CyberWire Daily - This call may be monitored. [Special Edition]
Episode Date: September 7, 2026In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese ...state-owned telecommunications companies inside U.S. internet infrastructure. The House Select Committee on China says China Mobile, China Unicom, and China Telecom remain deeply embedded in American networks even after federal regulators denied or revoked their authority to provide certain telecommunications services over national security concerns. The investigation found that restrictions imposed by the FCC limited what the companies could sell, but did not necessarily remove their equipment, network connections, or commercial relationships from the U.S. internet ecosystem. Links to stories: Stranger Pings: Chinese Telecom Companies Infiltrate U.S. Infrastructure
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Hello, Maria Vermazza is here.
And thank you for joining me today on this Labor Day, 2026.
In our chat today, we're going deep on a new report from the U.S. House of Representatives Select Committee on China.
And that report is called Stranger Ping's Chinese Telecom Companies Infiltrate U.S. infrastructure.
And to go into this discussion, I'm joined by none other than the host of the Cyberwire Daily, Dave Bittner,
and longtime friend of the show, Brandon Karp.
He is the leader of public-private partnerships at NTT.
Here's our conversation.
It is always my pleasure to get the gang back together here,
which is what we've done here today.
I've got Maria Vermazas, host of the T-minus Space Daily,
and also regular presence here on the Cyberwire Daily.
Maria, welcome back.
Thanks, Dave.
I should mention it's the T-Minez-Space Cyber Briefing.
We're not the daily anymore.
I'm sorry.
You know that it's hardwired in my brain.
I know. I know.
It's so good I wish it were still a daily.
How about that?
At least the music.
At least the music's the same.
We kept the music. That's right.
That's right.
And that other voice you hear is, of course,
Brandon Karp, who is the leader of international public-private partnerships at NTT
and our former N2K Cyberwire colleague here.
Brandon, welcome back.
Howdy, howdy, as they say, out west.
So you brought me this topic that you wanted to dig into today,
and this is a report from the select committee on the strategic competition between the United States and the Chinese Communist Party,
which just rolls trippingly off the tongue.
Great name.
Yeah.
And this is about telecommunications and kind of where we stand with the CCP when it comes to those sorts of things.
Let's start off with some background here.
What drew your attention to this and why do you think it's something worthy of discussion here today?
Yeah.
So first, the name.
The name is just fantastic.
Stranger Pings.
Yeah.
You know, it's immediately captured my attention.
But, you know, broadly speaking, this is a topic near and dear to my heart.
My background is, you know, networking and telecommunications.
And it just seemed relevant.
And so, you know, digging into this, right, this, as you mentioned, was the House Select Committee on the CCP.
It's a bipartisan committee, right, across the board.
And the trigger for this committee was something that, you know, everyone in our industry knows well,
which was the Salt Typhoon Revelations in the fall of 2024.
And they started this committee and had some hearings in 2025 through the rest of 2025.
And then this seems to be the kind of key report coming out of the committee's work related to
China telecommunications companies and U.S. telecommunications.
So continuing with the context here, where do we suppose we stood coming into the
the creation of this report.
I do want to kind of tease this, and this is probably worth the longer discussion here today,
because this is just one report in a whole ecosystem of actions from Congress and the FCC,
countering China technology and, you know, this CCP cyber threat activity.
And so, you know, it's one little piece of evidence in a longer chain of things.
But this particular piece I found interesting because it's a pretty complex report.
They had a bit of technical information in the report itself.
And then they had a whole series of recommendations for the FCC and Congress to take on,
including some that were a little surprising in terms of like controls and regulatory controls
and trying to oust China telecommunications companies from the U.S. ecosystem.
But some of them seemed legit.
Some of them kind of missed the boat a little bit.
At the end of the day, though, I mean, what they're addressing,
in this report. The problem specifically is that there are, to this day,
Chinese state carriers that rent space and plug into U.S. Internet hubs.
And these Chinese state carriers run from Hong Kong,
and there are really no local records being retained in terms of log records
within the U.S. where these telecommunications or Chinese state carriers plug into the U.S. system.
And so their fix, their calling is to kick them out, right?
kick out these Chinese state carriers, totally cut the connections, pull their racks out of
U.S. data centers, and then fund another big cleanup, rip and replace. And that another is kind of
a little tease as well. When I think about the context of all this with Salt Typhoon, I want to say
that the gist of it that I have understood is telecoms have essentially told the government or anyone
who will ask. Yep, Salt Typhoon happened, and we just assume that Chinese agents are,
their presence is embedded in our systems and we will never get them out. So,
hmm. First of all, is that correct? And second of all, I mean, is that sort of what this report
is reacting to? Is that sort of throwing hands up in the air going, we can't do anything about it
anymore? Maybe a little bit. I think more what this is, is Congress felt like they had to do
something after the revelations in fall 2024. And so they,
subpoenaed the Chinese telecommunications companies and of course were ignored by them.
And so they ended up putting eight employees under oath. And then, you know, based on that testimony,
they built this report and their findings based on some of the interconnections, right,
as I mentioned, between the Chinese state carriers and the U.S. carriers and their findings,
which, you know, they did find that China's mobile networks was on the road to the hackers' servers
in terms of kind of the activity that could be traced.
They, you know, in a number of incidents,
they found that, yeah, okay,
the path that Salt Typhoon took
into and out of U.S. telecommunications
went through these Chinese telecommunications companies,
which, quite frankly, is like saying,
you know, we caught the man eating cereal
and he was doing it out of a bowl.
It's kind of like...
Shocked.
Shuck.
Duh?
If there's an actor or some sort of...
sort of a system in China to get in and out of China through the internet, they're going to have
to go through Chinese carrier. So that seemed a little bit of like a sensationalized nothing burger
that just kind of misses the point of how the global network is actually, you know, connected.
But at the end of the day, it is still responding to what you pointed out, Maria, which is this,
the issue of Salt Typhoon getting into the telecommunications backbone of the U.S.
and kind of finding their way into things like the Lawful Intercept Program,
where telecommunications companies retain records that the FBI can warrant and go and search
and things like that and call data records.
So some pretty serious amounts of information.
Yeah.
Let me key off of that because when you talk about the point of presence capabilities within U.S. data centers, right?
Are you asking me to believe that our intelligence,
agencies aren't keeping an ear on those points of interconnection?
Yeah, so that's kind of surprising, right?
Because, you know, one of the key recommendations of this report was exactly what you're
kind of alluding to, which is, you know, get these points of presence out of the U.S., totally
disconnect and kind of force these Chinese telecommunications companies from having exchange
points or points of presence in U.S. data centers, which all that's going to do is move points
of presence out of the U.S.
And the nice thing about having points of presence in the U.S.
is the FBI can knock on the door and go in.
Right.
And, you know, when they're in the U.S., they're under U.S. regulatory controls,
which means the FCC could say you have to retain logs.
And those logs have to go back a certain number of days,
and they can be searchable and yada, yada, yada,
which is not something the FCC necessarily has done,
but they could if these points of presence are still in the U.S.
So that recommendation of totally extracting, whether it's the CCP or just some other foreign nation's infrastructure from the U.S., leaves something to be desired because of the way the global Internet works, right?
They're going to go through points of presence somewhere.
They're going to transit people's infrastructure.
If it's in the U.S., the U.S., the U.S. has lawful intercept programs where warranted searches, they can go and look at those things.
Right.
So tearing those out could potentially hurt our visibility into what's going on.
Right.
Yeah.
Yeah.
How about the hardware itself?
I mean, we've got – this report points out that there's Chinese manufactured networking equipment that's still operating in U.S. networks.
Can you touch on the significance of that?
Yeah.
So this kind of goes back to the how we got here piece where there's kind of these three phases of the control –
specifically the CCP and Chinese interconnects within the U.S. system.
And the first phase was really about the physical gear, right?
So from 2012 to 2019, there was a whole series of regulations and controls and rules that were banning,
focused on banning the gear, right?
Huawei and ZTE primarily, which is the kind of telecommunications equipment.
And there was a big rip and replace program that was stood up towards the end of that period.
Now, that program originally was subsubstably.
to the tune of $1.9 billion.
That has since grown to $5 billion.
And by the way, it's six years later in the program's only 42% complete.
Wow.
So we're still not, you know, not even to 50% ripped out of U.S. systems.
Now, there's not a ton in the U.S.
The U.S. is primarily other infrastructure providers, but there's still a good amount.
And so the report does kind of focus on that infrastructure and the fact that there are still, you know,
58% that needs to be ripped out.
The problem being, in my perspective,
and I'd love to hear y'alls,
that is kind of a whack-a-mole approach to this,
which is, you know,
it's not answering the question of
why is there Huawei and ZTE equipment
in these networks in the U.S.
This rip-and-replace program doesn't solve that problem.
Hmm.
I mean, my assumption, I'm doing a lot of assuming in this episode,
my assumption was just that it's expensive to do all this,
And it's just, it was just financial as a barrier.
So me looking at the takeaways from the policy recommendations saying, you know,
the U.S. federal government might help fund Rip and Replays.
My initial reaction was, okay, great, maybe that'll solve that problem.
But I'm sure it's not nearly that simple.
Well, I'm also reminded of the stories we've heard over, I don't know, the past decade or so,
about when people ask, but why can't we build the iPhone in the U.S. of A?
And people talk about how we no longer have those capabilities
or it would take us a long time to get those,
to be able to do that.
And so that leads me to the question,
do we feel like we're in a position
where there are viable alternatives
to replace the Chinese hardware when it gets ripped out?
Yeah, that's a great point, right?
And I mean, the big Western, not necessarily U.S., right,
but Western technology providers
who provide this infrastructure
are Erickson, Nokia, and Cisco, of course.
And all of those systems, right, a one-to-one comparison,
they can cost anywhere from 50% to 100% more
than a Huawei or ZTE device.
And that is a huge problem.
And I mean, part of the reason it's so much less expensive
to purchase Huawei and ZTE is because Huawei and ZTE are subsidized
by the CCP in China.
And so they can do this at a lower cost,
And at the end of the day, right, when these networks are standing up, especially in rural regions, not just in the U.S., but other parts of the world, think a lot of networks going up in places like Nigeria and Kenya right now, who's going to win the contract is going to be the least expensive.
In most cases, that's going to be the – I mean – economics win. Yeah. Yeah. Yep.
So it seems like it practically needs to be like a grants program to incentivize people to do this.
You know, we will tell us what you have and we'll replace it for free.
Yeah.
And I think that's one of the areas where this report, that this report really gets wrong,
which is it pushes for another rip and replace program.
Supplemental, on top of the existing rip and replace program that's been going on for nearly
half a decade and is only 42% complete and it's cost of $5 billion, which, by the way,
rip and replace is three times as expensive.
It's just getting there in the beginning and getting, you know, the, the,
systems in that we want. But there's no program, there's no coalition of like-minded countries
to support the competitor in the market. The competitors, whether it's Nokia, Erickson, Cisco,
or some other unnamed organization to compete with Huawei and ZTE. And right now, Huawei and ZTE are
deploying infrastructure all over the world in critical regions in South Asia and Southeast Asia and
Africa. And, you know, these regions where these networks are going up and they're going up
with Chinese equipment, not U.S. or European or Japanese equipment.
Where do our allies stand with this? Are they going along with us in ripping and replacing?
Some are, some aren't. It really depends. I mean, you know, the five eyes a little bit more so
kind of aligned, but other areas of Europe, not so much. Purely, again, the economic reasons.
The fact that, you know, budgets are only so big, right? And so.
So these organizations, these carriers who need to build networks, they have to build them.
Sometimes they're under regulatory pressure to provide broadband to rural areas, which there's never
going to be a return on that investment unless it's heavily subsidized.
And so to just add 50% higher equipment costs on top of that just makes no sense.
And so I think it's really hit or miss around the world, but I think that we're losing ground.
And we're seeing it right now in terms of the trade war with Canada, right?
where Canada's starting to look about diversifying their supply chain and they're looking towards
China. So it's not helping us in this respect right now.
There's a case study in this report about cloud radium, which sort of illustrates the complexity
of some of the relationships here. Companies with U.S. infrastructure, but they may be controlled
by companies that have Chinese parents. Cloud Radium has connections to China Mobile International.
I have that right?
I believe so, yeah.
So what's the broader lesson here of the tentacles, the roots, the branches,
interconnecting all these companies, and they're not always straight lines?
Yeah, and this is a great kind of circle back to, again, how we got there.
I alluded to these kind of three phases over the last 15 years.
The first one was the equipment.
The second one, which we didn't really talk about,
but kind of 2019 to 2020 was really about banning the carriers,
the telecom carriers and pulling their licenses to operate.
The third phase, which is right now, is kind of, you know,
since the typhoon hacks were revealed until today,
there's been more pressure on controlling supply chains
and actually looking at supply chains.
And so we're seeing a whole bunch of rules coming out,
especially this year, just this year alone, from the FCC,
which is banning, you know, drone manufacturers,
you know, Chinese drone manufacturers,
banning routers, banning or requiem.
ownership disclosures of who owns your companies. There is some talk about new equipment
that's, you know, logic-bearing equipment being, you know, banned out of China to the U.S.
Robot vacuum cleaners. Robot vacuum. Yeah, robots, exactly. That's a big one. Other telecommunications
equipment like transceivers and that kind of stuff. So, you know, to your point about, you know,
how we address that case study where there are these parent companies, well, that's all controllable
in terms of the regulator in the U.S. being FCC, but also the regulator overseas.
And our partner nations who are looking at, okay, you company need to report your supply chain.
You need to first know your supply chain.
You need to know where the equipment's coming from.
You need to understand if you're ordering this part from this subsidiary.
Is it really just a Chinese shell company, which a number of them have been, as we saw with that example,
and controlling that.
And doing that will drive a market change, which could help.
it's not necessarily going to bring the cost down, though.
So you kind of have to attack both of these.
And this is Brandon's, you know, my opinion.
You have to both subsidize, you know, the champions and build some sort of international coalition
to support the infrastructure providers and technology providers at the same time as controlling
the supply chains of the carriers and, you know, what they're allowed to plug into systems
and where that technology comes from.
Brandon, I wanted to ask you a question.
As we've been talking about physical infrastructure and hardware,
when we're talking about security issues regarding the Internet,
I mean, I was joking about it earlier,
but the report touches on this, BGP.
It's been a while since I've talked about anything networking related,
and I'm very rusty on it.
But the report, I mean, it mentions BGP,
and there are just a lot of issues in terms of how the modern Internet
works where, I mean, we try to put Band-Aid solutions on them as best we can because the
internet was not originally designed with security in mind.
Of course.
I mean, we're talking about hardware and that kind of thing.
But, I mean, when we talk about the protocols that actually run the internet, I mean,
we can't, I mean, how on earth would, China would have to sign on to these changes for all
this to work.
So anyway, my mind's a million different places.
Yeah, yeah, yeah.
I mean, we're not going to change BGP, right?
Can we just pause for a second?
BGP is the border gateway.
protocol, which is how it's basically how the internet decides where to route packets at the highest,
you know, at the largest network size. And so the classic analogy is you think about a postal
service and, you know, they route your mail to your address. And so BGP is kind of like how
the central mail processing facility knows to send this.
packet of letters to this other mail processing center from, you know, you got one in New York
and one in Maryland, and, you know, the one in New York receives this big package of letters and
it needs to know, okay, these letters have to go to some place in Maryland. I don't know exactly
how to drive in Maryland, but I know if I send it to this other big processing facility in
Maryland, that processing facility will figure out how to get these letters delivered. So that's kind of
like BGP at the highest level.
It's the largest organizations that run the largest portions of the networks and how you
route between them, which this report, this report that we started this conversation with
touches on that issue of how internet packets get routed between what are called autonomous
systems, ASs.
So that's BGP in a nutshell.
The problem with BGP in terms of security is that it's a rumor algorithm, right?
it just inherently trusts what it's being told.
And so it's basically like, okay, mail processing facility got a letter for me.
And it just heard from someone down the street that my address is one, two, three, main street.
And so it's just going to send my letter to the, you know, house after house after house,
thinking that it's going to get to me.
It's not necessarily guaranteed.
So that leads me to the question, how much does proximity actually matter?
Does the hardware have to be within our borders?
For what?
For China to have the advantage that they've enjoyed so far.
No, not at all.
Not one bit.
And I'll point out, you know, the motivator again for this committee
and this report was the Salt Typhoon hacks
against U.S. telecommunications companies
that were revealed in 2024.
But Salt Typhoon didn't use Chinese telecommunications infrastructure.
They hacked Cisco devices.
and Avanti VPN, you know, devices and Palo Alto network devices.
And by the way, they used zero, zero days during all of this.
It was all known CVEs against our own equipment, not Chinese equipment.
Those companies are all U.S. companies, right?
And so the hacks themselves that were the motivator for this committee and this report
really had nothing to do with the global network backbone in terms of telecommunications
industry connects.
And even, you know, if it did,
just China Telecom, the fact that they have a large autonomous system that is advertising routes through BGP,
they can certainly hijack routes. That's not, you know, there's nothing that's keeping them from doing that.
And I'm sure that they have in the past. I think there was some evidence of that in this report.
But they don't need to be in the U.S. to do that. They can do that from China. Right.
Yep. Yeah, before we started chatting today, I actually went back and rewatch Loft to testify.
in front of Congress in 1998 talking about this exact thing.
And just for fun and also just to remind myself that it's amazing how long certain problems
have been around.
But again, it's because forever.
Forever.
And, you know, this is not a new problem.
And it's not going to shock anyone that, you know, this is an issue at the same time.
That's just how insidious this is as a problem.
And then my space brain goes, oh, well, that's why a lot of governments are trying to build
a brand new internet in space because they can maybe design it more.
more securely?
We talked about this notion of the splinternet, you know, where in Russia was, I guess,
the poster child for this of kind of putting a wall around themselves and only letting
certain things in and out.
And what does that do to the global internet?
Yeah.
So.
Well, and their fix, which, you know, to some up, this report's fixed in one word, it's eviction.
That is their proposed fix, right?
That won't work, right?
Packets to China cross Chinese carriers, no matter where that.
router is, whether it's in Virginia or whether it's in Hong Kong, right? And so evicting the racks
and, you know, the same thing keeps popping up in Hong Kong or in other parts of China.
And as we noted in the beginning, right, that is outside of the FBI's reach, which is a bigger
problem. So eviction won't work. What might work is fixing control, right? Leave the location alone,
you know, mandatory local U.S. controls on logging, right? Any foreign adversary operator or any foreign
equipment has to log, source a certain number of days or something like that. And then these ideas
of, you know, this is getting a little more technical, but there are route origin validation
techniques within BGP. And, you know, mandating that on every American autonomous system, you know,
route prefix or subnet within the big autonomous systems and mandating that from carriers and
mandating the carriers report on the route origin validation, which, you know, which, you know,
would go a long way in terms of, you know, keeping this route hijack issue from, it wouldn't solve
the issue, but it would move the system in a safer direction. And a lot of carriers are already
doing it, but it's not a mandate. And so, you know, you're going to have stuff pop up where
it's not following through with that. I imagine there's also an optics angle here for, as there
must be with politicians of it, but it feels so satisfying to say we physically evicted these
guy. We perp walked
them out of the service farm.
Right, right. Even though it maybe
doesn't do as much as we think. Right.
We moved all the smokers on the airplane
to the smoking section of the airplane.
Yes, exactly.
That's exactly right.
Yeah, yeah, yeah.
Talking about the hardware, again,
how much of an inventory
problem do we have here of
knowing what's out there
in that, you know, I'm thinking of that
small, I don't know,
water facility, right, has a rack that doesn't get messed with and hasn't been touched in a while,
and who knows what's on there.
Yeah, there's some interesting research coming out around how you can actually fingerprint,
or maybe be able to fingerprint devices at various parts of the network.
And that's not necessarily an easy thing to do, and it's not a foolproof method.
Right.
But there's some kind of recent research coming out of universities.
I think of UCSD and Johns Hopkins around this problem of identifying the OEMs,
the original manufacturers of devices, just from an external view, from measuring the network.
At the end of the day, if it's in the U.S., the regulator, the controller, Congress, whatever,
they can just mandate it, right?
And mandate that an organization has to, you know, know what their devices are and who the manufacturers are.
And if it's Huawei or ZTE, rip and replace them, which is kind of,
what they've been doing. It's just taking a really long time. And then if an organization like that
little water treatment plant you mentioned doesn't do it, well, they're the ones taking on the risk,
right? And that's, of course, a decision that any organization can make for themselves. But, you know,
it's probably not an advisable one if the fines or the punishments are severe enough.
Looking at this at a really high level again, if I'm a defender at an enterprise or a critical
infrastructure organization, how much visibility do I have?
into these sorts of things? How much visibility do I have into the carriers, the transit providers,
the routing relationships? Do I get to see and trace any of that? Yeah, I mean, that's a really
good question. It always depends on where you sit in the network, what you can see, you know,
from your home router going through Verizon or Comcast or whatever. You can see the route you take.
And all of this is actually public knowledge. There's a number of providers who measure these things
and track what autonomous systems are advertising what routes through BGP.
You know, Cloudflare has a big database on this.
I think even the FCC has a large database.
This is all public information you can see.
As an individual user, it would take a little bit of work to kind of say,
okay, the path that my packets are taking hits these IP addresses,
and now I need to go at a final lookup table and correlate those IP addresses with these
autonomous systems and who's in charge of these autonomy.
And all that's totally solvable.
You know, there's nothing secret about this information.
It's actually very public and really anyone can look it up.
And it's pretty easy to figure out if there's a BGP hijack going on.
You know, at that point, once it's observable,
that means that the routes have been accepted by the other BGP routers
and it's kind of propagated and flooded the network.
And so for a period of time, that false route has created an opportunity for a man in the middle
attack or collection or something like that.
So I hope I'm answering your question,
But from a defender perspective, yeah, you can definitely see that.
I think that for the carriers and the service providers, internet service providers and kind of the high-level carriers, the AT&Ts of the world, the NTTs of the world, they're constantly looking at the routes to their autonomous systems.
And the paths that that net flow data is going through because there's always a risk of malicious activity at that level.
What does an organization like NTT, your employers, how do they ingest and respond to a report like this?
Yeah, it very much depends, which is like the classic security answer.
I would say from my perspective and where I sit, we are very focused on our own supply chain security and our relationships globally.
We are constantly aware of the new rules coming out from the FCC primarily as the key regulator for our position as a carrier in the U.S.
And so, you know, we're always trying to decrease the risk inherent in our network at a certain point, though.
It's, you know, there's only so much you can do.
We control our infrastructure.
We do not control the Chinese telecommunications infrastructure and those companies.
Just kidding.
As much as we'd like to.
And, I mean, they can advertise what route they want.
And by the way, if you want to interact with a server in China, you are going to have to go through a Chinese
telecommunications provider at some point in the network.
And so, you know, that's the whole kind of idea of a global network.
Everything is interconnected.
You can reach everything else at a certain point.
You're going to go through infrastructure that is not controlled by your service provider or your
company. You know, your packets will touch some other organizations, autonomous systems and network
and routers, and there is inherent risk in that. At the end of the day, when you evaluate this report
from Congress, how much utility do you see there in this? Do you see there being in this? How,
how useful will it ultimately be? There is some utility. I mean, they got a couple things right, right? The first
part of the report and their findings are solid, right? They found information, you know,
these telecom subsidiaries in the U.S. are running from Hong Kong. They're not retaining any
records or logs. They don't have any of that information here in the U.S. That is a problem.
And so kind of raising, raising the profile of that, I think, is wise. Then the question is,
okay, what do we do about it? And that's where I take issue with the report, which, you know,
I think, as I've said in this conversation already, leave the racks, leave them where they are,
fix the control. Require records, right? Require logs. Verify routes. Make sure that you're controlling,
at least the extent to which you can in the U.S., verifying your actual autonomous system and network
routes that they're taking. Make our own carriers lock their own doors, right? Actually
have controls and regulations and standards, which, by the way, have been continually removed.
Review those private deals, Dave, that you mentioned, right? The fact that there are these
subsidiaries that are just shell companies for adversary organizations, right? Review those private
deals. And then the big one for me, back to infrastructure, fund the real competitors to Huawei and
CTE. Do that as a coalition. We can't do it alone as the U.S. We've got to do it with Canada and the UK and
Germany and France and, you know, et cetera, et cetera, et cetera. And if we do that, if we build
legitimate competitors in the market, that fixes this at the root of the problem. But at the end of
the day, I think reports like this are valuable. I'm a little concerned when they go into something
that is fairly technical and they seem to miss the ball a little bit in terms of how networks work
and how they're connected and what it means to have a global network and packets are just going to
flow one way or another. So maybe there's a little bit to Maria's point earlier of like, hey, look,
we're saying we're doing something. We're just evicting them and that's great for us. And so there's a little
bit of a political positioning there, but it's not going to solve the actual security risk.
There's almost a philosophical angle to this of, and I'm not trying to say, you know, don't try to
secure things because they're unsecurable. I'm not trying to say that, but I'm just wondering if,
you know, the government's position is going to be, we need to lock this down, you know,
we need to kick them out. And to some degree, like, that's not attainable. You're trying to, like,
grab a waterfall with your hands. It's just like, it's just not possible, short of segmenting everyone's
national networks completely separately from everyone else's, but who would want that internet fear?
And I'll remind you again, Marie, you made this point earlier. Salt Typhoon walked in through our
routers, our own infrastructure that was not secured, that were not patched, even though the patches
were out there, right? So, you know, this is not going to solve that problem. We solve that problem
by doing, you know, security fundamentals.
Yes. But also, also maybe looking at the line.
reliability frameworks of who's liable for these things of looking at the products of these large
infrastructure providers.
Again, the Yvantees of the world, the Palo Alto networks, the Cisco's of the world,
the Erickson's, the Nokia's who are providing this technology and supporting them and improving
their baseline security of the products that we're all relying on and using.
Because right now, that risk is all just being handed off to the,
the buyer of the equipment, whether it's a carrier or a small business on Main Street,
we're just taking on the risk of these insecure, poorly secured products.
And then we all pay the price.
Yeah, but don't segment the Internet more than, you know, the splinternet is not, you know,
what we want here.
No, no.
Yeah.
I know, but sometimes I wonder where we're going.
And, yeah, and I just, given the geopolitical tensions and everything that's been
changing and I just I just can't help it wonder and again that's it's not what I want to see um yeah
that's a whole other show it is and and I mean the the eviction the rip and replace mandates that
they are taking a long time they're not really working um or they're working very slowly
you know it's okay we we tried something it didn't work let's try something else
all right well the report is titled stranger pings uh again it's from the select
Committee on the Strategic Competition between the United States and the Chinese Communist Party.
That is our United States Congress. We will have a link to that report in the show notes.
Brandon Karp is leader of international public-private partnerships at NTT.
Brandon, thanks so much for joining us.
Thank you, Dave.
And Maria Vermazas is host of the T-Minus Space Cyber Podcast.
Not longer a daily.
One of these days, I'll get it right.
Maria, always a pleasure to have you join us and very much appreciate your insights.
Thanks to both of you for joining us today.
Thank you.
Thank you, Dave.
Appreciate it.
Thank you for joining us today, and I hope you enjoyed our chat.
Have a great Labor Day, and we'll see you next time.
