The Register Home Page

back to article Iran claims US used backdoors to knock out networking equipment during war

Iranian media is claiming that the US used backdoors and/or botnets to disable networking equipment during the current war, and Chinese state media is dining out on the allegations. Reports from Iran claim hardware made by Cisco, Juniper, Fortinet, and MikroTik either rebooted or disconnected during recent attacks on Iran – …

  1. Pascal Monett Silver badge
    Trollface

    False flag operations

    What ? The USA would conduct false flag ops to smear China ? Say it ain't so.

    The country that has the greatest president since 2025 could not possibly reach such a level. After all, its wonderful president is running a perfectly legal, honest-to-goodness crypto scheme for the good of the citizens of the country (subject to ICE approval, minimal possible investment is $1 million).

    1. cipnt

      Check the source code

      Trust but verify

      1. herman Silver badge

        Re: Check the source code

        You won't be able to find the HW/SW implants.

        1. NoneSuch Silver badge
          Devil

          Re: Check the source code

          This strikes me as a pot calling the kettle black moment.

          You have as much privacy as the government allows. And by that, I mean none.

          PS. By government I mean all of them. EU is doing a good job, but it's only a matter of time until lobby funded cracks appear there as well. They are politicians as well.

          1. M.V. Lipvig Silver badge

            Re: Check the source code

            The only thing tbe EU is doing a good job on privacy is where commercial interests are involved. Any government who uses the "think of the children" excuse is absolutely not protecting privacy from the government.

          2. John F Jennings

            Re: Check the source code

            If you think the EU is doing a good job re privacy (where the State is concerned) - then I have a bridge to sell you.

            I can assure you, from first had experience, that the State has more sight into your private stuff in Europe than Kim in NK could dream of. EU privacy is as much of sham as it is elsewhere.

            1. NoneSuch Silver badge
              Stop

              Re: Check the source code

              The EU has strong privacy laws. Governments and public officials are supposed to follow strict rules before accessing people’s personal information, and there can be serious penalties if they abuse that power. Those penalties can include big fines, disciplinary action, losing their job, and in some countries even criminal charges or jail.

              The U.S. has allowed broad surveillance under secret FISA court procedures, including program-level approvals that do not work like ordinary warrants naming a specific person. Critics argue that this system has enabled overcollection, swept in Americans’ communications, and led to repeated misuse by officials searching that data

              EU: 1 USA: 0

    2. Anonymous Coward
      Anonymous Coward

      Re: False flag operations

      The real question is does running OpenWrt, DD-WRT, or FreshTomato on routers with these backdoors remove or disable the backdoor?

      1. Clausewitz4.1 Bronze badge
        Devil

        Re: False flag operations

        ” on routers with these backdoors remove or disable the backdoor?”

        If it is a software implant, yes it disables the backdoor.

        If its a hardware implant, no.

        If its a firmware implant, also no.

        If you have the knowledge to extract the firmware or the physical implant, they are worth some money.

      2. coredump Bronze badge

        Re: False flag operations

        Even though I don't consider OpenWRT the magic elixir to fix all woes, I use, like, and recommend it (and others, e.g. pfSense/OpnSense, etc.) because:

        - it's arguably better in some cases than the vendor's software

        - it's nearly guaranteed to be supported longer than the vendor's software

        - it removes vendor-software-backdoors as an attack surface

        Plus other goodness like keeping otherwise good kit out of landfills and so on.

        Now of course, OpenWRT et al are open to bad actors, supply chain attacks, and ordinary bugs like any other software product. But I have more faith that an opensource team is more likely and motivated to address those than a throw-it-over-the-wall abandonware vendor, whose main motivation is just to sell you another one.

        If some of those vendors would release their hardware specs we might even see more improvement in OpenWRT et al hardware support; but that undermines the hardware peddler's efforts to get people buying a new wifi router or some such thing every year or three.

        Whether USA's agents in NSA, CIA etc. are actually able to implement true hardware backdoors in some of this type of gear, I dunno. I tend to suspect not, if only due to the effort of doing it at scale, to say nothing of keeping it quiet. Though perhaps that latter point feeds into the idea of these same vendors *not* releasing their hardware specs. </tinfoil_hat>

        I do think it's more likely those black hat agencies are actively going after software exploits, and perhaps even keeping some of them quiet for a time, for their own purposes. They wouldn't even have to infiltrate or influence/control a vendor for that.

        1. Sproggit Silver badge

          Re: False flag operations

          While I absolutely agree with your point... my concern isn't e.g. pfSense or opnSense... it's the hardware to run it on.

          Glovary? Made in China

          Protectli? Made in China

          And on and on.

          We've just had OpenRetch put fibre along our road and are waiting for connections, so I'm looking to sign up with CityFibre's 5Gb service and host@home. The problem is... can I trust the Chinese manufacturer of the hardware that pfSense is going to run on? I think the code can be robustly audited... but how hard would it be to compromise e.g. the Ethernet sockets?

          [Yes, I know that some of these machines run Intel Ethernet for that very reason... but in my case I could not spot a "genuine Intel" Ethernet socket from a fraudulent, compromised clone.]

          The concern is that if it's your perimeter firewall that is compromised you have a much-reduced chance of independently spotting unexpected network traffic between the compromised device and it's remote operator, because it literally provides your outer perimeter.

          Tricky.

          Intrigued to know if you've come up with any decent/effective way to select a good h/w platform for the likes of pfSense?

          1. coredump Bronze badge

            Re: False flag operations

            > Intrigued to know if you've come up with any decent/effective way to select a good h/w platform for the likes of pfSense?

            For pfSense/OpnSense functionality itself, IME the main thing is "Intel NICs", since they tend to be among the best supported by the underlying FreeBSD.

            For the problem of hardware backdoors and such, I have no magic solutions, any more than anyone else, whether for *Sense or *BSD or *WRT or Linux or any other OS.

            So for running the infrastructure here, without a chip fab and manufacturing line, hw & sw platform dev team, finite (small) budget etc., options are limited. I don't imagine I'm unique in this. So I simply try to reduce the attack/instability surfaces I can, whether it's security, complexity, exploits (intentional or otherwise), bugs, etc. That's about all any of us can do.

        2. NoneSuch Silver badge
          FAIL

          Re: False flag operations

          "I do think it's more likely those black hat agencies are actively going after software exploits, and perhaps even keeping some of them quiet for a time, for their own purposes. They wouldn't even have to infiltrate or influence/control a vendor for that."

          They are doing whatever they can to undermine communications. If they have three solid methods of accessing a piece of software, they keep going looking for more. Day after day after day with no end game in sight. They are ravenous for information regardless of whether it is tied to criminal behaviour or not. Everything, everywhere.

          Snowden in his deluge of data only told us about what he knew about. There are compartments he did not have access to.

      3. Eric 9001
        Boffin

        Re: False flag operations

        If the backdoor is implemented with proprietary peripheral software (i.e. software that runs on a Wi-Fi card or wired NIC), installing OpenWRT, DD-WRT and FreshTomato won't do anything, as such proprietary OS's include such proprietary software.

        It would be feasible with careful design and programming, to include a "feature" in a router, to make it reboot if the Wi-Fi card stops working and then add a "bug" to the Wi-Fi peripheral software, that makes the Wi-Fi card software hang on receiving "interference" on a specific frequency (i.e. from a satellite - ideally that would be within the ~2.4GHz bands, but that doesn't transmit very far through the atmosphere - but specific lower frequencies likely could still be received) and hey presto, the router continuously reboots.

        Such backdoor would be easy to keep secret, as Wi-Fi card software is developed in secret by a handful of developers and the source code is not available - only proprietary binaries.

        Such backdoor would also be deniable - as decompiling the software wouldn't reveal a obvious backdoor like a backdoor password - such bugdoor would be extremely subtle and be next to impossible to find unless you know exactly what to look for.

        Even if you were to capture or find the reboot interference pattern and prove that such "interference" causes the router to reboot, the router company would just apologize for the "bug" and tell you to buy the next model and see if it's fixed (it won't be, there will be more "bugs").

        As for routers without wireless interfaces, it'll actually be far easier to implement a similar bugdoor in the wired NIC software that is triggered by specific ICMP packets received over the internet.

        In the case of a hardware implant, or hardware backdoor, replacing the OS won't help, although the physical evidence such backdoor are hard to hide from destructive physical analysis techniques, are not deniable when found and are also hard to keep secret from the start (many people on the production line need to know).

        Intel for example hasn't implemented any hardware backdoors, but how anyone could login to the intel ME without a password, was definitely a honest mistake and not a bugdoor.

        1. Sproggit Silver badge

          Re: False flag operations

          i agree with the principle/outline that you describe here, but implementing the attack in software is too vulnerable to detection.

          The issue lies in the non-volatile nature of the storage... That must be readable... and even though modern routers all include the ability to update their firmware, the image that runs is stored in a form that has to be *read* in to be able to execute. If you can *read* it while the router is running, then you can dismantle the router, pull the non-volatile storage, and it's pretty simply to wire it up to a PC and simply dump the code.

          We have to make a distinction here between a vendor-supplied exploit and a hacker-installed one. Phineas Phisher - the anonymous hacker that broke in to the "Hacking Team" - the Italian security company - achieved his attack by compromising and rewriting the firmware in an IoT device they had connected to their "office" network, which allowed him to detect and penetrate their "secure" network.

          But anyone examining that IoT device would immediately detect the changes in the device firmware introduced by Phisher and realise the device was compromised.

          By contrast, if you're a device manufacturer and you want to compromise some hardware you're making... what you do is include a chip in your device that looks like a well-known integrated circuit - and which provides all the functionality of that commercial IC... but, when given a specific set of inputs ... unlocks additional, un-documented capabilities.

          For example, you could have a network adapter IC that is responsible for collecting the received electrical signals from the pins of an Ethernet cable and converting them and assembling them in to a data packet. A bunch of companies have chips that do that. But you could develop a chip that did *more* than that by giving it the ability to recognise a very specific bit-pattern in a received network data packet, you could unlock additional functionality.

          Very high speed network peripherals employ "DMA" - Direct Memory Access - so if you wanted to, you could have a network interface card that is designed to push malicious code directly in to memory when remotely instructed to do so... Much harder to detect than software as it would require you to dismantle or reverse-engineer the hardware.

          1. Eric 9001
            Boffin

            Re: False flag operations

            An attack in software is only vulnerable to straightforward detection if the software is added later - if the attack is included as a bugdoor in the default peripheral software for the router by the peripheral device vendor, then anyone inspecting the router after the fact is only going to find that the software is the same as X version of the software in any other router that uses that peripheral device.

            Decent attacks against IoS devices don't write anything to flash - rather everything is RAM resident and therefore erased on power loss (the Mirai botnet worked in that way) - anyone who inspects such IoS device would unplug it first to be able to dump the flash externally etc and won't find any flash changes regardless - the only way to find out is to dump the RAM without the device powering off once, which is made very hard by the device manufacturer, as root access to the user is denied (although root access to attackers who have reverse engineered is granted via backdoor passwords etc).

            It often takes the work of dozens of skilled people to get an IC designed and manufactured correctly - many of them may notice that there's a bunch of extra logic added to the IC beyond assembling the data packet.

            That would also be easier to detect than bugdoored peripheral software, as if it was determined the IC was likely backdoored - then the IC could be decapped and inspected under a microscope and all the extra backdoor circuity would be visible and would not be deniable ("why is this circuit more than twice as complicated as needed for what it does and is that trigger logic for a secret mode?").

            Software backdoors are far more likely solely due to cost reasons - if the hardware backdoor is discovered, even if the manufacturer successfully claims that the remote DMA backdoor was a hardware bug, then the manufacturer would need to either close down, or do a product recall and provide replacements, which is extremely expensive - while offering a software update that claims to have fixed the "bug" is cheap.

      4. FordPrefect

        Re: False flag operations

        Here is the thing. There are millions of lines of code in all of these things. The NSA and the other western agencies like GCHQ its worked with for years have nearly unlimited funds and national security powers that can be used to compel businesses in some cases to comply with requests. Open source projects rely on volunteers from all over the place who vets all of those people how do you check not only the work they are doing in isolation but how those modules work in conjunction with other modules. Then realise its NOT only the software, you have firmware on hardware devices and then the physical instructions burned into microprocessors and chipsets. If you have the resources of the NSA you could embed people into all sorts of people and embed what you need and nobody would be the wiser. As we know from the Snowden files they had backdoors on Huwei products.

    3. MyffyW Silver badge

      Say it ain't so.....

      Na-na, na-na, na-na, na-na, na, na

      I wish I had anything more useful to say, but Pascal just tripped a deeply buried Blink 182 memory:

  2. wolfetone Silver badge

    There will be people who will automatically think "Iran are lying", and there will be people who will automatically think "Well duh Iran of course". But then there will be people who remember the Snowden leaks and they will rightly say "You want us to be surprised by this?".

    Everyone is at it.

    1. cipnt

      Most people I speak to don't know about Snowden and think I'm exaggerating when I tell them about the things he revealed.

      Lesson is: people believe what they were thought to believe.

      1. You aint sin me, roit Silver badge

        But we know this!

        All the talk is about Huawei gear having backdoors allowing control from Beijing, but the only actual backdoors we know about were put in Cisco gear by the NSA.

        1. Yet Another Anonymous coward Silver badge

          Re: But we know this!

          IIRC the CISCO backdoors were put in by the MMB who were intercepting CISCO shipments on the way to customers. Presumably because CISCO's own implementation of backdoors wouldn't work and would require the victim to login and maintain them.

          The proof Oracle kit doesn't have backdoors is that they would sue you not paying the license fee for the hidden backdoor

          1. Blitheringeejit
            Coat

            Re: MMB

            What I want to know is - how long have the Milk Marketing Board been a player in global cyber-security?

            Mine's the one with the TLA dictionary in the pocket...

            1. Yet Another Anonymous coward Silver badge

              Re: MMB

              >how long have the Milk Marketing Board been a player in global cyber-security

              The Milk Marketing Board are behind all global conspiracies

              ( except for the JFK shooting, that was Nessie)

              1. Zack Mollusc Silver badge

                Re: MMB

                JFK killing was the cheapest hit ever. Only tree fiddy.

                1. Rol

                  Re: MMB

                  haha Upvote for the South Park reference.

                  Seems there's nothing happens on or off this planet where South Park isn't a perfect reference.

              2. Fr. Ted Crilly Silver badge

                Re: MMB

                Nah that was put down to a rouge team from Mac Fisheries...

            2. Tim99 Silver badge
              Coat

              Re: MMB

              The Egg Marketing Board were big players too, until everyone realised that their equipment had to have a Lion stamp.

              1. Yet Another Anonymous coward Silver badge

                Re: MMB

                The Egg Marketing Board ate just the political front for the Potato Council

      2. Dbs5347

        No the lesson is that not everybody subscribes to evidence free conspiracy theories.

    2. Blazde Silver badge

      They don't have a clue what happened, so they've not even lying. There're 4 possibilities they give and 3 of them theorycraft involvement of US manufacturers of the equipment without any evidence, then reach the conclusion that US gear must be purged from their networks just as is happening in many other countries for Chinese or occasionally US networking kit.

      Of course it's possible, and yes they definitely should manufacture their own network circuit boards, or at least risk letting the CCP have backdoors rather than the plainly adversarial US.

      However the more straightforward explanation is the "internal malicious packets triggering 0-day" theory. The idea they can just shutdown their international internet links and that does more than slightly impede nation-state adversaries like Israel and the US conjuring up malicious packets is completely naive. Even some regular Iranian citizens are evading the internet block, there are many dissidents, and Israel has spent about 45 years developing assets inside Iran to the extent they were able to pinpoint large numbers of very high ranking leaders in apparent real-time. Of course, it's a better look to write news reports that blame evil satellites pinging routers from space than question their wider counter-intelligence problem.

    3. Kurgan Silver badge

      Of course I expect US made devices to be backdoored by the CIA. But Mikrotik? Probably the CIA has zero days for these? But if you allow for public access to the web UI or to the winbox port, this is poor security on their side.

      1. Dbs5347

        It would be the NSA not the CIA and your expevtation is without logical basis.

    4. Rich 2 Silver badge

      As has been mused by many other commentators, I’m inclined to believe the heinous regime in Iran long before I believe anything that the Orange One or any of his clowns spout from the heinous regime in the US

      1. Doctor Syntax Silver badge

        But the Orange One spouts so much self-contradicting if not random stuff that the stopped clock principle comes into play. It's just a matter of trying to work out which bits are right.

        1. khjohansen

          Far too r4nd0m

          *Sigh* - I miss the stability of the AutoPen! < the clock needs to be ++stopped++ to be correct twice a day!>

        2. Anonymous Coward
          Anonymous Coward

          It's just a matter of trying to work out which bits are right.

          In his case I suspect the evil bits.

    5. BartyFartsLast Silver badge

      Yup, one of the first things that came to mind were the Snowden files and all the others where xh have exposed a small percentage of the US cyber capabilities

      1. Yet Another Anonymous coward Silver badge

        But what if the Snowden files were deliberate leaks by the MMB to distract you from what's really happening ?

    6. Anonymous Coward
      Anonymous Coward

      Everyone is at it.

      I doubt Britain is, our government lacks the foresight, technical competence and resolve.

      1. Excused Boots Silver badge
        Holmes

        And that is what they wan’t you to believe.

        Nothing to do with the government, it’ll be the people working behind the scenes. I suspect they are actually training the NSA et. al. as to how to do it properly!

        1. Anon

          Yeah, somehow the "ID cards" thing seems to keep surfacing despite different political parties getting in over the past few decades.

          Maybe the person behind the scenes for that one will retire soon, but there is no doubt that they've made sure that their malware has been installed in the successor. Even though it is to the detriment of their grandchildren or later.

          Some greed, OK, we can bear it. Excessive greed, we all suffer.

    7. Dbs5347

      There are multiple other explanations for this. The most obvious is it didn't actually happen like the Iranians think and they are paranoid over network failures actually caused by dirty power related to bombing etc. The next is that US and Israeli intelligence simply took advantage of the same sort of unintentional cyber weaknesses that are exploited all over the world by numerous actors every day and used them to long ago gain persistence in Iranian networks which are not as air gapped as Iran thinks they are. No intentional backdoor required.

  3. SnailFerrous Silver badge

    A country that makes network equipment and also plays the Great Game of Empire.

    Embedding back doors in said equipment sold to other countries gives great advantages in any conflict. It is relatively easy to do. It is hard to detect it is either present during peace time, or doing nefarious stuff during a war. It is easy to deny, if caught. It is easy to accuse your rival equipment manufacturing country of doing it, while claiming to be squeeky clean yourself. It is very hard for anyone else to separate fact from propoganda.

    Put all that together, then why not? This logic applies as equally to China as to the US.

    1. Anonymous Coward
      Anonymous Coward

      Embedding back doors in said equipment sold to other countries...

      What would make you think it's not also in the equipment sold domestically and to friendly countries?

    2. stronk

      I'm not sure about all that. Embedding backdoors is not easier than finding security flaws. It requires conspirators and conspiracies tend to snowball. Private businesses will object strenuously to government compromising their devices, so anticipating everyone in the industry who is tapped on the shoulder to keep quiet forever about this is not a great plan. 'Hard to detect' is debatable, especially once the backdoor is used (it may delete itself+records, but what about the spare in the cupboard?). It's not easy to deny. In fact, it's relatively easy to prove because the flaw is in a device that's under the control of the victim. Doubly so if the backdoor exists in devices shipped to other customers and those customers can corroborate.

      Not saying they don't exist (I wouldn't know), just that on the face of it, it is much riskier than you say. Taking advantage of unintentional security flaws is simpler and less risky. You could even recruit people at the manufacturers or the testing companies who might overlook some of the juicier or better hidden flaws and pass them along to your state hackers. No conspiracy needed. And if you're doing this anyway, why not target a non-US/Chinese manufacturer so the reputational damage doesn't affect your own companies?

      1. Anonymous Coward
        Anonymous Coward

        And if you're doing this anyway, why not target a non-US/Chinese manufacturer so the reputational damage doesn't affect your own companies?

        no use when your target is running US developed tech.

        so many chips in a router, switch, computer. Who's to say that the exploit isn't in 1 of those chips. that no one knows what it does but knows its important for the operation of the device.

        how many people know that cpu's run microcode? microcode being firmware that is upgradable that runs on the chip

        https://en.wikipedia.org/wiki/Microcode

        who has teh capability to check the microcode for backdoors?

        1. Anonymous Coward
          Anonymous Coward

          You can also check for behaviour, for anomalous events - that's how a lot of good anti malware works because checksum matching is easily outwitted.

          It's not just a matter of embedding something - at some point it also has to do the job, and if you're at the firmware level in the stack it'll take a while before you have taken stock of what's around you - by that time your activity may be picked up unless you also control the rest of the stack - in which case you wouldn't need the firmware infection in the first place.

        2. Claptrap314 Silver badge

          Who has the ability to put a backdoor in there that could then either receive or transmit data from or to the general internet without a compromised OS?

          Badware in firmware is a real problem, but in order to put it there, you need to compromise the enclosing OS first.

    3. Dbs5347

      It applies nowhere near equally because China without a doubt has the ability to legally compel its tech companies to embed backdoors and the US government simply does not have any comparable legal tools with regard to US companies. Thus it is much more feasible for China to get companies to embed back doors than it is for the US which makes it much more likely.

      1. Yet Another Anonymous coward Silver badge

        > the US government simply does not have any comparable legal tools with regard to US companies.

        Are you ding a Fringe Standup show this year ?

  4. alain williams Silver badge

    Open Source firmware

    This has got to be the way that everyone should go. Not a 100% guarantee but a good start. Something like Openwrt.

    1. Julz

      But

      What does the firmware run on?

      1. TReko

        Re: But

        or even deeper, the hardware RTL that controls the low level MAC can easily detect some sort of magic packet header and misbehave.

        Even more evil is not to knock out the equipment totally - this is easy to detect. Just make it start being unreliable.

  5. sanmigueelbeer

    If Iran and PRoC are very close, why is Iran still using Cisco, Mikrotik, etc. when Huawei is available?

    1. Duncan Macdonald
      Black Helicopters

      Old equipment - no budget for replacement

      Iran probably had a lot of Cisco equipment and no one provided the budget to replace it with NSA-backdoor free Huawei equipment.

      Given what happened, I expect there to be a LOT of Cisco equipment on the secondhand markets in the next couple of years.

      (Also expect a lot of anti-Huawei rules to be removed in countries outside the US.)

      1. Bebu sa Ware Silver badge
        Coat

        Re: Old equipment - no budget for replacement

        "Also expect a lot of anti-Huawei rules to be removed in countries outside the US."

        Wasn't there a joint Huawei-European facility to clear Huawei kit of this skulduggery (more than ten years ago I think) but I was abandonned in some all-the-way-with-the-usa lunacy? All the way down the garden path to mind numbingly senseless buggery.

        1. Doctor Syntax Silver badge

          Re: Old equipment - no budget for replacement

          IIRC the reported conclusion was "clean but not great quality".

          1. Paul Crawford Silver badge

            Re: Old equipment - no budget for replacement

            Close, but pisspoor was used by El Reg:

            https://www.theregister.com/2019/03/28/hcsec_huawei_oversight_board_savaging_annual_report/

            1. sabroni Silver badge

              Re: Old equipment - no budget for replacement

              Wrap that in an anchor tag and you can post a link.

              https://www.theregister.com/2019/03/28/hcsec_huawei_oversight_board_savaging_annual_report/

        2. You aint sin me, roit Silver badge
          Black Helicopters

          Re: Old equipment - no budget for replacement

          Indeed there was. In order to be allowed into the UK's infrastructure Huawei had to fund an independent lab, associated with Cheltenham, to assess their code. No backdoors were found, just some shoddy code and poor use of multiple versions of open source libraries.

          Allegedly, when the lab applied the same evaluation criteria to other companies' gear their code was found to be even worse... allegedly.

          1. Anonymous Coward
            Anonymous Coward

            Re: Old equipment - no budget for replacement

            One would think the backdoors would be at a level below the regular firmware, like in the SOC microcode.

            1. Anonymous Coward
              Anonymous Coward

              Re: Old equipment - no budget for replacement

              It's not that easy to work your way all the way up the stack without it being noticed.

              Unless it's Windows, of course, but nobody sane runs networking gear on Windows.

              1. Paul Crawford Silver badge

                Re: Old equipment - no budget for replacement

                Unless it's Windows, of course, but nobody sane runs networking gear on Windows.

                Fixed it for you.

      2. Dbs5347

        Re: Old equipment - no budget for replacement

        It is VASTLY more feasible for the Chinese government to compel Chinese companies to install backdoors than for the US government to do the same with US companies.

    2. Anonymous Coward
      Anonymous Coward

      @sanmigueelbeer - In case you don't remember

      the VP of Huawei was arrested and detained in Canada at the behest of the US and being accused of allowing one of its subsidiaries to do business with... Iran of course.

      So Iran had to buy that backdoored kit.

      1. This post has been deleted by its author

      2. sanmigueelbeer

        Re: @sanmigueelbeer - In case you don't remember

        First off, Cisco et al cannot just sell kit to Iran directly. If I remembered correctly, almost all Cisco kit were delivered in a country that is not sanctioned and then sent on a truck to Iran for final delivery.

        Same goes, I guess for Huawei kit. Deliver somewhere in HKG, for example, and then hop on a boat to final destination.

        It can be done.

        Secondly, this is not the first time Iran's Cisco kit got hacked.

        https://www.theregister.com/2018/04/09/cisco_smart_install_clients_attack_vector/

        https://thehackernews.com/2018/04/hacking-cisco-smart-install.html

  6. JohnG

    I am surprised that anyone would be surprised that US intelligence agencies might want to use equipment being shipped to countries on their naughty list for espionage.

    That the Chinese are trying to pretend that they are squeaky clean in this is like the proverbial pot calling the kettle black.

    Having spent some years looking after networks and firewalls at two intergovernmental organisations in Europe, I was witness to almost daily attacks from Chinese sources I also dealt with the aftermath of successful Chinese attacks on third party systems that were outside our scope and perimeter.

    1. Yet Another Anonymous coward Silver badge

      >I am surprised that anyone would be surprised that US intelligence agencies might want to use equipment being shipped to countries on their naughty list for espionage.

      Yes because we assumed the American intelligence was mostly focused on attacking allies and trading partners

  7. Anonymous Coward
    Anonymous Coward

    Well of course the US used backdoors in networking gear and servers.

    Its the real reason they don't want Chinese gear in their or any of their Allies countries, because the Chinese gear has no backdoors, and the US can't spy on countries using Chinese equipment.

    1. Joe W Silver badge

      I'm pretty sure the Chinese gear has backdoors. Just not ones the US controls. I would call it negligent to not do this, we as consumers might not like it, companies won't like it but they will do it.

      1. Fido

        I see no reason to believe a spy agency, upon finding a backdoor in networking equipment manufactured by a hostile nation, would not proceed to use that backdoor themselves as needed.

        On the other hand, I'd be surprised if Iran over the years was able to procure large amounts of genuine Cisco networking gear. It's more likely counterfeit with the Cisco name printed on it. Also, I would not be surprised if counterfeit Cisco gear was the least secure of all.

        1. Anonymous Coward
          Anonymous Coward

          The only difference is that the knock-off Cisco gear was produced in excess of the quota made by Cisco's Chinese suppliers to meet their Cisco production goals, or it was made in the shadow factories built at the same time as the ones that Cisco actually knows about.

        2. Dbs5347

          It isn't going to matter. Israeli and US intelligence likely achieved persistence in Iranian networks years ago. They certainly would have tried and they likely succeeded just like China succeeded in achieving persistence in US telecom and other networks. It would be extremely naive to think US and Israeli intelligence wouldnt make doing the same in Iran a very high priority.

      2. Dbs5347

        You have zero evidence of any signuficant presence of government backdoors in equipment sold by US companies and the government has no legal means of compelling any such thing. Just another baseless conspiracy theory.

    2. Anonymous Coward
      Anonymous Coward

      Bad assumption

      Bad assumption to presume anyone's routers don't have backdoors, unless you build your own router from the ground up like put OpenWrt on a Raspberry Pi.

      1. R Soul Silver badge

        Re: Bad assumption

        That guarantees nothing. The only way to be sure your router has no backdoors is to build everything from scratch, starting with the sand used for the silicon. Read https://dl.acm.org/doi/pdf/10.1145/358198.358210. Here are a couple of snippets from this remarkable paper: " You can't trust code that you did not totally create yourself. ... No amount of source-level verification or scrutiny will protect you from using untrusted code." and "A well-installed microcode bug will be almost impossible to detect."

      2. Dbs5347

        Re: Bad assumption

        Bad assumption to assume they do absent any actual evidence and, particularly in the US government context, absent any legal basis to compel it.

    3. prh99

      I doubt that either are all that clean. Also you don't have to code an explicit backdoor, an exploitable flaw in a library or other code can be just as good.

      1. Dbs5347

        And the latter is likely all that was needed for Israeli and US intelligence to gain persistence on Iranian networks long ago. No deliberately designed backdoor needed.

    4. Dbs5347

      The vast disparity between Chinese government control of Chinese business and industry and the relative lack thereof in the US makes your claims highly illogical.

  8. TheMaskedMan Silver badge

    The left pondians would be pretty bloody stupid not to have backdoors, but just because they have then does not mean that China doesn't. They, too, would be pretty bloody stupid not to have.

    On the other hand, Iran would be equally bloody stupid to expect otherwise and not have taken precautions. Whether or not said backdoors have been used as Iran claims is debatable, though. While I'm sure they could be, it's also a good propaganda opportunity, and might be a useful excuse for getting pasted, too. It's not like Iran is the most open and honest country in the world, or the most technically capable.

    I doubt we'll ever know, but the notion of backdoored kit shouldn't come as a surprise to anyone.

  9. Claude Yeller Silver badge

    Disconnected?

    "Fortinet, and MikroTik either rebooted or disconnected during recent attacks on Iran – despite the regime disconnecting the nation from the global internet."

    I assume the commands to disable the routers must have been given before the disconnection of Iran. But nationwide router reset should set off alarms which could have warned Iran about the attack.

    I am wondering about the precise timing of events.

    1. Anonymous Coward
      Anonymous Coward

      Re: Disconnected?

      And how do you expect them to communicate if their communications channels have all rebooted? Carrier-grade routers don't boot in 15 seconds like a laptop.

    2. Claptrap314 Silver badge

      Re: Disconnected?

      The truth is the first casualty in war. Of course, the current regime in Iran exists in a continuous state of war.

      So yes, the truth would be VERY interesting. I have approximately 0 confidence in the various propaganda / news reports that come out. Baghdad Bob might be one of the most famous, but he barely stands out.

    3. Withdrawn

      Re: Disconnected?

      If I wanted persistent access for my backdoor I might have the device reboot if unable to access the Internet for x amount of time.

    4. DS999 Silver badge

      Just because the "regime is disconnected from the internet"

      That doesn't mean much. It means someone sitting in another country couldn't directly access those routers. But all they would need is one system that's connected to Iran's network, which is also accessible from the outside world.

      I would suggest embassies as one way in. Or more likely spies inside the country - you contact them and have them execute a preplanned cyberattack package of 0 days against the various infrastructure.

      Anyway if I had to bet this wasn't the US, it was Israel. They've been chomping at the bit to attack Iran since forever and finally got a US president dumb enough to go along with it. They've probably had double agents embedded there for ages and had all this stuff set up.

    5. Anonymous Coward
      Anonymous Coward

      Re: Disconnected?

      So any of those products in air-gapped environment should reboot randomly? Or every device can receive satellite messages - inside a metallic case, inside a metallic rack, in a concrete datacenter?

      While I do not exclude backdoor could exist, Iranians should set up their narrative better.

  10. Paddy

    Any open-source network switches?

    1. hammarbtyp

      wrong question - are there any open source enterprise level network switches?

      answer is no, because these are high performance, high capacity switches that are designed for backbone operation, not the kind of thing that sits on your home network

      also open source does not garuntee security. Apart from places security services polluting open source repositories, you need hardware support for secure opeartion, plus the skill and knowledge to lock it down appropiately

    2. Anonymous Coward
      Anonymous Coward

      white box switching and routing is a thing

      dell sell spine & leaf switches that run Open Networking OS

      https://opennetworking.org/onos/

      https://openswitch.net

      https://www.ruijie.com/fr-fr/support/tech-gallery/white-label-networking-oem-odm-solutions

      https://www.nomios.co.uk/resources/white-box-switching/

      https://stordis.com/what-is-a-whitebox-switch/

      https://www.reddit.com/r/sysadmin/comments/ud6p1x/would_you_use_white_label_switches_in_a_small/?solution=f11861a1bf968127f11861a1bf968127&js_challenge=1&token=bbbe4bf1c9a2b5160829c4be34da5861d24ca0cc43276ffb90c7412b874e12b0&jsc_orig_r=

  11. Nik 2
    Holmes

    Internal triggers

    There seem to enough anti-regime, and even pro-israel actors in Iran that I think it's more likely that the attacks were triggered from within the county than by some hypothetical satellite signal, surely? The beauty of cyber attacks is that the agent triggering them doesn't even need to know what they're doing, then can just be told to send am email or switch on a Raspi that's been sent to them.

    1. Anonymous Coward
      Anonymous Coward

      Re: Internal triggers

      Well, yes, they're known as Persians.

  12. elsergiovolador Silver badge

    Who

    The question always was who you wanted to smash your backdoor in - The "As seen on TV" or Temu lot with occasional drive-by Lada.

    1. Anonymous Coward
      Anonymous Coward

      Re: Who

      "The question always was who you wanted to smash your backdoor in"

      Perhaps, but I'm pretty sure a PG-rated tech site isn't the most appropriate place to discuss that sort of thing.

  13. ZedaZ80

    New prank idea:

    Can some body figure out the backdoors plz?? I wanna see how long we can keep our networks down.

    1. dadbot5000

      Re: New prank idea:

      It's like a snow day from school.

  14. Sproggit Silver badge

    Policy Change - in the Wrong Direction

    Thanks to Edward Snowden, those of us paying attention have been aware of these possibilities for more than a decade.

    However, what has been interesting is that we haven't seen significant evidence of the offensive use of cyber weapons/tactics/techniques by the US prior to this administration and the appointment of Pete Hegseth.

    Since Hegseth came on board, we know that he spends his days looking at war plans.

    We know that the US used offensive cyber techniques against ***Venezuela*** and ***Iran***...

    As even a moderately competent "Top Trumps" [sic] player will tell you - or "Contract Bridge" if you want to be a bit more formal about it, you don't play the strongest card in your hand to win a round when a weaker one will do. You play the weakest card that will be sufficient to win the round.

    What we've seen from the US military in the tenure of this Administration is perhaps best described as the bombastic use of offensive cyber weaponry where likely none were needed. Not when you're dropping bombs from 10s of thousands of feet and have no "boots on the ground". In other words, what we've seen from the US military is nothing short of strategic stupidity.

    Surely someone in the US DoD has told Command that there will be Chinese [or Russian] agents on the ground, collecting any technology suspected of being compromised by the US in order to enable forensic analysis and auditing to take place. Surely someone in the US DoD has told Command that deploying sophisticated cyber capabilities against a third-world nation which - outside of it's petrochemical sector - is based almost entirely on agriculture?

    I'm sure that China - and Russia - are celebrating. Just that I'm not sure that it will be for the reasons suggested here. Rather, I think that China and Russia are going to be so incredibly grateful to Iran for helping them to get a handle on US cyber-offensive capabilities.

    I'm sure that will come in useful when Putin invades his next neighbouring state, and/or China decides to take Taiwan by force.

    Another foot-gun moment.

    1. Claude Yeller Silver badge

      Re: Hegseth not US strategic mastermind?

      "In other words, what we've seen from the US military is nothing short of strategic stupidity."

      You want to tell met the Mad Red Hatter did not select the best of the best for his team?

      Unbelievable!

    2. Claptrap314 Silver badge

      Re: Policy Change - in the Wrong Direction

      There are many reasons to play strong or even strongest "cards" when a lesser one might win a particular engagement.

      We certainly did not need to nuke Japan in order to win. We just didn't want to lose a million of ours + three million of theirs to do it. We also wanted to make it clear to the Soviets that we had & were willing to make use of the weapons.

      In the case of cyber exploits, however, a major one is that vulnerabilities don't age very well. It's not "user or lose" like in a missile exchange, but EVERY SINGLE report of a RAT happens when they get discovered. When that happens, not just the discoverer, but most (hopefully all, but I'm not stupid) users then update their systems to close the back door.

      Another way to put it is, "Who said that the back doors we used were the latest/greatest/best?"

      1. Sproggit Silver badge

        Re: Policy Change - in the Wrong Direction

        Two quick observations on your points.

        First, there is plenty of evidence - if not overwhelming evidence - that the US had cracked Japanese Navy ciphers and had decided the message that informed the fleet of Japan's intent to surrender *before* Enola Gay dropped "Little Boy" on Hiroshima, on August 6th, 1945. I don't think that undermines the spirit of your argument - that sometimes you need to "make a move" that also "makes a statement" .. but I don't think I can agree with anyone who says that it was right to "make a statement" that resulted in the deaths of between 80,000-140,000 people, most of whom were civilians.

        Second, I may have failed to articulate my point clearly. In your reply you suggest that many vulnerabilities may be of the "use them or lose them" variety and this is why it made sense for the US to exploit those back doors before they were discovered and patched. I think there's something of an argument that we might be able to make in that regard... if the target had access to new technology and the budget to keep their tech and vulnerability patching up to date. But my point was much more "ATT&CK" than "CAPEC" - namely that the risk to the US was as much about "sources and methods" (Tactics and Techniques) as it was about specific vulnerabilities.

        For example, think about SPECTRE and Meltdown, the two high-profile speculative execution vulnerabilities that were found in Intel chips a little while back. As soon as news of those flaws became public, other researchers found similar vulnerabilities in other silicon. It wasn't knowing that SPECTRE existed on Intel chips that was the big deal, it was knowing how it was found, what to look for, how to scan an environment to find similar examples and so on.

        China, Russia and others are going to be able to "work backwards from the point of impact" and learn a great deal about US techniques. They may find forensic evidence left behind. They may find new ways to scan for the exploited vulnerabilities - once they know what they are and devise test to detect them for themselves.

        But most importantly of all... the last thing you want to be doing with your cyber offense capability is a "shock and awe" campaign. Not when you don't know who else is watching or what they will see.

        1. Claptrap314 Silver badge

          Re: Policy Change - in the Wrong Direction

          Wow. That's quite a load you've got there.

          1) There were not 80000 -140000 Japanese deaths caused by the bombs, unless you only count the immediately killed. A more realistic number is 400000.

          2) US war planners estimate 1000000 US soldiers, 1000000 Japanese soldiers, and 2000000 Japanese civilian casualties in the event of an invasion. The Japanese exhibited astounding martial spirit, which these numbers reflect.

          3) Even AFTER the second nuclear bomb, the Japanese cabinet voted to continue fighting. The Emperor intervened to bring about the surrender.

          4) Given the above, it is deeply insulting to suggest that the Japanese navy would consider surrender without being ordered to do so.

          5) As documented in David Khan's The Codebreakers, written in 1970, the US had the ability to read essentially all Japanese communications during the entire war. There is no "evidence" to trumpet 50 years after the fact.

          6) As for ATT&CK, feel free to pontificate as to how the game is played at that level. But what we've seen from the Spanish Civil war through the Russian invasion of Ukraine, second- and third-tier conflicts have historically been testing grounds for new systems by the major powers. We appear to agree that cyber warfare is fundamentally of a different character than what has come before. I don't agree that you or I have ANYWHERE near the amount of level of data to make sound judgements about the impacts of the use of such weapons.

          7) I never intended to suggest that cyberweapons are good for shock & awe. I was merely pointing out that war ain't contract bridge.

    3. Anonymous Coward
      Anonymous Coward

      Re: Policy Change - in the Wrong Direction

      China doesn't need to be grateful. They already know everything about US cyber-offensive capabilities because all that stuff is made in China.

      1. Sproggit Silver badge

        Re: Policy Change - in the Wrong Direction

        When you use the term "made" you may be implying hardware... But of course that is not true with software. And it is in software that vulnerabilities and exploits are most common [that's inherent to the "nature of the beast" - hardware is rarely as complex as software - with the possible exception of microprocessors, some microcontrollers and VLSI chips.

        We don't know the details of the cyber strikes or what specifically was attacked.

        But my hunch is that it will be software vulnerabilities that were exploited. Not an absolute certainty - Stuxnet is proof of that.

        But on a balance of probabilities, this was a software-based attack.

  15. Fruit and Nutcase Silver badge
    Black Helicopters

    Buy American to ensure no Chinese backdoors

    Buy Chinese to ensure no American backdoors

    1. retiredFool Silver badge

      Buy Euro

      to ensure neither US or China back doors. Come on EU, make some enterprise routers.

      1. Claptrap314 Silver badge
        Trollface

        Re: Buy Euro

        With their components designed in the US & manufactured in China....

        1. Paul Crawford Silver badge

          Re: Buy Euro

          Hopefully not the software...

          1. Excused Boots Silver badge

            Re: Buy Euro

            Yes but if the hardware/firmware is pre-compromised, then.....

          2. Fruit and Nutcase Silver badge
            Mushroom

            Re: Buy Euro

            ...it'll be offshored to India

        2. Anonymous Coward
          Anonymous Coward

          Re: Buy Euro

          ... and Ethernet done in Israel.

    2. Dbs5347

      The problem with this logic is that the Chinese government without a shadow of a doubt has the legal authority over Chinese companies to force them to backdoor equipment. The US government has no such legal authority over US companies. It has also tried this with apple and been rebuffed. It is therefore NOT equally probable that US and Chinese companies have installed government demanded backdoors on a wide scale. Very probable for China, possible but not probable for the US.

      1. Claptrap314 Silver badge

        I am particularly fond of when they sent NSLs to the major shipping companies redirecting all packages sent to particular addresses to a classified location wherein certain modifications were made to the items being shipped.

    3. Anonymous Coward
      Anonymous Coward

      Or buy a US device made in China to ensure you get the best backdoors of both worlds...

  16. tekHedd

    Oh I doubt...that it was just US equipment we hacked

    The claim is that the US engaged in cyber attacks, and *only* targeted backdoors in US made equipment? Now THAT is what I call BS. Obviously we would have used any exploits we know about, including those in Chinese-made equipment. Is there perhaps some doubt that the NSA knows where the backdoors are? That they don't have a stash of 0-days in reserve?

    We might have hypocritical propaganda, but we're not stupid.

  17. Anonymous Coward
    Anonymous Coward

    All backdoors eventually get leaked..

    As per the title, all backdoors will eventually get discovered or leaked and spread across the world.

    The most recent case of the iPhone malware called Coruna was suspected to be leaked by the government contractor L3Harris by a rogue employee.

    But the earlier version of the malware was discovered by the researchers at Kaspersky Labs when they discovered unusual network traffic coming from their own employees iPhones and they were able to extract and decompile the malware which led to the mystery of how the malware developers were able to exploit an undocumented and unused section of Apple's hardware.

    I highly suggest you read Kaspersky's fascinating reverse engineering of the iPhone malware and the fuzzing of Apples chips. It does raise many questions in the "Last Hardware Mystery" link below:

    https://techcrunch.com/2026/03/10/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine/

    https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/

    1. Anonymous Coward
      Anonymous Coward

      Re: All backdoors eventually get leaked..

      Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake. Because this feature is not used by the firmware, we have no idea how attackers would know how to use it.

      I'd suggest that the chip design that was approved to be sent to the Fab wasn't the chip design used by the Fab.

      1. retiredFool Silver badge

        Re: All backdoors eventually get leaked..

        Years back, a friend who does litho told me DARPA had been sending out feelers for how to verify a chip was what you thought it was. Because of that very reason. I remember thinking at the time that is crazy and a very poor way to ensure both that your design doesn't leak to a foreign entity and that your design isn't modified by a foreign entity.

  18. Groo The Wanderer - A Canuck Silver badge

    Anybody who thinks the USG has no backdoors into America products is a complete and utter fool. The very first thing someone who feels guilty about doing something does is accuse the opposition of doing the same thing, but for evil intent. Enter the claims about Chinese back doors.

    Meanwhile the European vendors sit on the sidelines and giggle at the political theatre the two "world powers" bicker over.

    Every government with a bent for surveillance has such back doors into their nation's products. And the vendors based there will deny it to the end because the back doors are "national security" issues that result in hard jail time if you talk about them, the same as if you were working for the military.

    1. Anonymous Coward
      Anonymous Coward

      If you think its the same as if working for the military, you're naive. Militaries have rules, governments don't.

    2. SundogUK Silver badge

      Also:

      Anybody who thinks the CCP has no backdoors into Chinese products is a complete and utter fool.

  19. DoctorNine Silver badge

    Willie Dixon

    "..the men don't know, but the little girls, they understand..."

  20. theModge

    Back in the day getting passed Irianian internet censorship had a price

    An Iranian friend tells me an internet connection that could get porn was a thing one could bribe an official for back when he lived there (15 years ago), the idea that the blockade is selective seems highly credible.

    People who can get phone signal from neighbouring nations use that as a solution too, now for contacting loved ones abroad, to assure them they're well during the war, rather than anything fun.

  21. dadbot5000

    According to Reuters, Huawei and ZTE are the largest providers of internetworking/telecom equipment to Iran, which isn't surprising since China and Iran used to have a cozy relationship. It is also almost certain that Chinese telecom equipment has built-in backdoors for the CCP to snoop on communications. No doubt US operatives are well aware of these exploits and possibly used them during Epic Fury. It is a war, after all.

    1. retiredFool Silver badge

      It was an illegal attack by the us, not a war. Plain and simple. And I'd like to see everyone involved from el trumpie to kushner to hegs to marco charged with war crimes and have them spend the rest of their lives in prison for it. It is no different than what russia did to ukraine.

      1. Groo The Wanderer - A Canuck Silver badge
  22. Dbs5347

    The most likely explanation is that 1. Iran's networks are not as isolated as they think they are. 2. That precious little is actually secured from state actor cyberwarfare even without an intentionally designed back door. 3. That Israeli and US intelligence achieved persistence on networks of interest in Iran long ago.

  23. PWgr

    How much Cisco gear even exists in Iran. Have to imagine most routers are Huawei with bootleg OS from 2000's. More vulnerabilities than Swiss cheese. Who needs backdoors.

    1. Jellied Eel Silver badge

      How much Cisco gear even exists in Iran.

      Lots. Sanctions only really work when people play by the rules, but money is money. So Iran and other sanctioned countries have often created businesses outside their borders. Set up a systems integrator or Cisco reseller/distributor in say, the UAE, Pakistan, Indonesia etc and ship some of the tin into Iran. Or disties might prefer money over the risk or threat of penalties for violating US or EU law and sell to Iranian entities anyway. Cisco's compliance people might try and conduct audits to spot sanction violations, but there's a lot of tin and probably not many compliance people. Then there's the second hand market as well.

      But it's something I've encountered a few times. Sales get excited about a deal into Iran. I point out that it's illegal and we can't ship tin there. Then it's the Iranian customer can supply the tin, can't we just manage it? And much the same answer, and if they'd want their commission paid into their commissary card. It's never been hard to supply, it's just the penalties for violating sanctions can be severe, with large fines and jail time for anyone involved in those deals. But I also had a curious contract offer from a well-known company via an arms-length subsidiary. Part of the contract included a pseudo-idemnity that if they got caught, they'd provide substantial legal expenses and compensation.. But as what they were proposing was outright illegal in the first place, I declined their generous offer. I was tempted at the time to report that one to TPTB, but there were also hints from the client that TPTB already knew.. But not a risk I was prepared to take

      The safe way though is to just apply for and be granted a licence, which happened one time, but more often applications were just refused.

      Vendor compliance has probably been made a bit easier with stuff like Cisco's PITA licence and update systems, and the potential to geolocate where tin might be sitting, then if vendors can give that tin a 'special' software version, or TPTB can insert that. But the politics can sometimes get interesting. So clients in the Middle East might specify no Israeli products, but the US has Israeli boycotts illegal. Then figuring out what, if any risks might be when things like Ethernet chipsets or SFPs contain their own microcode and might end up being used for something nefarious.

  24. Anonymous Coward
    Anonymous Coward

    Dirty deeds

    For a fee, I'm happy to be

    Your back-door man, hey

  25. Andy3

    'Chinese state media has seized on the Iranian reports to restate Beijing’s position that China is a pacifist in cyberspace'. Oh of course, I was forgetting....

  26. In the company of clowns

    It should be no surprise. About 15 years ago, I can remember the CIA/NSA backdoor chip was even listed on the Cisco product specification list for new routers and switches.

  27. heyrick Silver badge

    Hypothesise the presence of a back door?

    I'd be quite surprised if there wasn't such a thing.

  28. Anonymous Coward
    Anonymous Coward

    If you haven't figured out already...

    Cuba, Venezuela, Iran ... all (Belt and Road?) buddies of China.

    Iran is a side quest or bonus quest. The final boss is China.

    Once Iran is dealt with, I expect some action to commence in the Straits of Malacca and South China Sea. Refer to the recent US-Indonesia defence agreement signed. Combine that with Australia, Philippines, Taiwan and a Japan which might remove the post-WW2 pacifist shackles. And I believe Singapore was caught red-handed smuggling nVidia A.I chips and Iranian oil to China last year.

    I also expect Russia to backstab China at some point depending on some conditions, thus ending the Russia-China marriage of convenience, formed in 2022.

    It'll be a super exciting year, to say the least.

    TLDR: China is fecked.

    1. amanfromMars 1 Silver badge

      Re: If you haven't figured out already...

      That diatribe is worthy of Jackanory, AC. Bravo.

      1. heyrick Silver badge
        Happy

        Re: If you haven't figured out already...

        Following link to wiki-pee:

        Coverage of the live broadcast of the Apollo 8 mission in 1968 was interrupted so Jackanory could be shown.

        Priorities.

    2. Groo The Wanderer - A Canuck Silver badge

      Re: If you haven't figured out already...

      The only thing "fecked" is the people at ground zero when the bombs drop, and the people who survive at the fringes of the radiation fallout are double-fecked because now they've got to deal with psychos fighting over society's scraps and leftovers.

      The billionaires and autocrats will be just fine in their bunkers and bomb shelters, often luxuriously appointed far beyond anything we'd ever be living in. And that's what they consider "roughing" it.

  29. amanfromMars 1 Silver badge

    FFS Stop whining. Just find any of the Magic AI Buttons and press them for more than Just Fun Runs

    All governments are absolutely useless at not having to spy on everything and everyone in order to keep themselves and their backers in clover and their multiple enemies in the dark and pig ignorant about that which is able to disable and topple them.

    What do you think AI is really for ‽ The reinforcing of a whole host of right dodgy shadowy infrastructures/exoskeletons or ITs fast flash cash crashing of them?

  30. WSWS Bronze badge

    It's plausible that the US might have backdoors - though hoarded zero-days are perhaps more likely. It's just as plausible that Iran are lying. What is in no way plausible and you're an idiot if you believe it is that China does not have any backdoors in *their* hardware.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon