I don't think there's a country that has issued a complete ban comparable to the US, and most European countries will probably purchase 5G tech from Huawei for parts of their networks.
These really basic maintenance tasks aren't happening, leaving cell networks vulnerable to anyone who can be bothered to look up a CVE and run the provided demo exploit code. Hard to maintain a network you can't secure :c
it's reasonable to think that regardless of their SSL implementation, you should assume that the network owner is going to try and spy on your traffic and sell it to the highest bidder
Telcom security is a mess, but the frontline gear is usually the saving grace of the network.
There could be TLS involved in higher level protocols like IMS though. Or not. Does anyone know if eg VoLTE relies on the network for security or does it run SIP over DTLS or something?
Problem is, really basic maintenance tasks like updating OpenSSL aren't happening on Huawei's existing cellular basestations, leaving cell networks vulnerable to anyone who can be bothered to look up a CVE and run the provided demo exploit code. Hard to maintain a network you can't secure :c
https://hmgstrategy.com/resource-center/articles/2019/04/04/...