Carmakers Rush To Remove Chinese Code Under New US Rules (msn.com) 141
"How Chinese is your car?" asks the Wall Street Journal. "Automakers are racing to work it out."
Modern cars are packed with internet-connected widgets, many of them containing Chinese technology. Now, the car industry is scrambling to root out that tech ahead of a looming deadline, a test case for America's ability to decouple from Chinese supply chains. New U.S. rules will soon ban Chinese software in vehicle systems that connect to the cloud, part of an effort to prevent cameras, microphones and GPS tracking in cars from being exploited by foreign adversaries.
The move is "one of the most consequential and complex auto regulations in decades," according to Hilary Cain, head of policy at trade group the Alliance for Automotive Innovation. "It requires a deep examination of supply chains and aggressive compliance timelines."
Carmakers will need to attest to the U.S. government that, as of March 17, core elements of their products don't contain code that was written in China or by a Chinese company. The rule also covers software for advanced autonomous driving and will be extended to connectivity hardware starting in 2029. Connected cars made by Chinese or China-controlled companies are also banned, wherever their software comes from...
The Commerce Department's Bureau of Industry and Security, which introduced the connected-vehicle rule, is also allowing the use of Chinese code that is transferred to a non-Chinese entity before March 17. That carve-out has sparked a rush of corporate restructuring, according to Matt Wyckhouse, chief executive of cybersecurity firm Finite State. Global suppliers are relocating China-based software teams, while Chinese companies are seeking new owners for operations in the West.
Thanks to long-time Slashdot reader schwit1 for sharing the article.
The move is "one of the most consequential and complex auto regulations in decades," according to Hilary Cain, head of policy at trade group the Alliance for Automotive Innovation. "It requires a deep examination of supply chains and aggressive compliance timelines."
Carmakers will need to attest to the U.S. government that, as of March 17, core elements of their products don't contain code that was written in China or by a Chinese company. The rule also covers software for advanced autonomous driving and will be extended to connectivity hardware starting in 2029. Connected cars made by Chinese or China-controlled companies are also banned, wherever their software comes from...
The Commerce Department's Bureau of Industry and Security, which introduced the connected-vehicle rule, is also allowing the use of Chinese code that is transferred to a non-Chinese entity before March 17. That carve-out has sparked a rush of corporate restructuring, according to Matt Wyckhouse, chief executive of cybersecurity firm Finite State. Global suppliers are relocating China-based software teams, while Chinese companies are seeking new owners for operations in the West.
Thanks to long-time Slashdot reader schwit1 for sharing the article.
Canâ(TM)t the Chinese just buy all the info a (Score:3)
Maybe this is less about security and more about who gets paid?
Re: (Score:2, Funny)
no the software will be written by an america company who out sources it to the same people who they took it form.
Re: (Score:2)
Re: (Score:3)
How about removing ALL hardware and software that new cars have in them to "phone home" period.
I don't want a car with WiFi....with built in cellular....I have that on my phone if I wish in a car, I don't need the car to check in with company/govt or whomever.
I don't need or want automatic updates, I don't want features added, turned off/on at any time. I don't want the company or govt to be able to readily disable my car at the touch of a button, nor open up ways for
Re: (Score:1)
Clearly. As this is totally unworkable, anybody needs to throw money at the orange rapist to get an exception.
Re: Canâ(TM)t the Chinese just buy all the in (Score:3, Insightful)
I don't see any restriction from say Japanese, Korean or European vendors. Who, specifically, do you believe is getting paid?
Honestly I see exactly the concern with this: Always available cameras with an always eye level 360 degree view high resolution camera that likely also provides distance measurement. Have them ubiquitous everywhere, and if you're a spy agency, you've got a fantastic surveillance tool. Especially great for blackmail.
The Chinese government is already well known to establish an illegal p
Re: Canâ(TM)t the Chinese just buy all the i (Score:1)
> The Chinese government is already well known to establish an illegal police presence in other countries.
No, they're not.
Re: Canâ(TM)t the Chinese just buy all the i (Score:5, Informative)
Yes, they are.
https://en.wikipedia.org/wiki/... [wikipedia.org]
https://www.cnn.com/2022/12/04... [cnn.com]
Re: Canâ(TM)t the Chinese just buy all the i (Score:1)
Just this past year, dozens of Chinese nationals were arrested in multiple countries for harassing and intimidating Chinese dissidents in those countries. It is believed that several people were kidnapped or disappeared as well.
Re: (Score:2)
It's to keep the populace busy while they're robbed blind by the ruling class. That and Epstein.
Re: (Score:1)
Europeans should check how American are their cars (Score:4, Interesting)
Right? Make sure that there's no American code. Make sure everything is open source if used. After all it seems that all the cars that have stopped working so far have been American cars, that have been remotely disabled, etc.
Re: (Score:1)
Right? Make sure that there's no American code. Make sure everything is open source if used. After all it seems that all the cars that have stopped working so far have been American cars, that have been remotely disabled, etc.
LOL. What would be the point? How many Americans cars do you think they buy now?
Re: Europeans should check how American are their (Score:3)
The trumpistani cars that sell in Europe are either cheap, EU made utilitarian models or individual imports of "muscle car" monstrocities for the occasional connoisseur of stupid waste.
Why would you buy junk that breaks often, guzzles gas and destroys the environment when you can actually have a much nicer European, Japanese or Korean car?
Re: (Score:2, Funny)
Re: (Score:2)
Fine, but what have I got to do with it?
Re: (Score:2)
Re: (Score:2)
The argument of the AC is code sharing. For example, the Stellantis group might reuse parts of their code between Jeep and Fiat. If a mole, a suitable EO from a stakeholder government (the USA or Italy in this example), or an external bad actor, get remote access to the cars of one brand through a rootkit or a vulnerability, they could also simultaneously gain access to other other brands.
Plenty Would Take that Trade-Off . . . . (Score:4, Interesting)
New U.S. rules will soon ban Chinese software in vehicle systems that connect to the cloud
"Cool, disconnect my car completely then."
. . . but of course, this decision will be made by the real owners of the car, not the guy who merely "bought" it.
Re: (Score:1)
Re: (Score:2)
It's not Toyota, it's everyone. Hell we just ran a story here a few weeks ago about Porches in Russia refusing to start due to communication issues. Many car vendors implemented remote key switches. Customers kept asking for them. Well not directly, but customers wanted a car that was more theft proof.
Connected cars are a plauge (Score:3, Insightful)
Re: (Score:2)
Yes greed and lazyness. Certainly no one every asked for connected features in a car. *Opens app hits the pre-heat cabin button because it's -5 out right now.* Now if you'll excuse me I'm going to get a coffee and stand in the window while I watch my neighbours scrape ice from their windshields in the dark.
Yeah it is lazyness, but it's mine. Some of us prefer to buy cars with lazy remote features like this. The kind that can tell me when it's full so I don't need to pay charger blocking fees, the kind which
Re: (Score:1)
Re: (Score:2)
You conflate "understanding" with "caring". Yes there's a cost, but I frankly don't give a shit. We live in a world where one can reasonably be expected to be stranded in vehicles at multiple times. That's what auto associations are for. Yes I've been stranded before, and it was a minor annoyance at best. Whoop de fucking do.
Also no my data is not being collected and shared in any meaningful way by anyone who can meaningfully impact me. We have laws against that. Attempts by insurance companies to do what y
Re: (Score:2)
Another work day done. I tried your suggestion but it turns out my keyfob didn't reach from my desk to the parking lot on the other side of the campus. Got any other stupid ideas?
Now if you'll excuse me I'm going to get a coffee and stand in the window while I watch YOU scrape ice from your windshield in the dark because the internet/power is down.
If the internet is down I'm in literally no worse position than the position you people are promoting. I mean did you engage a single braincell when attempting to come up with a point? Don't drink and Slashdot.
Re:Connected cars are a plauge (Score:5, Informative)
The original Nissan Leaf had connectivity for driving stats, charge monitoring, and remotely turning on the AC before you set off so that the car is defrosted and warm using AC power. It was free and was supposed to become a paid service, but they never got around to charging for it.
The driving stats were of limited use. The charge monitoring was useful. The remote AC/defrost is one of the best features of EVs.
What killed it in a lot of Leafs is that the originals had 2G modems, which are no longer supported by the networks. You can replace them with an open source module with a more modern modem and your own SIM.
Re: (Score:3)
I can understand self-driving cars needing to be connected
I can't. I don't want to die or be left stranded because of a disruption in communications. Just no.
If they can't do this; might as well pack up. (Score:2)
The chinese aren't the problem (Score:5, Insightful)
Our government is the problem.
They're well beyond what they're allowed to do at this point in terms of surveillance, and the law doesn't protect people like it should.
Cars shouldn't be building psychometric profiles on you and selling them to everyone and anyone who wants to know how often you've used your drink holder.
The adversaries to personal freedom here are local.
Re:The chinese aren't the problem (Score:5, Interesting)
You can expect the quality of these cars to drop rapidly as tested, debugged software is replaced by hastily lashed together vibe coded crap.
Maybe that's the point. Easier for the US government to hack it.
Re: (Score:1, Troll)
Re: (Score:2)
I don't think Pooh and the CCP believe that. They folded over COVID lockdowns, and that's not the only example.
Re: (Score:2)
The US government is the biggest problem. Any adversary we're importing products from is also a problem.
If you're concerned about your government having info on you, you should be concerned that they would be able to buy it from another entity which got it from your foreign adversary, or even directly. Why not charge your adversary for partial information on their own citizens?
How much Chinese code in Linux? (Score:2, Interesting)
How much Chinese code in Linux and other car related OSS?
For example are Shawn Guo and Huacai Chen from China?
https://insights.linuxfoundati... [linuxfoundation.org]
Re: (Score:1)
yep, they should stop using Linux in cars, mobile phones...
Sounds crazy, until... (Score:2)
Should they reciprocate? (Score:1)
Tesla sells well in China, what if US software is banned?
Simple protectionism (Score:3)
American car makers are apparently scared sheepless that Chinese EVs would be a big hit. As usual, they employ the government to screw with the market instead of improving their vehicles. Your take on this should be to accept their evaluation that American cars aren't worth buying.
Re: (Score:3)
This will fail. (Score:5, Interesting)
Can't trust U.S. software for quality or security (Score:2)
Re:Corrected title (Score:5, Informative)
This isn't about the ethnicity, it's about geopolitics and the different goals of our government and theirs. That said, I question the value of that when half our electronics are manufactured there and can have hardware level spying already there.
Re:Corrected title (Score:5, Insightful)
Compared to the US government, I'm far less concerned about what China does with my data. The Chinese government can't send masked secret police to my home to abduct me.
Re: Corrected title (Score:2)
You DO know that the CCP literally has secret police all over the world and they actually do abduct people and bring them back to China or make them disappear or both?
In the literal sense of those words, not in the orange-man-TDS-screeching sense.
Re: (Score:1)
The Chinese government can't send masked secret police to my home to abduct me.
Federal police can arrest you for violating federal law. Of course. (Calling an arrest an "abduction" is just lame.)
You do know that you can peacefully change federal law, right? Just elect senators and representatives who will do so to your liking. We could call it "democracy".
You would have to actually convince voters that they want the immigration floodgates to open wider though, and I think you know that you can't really do that.So you choose street violence instead.
Re: (Score:3)
Federal police can arrest you for violating federal law. Of course. (Calling an arrest an "abduction" is just lame.)
My definition of armed masked men without badges snatching people off the street into unmarked vehicles is different from yours. Deportation requires a judge to sign off on a warrant. No warrants are ever produced.
Re: (Score:2)
Re: (Score:2)
However, when these agents spot an illegal that maybe hasn't committed any further crimes, other than illegally crossing the border,, do you expect them to just let them go?
How do you "spot an illegal"? We're not talking about people apprehended sprinting away from the border.
Re: (Score:2)
Re: (Score:2)
Well, unfortunately with 12-20+ million illegals in the US, in sweeps you're going to get some false positives.
So, far the numbers seem to be low and once identified US citizens are quickly released.
Sucks, but due to the size of the problem, statis
Re: (Score:2)
Re: (Score:2)
Re: Corrected title (Score:1)
Why, are you here illegally, having broken our laws and snuck over our border?
Re: (Score:3, Insightful)
Were any of them convicted of 43 felonies? Because I know more important guy still walking free.
Re: (Score:2)
Well, you got to feel like you did at least.
Re: (Score:2)
34 felonies would preclude me from nearly all professional career choices. But hey you can still lead the country and the cult.
Re:Wanna bet? (Score:4, Informative)
https://www.bbc.com/news/artic... [bbc.com]
Re: (Score:1, Insightful)
Not the same thing -
"The US immigration agency whose officers have been involved in a fatal shooting in Minneapolis has said it is sending agents to help support American security operations during the Winter Olympics, which start in Italy on 6 February."
Re:Wanna bet? (Score:4, Insightful)
Sure if you narrowly define which department you mean then we can say the same thing to China. In the mean time I think Maduro will disagree about the USA operating police in other nations.
Re: (Score:1)
Sure, if you move the goal posts then you can redefine your argument however you want - but if you insist...
https://freedomhouse.org/repor... [freedomhouse.org]
Re: (Score:3)
I'm only disagreeing with your arbitrary idea of where you set the goalposts in the first place. They weren't in the correct position for the ball game being played.
Re: Wanna bet? (Score:2)
Re: (Score:2)
No he was a drug dealer. ICE only deports normal law abiding immigrants. It's the drug dealers that get brought in front of the court, put through legal channels, convicted and then pardoned.
*yes being sarcastic here*
Re: (Score:1)
Re: (Score:1)
Kind of -- but in the way opposite to what you meant. People get modded down for stating uncomfortable truths, and modded up for repeating politically correct fictions, because the truth hurts mods' feelings. That distortion is what makes the politics toxic, not the substantive positions.
Re: Wanna bet? (Score:2)
It's a long tradition here, dating back to at least the introduction of modding.
Re: (Score:1)
ICE didn't murder people and didn't kidnap children from the streets when Obama was president
Re: Corrected title (Score:2)
Then Trump needs to learn from Obama; "do it THAT way"
Re: (Score:2)
Re: Corrected title (Score:2)
I can't speak to cause and effect, but there is a peculiar strain of cruelty about ICE under Trump. He would do well to address it, as it does a gross disservice to his agenda. People sense it and bridle at the dehumanisation
Re: (Score:2)
Border Patrol agents were doing ICE work (they weren't exactly patrolling the border), so I understand the conflation.
This is not optics. These are power-drunk "Respect my authoritah!!" agents, reacting with extreme violence and executing protestors in essentially low-risk scenarios.
The US Capitol police (real police) didn't treat protestors that way.
The last border patrol agent murdered in the line of duty was in 2017. The last ICE agent murdered was in 2011. What are they so keyed up about? Where is the r
Re: (Score:2)
Re: Corrected title (Score:2)
Wrong. They've grabbed almost 200 US citizens already, most of whom had their ID with them (they just claimed that it "looked fake", some of them were deported to Mexico (including Native Americans who didn't even speak Spanish), and multiple people have had their Green Cards revoked and were deported to countries where they knew no one without money or valid papers.
TLDR; You have no idea what you're talking about.
Re:Corrected title (Score:5, Insightful)
And how many masked men did Obama deputize? How many American citizens did these masked men murder under Obama? Zero.
Re: (Score:2)
And how many masked men did Obama deputize? How many American citizens did these masked men murder under Obama? Zero.
Right, Obama was only approving murders without due process in other countries.
Re: Corrected title (Score:3)
Looks like it. Trump's probably surpassed him there too with the double-tap boat strikes
Re: (Score:2)
He surpassed him as far we know before that, but then he rescinded Obama's EO requiring notifying The People of drone strikes.
Re:Corrected title (Score:5, Insightful)
You know Obama deported more people, then Trump...right?
No one is complaining about the number of deportations. They are complaining about the *method* of deportations.
To equate Obama's deportations with Trumps where multiple constitutional guarantees are violated and American citizens have been executed summarily in the street makes you a truly despicable piece of shit. I'm only sad that you're not being deported in lieu of the immigrants contributing to actually making American great rather than your efforts of simply tearing the country down with bullshit partisan politics.
Re: (Score:2)
Methods that only became necessary when places declared themselves to be "sanctuaries" against Federal law.
Oh look more bullshit partisan politics. The overwhelming majority of cases where ICE have taken people have been determined to be in the country *legally* by a federal judge. You *DO* think federal law applies here right? You *DO* support the idea that we have federal judges that tell the government to release / no deport people in question right?
Also why do you care? If you support the methods which have violated 4 constitutional protections over and over again it's clear you don't give a shit about feder
Re: (Score:2)
Where's your evidence for the (clearly absurd) claim that "The overwhelming majority of cases where ICE have taken people have been determined to be in the country *legally* by a federal judge"?
Why shouldn't I care about immigration laws being flouted? Why shouldn't I care that tens of millions of people are here illegally? Why shouldn't I care that some States are concentrating them in a way that dilutes everyone else's votes wi
Re:Corrected title (Score:5, Insightful)
Sooner or later we'll have geopolitically aligned software. The Israeli pager attack showed how dangerous it is to not have a friendly superpower produce your electronics. The same problem exists in software, perhaps to an even greater degree.
In that world I expect open source to win, because that's the only way to create trustworthy software while avoiding doing a huge amount of duplicate work.
Re: (Score:2)
The Israeli pagers were very specifically targeted at a unique group of people - Hizbullah terrorists - who were out to kill them. Who in the world uses pagers these days, when one can have cellphones simulate the same effect? The reason Hizbullah used pagers was to operate under the radar, and uninterceptable by the Israelis. Instead, the latter managed to insert their operatives into that supply chain and rig them to make them explode when the Israelis sent the signals
Putting aside the question of wh
Re: (Score:2)
If a tiny country like Israel can do it, so can anyone else. It would be grossly irresponsible to buy anything from a potential adversary or hostile-aligned nation, especially if you don't have the expertise to reverse engineer their product. And I'd argue for software, reverse engineering it to ascertain its safety is basically impossible.
As for the morality of the Middle East situation, I'm not going to judge. My government may no longer be sovereign and they have no problems ignoring the First Amendment
Re: (Score:1)
The US has been afraid of those "nefarious Asians" for over a hundred years now.
Re: (Score:2)
Re: (Score:2)
Yeah, we need to move manufacturing to other countries that don't dictate to their companies how they can or can't build their products
Re: (Score:2, Insightful)
PRC has significantly tighter rules on cars being sold into their massive market that this.
You can't even do it. Until very recently, you had to partner with a local and give them access to your technology. Which meant local just put up a second factory with their copy of your tech next door.
Does that mean PRC can't compete or is there perhaps another reason?
Re: Corrected title (Score:1)
You contradict yourself, but you don't even see it.
Re: (Score:1)
That's because you hallucinated a contradiction. Requiring companies to give to their IP to a local, and then refusing to rule against the local when they pirate that IP, is very much a higher trade barrier than this.
Re: (Score:2)
Totally. There are no Changan Fords in PRC, only Fords. Changan isn't real.
Same for all GAC Toyota. GAC is just there for lulz. It's totally not a company. You just hallucinated it.
P.S. PRC bots just openly lying about the most obvious shit is out of control.
Re: Corrected title (Score:2, Flamebait)
Yep, /. is keeping up it's long tradition of modding down unpopular truths.
Re: Corrected title (Score:3)
It would racist if the rules said "Chinese engineers," but it says "Chinese companies."
Nothing stops those companies from relocating to say Singapore.
Re: (Score:2)
Also, the US has nothing against companies based in Taiwan or Singapore - both of which are majority Mandarin populations. Only problem w/ China is due to Beijing wanting to remote-control everything
Re:Corrected title (Score:4, Insightful)
Replace it with homegrown spyware
Re: (Score:2)
Re: (Score:2)
This is from the law for the tiktok ban. It uses a list of "foreign adversaries" that was set up under Obama.
Re: Corrected title (Score:2)
New GEOPOLITICIST US rules .. or is Taiwan, Japan, Korea, etc on the list too?
Re: (Score:2)
Re: (Score:2, Insightful)
"Someone once observed to me that my attitudes towards people I've never met were unfounded, and I've since spent my entire life orbiting the memory of this unjustified event"
It's sort of funny how often people with extremely niche perspectives consider them to be universal but suppressed. I'd tell you to stop telling on yourself but that ship sailed years ago.