1 March 2019

Huawei Security Scandal: Everything You Need to Know

Kate O'Flaherty

An illuminated Huawei Technologies Co. logo is displayed above their stand on the opening day of the MWC Barcelona in Barcelona, Spain, on Monday, Feb. 25, 2019. At the wireless industry’s biggest conference, over 100,000 people are set to see the latest innovations in smartphones, artificial intelligence devices and autonomous drones exhibited by more than 2,400 companies. Photographer: Stefan Wermuth/Bloomberg© 2019 BLOOMBERG FINANCE LP

Cyber-espionage has been going on for years. In one famous example in 2012, it emerged that China had hacked UK defense firm BAE Systems to steal data about a $264 billion F-35 Joint Strike Fighter (JSF) jet. And it wasn’t the first time the country had been accused of stealing military jet plans.

But recently, the focus has moved to Chinese companies, particularly those that manufacture network equipment as 5G services start to roll out. So, why is all the focus on Huawei, and how secure is it to use its products and services?


Founded in Shenzhen, Guangdong, in 1987 by Ren Zhengfei, a former People's Liberation Army officer, the firm is owned by 80,000 of its 180,000 employees. Like its rivals Nokia and Ericsson, Huawei has manufactured mobile network equipment for years.

During the last decade or so it has stormed into the consumer market as a smartphone manufacturer and now owns 16% of the market. At Mobile World Congress (MWC) this week, it became the latest to announce a folding smartphone with the launch of the Mate X.

The story so far

There is growing concern about Huawei from governments around the world. So much so, that many have blocked telecoms companies from using Huawei gear in next-generation 5G mobile networks.

So far, the US, Australia and New Zealand have banned Huawei from providing equipment for their 5G networks, while Canada’s relationship with the firm is under review. There is also concern among European telecoms network operators, with some considering removing Huawei’s equipment. BT, for example, has removed Huawei equipment from key parts of its 4G network.

At the same time, the UK has expressed concerns, with the National Cyber Security Centre (NCSC) asking Huawei to fix issues that could pose a new risk to the network. 

The US is particularly concerned about Ren’s military background. And the State Department's top cyber official, Robert Strayer, certainly thinks there is an issue.

"A country that uses data in the way China has - to surveil its citizens, to set up credit scores and to imprison more than 1 million people for their ethnic and religious background - should give us pause about the way that country might use data in the future," Strayer said, according to The Washington Post. "It would be naive to think that country, [given] the influence it has over its companies, would act in ways that would treat our citizens better than it treats its own citizens."

Meanwhile, the daughter of Huawei’s founder, Meng Wanzhou was last year arrested by Canadian authorities, after the US government alleged that she was assisting Huawei in dodging US sanctions on Iran. She and the firm deny any wrongdoing.

Are Huawei phones safe?

Last year, Huawei phones were banned by networks including Verizon and AT&T after being labelled a security threat. Meanwhile, tech site Tech.Co interviewed Timothy Heath, senior international defense research analyst at the RAND Corporation, who believes it is entirely plausible that the firm’s phones could be used to spy:

“The threat is legitimate, given the murky links between Huawei and Chinese authorities. The Chinese state has the authority to demand tech companies like Huawei turn over useful information or provide access to the communications and technologies owned and sold by Huawei.

"Chinese authorities can use this information and access to facilitate espionage or cyber attacks over Huawei communications technologies. Consumer tech devices like phones that rely on Huawei technologies will be easier for Chinese authorities to penetrate and exploit for these reasons.”

He added: “Tech companies play a critical role in developing the dual use technologies that the PLA needs to fight a hi-tech war against world class militaries like that of the United States.”

What about Huawei network equipment?

As an equipment vendor, it is technically possible for Huawei to conduct espionage through the network, or even for it to disrupt communications with disastrous consequences. As more devices are connected to the internet, including autonomous vehicles and electrical grids, this threat becomes all the more real.

Meanwhile, the country’s 2017 National Intelligence Law passed in 2017 says organizations should "support, co-operate with and collaborate in national intelligence work".

The risk becomes bigger with 5G because the way the networks are designed and run makes it harder to monitor security, according to the head of the UK's intelligence service MI6, Alex Younger.

However, many of the UK providers including EE, Vodafone and Three have been working with Huawei to build their 5G networks. They are currently waiting for the UK government to decide whether they will be permitted to carry on doing so, with a decision coming in Spring this year.

What does Huawei say?

It’s Mobile World Congress this week so what better place for Huawei to hit back at recent comments from the US? During his keynote Huawei chairman Guo Ping denied that the firm spies on behalf of its country’s government. It has "no evidence, nothing", he said, adding that the vendor had never planted backdoors in its equipment and would not permit third parties to meddle with its kit. Guo said, according to Business Insider: "Carriers are responsible for the secure operations of their own networks. Carriers can prevent outside attacks."

He also hit out at the US government for its new law allowing it to demand data stored with Amazon, Microsoft, or other cloud providers.

What should you do?

First, don’t panic. Ian Thornton Trump, head of cyber security at AMTrust international, points out: “If nation states are going to hack, they are going to hack. This has very little to do with security; this has everything to do with market protectionism and vendettas against companies that don’t bend to the will of the US.”

He therefore thinks security is a side show “being used as leverage and FUD to promote someone else’s products and services”. He says: “There has been no public mention of a security issue with Huawei and you can bet an indictment that if it did have a back door this would be blasted to the media.

“The indictment of Huawei is about intellectual property theft – allegedly and perhaps not even an American company – and selling to Iran using front companies. How a Chinese company is subject to American law is of course the big and larger question.”

Huawei is certainly producing some innovative phones and it’s been working on network equipment for years. Of course, intelligence personnel will know a lot more about what’s happening behind the scenes, so it’s important to be wary. But at the same time, much of this is about political posturing: Do we really think Huawei has manufactured a folding phone so it can tap all our calls and take over the network? Probably not.

No comments: