Huawei set for limited role in UK 5G networks
bbc.co.uk
bbc.co.uk
There is a real risk in using Huawei equipment, but the risk can be mitigated.
If the Chinese government tells Huawei to insert a backdoor, Huawei will certainly comply. But state actors don't necessarily need backdoors to exploit equipment. They're going to look for bugs, which they're just as likely to find in competitor's equipment as anything else. So the real solution is not to exclude Huawei because they're Chinese, but to make sure engineers fully understand the system from the hardware on up. This means insisting on open source systems and then conducting thorough audits.
All their code must be open sourced, in order to win foreign contracts. And all it took was a little trade war.
Also vulnerability is another vector. You concentrate on what you know but not others left open is very hard to know.
Huawei can require that the UK certifies the source code, and to even do the actual compilation step itself, and to sign the final executable programs and configuration files. At which point, the binaries are created, and the UK will have a cryptographic signature of the file.
Thus the binary is now cryptographically secured, that even China, with their mysterious black magic, cannot break the mathematical and thermodynamic laws of nature. /s
The UK team then approves this binary, and allows Huawei to begin mass installation on the hardware via firmware flashing. Then Huawei will initiate mass production, and begin shipping out the hardware to worldwide customers. Then the UK can post-certify that the same source code that they compiled and published, is the exact same code that is in the hardware.
The same process can be done for continuing code updates.
Huawei can mandate that the UK provides a team to do the final compilation and verification step, and this team must promise (by penalty of law) to remove themselves from any conflict of interest, meaning they cannot work on similar technologies in the future, to compete against Huawei. It’s like a non-compete agreement. And they also cannot disclose any Huawei trade secrets, or algorithmic details of Huawei’s 5G hardware. Their responsibility is to just ensure security, and do penetration testing for security weaknesses. And China can even mandate that the UK team relocate to China, to view the source code onsite.
And they can even run this for all hardware blueprints too. And monitor the code that also goes into the other chips on the SoC motherboard.
Then Huawei and China can claim that the code was validated by the UK itself, and here’s the genuine certification ID. And that it’s free of any known defects or spyware code.
That would be nice, and in any case I'm a big believer in protecting your information at the protocol level instead of trusting this or that foreign government.
But once you've put that much effort into vetting it, aren't you pretty close to being able to roll your own on commodity hardware?
Ultimately this is a problem with the technical literacy of our politicians and a matter of underpaying people that work for the technical agencies responsible for national security like GCHQ.
> They're going to look for bugs, which they're just as likely to find in competitor's equipment as anything else.
> [T]he real solution is not to exclude Huawei because they're Chinese, but to make sure engineers fully understand the system from the hardware on up.
> [T]his is a problem with the technical literacy of our politicians [...]
In my simple view [1], we're all thinking from an engineering "global optimum" mindset, as happens often here, but none of these solutions are realistic. Neither now nor going forward.
If you look at it from a political POV, the question should be: "how did Huawei find itself in a position like this?"
The approach, hence, should be a combination of a renewed massive investment in tech (similarly to military spending) on the one hand, and strong state support on the other hand. That sounds crazy and even "socialist" to a US audience, but on the other hand wouldn't be the first time this has been done. A follow up question would be about what's holding us back. I'll leave that to think about.
Similar reasoning for general infrastructure projects, I feel.
[1]: I'm not putting this out as gospel, so feel free to offer counters.
China has a competitive advantage on creating tech at lower cost. America is awash in investment dollars, but has burdens that the Chinese do not have (IP, compliance, competition with other market participants like Google / Apple for the same talent) and it isn't realistic to keep our hopes on America or other western countries always matching the lowest cost. Some things need to be prioritized strictly because they're national security interests. Our media companies shouldn't be owned by state backed foreign interests, our defence companies shouldn't be, and our networking gear shouldn't be riddled with gear from a country like China that mass incarcerates people based on religion or ideology.
I'm not saying things will be perfect if we keep China out of our 5G space—far from it—but the internet is essentially a nervous system for machines and if we allow their gear all over our networks it's going to be utilised against us. In an ideal world even a country like Canada would have their own networking gear providers, so that if a country like the USA slides into despotism we wouldn't have to worry about getting strong armed, but we're far from that ideal scenario and I'm only hoping for less of a bad bargain than we're likely to find ourselves in 20 years from now.
All Comms kit has back doors in it. Its about choosing whom you allow to put them in.
Cisco was riddled with backdoors, and if you were interesting, the five eyes would specially intercept your kit and put extra bits in before it was delivered to you.
The issue here is geopolitical. Who has control of your friend's internet.
Now there are few ways to look at this:
1) this is the present government's master plan to use this as a bargaining chip in negotiations
2) The kit is going to be at the edge, which if the network is designed properly, will mitigate attempts to snoop or spoof
3) GCHQ et al, can't plan for shit.
4) The government and civil service can't plan for shit, don't understand how tech can influence geo politics
5) Trump is trying to get allies to buy shitty expensive kit from the USA.
Out of all of these 4 is my favourite hypothesis, but there are bound to be more factors. Yes, Huawei have sponsored a lab to prove that their kit is secure. But of course they would, they are not going to ship gimped kit to be tested.
Also, As Huawei kit already operates vast parts of openreach's network (the company that runs the vast majority of landlines and fibre) the point is kind of moot. The decision to allow this is why marconi bit the bucket, killing the last bit on comms design the UK had. (like every other pioneering electronics/computing company in the UK.)
Existing Huawei equipment should be removed. Sunken cost fallacy is well...a fallacy.
You mentioned Trump to ellicit political emotions but oppositiin to Huawei by US started during Obama's era and had bipartisan support.
GCHQ and the UK can indeed plan "for shit" as you put it, possibly more than you CCP fellas.
Whether they use this a bargaining chip or not does not change China's hostilities.
And last but far from least!!!!! It does not matter if their equipment is on the edge, do you want HN readers to suspend all knowledge of networking? Even if their equipment is purely layer2 and will only see encrypted traffic:
1) this still lets them be poisitoned to exploit and track arbitrary devices. 2) this still let's be in a position where they can abuse trust with the core or exploit the core. 3) this still lets them be in a position where they can cripple UK's communication infrastructure (DOS),which if they're smart,that's the primary vulnerability they will exploit in case of an invasion/war/pre-kinetic-war
I've not called for it to be removed, I pointed out that Openreach's decision (backed up by government) killed the only domestic player. Hence my comments on not being able to plan. Also, being in my current position I work closely with policy maker and those who advise. The level of dysfunction, piss poor office politics and general incompetence, is all too depressing
> Whether they use this a bargaining chip or not does not change China's hostilities.
This is orthogonal to what a bargaining chip is for. Its not about hostilities, its about who is in control. As now small player, shopping loyalties is the last great choice Britain has. (EU/US/other) Think Israel in the 50s/60s. They played a blinder.
> 1) this still lets them be poisitoned to exploit and track arbitrary devices.
yes and no. They still require access. If we ignore that the entire backhaul touches huawei kit, nominally the control plane is going to be separated from the data plane, whilst they could in theory collect this data, they'd still need to get it out.
> 2) this still let's be in a position where they can abuse trust with the core or exploit the core.
if the control plane is on the same network then yes. But as you well know control planes needs to be isolated to stop all sorts of failure types.
> 3) this still lets them be in a position where they can cripple UK's communication infrastructure (DOS),which if they're smart,that's the primary vulnerability they will exploit in case of an invasion/war/pre-kinetic-war
THe same goes for all the backdoors in present kit. Just because a country "owns" a manufacturer it doesn't mean that they own the backdoors.
But all of this supposes that every telecom use the same kit. Unlike landline, which is monopolised by openreach, there are still four mobile networks. of course its possible to launch a DOS on all of them using technical means, but its far simpler, cheaper and quicker to bribe a few NOC operators.
I personally don't think we should be using huawei kit, marconi shouldn't have been killed. but politics is politics.
The USA is our long time ally. Yes, I can roll things off the top of my head where they’ve stitched us up but I can also do the same for areas where mutual cooperation with the US has greatly helped us.
That’s everything from military cooperation during the Cold War to the original Human Genome project.
I can’t easily do that with China. I can point to the constant cyber attacks coming from China or their closed markets but I can’t think of many ways China cooperates with us.
Perhaps I’ve missed some examples and someone could enlighten me where China has acted in the UK’s interest?
This is the only point I'm not sure I agree with. The US lost a major chunk of our Telecoms hardware capability when Lucent imploded in 2006 and took Bell Labs and all its engineers with it. Alcatel bought it, then Nokia bought it. So there's not much telecoms gear the US can provide to the EU/UK, that EU companies can't. Not much reason for the EU/UK to go with US suppliers here.
For years now, some European network operators (especially if they have government contracts) have silently limited what they buy from Huawei. Base stations and most hardware is OK. Operating services, network control, visitor and location registers, mobile switching centers, network monitoring, and related software dealing with the core network can be bought from others if there is need. Interfaces are standardized and you can buy different components from different vendors. Many EU countries just "happen" to have one or two carriers with strategically shielded core networks.
The real problem with Huawei has been lower quality software relative to competition. If I had to guess, I would say that NSA exploits holes in Huawei software to spy European allies at least as much as Chinese do or as much as Europeans spy each other.
It's no different than Russia and China govs having a blanket ban on Windows and some western hardware.
Interesting twist at the end there, so the NSA is the big concern even with China designed and built hardware eh? Exactly how gullible do you expect readers of your comment to be? Let's say for a moment that even though China (a nation very hostile to the US and UK with a myriad of APT groups who focus on different goals such as corporate espionage,strategic compromise,misinformation and state espionage!) has the advantage of being able to instruct (not coerce since in China this wouldn't be against Huawei's rights) Huawei to implement layers of hardware and software backdoor,they somehow exploit Huawei devices at the same rate as NSA,let's say that's true, so what? Do you expect people to believe the NSA would target the UK as much as China does? Haha, let's say even that is true,so what? The UK are the US's closest ally, while China is probably the most hostile nation to the UK right now, vulnerabilities mean nothing without a threat that causes their exploitation to reduce a security property right??
You're essentially using clever wording to say "Hey, that's just a wooden horse,so what if our enemies left it at the gate? Even our allies send us gifts sometimes,they are just as likely to use it to a malicious end"
And no wonder your comment is top! I use to see this a lot when I was using quora a few years ago. Chinese "trolls" are so different than russian,they're always intelligent,word things well and very very subtle with good knowledge of western context but the propaganda angle is always clear like this. They specifically target influential academic(ish?) sites to exert influence. I am not fully sure you're one of them,but your comment is uncanningly similar. I never thought about an influence operation on HN,but man it makes so much sense.
There's years' worth of further explanation at https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme... if anyone wants it.
edit: remove paste garbage from the beginning
China couldn't kidnap me - they'd get huge political repercussions from the US. China kidnapping me on US soil would be very risky for them too.
On the other hand, the US could totally imprison me on bogus charges constructed from spy data.
If I was a Chinese national living in China, all of the above would reverse.
EDIT: By the way you are wrong about kidnappings in the US by China. This has happened in the past and still happens today where China uses Chinese nationals based in the US to locate dissidents or “tax-evaders” and force them against their will to fly back to China.
What’s the capital investment of 5G — how much money are we talking about here?
The article doesn’t mention one, but is there a major US supplier of telecoms equipment that is vying for these contracts, being propped up by the state department?
Edit: The following report says £2.5b capex, £1.7b opex over the next decade
https://assets.publishing.service.gov.uk/government/uploads/...
So really, given the amount of auditing that has been done on Huawei equipment recently, we could almost say that their equipment can be trusted more than that of other manufacturers.
> The results of the analysis show that Huawei devices quantitatively pose a high risk to their users. In virtually all categories we studied, we found Huawei devices to be less secure than comparable devices from other vendors
https://www.scmagazine.com/home/security-news/vulnerabilitie...
There was some good discussion on the report 6 months ago: https://news.ycombinator.com/item?id=20421148
Are the margins thin and production slow so that multiple suppliers are needed? If someone does not trust a supplier why it is hard to just keep them out completely? Is it more about politics beyond the network rollout?
In true British fashion we'll end up with a compromise that upsets everyone.
Personally, I'm worried (not sure that's the right word) that China will just do it's own thing in the near future. It was a miracle that LTE phones work worldwide, IMO. China had/has its own 3G CDMA tech. I wouldn't be surprised if the market gets fragmented in later releases of 5G or with 6G.
So they were allowed to join the WTO, and Qualcomm made billions in IP royalties.
I don’t have the evidence at hand. Perhaps someone else can find it.
If a major Chinese supplier is completely excluded because they are Chinese then it will be seen as a very deliberate snub. This in turn will make it harder to achieve the goals mentioned above (investment, trade, etc). Instead, this kind of compromise is so the Chinese government don't lose face and Britain can still meet the national security requirements defined by the United States.
My concern is the 23.8GHz frequency used by 5G being devices so close to the 24GHz used by meteorology satellites.
https://money.cnn.com/1999/03/25/europe/ericsson/
https://www.wired.com/1999/03/ericsson-qualcomm-accord/
The americans won the really lucrative (and powerful - witness Trump/Brexit) application layer though (e.g. Google/Facebook/Amazon) so they shouldn't feel that bad.
The US will be looking for the UK to pay US-style inflated prices for pharmaceuticals, change food safety standards to accept subsidised US farm produce, and install an ISDS court to protect corporations' anticipated future profits.
Compared to these, banning Huawei - which isn't even a British company - would be a trivial concession.
Personally, I don't trust Huawei but that's mostly down to stories I've heard about industrial espionage against alternative suppliers.
For instance I never liked the way that BT replaced Marconi equipment with Huawei stuff in their 21CN network way back when. I think the government of the day was foolish to allow that to happen.
The bosses at BT at the time are long since retired on fat pensions and Marconi is now gone for good.
https://www.washingtonpost.com/opinions/2020/01/27/congress-...
The deal is that core networks are supplied by European NEP's mostly Nokia and Ericsson and radio elements are supplied by Huawei. There is very little information can be gleamed from from RAN, its all encrypted between the end point and the core network. Anyone wanting to harvest data will want to backdoor core network elements.
Another factor is that Huawei code has been provided and audited for a number of years now. Sure that is not full proof, but its way more than we have had available from any US vendors. I will be honest, as it stands I would trust a huawei box, way more than a cisco box.
On another note I expect this is a political play. The UK gets to not piss off the Americans too much (well putting aside Trump and his crazies) and the Chinese see us as favorable still. It's also quite interesting how this is coming off the back of Trump stating his displeasure at the UK governments plans to tax the tech giants more, with most of them being companies who are spying on global citizens at a volume never seen before.
https://en.wikipedia.org/wiki/Criticism_of_Huawei#Espionage_...
Guess we'll need to wait 50 years to get an idea.
I trust the Chinese more with our data than USA, tbh. Businesses should be end-to-end encrypting any way, so ...
I'd like to have seen them [UK politicians] tell Trump to go suck it, like "we'll use the technology we want and aren't going to be bullied into using USA companies just so you can get access to our data through NSLs". That would have been a display of this mythical sovereignty we're burning the country down for.
Don't take this as sticking up for China. It's more, shitting on all governments.