Contd. Designed for interoperability with commercial hardware vendors, making targeted
sanctions more challenging
already be present in a client country’s internet service providers’ networks. Integrations
are
based
on
open
standards.
This
also
means
that
when
sanctions
target
a
specific
company, such as the case of Sandvine in Pakistan, Geedge Networks has been able to
work
with
that
company’s
client
governments
to
fill
the
gap
and
build
on
existing
infrastructure.
Internationally-funded ISPs are implicated
Geedge
Networks
works
with
Internet
Service
Providers
(ISPs)
directly
to
install
their
products. Data is captured and stored on the premises of ISPs’ data centers. Government
workers access the data remotely from a command-and-control center. These ISPs may
have no choice about whether to install Geedge Networks equipment in their data centers
if they want to continue operating in a given country. However, this implicates specific
providers,
such
as
Frontiir
in
Myanmar,
that
have
publicly
denied
collaborating
with
governments to censor and surveil. Additionally, ISPs such as Frontiir and Safaricom that
are
working
with
client
governments
and
Geedge
Networks
receive
foreign
direct
investment from Western countries, companies and financial institutions. How much of their
work
with
Geedge
Networks
is
disclosed
to
their
Western
investors
and
shareholders
remains a question.
Copying and building on existing commercial products
and open source code
This research makes clear that Geedge Networks often copies existing products developed
by Western companies. Geedge Networks appears to be plagiarizing certain commercial
products, such as Greynoise and Fortinet networking appliances. They also incorporate
open-source code in ways that may violate licensing terms. Geedge seems to be using
these tactics for competitive advantage — to more rapidly offer a set of products that
match the capabilities of leading competitors while also building resilience to sanctions.