Huawei was able to eavesdrop on Dutch mobile network KPN: Report
nltimes.nl
nltimes.nl
I assume they had some contract to spell out the legal level of access that Huawei had... the level of technical access would presumably have been exactly the same had they outsourced the maintenance to a western company, the legal protections would presumably just have more weight in that situation.
The worrying part is that the owner of the network apparently lacked audit logs of any such technical level access. That's still just as much of a problem with insider threats if the company manages the network themselves?
You can run a mobile network with minimal external access, but the economics are such that few want to - in an era of outsourcing and managed services, it's less about what can be done, and more about what is done in reality.
Managed service providers have significant levels of access into mobile networks, beyond what many are aware.
For me as a private citizen of the UK the Chinese having access seems less likely to impact me than USA having that access.
How about "no" to all of that nonsense?
I agree, but I'm not sure if we can stop it.
I think it's desirable to ask them to be transparent about it though. Knowing what's is place and how it works seems like a basic right.
This is what made me think that this is at its heart not about security at all and more about just isolating Huawei.
"As an icebreaker, [telecommunication operators] were asked if they thought the Chinese could eavesdrop through “backdoors” in Huawei equipment. Every single hand went up. One of the bankers then asked, for balance, if they thought the US could access communications through key Cisco equipment. “All the hands went straight back up without hesitation”
WHY HE WAS EVEN ASKING ??????? What is wrong with suits ?????
Retoric of course. But wrong is that they work in managing things. Not technicaly improving/creating/replacing things. So any action is just manage, risc ma^H^H ditching.
We need to replace our managers with technology peoples.
PS. Still US is preffered option. PPS. Avoid Cisco at all costs !
Through in both cases both powers most times don't need to use any backdoors or similar as they can just influence the companies in questions directly. Like don't forget the currently ongoing law suite against a (Chinese) Zoom executive or how they repeatedly successful pressured Apple, to erode how much apple users can go against the CCP... (e.g. removing disliked censor resisting Apps and similar).
And lets be honest for most (but not all) people neither power would ever bother targeting them directly, but the side effects of targeting which isn't against them directly still has a good chance of long term degrading their live quality (IMHO).
> Huawei’s says it never acted inappropriately by abusing its position in the Netherlands.
I believe Huawei (as company) never did so, and the IMHO most likely existing Huawei employed which might do so anyway also likely didn't do so because they had no reason to (as far as I know). The think about people you install somewhere is you don't us them until you necessary. Because then they likely won't get caught.
The original Capgemini report would definitely be interesting reading, but I don't expect that to become public.
[1] https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...
Isn’t this basically the position that Ubiquiti took in the last few weeks?
What’s this called? Plausible deniability?
It was a "bug", something a dev forgot. Sorry for that.
I am french and have zero trust in Chinese or US equipment but since we do not have our own (at least style that makes sense) I use theirs and hope for the best.
Given the prevalence in enterprise networking equipment of undocumented admin accounts, you need to manage the risk when the vendor itself is the one getting direct manager service access.
The lack of technical layer logs is a concern, but these logs also need to be independent and generated by equipment from a different vendor - it would be easy to (for example) not log any received command packets with the TCP evil bit set. An external logging system from another vendor would detect this.
Unfortunately mobile core networks are often relatively limited in vendor diversity, so it's possible you won't have this in place.
Such audit logs are very much dependent on the integrity of the system generating them, and the vendor themselves is certainly in the best possible position to compromise that integrity.
I suppose that switching from a vendor-operated system to an independently-operated system would simplify the implementation of trusted audit logs for mitigating the remaining insider threats, though.
Ultimately, you'd need to log every packet in full if you don't trust the core vendor - a control packet could contain an undocumented field like 'cmd', whose value is executed by root...
That's the kind of threat you'd be looking to catch. That means you'd need to terminate transport layer encryption on this "firewall/log" system, so that you can see and log the content of control messages.
Ultimately, you'd need the cooperation of the vendor to actually build a system that could meaningfully understand these control/management messages, and therein lies the problem!
it can be a minimal requirement, more so if it is such a sensitive system.
That is intentional, probably a lot of money is spent by governments to create a narrative, then later they can justify different actions based on fantasies.
Just look at what happened to J&J last week. The damage is done, no one will want it if it turns out to be safe.
Anyway,
KPN laat vanochtend aan de NOS weten dat nooit is vastgesteld dat er
door Huawei klantgegevens zijn ontvreemd uit het netwerk of de klantsystemen, of dat er is afgeluisterd.
KPN told NOS (the above news site) that there is no evidence Huawei collected customer personal info or that they've eavesdropped. The bad news is that that's because they have no way of knowing, as mentioned elsewehere in the article.That said, a month ago it was reported [1] that Huawei did explicitly add a way for them to access customer data of one of KPN's subsidiaries, and that it used that "regularly". Could theoretically be e.g. to aid debugging or something, but not a great look.
[1] https://nos.nl/artikel/2374551-huawei-had-onbeperkt-toegang-...
https://0bin.net/paste/poCzYk4t#IRjhnXLT31zdiDMCVJIIqvZgLDqh...
Edit: updated to add responses of KPN, Huawei and several experts.
If that's true it's bad enough. But it sounds like they are just saying Huawei engineers had access to the internal network at certain times for debugging purposes. Which is not surprising at all.
Logically police and intelligence services should be ones telling ISPs what to tap. And they should only comply with proper process. Anything else is totalitarianism.
Reality is the anglo-europeans(atlantic coastal folks) wants to split the world in half at least in cyber space. Pompeo talked about it openly with the Clean network initiative. That means no Chinese tech or hardware in the west. They will pull the whole of the EU with them either peaceful and if that doesn't work forcefully.
But the clean network initiative isn't only about China, its also about Iran and Russian. I expect a big boom in Iran tech, the following next two decade now that China has given them a get out of jail card from the western financial siege war.
Its not like western companies don't have access at all, Facebook for example still earns quiet some money from China selling ads, Google was planning on making a Chinese specific search engine called Project Dragonfly. Would google really allocate all those resources for a market they can't access?
If the Chinese networks / markets were so easy to penetrate as you are suggesting, why would Google have to spend so much time developing a separate search engine for them to be approved by the CCP? Why wouldn’t they just use the search engines that are already out there? It’s pretty obvious as to why.
Like the saying goes, When in Rome, Do as the Romans Do. So when in China, follow the Chinese regulations. The Chinese should do the same when they want to invest here in the EU.
We can do better as a civilization and learn from past mistakes. The fact China downplays and denies theirs while trying to gaslight the world should be reason enough to never do business with them until this changes and they can be transparent and honest.
Unsurprisingly comments like yours come to their defense anytime a news story like this comes along. It's tiring, frankly.
Ultimately it works like this - all rising powers have the choice to stay fully shackled by IP and remain subordinate and poor forever, or they can take that IP and provide a better life for their people. Unless there is some alternative there, I just can't fault a country for doing it. Especially when the current top dog is only there because they did it too.
The concept of IP is already morally questionable to begin with, now we want to use it to keep half of the world poorer and dependent in perpetuity?
I'm not well versed in game theory, but if tit-for-tat is a winning strategy, it's unreasonable to continue to cooperate with a party that actively tries to screw everyone else over at every turn.
What I'm not sure about is why anyone is surprised. Especially in an age where everything is framed as a struggle for power, you would expect this to be the case, especially for an emerging superpower. Economics is here just war by other means, and consumerist lust for cheap goods the Trojan horse by which China will succeed.
But one thing I want to highlight is the fact that this story appears to be based off a report written by a consulting firm, Capgemini. For that reason alone I would bet that this report identifies hypothetical risks, not actual instances of unauthorized access.
But doesn't the article also imply (who knows if it's true) that such access would not have been logged, in which case how can Huawei be sure there was no access by an employee which did abuse it (and was neither asked by Huawei to do so nor did Huawei know about it).
Much of the "spying" attributed to companies like Cisco or Huawei are generally not done by the company but by people working for it which act outside of the companies directions (but likely where directed by external powers like the Us or China).
Similar in both countries there are non-public court decisions under which we can't guarantee that the Company wasn't forced to do so and forced to tell everyone they didn't do anything like this. (can't guarantee doesn't mean it happened, just that there is no guarantee).
Which is in the end the whole problem with Huawei (or Cisco) even if the companies clearly have no intention to do such thinks, it's very likely that employees from them or even they themself are forced to do such things in some cases, especially if trade and/or political relationships degrade.
This isn't the case with Cisco or others. Which you are implying.
https://tweakers.net/nieuws/180606/huawei-kon-rond-2009-onge...
( Dutch IT site)
But, maybe we should talk about outsourcing! Most people do not know how awful is their trusted brand at managing its contractors. Often there is no technical team to lead and control. They only hire a bunch of incompetence product managers with power point skills that have no clue about what is going on.
"Huawei was able to eavesdrop on Dutch mobile network" in the original sounds a lot less incriminating than "Huawei eavesdropped"
Weapons of mass destruction capable of reaching the capitols of Europe.
>KPN informed the news source ANP on Saturday that "it has never been established in all years that customer data was stolen by Huawei from our networks or our customer systems, or that it has been tapped."
[1] https://en.wikipedia.org/wiki/NSA_ANT_catalog (see DROPOUTJEEP)