons of laws that undermine US business competitiveness in global markets. There are tons of laws that undermine domestic competitiveness too, that's just how our society is set up. Profit is not our first priority.
Anyway, when I referred to your "objection", it seemed like you were saying any laws affecting business outside the country are pointless and wrong. I don't think I know enough about the FCPA to discuss it specifically.
Anyway, when I referred to your "objection", it seemed like you were saying any laws affecting business outside the country are pointless and wrong. I don't think I know enough about the FCPA to discuss it specifically.
Why doesn't it make sense? Cisco is an American multinational company. If you don't want to abide by American laws, don't base your company in America. I don't think laws should apply to actions abroad by default, but we have laws specifically written for these scenarios.
US citizens can be prosecuted for some serious crimes committed abroad. It doesn't make sense to treat companies differently.
US citizens can be prosecuted for some serious crimes committed abroad. It doesn't make sense to treat companies differently.
We have laws against bribing foreigners, no matter if that can be made to look legal-ish in a foreign country because that practice can lead to corruption of a US company.
Unfortunately, the government is a hypocrite in this case, by treating its own mass surveillance as legal.
Unfortunately, the government is a hypocrite in this case, by treating its own mass surveillance as legal.
I'm really tired of "business" being used as an excuse for oppression and torture.
[deleted]
Cisco provides Internet Protocol services, not what is being done with them. If Electricity from France is exported through Russia to China, can they be held responsible too? And what about the oxygen produced by the US flowers? Are US farmers responsible for providing oxygen supplying the evil Communist regime with oxygen? That electricity was as crucial to conducting the dreadful things just like IP, and just like oxygen.
This logic has no bounds.
Did you even read the article? Cisco (allegedly) built custom software to persecute a religion.
Yes, the article, yes, but I've also been a part of too many projects like this, when a technological marvel is being developed for a number of years, creating new capabilities, technology innovations, and driving efficiencies. Thousands of American man-hours were spent in creating this marvel, only for someone to summarily judge on a whim of what was that effort was about. It wasn't about what EFF said. That just simply wasn't in the RFP/RFC/RFWhatever.
Throwing up your hands and saying, "I just built it! It's not my job to think about how it's used!" is a cop out. It's also against the ACM Code of Ethics and Professional Conduct[0].
[0] https://www.acm.org/about-acm/acm-code-of-ethics-and-profess...
[0] https://www.acm.org/about-acm/acm-code-of-ethics-and-profess...
How about "it's just a tool"? You could say the same thing about knives, cars, Tor, Bitcoin or the Internet itself if you wanted.
You can't blame a creator for how a finished product is used. Their vision might greatly differ or it might not exist at all.
You can't blame a creator for how a finished product is used. Their vision might greatly differ or it might not exist at all.
In this case though, the tool only had one purpose, and the creator knew exactly what the buyer would be doing with it.
They knew they'd use it to torture? I highly doubt that.
Monitor, perhaps. But that's very different. It's also not exactly specified what they built - was it generic and something they might be able to sell to corporations or other governments who want traffic monitoring or something designed only for this purpose?
Monitor, perhaps. But that's very different. It's also not exactly specified what they built - was it generic and something they might be able to sell to corporations or other governments who want traffic monitoring or something designed only for this purpose?
> They knew they'd use it to torture? I highly doubt that.
Well them they've been living under a rock. It's been officially banned for 17 years, and there's literally a wikipedia article about it. https://en.wikipedia.org/wiki/Persecution_of_Falun_Gong
Well them they've been living under a rock. It's been officially banned for 17 years, and there's literally a wikipedia article about it. https://en.wikipedia.org/wiki/Persecution_of_Falun_Gong
It's entirely possible they assumed otherwise. Are you trying to say you must assume the worst possible intentions from your customers and that anything less should be illegal?
Surely Tor developers could have guessed it would be used for child pornography - should that have stopped them?
Surely Tor developers could have guessed it would be used for child pornography - should that have stopped them?
You're dealing with a known actor with a known track record against a known target. It's completely different. At this point it's being willfully ignorant[0] and you're being intentionally obtuse.
[0] https://en.wikipedia.org/wiki/Willful_blindness
[0] https://en.wikipedia.org/wiki/Willful_blindness
> You're dealing with a known actor with a known track record against a known target.
People with anonymity aren't "known actors"?
You could just as easily argue willful blindness with Tor or end to end cryptography devs. And that's how I'm worried that a case like this will be used if it's successful.
People with anonymity aren't "known actors"?
You could just as easily argue willful blindness with Tor or end to end cryptography devs. And that's how I'm worried that a case like this will be used if it's successful.
When you custom build a tool and you sell it saying - specifically - that it can be "used to monitor Falun Gong members", the whole "it's just a tool, not my fault how it's used" thing becomes disingenuous.
Yeah guys, sue the firewall vendor for your unencrypted internet traffic getting you fucked.
Are we supposed to forbid companies from complying with customer requests, even if they're unaware or just don't really care how those will be ultimately used? I know I'd implement similar things if it were requested of me.
I doubt this will be a popular opinion on HN, but I don't think Cisco was in the wrong here. Once traffic crosses your network boundary, it's fair game.
Are we supposed to forbid companies from complying with customer requests, even if they're unaware or just don't really care how those will be ultimately used? I know I'd implement similar things if it were requested of me.
I doubt this will be a popular opinion on HN, but I don't think Cisco was in the wrong here. Once traffic crosses your network boundary, it's fair game.
> Are we supposed to forbid companies from complying with customer requests, even if they're unaware or just don't really care how those will be ultimately used?
"Unaware" is a red herring because Cisco knew exactly what they were doing. From the court filing:
174. In October 2002 and September of 2003, 2005, 2006, 2007, 2008, and 2010, Cisco shareholder resolutions identified concerns regarding potential human rights abuses arising from Cisco network technology solutions provided to foreign countries, including and especially China, and called for investigation into Defendant Cisco’s complicity in these abuses. These resolutions were presented to the Cisco Board of Directors, including Defendant Chambers, and in each instance, the Board of Directors issued a statement recommending that shareholders reject the proposal. Well after this point, Defendant Cisco continued to help the Party and Public Security officers to suppress Falun Gong through use of the Golden Shield.
175. Cisco’s Golden Shield files include several court and prosecutorial reports identifying the douzheng of Falun Gong and other “hostile elements” as one of the five tasks of the Strike Hard campaign created to suppress Falun Gong with the Chinese for the term “element” designating targets of persecutory campaigns in the PRC.
176. Cisco’s marketing materials in China repeatedly boasted that Cisco’s technology solutions could guard against Falun Gong, block and track Falun Gong, monitor and profile Falun Gong, and in other ways persecute Falun Gong.
If someone "just doesn't really care" about actively helping a foreign government to capture its political enemies and torture them to death, I have no problem making a moral judgment about them.
"Unaware" is a red herring because Cisco knew exactly what they were doing. From the court filing:
174. In October 2002 and September of 2003, 2005, 2006, 2007, 2008, and 2010, Cisco shareholder resolutions identified concerns regarding potential human rights abuses arising from Cisco network technology solutions provided to foreign countries, including and especially China, and called for investigation into Defendant Cisco’s complicity in these abuses. These resolutions were presented to the Cisco Board of Directors, including Defendant Chambers, and in each instance, the Board of Directors issued a statement recommending that shareholders reject the proposal. Well after this point, Defendant Cisco continued to help the Party and Public Security officers to suppress Falun Gong through use of the Golden Shield.
175. Cisco’s Golden Shield files include several court and prosecutorial reports identifying the douzheng of Falun Gong and other “hostile elements” as one of the five tasks of the Strike Hard campaign created to suppress Falun Gong with the Chinese for the term “element” designating targets of persecutory campaigns in the PRC.
176. Cisco’s marketing materials in China repeatedly boasted that Cisco’s technology solutions could guard against Falun Gong, block and track Falun Gong, monitor and profile Falun Gong, and in other ways persecute Falun Gong.
If someone "just doesn't really care" about actively helping a foreign government to capture its political enemies and torture them to death, I have no problem making a moral judgment about them.
> Cisco’s marketing materials in China repeatedly boasted that Cisco’s technology solutions could guard against Falun Gong, block and track Falun Gong, monitor and profile Falun Gong, and in other ways persecute Falun Gong.
Note that none of the things you list include torture. You've shown nothing more than a tangential possibility of awareness. Without showing their direct knowledge of the torture and a direct link to requests from Cisco, you've proven nothing.
In fact, if anything you've shown they really went the extra mile to look into it. That's way more work than I would have done at least . the reality is that looking into something like this makes it more likely you'll get screwed over if it comes up legally later.
What do you think about manufacturers of end to end encryption tech? Certainly there's evidence that it can be used for bad things too. I worry that cases like this, if successful, could be used against Signal or similar next.
Note that none of the things you list include torture. You've shown nothing more than a tangential possibility of awareness. Without showing their direct knowledge of the torture and a direct link to requests from Cisco, you've proven nothing.
In fact, if anything you've shown they really went the extra mile to look into it. That's way more work than I would have done at least . the reality is that looking into something like this makes it more likely you'll get screwed over if it comes up legally later.
What do you think about manufacturers of end to end encryption tech? Certainly there's evidence that it can be used for bad things too. I worry that cases like this, if successful, could be used against Signal or similar next.
meepmorp(1)
"...firewall vendor..." you clearly did not read the whole thing.
What is it with all the "yes of course you should help torture people if it's good for your business" in this thread? Hacker News is usually pretty laissez-faire, but this isn't the normal tone here.
Hacker News is usually pretty laissez-faire, but this isn't the normal tone here.
I think one can distinguish between laissez-faire that amounts to "leave human beings to live as they will" and another concept that is "everything is permitted to the powerful". Actually IMHO it is a corruption to consider the latter to even be related to laissez-faire. However, many people conflate the two propositions, and would like the rest of us to conflate them as well.
I think one can distinguish between laissez-faire that amounts to "leave human beings to live as they will" and another concept that is "everything is permitted to the powerful". Actually IMHO it is a corruption to consider the latter to even be related to laissez-faire. However, many people conflate the two propositions, and would like the rest of us to conflate them as well.
It's an election year. That always brings out the most extreme positions. Especially since shocking extreme positions seems to be par for the course this cycle.
Thats ... pretty messed up.
[0]https://www.eff.org/files/2016/01/12/113_second_amended_comp...