Part 6 of 8. Part 5 looked at how far one country’s law reaches.

What this post covers

  • The reason given for shutting some suppliers out.
  • What has been established about weakened products.
  • What happened in 2024.
  • Why this lands on Europe too.
  • What you can do about it.

The reason given for shutting some suppliers out

Several governments have shut Chinese suppliers out of telephone and internet networks, and restricted some Chinese apps on official devices.

The reason given is usually the same: a company can be made to help its own government. So the kit carries a risk, whatever the code does.

That reasoning is sound. It is also the same reasoning used in part 2 about whose law applies to your data.

Let us be straight about one thing before going on.

Cyber operations by the Chinese state are real. European national security agencies document them as well as American ones, and they include large-scale theft of commercial information. Nowt in this post is a defence of that.

But if the principle is that a supplier can be made to help its own government, then it applies to every supplier that has a government.

Apply it evenly and the record on the European and American side is not empty. In places it is better established than the accusations, because parliaments have investigated it.

What has been established about weakened products

Three items, each with a source, in order of how firmly they stand up.

An intelligence service owned an encryption company.

Crypto AG was a Swiss company that sold cipher machines to more than 120 governments from the 1950s onwards.

It was owned by the American CIA and the German BND. The machines were altered so those services could read the messages of the governments buying them.

It rests on more than journalism. After the story broke, the Swiss Parliament’s own intelligence oversight body investigated and published a report in November 2020.

Swiss public broadcaster SWI has covered the findings, including that Swiss intelligence had known since 1993.

Customers included European governments. It ran for roughly 50 years.

A cryptographic standard was withdrawn.

A random number generator called Dual_EC_DRBG was published as a United States standard — random numbers are what encryption uses to make keys unpredictable.

Researchers showed its design let whoever picked certain values inside it predict its output.

The standards body advised against using it in 2013 and removed it in 2014. The Register reported on the related commercial arrangements at the time.

Kit has been intercepted in transit.

In December 2013 the German magazine Der Spiegel published a catalogue of interception tools covering routers, firewalls, servers and storage firmware from well-known manufacturers.

The reporting also described kit being diverted in transit, altered, repackaged and sent on to the customer.

That last one is worth a moment from anybody who buys hardware.

It means the trust boundary is not just your supplier — it is your supplier and everything that handles the delivery.

An honest supplier cannot give you an assurance about the second part.

What happened in 2024

This is the event that answers the engineering question, and it is the most useful thing in this post.

In 1994 the United States passed a law requiring telephone companies to build their networks so communications could be intercepted on a lawful request.

So the way in was permanent, built in, and governed by legal process.

In 2024 a group linked to the Chinese state, publicly named Salt Typhoon, was found to have got into at least 9 major American telephone companies.

Among the systems reached were the interception systems themselves. The Register reported on the response from lawmakers.

The way in that one government required to be built became the way another government got in.

That is not bad luck. It follows from how such a thing works.

A built-in way in is a capability, not a rule. The law governing it only binds people who accept that law. Somebody who has broken in does not.

Every argument for built-in lawful access assumes the access can be kept to the intended user. This is the clearest evidence going that the assumption does not hold.

Why this lands on Europe too

If that reasoning is right, it is right everywhere, and as such it lands on European proposals too.

Proposals to scan messages on the device before they are encrypted create the same sort of built-in way in.

The United Kingdom has a power to require companies to provide technical capabilities. It has been used to require changes to an encryption feature, and the supplier pulled that feature in the United Kingdom rather than change it.

Both are pursued by democracies, with oversight, for serious reasons such as protecting children.

Both also build exactly the kind of capability that 2024 showed cannot reliably be kept to its intended user.

A European way in is no safer than any other, because an intruder does not care how accountable the institution is. What they care about is whether the thing exists.

Which is why the useful version of this argument is a technical one, not a political one.

“Do not trust suppliers from country X” has to be reopened every time the politics shift.

“Assume any built-in way in will eventually be used by somebody it was not built for” holds regardless.

What you can do about it

The practical answer is not mainly about who you buy from. It is about designing so the question matters less.

Treat the network as untrusted. Encrypt traffic end to end, and do not let one system trust another just because of where it sits on the network.

Hold your own encryption keys where you can. Part 2 explained why that changes who can be asked for your data. It also limits what an intruder finds worth having.

Send less. Data you never collected cannot be intercepted, requested or lost. Least fashionable control on the list, and often the most effective.

Check what your kit runs before you trust it. Verified boot and firmware checking are worth turning on where your hardware supports them.

On genuinely sensitive systems, check deliveries. Tamper-evident packaging and recorded serial numbers are simple enough.

None of these need you to decide which government to worry about most.

That is exactly why they are the better answer. A control that only works if your guess about politics is right is not really a control.

Part 7 steps outside technology, and looks at how other industries handled the same problem.


First published: 2026-08-25. Last updated: 2026-08-25.