Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

[ Create a new account ]

Report Says China Will Demand Source Code

Posted by kdawson on Sunday October 05, @04:53AM
from the said-the-spider-to-the-fly dept.
An anonymous reader alerts us to a two-week-old story that hasn't gotten much traction in the press to date. A Japanese newspaper and the AP report that China plans to demand source code from hardware manufacturers, and ban the sale of products from companies that don't comply. China is calling this an "obligatory accreditation system for IT security products." The plan is to go into effect next May, according to sources. "Products expected to be subject to the system are those equipped with secret coding, such as [a] contactless smart card system developed by Sony Corp., digital copiers, and computer servers. The Chinese government said it needs the source code to prevent computer viruses taking advantage of software vulnerabilities and to shut out hackers. However, this explanation is unlikely to satisfy concerns that disclosed information might be handed from the Chinese government to Chinese companies. There also are fears that Chinese intelligence services could exploit such confidential information by making it easier to break codes used in... digital devices."
security software government china it
it security
story

Related Stories

The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More | Login | Reply
Loading... please wait.
  • Simple solution (Score:5, Insightful)

    by DeltaQH (717204) on Sunday October 05, @05:00AM (#25262207)
    Just use open source. ;-)
    • Re:Simple solution (Score:5, Insightful)

      by EdIII (1114411) * on Sunday October 05, @05:23AM (#25262309)

      I'm thinking along the same lines in a security context. I have never supported Security Through Obscurity.

      If your security depends on your code being hidden, then I don't find it as valuable as a method that is open to scrutiny. Open Source Vs. Closed Source is a heated debate as always, but Open Source has a serious advantage when it comes to security. Trust. If the public at large can scrutinize the code, it is harder to say that anything nefarious is going on. With Closed Source, you HAVE to trust the company.

      Sony?

      Be fucking serious. The people that brought you a widespread implementation of a root kit to further their own agenda? I am going to have a hard time trusting ANY of their security products.

      I don't know why China may want to do this, but there are good arguments to support their position.

  • Makes you wonder (Score:4, Insightful)

    by Anonymous Coward on Sunday October 05, @05:03AM (#25262223)
    My guess is that this is to check the hardware for backdoors. Probably figures that they have put out so many backdoors in products like Cisco, Dell, Acer, HP, Apple, etc and now wants to check to make sure that nobody is doing the same to them.
  • yeah, right (Score:5, Insightful)

    by speedtux (1307149) on Sunday October 05, @05:04AM (#25262227)

    that disclosed information might be handed from the Chinese government to Chinese companies

    It might. And then they have a massive re-engineering problem on their hands. It would usually be easier for them to reimplement the functionality than try to start with undocumented, unsupported source code.

    Doing security audits on software is a legitimate request by a governmental agency. Of course, they should just request that vendors provide open source software.

    • Re:yeah, right (Score:5, Insightful)

      by unlametheweak (1102159) on Sunday October 05, @05:37AM (#25262379) Journal

      It would usually be easier for them to reimplement the functionality than try to start with undocumented, unsupported source code.

      I'm sure they would demand that the source code be fully commented and documented. I'm sure they would also insist on having the engineers explain anything that may be obtuse. If they can't understand the source code to begin with then it would be no use to them in the first place.

  • The big question. (Score:5, Insightful)

    by upuv (1201447) on Sunday October 05, @05:06AM (#25262235) Journal

    Do companies think that the market in China is big enough to justify giving them the source code?

    It doesn't really matter what foreign governments think of this. The can scream all they want. If a company thinks the Chinese market is big enough and they want a piece of it. Then they will cough up the code.

    Privacy, security and IP rites are second tier considerations when it comes to product sales.

    So again. Do companies think that the market in China is big enough to justify giving them the source code?

  • by Anonymous Coward on Sunday October 05, @05:20AM (#25262299)

    China is out of control. How can anyone compete if they have cheaper labor and can demand everyone hand over technologies. They can pirate the hardware but reverse engineering the rest is harder. What's next them demanding chip manufacturers hand over chip templates to "make sure they meet China's standards".

    • by RAMMS+EIN (578166) on Sunday October 05, @06:06AM (#25262489) Homepage Journal

      ``China is out of control. How can anyone compete if they have cheaper labor and can demand everyone hand over technologies.''

      Well, for starters, they can "demand that everyone hand over technologies", too. That's a choice you can make. There is nothing preventing you from competing with China there. If the choice you make causes you to lose, it's not because something is preventing you from competing with China - it's because you competed, but China won.

      That leaves the cheaper labor. And, frankly, if China has cheaper labor, that's an advantage they have. So if they win, based on that, it's not because something is preventing you from competing - it's because you competed with China and China won.

      So, really, your "How can anyone compete?" is a bit misplaced.

      Perhaps a more interesting question would be how to get desireable results, given what China is doing, but that would require you to, first of all, define what results are desireable.

  • by mrboyd (1211932) on Sunday October 05, @05:27AM (#25262327)
    • When RMS wants the printer driver source code it's freedom protection.
    • When the chinese government wants his printer driver source code their trying to embezzle the gentle and caring westerners...

    I thought source should be free?

    I know American are scared, losing world leader status, economy going down the drain, hockey mom for vp and everything but seriously it's a great move on the Chinese government that you should be applauding. You should be hoping it will be replicated by ALL other governments and that distributing the source becomes an habit for HW manufacturer.
    China has its issue (police state, freedom of the press...), but they seem sometime to have the balls to go where no other lobbyist sponsored government in the "free world" would go and when it's a good move at least have the intellectual honesty to recognize it.

    • Ummmm (Score:5, Insightful)

      by Sycraft-fu (314770) on Sunday October 05, @06:08AM (#25262503)

      If you live in a world where you believe everyone has the same motives, well then I hope when you get burned by that view it is in a way that doesn't hurt you too much. People are perfectly justified in calling in to question the motives of various entities. For example if your family doctor tells you to remove your clothes because he needs to perform a complete medical check, I think it is reasonable to trust him. His motives are most likely pure. However if a random guy in an alley with unkempt hair and a crazy expression asks you to do the same thing, I'd say you should probably question his motives, lest you end up getting hurt.

      You are also mistaken that various governments haven't seen the source to commercial products. Microsoft, would be an example. The Windows source code isn't secret. It isn't public, but it isn't secret. Many organizations, including universities, have it.

      The reason people find China's proposition scary is because of their track record. For example if you search around on the web you'll find that counterfeit Cisco gear form China is fairly common (often called 'Chisco'). It looks similar to real Cisco gear, but it of inferior production quality, and is of course unsupported. China has a very poor track record with regards to ownership laws and thus it is reasonable to call their motives in to question.

      There's also a big difference between believing in open source, and believing in ripping people off. Let's not pretend that it doesn't take a lot of work to write good code. If you want people to be able to do that work as a job, they need to get paid. However if what you support is for company A to spend lots of money writing it, and then company B to just rip it off and give nothing back, well you'll find that doesn't work. Open source works only when everyone contributes. If you have a bunch of people/companies that spend a lot of time and money to make something, only to have it ripped off, well they can't afford to keep doing it.

      So the problem isn't with a government wanting to see source code. I think you'll find that the US government verifies the code for anything used in critical systems. The problem is that the Chinese government does not have a good track record on this kind of thing. Thus I (and others) question their motives. I don't believe it is really about openness. I do not question RMS's motives. I believe he really just wanted openness.

      • by MobileTatsu-NJG (946591) on Sunday October 05, @06:33AM (#25262567)

        You've committed the common fallacy of supposing that there is some kind of "average" slashdot user, who represents every user, and believes every opinion that has ever been expressed on this message board. Obviously that can't be the case. Anybody like that would have to contradict every one of their own opinions. ... ... And stop assuming everybody here is a cookie-cutter version of everyone else.

        I mainly agree with the spirit of your post, but I had to say something about this little blurb: There are topics on Slashdot where a majority of the people who post agree. This is also reflected in the moderator pool. It is rather common for these opinions to be enforced via mod-points. For example: If you were to travel back to the year 1999 and post on Slashdot that 'Microsoft kills babies', that post would rocket up to +5. If you were to then post that 'Linux could use a little improvement in this particular area...', that post would disappear into a sea of other -1 posts. The specific attitudes change over the years, but the underlying principle always remains. That's why sometimes you really have to walk on eggshells with certain opinions to avoid your posts disappearing into oblivion. People who happen to be on the majority's side of opinion could make a great speech and get cheered for it. Now, here's the funny bit. Everybody's post comes with its own little score. There are a fair number of active posters who posture themselves to raise that score, appealing to the majority view. These are the guys that come in and say things like "I just want a phone that's just a phone!!!". All these people get talkative on certain topics, whether it be praise or waving of pitchforks. And Slashdot, which is ad-supported btw, caters to these people with stories that are going to interest them.

        Slashdot most definitely has a voice, some call it the GroupThink. Some people have taken offense to this, but really, the "but there's one guy that doesn't agree!" argument just doesn't apply. It's not an absolute term, it's just about majority. Generalizations always suck, right? Well, okay, but through the natural path of posting on Slashdot, you have to pick up these generalizations if you want to post your opinion without too much trouble. (I personally blame the moderation system for giving power to those with extreme opinions. I think it illustrates why vigilantism is illegal.)

        In any event, Slashdot does have opinions. If you'd like to test that theory, wander into an iPhone thread and say it's the best phone ever. ;)

  • by apodyopsis (1048476) on Sunday October 05, @05:54AM (#25262439)
    I used to work in a CE firm that manufactured in China and sold across the world - reverse engineering was a particular problem and IP protection was the talk of the day.

    And now they demand source code? Well I can assure you that it will *not* happen.

    I hear Hungary and eastern Europe are offering particularly cheap factory sites - and this might persuade some firms to relocate.

    Honestly you cannot make this stuff up. I suspect they will allow manufacturing in china of export goods with no access to source code (to protect their national growth and wealth), but only "approved" population control devices will be allowed to be sold inside China (to spy on their own citizens) - it's control freakery gone mad. This would allow them the best of both worlds, after all its no secret that China has various special economic zones (and they are huge) to allow export factorys to undercut everywhere else in the world - so they just make export rules different.

    We really are a joke to them, I remember the hilarious conversations we used to have about IP in Shenzhen with the local engineers, they have no concept of it at all. Its all fair game if they can work out how we did it. Of course, that never stopped them abusing our own system by buying as many patents as they could and hitting us over the head with them on one side, whilst copying everything we did on the other. And now they will try and demand the source code as well? No matter what safeguards they pretend to employ corruption is a business tactic out there and the information will be just another market to exploit. I remember sitting at a conference table with out local contact (who we found out was also employed by the client) taking both sides of the argument as well as two pay checks, literally forwarding out confidential information to competitors because they paid him to do so. NDAs, contracts and so are meaningless.

    Yes I am rather bitter and annoyed about it years later, and I accept that they are probably not all like that and things *might* of improved.
  • The Chinese government is well within it's rights to make decisions regarding what goes on within it's borders. Infact, the whole purpose of a government is to put the interest of it's own country first above the interest of any foreign power.

    In this case, seeing the source code of electronic devices being sold in China is very much in their interest, why should the chinese government trust foreign corporations to supply black box equipment when they have no idea how it works? There are many people who boycott products, at least in certain areas, where they don't have source code... I wouldn't run an internet facing server on anything for which i didn't have the source for many reasons.

    If you don't like it, noone is forcing you to sell or manufacture your products in china. If you don't like their rules, go somewhere else... If you want to take advantage of the large customer base in china, as well as the cheap labour costs then you have to play by chinese rules.

    Ofcourse, this policy is also beneficial for those companies who already release their source code, since they're already compliant.

    • by jellybear (96058) on Sunday October 05, @05:35AM (#25262371)

      It's the Prisoner's Dilemma. Unless you want to make it illegal to give source code to the Chinese, there will be some companies who will comply because it is better for their bottom line to do so.

      They are doing by legal fiat what the open source community has failed to do through voluntary cooperation, namely, boycotting products that don't provide their source code. Ironically, this autocratic move could be a boon to open source.

    • by sakdoctor (1087155) on Sunday October 05, @06:27AM (#25262547) Homepage

      It just doesn't work like this because those "western devices" are probably already made in Asia.

      I was visiting a Chinese factory that made widgets, and member of staff showed me a widget branded by a "famous western company" to impress upon me that the widgets made in their factory were of a high standard. "Here's a sample to take home, but don't tell anyone *wink* *wink*".

      Their agreement may not exclude selling the widget in part, or in whole on the domestic market, so the brands are in fact a complete myth. Those fake Sony goods that have been re-badged as a Chinese brand could be close to functionally identical, albeit with a much lower price tag.

      Another experience I had, was with a certain widget that had interchangeable parts. The product as a whole would be sold on the domestic market with Chinese branded parts, or swapped out for a brand that would know for export.

      It's all bullshit but very interesting to observe, and as an audience you are really overestimating the Chinese government's intervention which is close to none. This is just companies chasing profits with as much regard for ethics as our own companies.

      • by magarity (164372) on Sunday October 05, @07:17AM (#25262699) Journal

        They might manufacture the physical widget there but they didn't program the driver or firmware - it came on a master rom or was bundled in a cd already compiled.

      • by ShakaUVM (157947) on Sunday October 05, @02:44PM (#25265965) Homepage Journal

        >>Their agreement may not exclude selling the widget in part, or in whole on the domestic market, so the brands are in fact a complete myth.

        It also assumes they hold up their end of an agreement, which is laughable. After Qualcomm got a bunch of Chinese factories up and running with their Q-phone, China Telecom started selling their C-phone, which was an exact duplicate of the Q-phone, made by the same people that Qualcomm had trained in making their phones. They're so dishonest, it's fucking scary that so much of our technical manufacturing is being done over there - we're paying for their postgraduate education, and giving them free blueprints to rip us off with.

        • by edittard (805475) on Sunday October 05, @07:24AM (#25262719)

          if you ask me, it's about time profligate western nations got a taste of what it's like at the other end of the stick.

          Brought to you by the two-wrongs-make-a-right department.

          One other thing. Extort doesn't normally take a person or people as its direct object.

    • by Anonymous Coward on Sunday October 05, @06:38AM (#25262583)
      "Expect to see more Sorny goods if this goes ahead!"

      Maybe not. Maybe: "Expect to see a lot of counterfeit products labeled Sony, in the same kind of packaging Sony uses."

      Ever since the days of the DOS operating system, when it was only the Taiwanese who supplied computer parts, the Chinese have been extremely dishonest. They would deliver computer parts until a distributor got established. They would get paid when a load was delivered to a ship in Taiwan. But, the would eventually deliver a huge load of junk, stuff that had failed testing but had been saved for that purpose. That would put the U.S. distributor out of business.

      At the same time, there would be a Chinese distributor in town that just began doing business, selling the same items.

      Now that everyone has paid to build factories and complicated procedures in China, they are very vulnerable to Chinese control.

      Here are a few stories, chosen from thousands. The Chinese governments, in Taiwan and mainland China, have always pretended to be interested in stopping counterfeiting:

      FBI and Chinese seize $500 million of counterfeit software [iht.com].

      Dangerous Fakes: How counterfeit, defective computer components from China are getting into U.S. warplanes and ships [businessweek.com].

      YouTube videos about Chinese counterfeiting [google.com]

      The World's Greatest Fakes: Chinese Copies Are Making Their Way Back To U.S. [cbsnews.com]

      Heparin Find May Point to Chinese Counterfeiting [nytimes.com]

      Chinese Product Counterfeiting Causes US Job Layoffs [voanews.com]
      • by ozphx (1061292) on Sunday October 05, @06:58AM (#25262639)

        Wow, just like the west is very serious in cracking down on copyright infringement. An outsider would see the US govt's complete lack of dealing with mass scale copyright infringement as collusion. Leaving it to the copyright holders when theres such widespread infringement? I would say they aren't even pretending to be interested.

        I'm in China right now. The majority of the "fakes" are misapplied trademarks. They work nothing like the real item, and often look nothing like a real item from the Brand.

        You'd have to be a complete moron to be suckered in.

        The other end of the scale is when the factory owner lets the Gruntmaster production line run for an extra hour or so and slaps "Oinkmaster" on the side. I've picked up a few "grey-market" items this way - identical to the branded product.

    • by uberjack (1311219) on Sunday October 05, @06:43AM (#25262601) Homepage
      Hey, a Sorny would complement my Panaphonics and Magnetbox quite nicely