9 ms·
The title is misleading... my interpretation of the contents is that KPN outsourced the maintenance of their mobile core network to Huawei, and that Huawei pers
by terom 5y ago
The title is misleading... my interpretation of the contents is that KPN outsourced the maintenance of their mobile core network to Huawei, and that Huawei personnel as a result had full technical access to the network. There is no evidence given than Huawei actually abused that access, which would indeed be major news.
I assume they had some contract to spell out the legal level of access that Huawei had... the level of technical access would presumably have been exactly the same had they outsourced the maintenance to a western company, the legal protections would presumably just have more weight in that situation.
The worrying part is that the owner of the network apparently lacked audit logs of any such technical level access. That's still just as much of a problem with insider threats if the company manages the network themselves?
- rapsey 5y agoIf you buy huawei 4g/5g equipment, can you run it yourself completely? It is probably completely standard if you have their gear to also pay for their support and thus needing to give them access to your network.
- g_p 5y agoMost operators take a support and maintenance contract. It's also worth remembering that many operators don't have the staff needed to even install radios and other distributed equipment - often the radio vendor can offer that service to you as well. You can run a mobile network with minimal external access, but the economics are such that few want to - in an era of outsourcing and managed services, it's less about what can be done, and more about what is done in reality. Managed service providers have significant levels of access into mobile networks, beyond what many are aware.
- rapsey 5y agoWhich is why the US was so adamant against western countries buying from a Chinese vendor.
- pbhjpbhj 5y agoThere's a few reasons, one is financial - USA wants those installation contracts. Another is that USA wants covert access to those networks (instead of the Chinese). For me as a private citizen of the UK the Chinese having access seems less likely to impact me than USA having that access.
- imiric 5y agoThere's something disturbingly dystopian about governments competing for access to private individual data, and us having to consider which one we're more OK with... How about "no" to all of that nonsense?
- stunt 5y ago> How about "no" to all of that nonsense? I agree, but I'm not sure if we can stop it. I think it's desirable to ask them to be transparent about it though. Knowing what's is place and how it works seems like a basic right.
- pydry 5y agoDoesn't explain why the US was equally adamant that western telcos with the know how shouldnt buy "dumb" Huawei equipment, vet it and install it themselves. This is what made me think that this is at its heart not about security at all and more about just isolating Huawei.
- sam_lowry_ 5y agoBert Hubert wrote on this subject last year. The trouble with Huawei is a symptom of a much bigger problem: https://berthub.eu/articles/posts/5g-elephant-in-the-room/ https://berthub.eu/articles/posts/5g-elephant-in-the-room/
- AndyMcConachie 5y agoPeople should take the time to read this article.
- Woodi 5y agoFrom that article: "As an icebreaker, [telecommunication operators] were asked if they thought the Chinese could eavesdrop through “backdoors” in Huawei equipment. Every single hand went up. One of the bankers then asked, for balance, if they thought the US could access communications through key Cisco equipment. “All the hands went straight back up without hesitation” WHY HE WAS EVEN ASKING ??????? What is wrong with suits ????? Retoric of course. But wrong is that they work in managing things. Not technicaly improving/creating/replacing things. So any action is just manage, risc ma^H^H ditching. We need to replace our managers with technology peoples. PS. Still US is preffered option. PPS. Avoid Cisco at all costs !
- retox 5y agoI'll echo (but not endorse) the standard reply; I feel better that the Chinese regime can access my data than the US regime who could seriously ruin my life. That balance may (will?) tip at some point.
- friedman23 5y agoYour beliefs are uninformed and selfish. The Chinese government wont use its control over networks to target people like you. It will use them to target human rights activists and Chinese dissidents along with stealing technology from your country.
- dathinab 5y agoWait? Why where the comments here flagged and removed, they where right in that china is most likely abusing such things for industry espionage and pushing political opinions, [rest mine:] and we know (Snowden) that the US does so. Through in both cases both powers most times don't need to use any backdoors or similar as they can just influence the companies in questions directly. Like don't forget the currently ongoing law suite against a (Chinese) Zoom executive or how they repeatedly successful pressured Apple, to erode how much apple users can go against the CCP... (e.g. removing disliked censor resisting Apps and similar). And lets be honest for most (but not all) people neither power would ever bother targeting them directly, but the side effects of targeting which isn't against them directly still has a good chance of long term degrading their live quality (IMHO).
- Gys 5y agoThe original article contains more details. Like the discovery of a work around that enabled direct access outside the procedure that was agreed upon. Indeed there is no proof it was actually used, but why was it there in the first place? Something that was not logged does not mean it did not happen. Actually, if it was my work I would make sure not to output something in local logs.
- terom 5y agoI assume you mean the original article from De Volkskrant [1]? Unfortunately it's a) paywalled b) in dutch, so I won't be reading it :( The original Capgemini report would definitely be interesting reading, but I don't expect that to become public. [1] https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle-gesprekken-van-mobiele-kpn-klanten-afluisteren-inclusief-die-van-de-premier~bd1aece1/ https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...
- bondarchuk 5y agoI've translated that article: https://news.ycombinator.com/item?id=26844234 https://news.ycombinator.com/item?id=26844234
- bredren 5y ago"it has never been established in all years that customer data was stolen by Huawei from our networks or our customer systems, or that it has been tapped." Isn’t this basically the position that Ubiquiti took in the last few weeks? What’s this called? Plausible deniability?
- BrandoElFollito 5y agoThere was a case where a backdoor was discovered on cisco devices. It was a "bug", something a dev forgot. Sorry for that. I am french and have zero trust in Chinese or US equipment but since we do not have our own (at least style that makes sense) I use theirs and hope for the best.
- g_p 5y agoYou are right, although I'd add one observation - when you have hardware from a supplier, and give that same supplier managed service provider access, you are giving them access beyond that which you understand - processes and procedures implemented/enforced by their systems have no independent scrutiny over. Given the prevalence in enterprise networking equipment of undocumented admin accounts, you need to manage the risk when the vendor itself is the one getting direct manager service access. The lack of technical layer logs is a concern, but these logs also need to be independent and generated by equipment from a different vendor - it would be easy to (for example) not log any received command packets with the TCP evil bit set. An external logging system from another vendor would detect this. Unfortunately mobile core networks are often relatively limited in vendor diversity, so it's possible you won't have this in place.
- terom 5y agoAgreed, as a random HN commenter it's way too easy to trivialize the complexity in audit logging such a complex system. Such audit logs are very much dependent on the integrity of the system generating them, and the vendor themselves is certainly in the best possible position to compromise that integrity. I suppose that switching from a vendor-operated system to an independently-operated system would simplify the implementation of trusted audit logs for mitigating the remaining insider threats, though.
- g_p 5y agoAbsolutely, but to build a suitable independent logging system that understands the protocols used, and all the relevant fields, would be hugely complex. Ultimately, you'd need to log every packet in full if you don't trust the core vendor - a control packet could contain an undocumented field like 'cmd', whose value is executed by root... That's the kind of threat you'd be looking to catch. That means you'd need to terminate transport layer encryption on this "firewall/log" system, so that you can see and log the content of control messages. Ultimately, you'd need the cooperation of the vendor to actually build a system that could meaningfully understand these control/management messages, and therein lies the problem!
- simion314 5y ago>The title is misleading. That is intentional, probably a lot of money is spent by governments to create a narrative, then later they can justify different actions based on fantasies.
- sschueller 5y agoFeels like the Huawei bashing is back. Justified or not. It always comes in burst as if one bad article is used as an opportunity to amplify negative press. If it is a state or competitors is hard to tell. Maybe just a result of all these ad algorithms that try to get as much engagement as possible resulting in one story that has a bit of traction getting amplified like crazy. Just look at what happened to J&J last week. The damage is done, no one will want it if it turns out to be safe.
- philliphaydon 5y agoI wouldn’t have taken the J&J one anyway after all the baby product issues they have had.