6 comments

[ 3.3 ms ] story [ 27.0 ms ] thread
> Dave Aitel, 46, a former NSA computer scientist who ran his own security shop, Immunity, for many years...was no less severe on Linux, noting that the biggest contributor to the kernel was the Chinese telecommunications vendor Huawei Technologies, which he claimed had been indicted by the US, and asking how one could rest content if so many patches were coming from a company of this kind.
“Ex NSA running a consulting/security shop” has become an identifier for wolf-calling by far.
No alternatives were provided. We should, what, leave any vulnerability identified by China as-is?

Just because it's possible that a fix may contain a logic bomb should not rule out the fix. The author of a software change is less important than the merit of the contents in the change.

All good points. I don't know what the interviewee expects to happen though. Ban @huawei.com emails from the mailing list? On what grounds? Without an ironclad case against Huawei, kernel contributors in China could take offense, and contributors around the world would surely lose some faith in the transparency of the kernel development process.
Huawei was targeted by US sanctions for political reasons. The intent was to prevent Huawei from becoming too dominant in the 5G space.
It seems they are not aware that most of Huawei's contributions are board-specific to their own hardware, not code running on 99.999% of built kernels.