The Enemy Inside the Machine
China and the problem of technological sovereignty
The Royal Navy recently discovered Chinese-made cameras installed aboard its new K3 Scout unmanned vessels communicating with an IP address in China.
The boats are not trivial pieces of equipment. The 27-foot unmanned vessels were purchased as part of a £12.3 million program and have been used by the Royal Marines, including near the headquarters of Britain’s Special Boat Service. Investigators reportedly discovered that cameras aboard the vessels were making what officials described as “heartbeat communications” with China even though the equipment appeared to be offline.
The British Ministry of Defence says there is no evidence that sensitive operational information was transmitted and has since removed the cameras’ internet connectivity. We should take that claim seriously. There is presently no public evidence that the Chinese were receiving Royal Navy imagery or other classified information.
The episode is nevertheless disturbing because of what it reveals about the structure of Western defense procurement.
A Chinese-origin subsystem had found its way into a British military intelligence and reconnaissance platform. That subsystem possessed network behavior apparently unknown to the ultimate military customer, and the behavior was discovered after the equipment had entered service.
This should be familiar to Americans.
The episode immediately reminded me of the controversy surrounding Supermicro servers. In 2018, Bloomberg reported that Chinese operatives had secretly modified server motherboards manufactured in China, allegedly creating hardware-level access to networks used by major American companies and government agencies. Apple, Amazon and Supermicro strongly denied the allegations, and the famous story of a tiny additional “spy chip” has never been publicly established.
Bloomberg returned to the subject in 2021, however, with much more extensive reporting alleging that American intelligence and law-enforcement agencies had investigated firmware compromises and physical modifications of Supermicro equipment.
The details of that controversy remain disputed, but the underlying strategic problem has only become more obvious.
For several decades the United States and its allies built increasingly sophisticated military systems while simultaneously allowing much of the electronics manufacturing base beneath those systems to migrate abroad, especially to China. Western defense planners concentrated on the capabilities of finished systems while the supply chains underlying them became longer, more opaque and increasingly dependent upon the industrial ecosystem of our principal strategic competitor.
Modern military equipment makes this especially difficult.
A contemporary unmanned vessel is less a discrete machine than a network of computers, sensors, cameras, processors, radios, storage devices and software. Each may contain additional processors and firmware sourced through several layers of subcontractors. A British or American prime contractor may have assembled the system without having designed, manufactured or even completely understood every electronic component within it.
Many of these components are also derived from ordinary commercial technology. Cameras communicate with manufacturers. Devices check for firmware updates, report diagnostic information, verify licenses and connect to cloud services. None of this is particularly suspicious in commercial electronics.
The same behavior becomes potentially important when the camera is mounted aboard a military reconnaissance platform.
Even the “heartbeat communications” reported in the K3 case illustrate the problem. Metadata can itself have intelligence value. Depending upon what a device reports, persistent communications can potentially reveal whether equipment is operating, when it is operating, its software or firmware state, network information and identifying characteristics. Combined with other intelligence sources, seemingly insignificant information can become considerably more useful.
There is no evidence presently available that the K3 cameras transmitted all of this information. The significance of the episode lies in the fact that the Royal Navy apparently did not initially control or fully understand the communications behavior of a subsystem installed aboard one of its military platforms.
This is a supply-chain problem in the fullest sense.
For thirty years, Western governments encouraged defense procurement practices emphasizing cost, efficiency, interoperability and the incorporation of commercial off-the-shelf technology. During the same period, China deliberately developed an enormous electronics manufacturing ecosystem. It became increasingly difficult to manufacture sophisticated Western equipment without components whose supply chains passed through China.
The consequences are now appearing inside military systems.
Washington has begun responding to this problem through restrictions on companies such as Huawei and through efforts to rebuild domestic semiconductor manufacturing. Those measures are useful, but the Royal Navy episode demonstrates how much deeper the problem extends. The relevant unit of analysis cannot simply be the nationality of the prime contractor or even the country in which the finished platform was assembled.
For genuinely sensitive military systems, the United States needs much better visibility into component provenance, firmware, software dependencies and network behavior. Critical subsystems require trusted manufacturing chains and continuous technical evaluation. Procurement authorities need the ability to examine bills of materials several layers below the prime contractor.
Congress should consequently ask the Department of Defense a fairly straightforward question: How far down the defense supply chain can the Department actually see?
Can DoD identify the manufacturer of a camera installed on an ISR platform? Does it know who designed the networking chipset inside that camera? Can it audit the firmware? Does it know whether that firmware initiates external communications? Can it identify the servers receiving those communications? And are these requirements being imposed upon subcontractors several tiers removed from the prime?
If the answer becomes uncertain somewhere down that chain, then the United States has identified an important vulnerability.
There is also a broader strategic lesson here.
The industrial policies pursued by the United States and China since the end of the Cold War were very different. The United States increasingly treated manufacturing as an economic activity that could be allocated internationally according to comparative advantage. China consistently regarded advanced manufacturing as an element of comprehensive national power and pursued market share, technical knowledge and control of strategic supply chains accordingly.
Military technology eventually inherits the industrial structure from which it is produced.
The Royal Navy appears to have caught this particular problem before serious damage occurred. We should hope that is the case. The useful American response is to assume that comparable dependencies exist throughout our own military establishment and begin systematically finding them.
Technological sovereignty requires considerably more than the ability to design an American weapon and place an American flag on it. It requires sufficient knowledge of the industrial system beneath that weapon to know what its components are, where they came from, what software they are running and what they are doing once the system is turned on.
That is a much more difficult undertaking than defense procurement has generally assumed. It is also becoming an unavoidable requirement of great-power competition.







Horrible. Thank you Ron. This is a good read.