Unlikely Voter

Conservative views on polls, science, technology, and policy

Archive for May 14th, 2018

Marco Rubio took to Twitter this morning to call the President’s statements on ZTE “crazy,” but the situation is actually worse than he lets on.

Rubio directly quoted Donald Trump’s statement and didn’t hold back:

Yes, it is “crazy” to allow ZTE free access to our technology. But it understates the case to say that ZTE “can be forced to act as a tool Chinese espionage”. The company is rigged to be a tool of espionage.

Take a look at the ZTE Board of Directors. Vice Chairman Jianheng Zhang is tied to CASIC, a state-run military contractor. Vice Chairman Jubao Luan, same. While Chairman Yimin Yin is allowed to have his title, the state military-political apparatus is there to watch him, and make sure ZTE is there to service the state whenever necessary.

Other board members are tied to the government in other ways, such as the People’s Political Consultative Congresses, which are organs for the Communist Party of China to direct policy.

This is the corporation Donald Trump is directing the Commerce Department to support. It really is crazy.

For over 25 years, people have relied on cryptography to protect themselves from more powerful snoops, such as governments. Some panicked tweets have gone out, that have done more to mislead than aid people. Here are the facts.

According to Sebastian Schnitzel, every major means of encrypting email is broken. Pretty Good Privacy (PGP, a cryptography core), GNU Privacy Guard (GPG, an open source clone of PGP), and S/MIME (a protocol for encrypting email) are implicated. He recommends that people stop using encrypted emails.

But there’s more to it than that. The GNU Privacy Guard team was not even notified. That is a clear indicator that PGP and GPG have nothing to do with the security hole in question. So we’re left with S/MIME. And guess what: the real problem is that email clients are loading external websites linked in emails, such as images.

The key line, buried way down in “EFAIL” website:

The EFAIL attacks abuse active content, mostly in the form of HTML images, styles, etc.

So stop using HTML email, and you’re fine. Relax, folks. It’s just bad clients doing bad things. Cryptography is secure. Just stop loading HTML.