More on Lenovo

A few days ago I discussed the US State Department/Lenovo deal and the theoretical security implications that have led some congressmen to get rather hysterical about the whole thing. Since then, the story has only grown, being featured on the front page of the BBC News site, among others. The BBC piece mentions the following.

The State Department is spending about $13m (£7m) on the Lenovo computers, which are assembled at factories in North Carolina and Mexico.

Mr Carlisle added that the circuit boards are originally made in US ally Taiwan, and not mainland China.

According to an article on Dailytech.com, computers assembled entirely outside of the PRC are in fact “an oddity in the PC manufacturing business.” They go on to say:

If US companies are intimidated by probes of the USCC, such probes could be easily applied to virtually every PC manufacturer in the US: Intel motherboards are built by Taiwanese Hon Hai Precision Industries from facilities in Shenzhen; Acer components are built by component manufacturers in Shanghai; Dell PCs are assembled in factories in Suzhou and Shanghai. The same spokesperson went on to say “We [Taiwanese manufactures] do more work in China than we do anywhere else in the world. I don’t even want to think about what would happen to our US clients if we got a USCC probe.”

CDW Government, the company originally contracted to fill the orders for the US government also carries several brands that are assembled in the PRC including Acer, BenQ, D-Link, HP, Sharp and Toshiba.

Really, this entire minor uproar is at best absurd and at worst moronic and insulting. In my previous post I briefly discussed some theoretical ways in which the Lenovo PCs could be bugged, but I don’t in fact believe that there is any more of a real security risk in purchasing Lenovo computers.

Various PC components are manufactured all over the world. Here’s a brief listing off the top of my head of country of manufacture labels that I have personally seen on hardware that I have owned and used.
Hard drives: Japan and Thailand
CPUs: AMD, Germany Intel, Singapore, Malaysia
RAM: Korea, Japan, Germany, Taiwan
Motherboards: Taiwan, China
LCD Panels: Korea, Japan, Taiwan

While this absurdity may not go anywhere, Lenovo may have far more serious problems down the line, of a non-political nature.

KSG students do a good job of keeping up stereotypes

Some Harvard kids got some intimate time with Shinzo Abe and Seiji Maehara. So guess what the Korean wanted to ask about?

Wait for it…

A student from South Korea said Abe’s stance on visiting Tokyo’s Yasukuni Shrine, which honors Japan’s war dead as well as Class-A war criminals, did not come up during the meeting due to time constraints.

Hahahahaha. Riiiiight.

“If he (Abe) becomes the next prime minister, there would be no improvement in Japan’s relations with South Korea and China,” the student said on condition of anonymity.

However, the student also said Maehara was an engaging politician who gave “clear comments” on the party’s stance against acts of worship at the contentious Yasukuni Shrine by top Japanese political figures.

Meanwhile, the Anglosphere types are more concerned about different issues:

Andre Stein of Australia held a different view, criticizing the DPJ’s contradictory stance on national security.

“While Maehara agrees with U.S. (military) protection of Japan, the party is not interested in supporting the allied forces in Iraq,” he said.

One’s concerned with mismanaging the past; the other’s concerned with mismanaging the future. To be fair, the Japan Times only published two opinions; perhaps they’re just looking for what they think is most conventional.

Congressmembers accuse Lenovo of spying for China

About two weeks ago I wrote a post about the security implications of buying a Lenovo, or any other brand of PC, manufactured inside China for the domestic market, following reports that Lenovo was including a government approved encryption module on their system motherboards. While I recommended caution when buying a domestic Chinese computer, I was not particularly concerned about the possibility that machines manufactured for the foreign market would be so compromised.

Well, it turns out that the US Congress is a little bit more suspicious of China than I am. (Gee, who would have thought?) The New York Times today is reporting that a number of Congressmembers from both parties are in an uproar over an announcement that Chinese-owned Lenovo computers has won a bid to supply 15,000 machines to the US State Department.
Red IBM

The critics warn that the deal could help China spy on American embassies and American intelligence-gathering activities, using hardware and software planted in the computers.

“The opportunities for intelligence gains by the Chinese are phenomenal,” said Michael R. Wessel, a member of the United States-China Economic and Security Review Commission, which was created by Congress to monitor and report on the bilateral relationship. Larry M. Wortzel, the commission’s chairman, said in an interview two weeks ago that while he would not be concerned if Airbus moved an aircraft production line to China, he would be worried if Lenovo ever started to sell computers to American government agencies involved in foreign affairs. Responding on Thursday to the Lenovo deal, he predicted that, “Members of Congress, I think, will react very strongly when they see a deal like this come through.”

The opposition seems to be a combination of misguided economic nationalism, mixed with a vague but real appreciation of possible security concerns. Surprisingly, this article does not mention the security chip Lenovo has been installing on their domestic models. Now, it would of course be trivial to see whether nor not that chip is installed on the machines being purchased by the State Department, but doing a full-blown security audit would probably be enough trouble so that it would become more economical to just go to the next lowest bidder instead.

The real question is this: are the possibly security concerns serious enough to justify the panic? Supporters of the deal point out that the computers will be used only for unclassified work, but honestly that shouldn’t do anything to relieve you. Most of the government’s paperwork is unclassified, but still not public-think of things like personnel records and so on that would be of great usefulness as intelligence.

Now, how possible is it that Lenovo could build a back door into the systems, that routine security procedurs (and let’s assume, perhaps incorrectly, that the government follows correct security procedure) would not stop? The security chip mentioned in my earlier post would probably not be used for encryption, in favor of a standard software solution. There could be some sort of back door hidden in the BIOS, but on modern operating systems, the BIOS code is no longer running once the OS starts. (Note, EFI is a whole other kettle of worms, but let’s not get into that now.) And I would hope that standard procedure is to do a clean install of all software of of a disk image file prepared by government IT personnel, so as to make sure that all security settings are correct, and there is no possibility of a disk resident trojan.

What is the final conclusion? I don’t have a firm answer, not having nearly enough information or time to analyze it, but I would be interested to hear other thoughts on the matter.

Man uses machete to chop off hand in front of Diet building

Report from The Mainichi:

A man almost completely severed his left hand with a machete in front of the National Diet Building on Tuesday, apparently to protest policies toward North Korea, police said.

The 54-year-old man approached the front gates of the building by car, stepped out, silently placed his left hand against the hood of his car and swung the 40 centimeter blade down across his left wrist, according to Tokyo police official Hideyuki Yoshioka.

The man, who identified himself as a member of a right-wing organization, then mumbled a few words about Japan’s handling of the abduction of its citizens by North Korea in the 1970s and 80s. Police snatched the machete and rushed him to a hospital, Yoshioka said.

The man “appeared to be in a lot of pain and his hand was hanging by a piece of skin,” according to Yoshioka.
[…]
Last October, another man linked to Japan’s extreme right tried to commit suicide outside the prime minister’s office by downing pesticide. Police said he was carrying a letter demanding that the prime minister pay his respects at a Tokyo shrine that honors Japan’s war dead, including convicted war criminals.

In the past year, a woman has also tried to kill herself by ritual disembowelment in front of Koizumi’s office, demanding the leader resign.

Curzon, if this keeps up, it looks like you may not be able to make fun of Korean as easily. What’s a few psychos over there cutting off fingers compared to entire hands in Japan?

Where are they Now? Nasubi edition

A commenter asked us whatever happened to Nasubi, the aspiring comedian who allowed Japanese TV to kidnap him and force him to survive by entering sweepstakes in 1998.

Well, as usual, Wikipedia has the answer (paraphrased):

Nasubi’s feature is, as noted by his stage name (Nasubi means “eggplant” in Japanese), his 30cm-long face. He has sought a dramatic acting career since he started, and is currently active mostly in stage productions. In 2002 he founded the “Eggplant Way” and serves as its chief.

Recently most of his television appearances have been on local programs in his native Fukushima, but in 2005 he appeared in national TV dramas “Train Man” and “Trick New Special.”

Looks like he survived his near-starvation experience to go on to moderate success as an actor. Good for him! Check Nasubi’s official website (Japanese only) for appearances. He also keeps a pretty regular diary (latest entry):

So, so strong!!

The World Baseball Classic semifinals… The overall game made me numb, but the third time’s the charm! This game showed us Japan’s sticktuitiveness? or its latent energy, it was 110% worth seeing (*^_^*)

Both teams…had very fine plays, also plays where they had to make up for mistakes, and I got the deep impression that we can be proud of Asia’s high level of baseball throughout the world!!

But truthfully? Don’t you feel kind of bad for Korea?

3/19/2006 (Sunday)

Umm, not really! I was just watching Japan trounce Cuba in the finals (right now it’s 6-3 in the bottom of the 8th). Once, when Ichiro was running home, he actually stopped the 3rd baseman from throwing home by intentionally blocking his line of vision. That’s some superhero shit, my man.

Rare Chinese frog uses ultrasonic communication

It may not be a mutant per-se, but it sure is an evolutionary rarity. From Reuters:

The frog, Amolops tormotus, is the first non-mammalian species known to use the ultra-high frequencies that humans cannot hear.

It comes in handy to be heard above the pounding waterfalls and streams in the mountainous region of east-central China where Amolops tormotus, which is known as the concave-eared torrent frog, lives.

Saipan, Desperate for Japanese Tourist “reparations,” Offers to Open its Own Version of Yasukuni

The governor of Saipan has made a morbidly cynical offer to the Japanese families of those who died in the bloody Battle of Saipan:

Banzai Cliff as cemetery for Japanese war dead?

By Agnes Donato
Reporter

Monday, March 13, 2006

The Banzai Cliff in Marpi could soon turn into a cemetery for the Japanese war dead, with the governor offering the property to the families of World War II soldiers who lost their lives on Saipan.

Gov. Benigno R. Fitial announced Friday that he had received two pledges of donation amounting 10 million Japan yen (about $84,000) each for the planned cemetery.

A separate offer of $100,000 has also been made for the sole benefit of the Public School System, he said.

“I am making land available at Banzai Cliff for Japanese groups to build a temple. This temple will be a token of our appreciation for the Japanese people visiting Saipan. I am also offering the same property to all the families and relatives of 47,000 war heroes who lost their lives here on Saipan to come and erect monuments,” Fitial said during his weekly press conference.

I can’t think of a more depressing idea. The Banzai Cliff was what hundreds of Japanese civilians jumped from in the aftermath of the battle. They chose to end it all rather than be raped and tortured by the Americans (UPDATE: …or so they may have believed. Another blogger, objecting to this “spin” – though it was unintentional – helpfully pointed out some of the sacrifices US soldiers made to save Japanese civilians in Saipan. Take a look.). I remember seeing on the History Channel a mother jump with her child no more than 50 feet from the American soldiers who looked on with a video camera rolling.

But will this save Saipan’s embattled tourist industry? It remains to be seen:

Tourist arrivals from Japan continue to drop as a result of Japan Airlines’ decision to cease all regular, scheduled flights to Saipan in October 2005.

Data from the Marianas Visitors Authority showed that the CNMI received only 25,555 visitors from Japan in January 2006. This represents a 29-percent decline compared with the 35,795 Japanese who came to the islands in January 2005.

But MVA is hopeful that the Japan market would recover when Northwest Airlines increases the frequency of its Tokyo flights beginning next month.

Northwest, which currently operates seven weekly flights between Saipan and Narita, will have 10 flights a week between the two points starting April 24, 2006.

The new service will operate a second Boeing 747 jumbo jet from Tokyo, flying three times a week. The aircraft will carry 400 economy and 30 business class passengers.

Homework assignment: Does anything similar exist in the world? There are certainly things like the Normandy memorial or Auschwitz, but are there any war memorials designed almost purely as tourist traps? I’m kind of offended — maybe Saipan does suck!

Does China own your box?

There have been rumours going around that Microsoft has been cooperating with the US government to build secret backdoors into the upcoming edition of Windows known as Vista to allow easy government access to all of your private data. Well, Arstechnica yesterday did what I think is a pretty good job of putting that particular rumour to rest, primarily with this quote from one of Microsoft’s cryptography programmers.

Over my dead body.

Well, maybe not literally-I’m not ready to be a martyr quite yet-but certainly not in any product I work on. And I’m not alone in that sentiment. The official line from high up is that we do not create back doors. And in the unlikely situation that we are forced to by law we’ll either announce it publicly or withdraw the entire feature. Back doors are simply not acceptable. Besides, they wouldn’t find anybody on this team willing to implement and test the back door.

If you stop and think about it, it’s really a rather absurd idea for Microsoft to add a “feature” like that. It would provide them with no business advantage, since they’re already going to achieve high market penetration based on other features, without having to agree to the NSA’s Big Brother demands.

Now, on the other side we have China. Last year this brief article was published.

Lenovo Group on Monday in Beijing released China’s first security chip – “Hengzhi” which has been approved by the State Encryption Administration and independently developed by the company.

It means that China’s information security-sensitive departments in the government, military and research institutions can now purchase safe PCs independently developed and controlled by Chinese.

According to relevant regulations the design, development and manufacture of China’s encryption chips must rely on independent domestic ability and are forbidden from using relevant foreign products.

Safe Lenovo PCs installed with Hengzhi chips will provide security-sensitive departments in the government, military and research institutions with PC terminals completely developed and controlled by Chinese.

As learned Lenovo will officially launch safe PCs installed with Hengzhi security chips within this year.

hengzhi
A reporter is taking photo for Lenovo’s Hengzhi chip at the 8th Beijing International High-tech Expo.

You may remember Lenovo as the company that now own’s what was formerly IBM’s popular Thinkpad brand of notebook PCs. What you have probably never heard of, however, is the State Encryption Administration. Unfortunately, little information is avaliable in English about China’s encryption regularions (and I wouldn’t be surprised if much of it isn’t even publicly avaliable in Chinese.) We do know, however, that this group was first created in 2000, and while specifics are unclear, the basic framework implemented by the law was as follows:

Import into the PRC: The import of foreign encryption products will only be permissible if approval has been obtained from the State Encryption Administration

Sale/distribution: Encryption products can only be sold or distributed within the PRC by entities which have acquired special permits. Such permits are unlikely to be granted to non-PRC entities such as foreign invested enterprises.

Manufacture: Restrictions also apply to the type of entities which can manufacture encryption products, and such products will require approval.

End-users: Users of foreign encryption products, in use prior to the introduction of the new law, must have registered such use with the State Encryption Administration by last January 31 2000 in order to continue using such equipment. In addition, unlike PRC entities, foreign users must also obtain approval for the use of encryption products.

What this basically means is that any encryption product imported to, or sold in China requires government approval, and I think it is fairly safe to assume that said approval requires a backdoor of the very same type as the rumoured Microsoft one.

In a wonderful bit of double-speak, another news tidbit describes the hengzhi chip as a “significant breakthrough in the field of trusted computing technology.” I presume that the breakthrough in “trusted computing” would be knowing in advance that you cannot trust your own hardware to protect your secrets no matter what procedures you implement. Clearly this does, in the most pedantic sense, represent a breakthrough of a kind.

This article, also referenced by Ars, has a little more to say.

“Lenovo ships a lot of PCs inside China with a Chinese government chip instead of the TPM,” he says. “We don’t know what it does.”

The obvious fear is that the chip gives the Chinese government the ability to access any encrypted communications, something that seems particularly sinister in light of the recent allegations that American technology companies (in particular Yahoo) have helped the Chinese government locate dissidents. But Anderson emphasizes that these machines are only sold within China. “They’re completely unsuitable for the American market,” he says.

The last part is important. While many of are computers are assembled in China, I don’t think that there is any significant danger that secret Chinese spy chips are installed in your Dell, Apple, or even Lenovo computer. Were such a thing discovered, it would immediately trigger the highest level sanctions against the Chinese government, and probably cripple their subcontracted manufacturing industry overnight. However, it seems to be certain that any new computer you buy inside China will most likely have this chip installed, and even a moderately lower price is not, in my mind, enough to make up for inviting the secret police into your secret documents. It may sound paranoid, but I would strongly caution anyone to reconsider a decision to buy computer hardware in China, and if you want to get a cheaper but well made notebook PC, just save your money for a nice Taiwanese Asus or BenQ .

A question of national economic security

I’ve been posting recently on the global backlash against FDI. So, in scanning today’s news, this headline caught my eye: “INTERVIEW-China official slams foreign investment spree.”

Here’s a sample:

Li Deshui, head of the National Bureau of Statistics, called for legislation to curb “ill-willed” acquisitions of domestic companies by foreign firms… Echoing recent concerns over China’s sale of stakes in its major banks to foreign investors, Li said that unchecked acquisitions by foreign multinationals could pose a threat to China’s economic security.

Reading this latter remark made me wonder just how one nation’s “economic security” should be defined. Where does one draw the line? Borders are the obvious place to start, but everyone knows that this is no longer true. The same may be said of nationality.

Let’s face it, when it comes right down to it, when someone (be it a company or an individual investor) stands to lose millions or even billions of dollars on an investment, national economic security goes right out the window along with concern for everything else but one’s own ass.

Think about a bank run: are those people lining up to withdraw their deposits before the next guy concerned with national economic security? Of course not. They’re worried about their own damned money.

I don’t mean to downplay the seriousness of the issue. “Bank runs” on an international scale are exactly what governments are worried about. But they should consider other ways of preventing such things from happening (i.e. better policy or more effective regulation) than by prohibiting them altogether. You don’t deal with bank runs by outlawing banking; you deal with them by creating systems of deposit insurance, by providing lenders of last resort, and by requiring banks to keep a certain percentage of deposits on hand at all times.

Say it with a nose

From the greatest magazine on Earth:

This Valentine’s Day in Shanghai, people said “I love you” not with roses but with noses. Business at Shanghai’s plastic surgery clinics has risen by 30% since the beginning of the month, a trend fuelled by Valentine’s Day and the Chinese New Year, when young people receive job bonuses and cash presents from relatives. Some clinics offered special Valentine’s Day packages, such as a 20% discount between February 14th and 17th. The most popular treatment was for couples to opt for matching noses, or to have their eyes reshaped.

Liu Yan, who is 24, was quoted in a newspaper as saying, “I suggested it [to my boyfriend] as a way of celebrating our relationship and bringing us closer together with a special kind of bond.” Miss Liu said her 28-year-old boyfriend “loved the idea of matching noses”, and readily paid the 10,000 yuan ($1,200) for the surgery.