Live data from Hacker News

Huawei was able to eavesdrop on Dutch mobile network KPN: Report

nltimes.nl

91–100 of 148 posts

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#91
I'm seeing a lot of misinformation here. The original source[0] is De Volkskrant, which is a _very_ reputable independent newspaper. It does not do sensation pieces.

Key points, from top to bottom:

- When a daughter company of KPN was looking for a new customer management system, Huawei's price was only 25% that of the competition. This was so low that employees initially thought it was a mistake.

- In 2009, KPN wants to reduce the cost of managing the mobile network by outsourcing ot to Huawei. It asked Capgemini to analyze the risks, which is the now-leaked report.

- The results are alarming enough that they are declared secret. Literally, "if those results were to become public, there will be a mass exodus among companies and governmental organisations to other providers. The existance of KPN as a whole would be seriously threatened".

- The core network is managed by Chinese citizans from a dedicated room in The Hague.

- Access from China is possible, but strictly limited. It requires explicit permission from the KPN NOC, who are supposed to provide temporary access.

- Unauthorized and uncontrolled access from China has been detected after 28 october 2009.

- The KPN network has a wiretapping system. A record of phone numbers being tapped is kept on a secure server. This server is managed by Huawei, who refuse to provide information about who has access to it and how it is secured. After a lot of pressure, they discover that tyis security is extremely weak and that Huawei has full control over it - meaning that Huawei has full knowledge of all numbers being wiretapped by the police and intelligence agencies.

- The six Chinese employees use a tool which allows them to listen to any phone call on the network. This is in direct violation of the law and it violates the agreement between Huawei and KPN. They can use this tool without anyone at KPN being made aware of it.

- Huawei is supposed to have access to second-long snippets for quality assurance. In practice, they had full access to all phonecalls. KPN had no way of knowing what they were doing.

- The tool used has no record keeping and the interface is in Chinese, meaning nobody is able to understand what they are doing.

So yeah, yikes.

This is way beyond admins having admin access. This is Huawei having unlimited access far beyond what they are supposed to, and evidence of this access being actively misused. It's not just the regular propaganda.

[0]: https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#92
This reminded me of "How Tech Loses Out at Companies, Countries and Continents" by Bert Hubert of PowerDNS.

https://berthub.eu/articles/posts/how-tech-loses-out/ https://news.ycombinator.com/item?id=26849669

KPN should be administering their own equipment.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#93

Earlier quoted context omitted.

> Now, obviously telco equipment can be used for spying, but there's absolutely no allegation of wrongdoing here at all. That's incorrect. The report made by Capgemini stated that there were clear boundaries as to what Huawei was allowed to access but they violated those boundaries. Apparently also a list of numbers under surveillance by Dutch intelligence was found in possession of Huawei. Which was clearly well bey…

Though I can't read the actual report, this article does not support your claims. >Apparently also a list of numbers under surveillance by Dutch intelligence was found in possession of Huawei. Which was clearly well beyond those boundaries Wouldn't the ones running the network need to know which numbers were under surveillance to provide the intelligence agency access?

The original source[0] definitely supports those claims.

"Ongecontroleerde en ongeautoriseerde toegang vanuit China heeft na 28 oktober 2009 daadwerkelijk plaatsgevonden"

which translates to

"Uncontrolled and unauthorized access from China actually took place after October 28, 2009"

> Wouldn't the ones running the network need to know which numbers were under surveillance to provide the intelligence agency access?

No. That data should only be on a server within the KPN network. Huawei employees had an office in a KPN building. There is no need for that data to ever leave that network.

[0]: https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#94
post #10

So there is no story, but a potential story on a potential (fill in the blanks) So you outsourced some services as many companies do and failed to keep tabs on it, just like many companies do. Forgetting to audit outsourced work is extremely prevalent. A report by Capgemini, a leading Western supplier for outsourced personnel to telecommuncations companies. No conflict of interest there.

As the original article[0] states, the report explicitly says that public knowledge of the report would threaten the existance of KPN due to the massive loss of trust in the company.

The report contains the sentence

"Ongecontroleerde en ongeautoriseerde toegang vanuit China heeft na 28 oktober 2009 daadwerkelijk plaatsgevonden"

which translates to

"Uncontrolled and unauthorized access from China actually took place after October 28, 2009"

KPN has zero incentive to admit to anything and every incentive to deny everything. I'd take such a PR statement with a grain of salt.

[0]: https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#95
post #63

Earlier quoted context omitted.

We have another thread actively discusses potential issues with Google's FloC [0], which is only a proposal at this time, no harm done yet. Do you think Huawei/China is less of a potential thread than Google? If not why do you think there is no story here? [0] https://news.ycombinator.com/item?id=26854073

...a threat to who, and for what? There are two main concerns at play here that are very different: consumer privacy and national security. The consumer privacy concerns are generally subject to regulation by law, but national security concerns often are extralegal in nature. This makes a big difference in the availability of tools to address the problems. Google will follow your laws or pay fines until they comply.…

>...a threat to who, and for what?

I'm sorry, are you just completely ignorant of everything that's happening across the globe? If so, why are you even commenting?

China routinely harasses, threatens, and then acts on threats given to human rights activists and expats. Chinese citizens that speak with reporters and human rights activists are put at severe risk because people like you are fine with letting Chinese technology infiltrate all aspects of your infrastructure.

Your ignorance is malicious.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#96
post #88

Earlier quoted context omitted.

I feel we need to read all these stories with a skeptical eye because, frankly, Huawei's become a political football, and there is a very strong motivation to cast events in the most unfavorable light possible by officials who are working backwards from the conclusion. Perhaps they do have some kind of spying master plan but I have found a lot of the fanfare for these stories hasn't held up to scrutiny.

Understand that feeling but Huaweis existence is born from corporate espionage stealing IP from Nortel networks in the 00s. Not a great starting point for a company and it really doesn’t take much of a stretch to see the concern about Chinese party wanting to spy on the rest of the world given the lack of freedom of their own people...

> it really doesn’t take much of a stretch to see the concern about Chinese party wanting to spy on the rest of the world given the lack of freedom of their own people

Perhaps not, but I try not to believe things just because they confirm my existing biases.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#97
post #5

The spin on this situation is dumb. What it amounts to is that KPN hired Huawei on a contract basis to administer its equipment, and as a result those contract administrators had... administrator privileges on the Huawei equipment. Now, obviously telco equipment can be used for spying, but there's absolutely no allegation of wrongdoing here at all. If there is any finger to point, it's at KPN for hiring an untrusted…

And that's pretty much the situation of every telecom in europe and probably many more countries https://berthub.eu/articles/posts/5g-elephant-in-the-room/

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#98
post #91

I'm seeing a lot of misinformation here. The original source[0] is De Volkskrant, which is a _very_ reputable independent newspaper. It does not do sensation pieces. Key points, from top to bottom: - When a daughter company of KPN was looking for a new customer management system, Huawei's price was only 25% that of the competition. This was so low that employees initially thought it was a mistake. - In 2009, KPN want…

Hopefully this get upvoted to the top. Answers a lot of speculations and questions in the thread.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#99

In China's South Song dynasty, a military leader by the name Yue Fei (岳飞) [1], was sentenced to death by his political enemy Qin Hui (秦桧) [2] on false accusations. What made this event particularly memorable, in addition to the fact that Yue Fei was considered a patriot; was that Qin Hui had blatantly responded to questions of how can you prove your accusations? Qin Hui's reply: Yue Fei, when given, the right power,…

The difference here is Yue Fei has had a solid track record of being loyal to the emperor. In contrast with Huawei being CCP controlled, having poor track record of intellectual theft, and that CCP having clear conflicts of interest with the countries Huawei is doing business with.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#100

Earlier quoted context omitted.

I agree that Huawei is not the worst issue to criticize China on. But, you don't need "proof" of a spying to recognize that it's high risk to put someone in a high-trust role if they are beholden to competing interests. The competing interests themselves are enough to establish the existence of risk. You're right that many people who outsourced to China previously wrote off all these risks as unimportant and later cr…

> outsourced to China previously wrote off all these risks as unimportant and later cried foul when their IP was stolen Give me one concrete example from a reputable source. I'll PayPal you $20 (gift option) look my profile to get my contact information.

I’m not exactly sure what you’re challenging, or what is controversial about my statement. Counterfeiting and IP theft is a approaching (if not already, by some estimates) a trillion dollar industry. A lot of it is something as simply as “third shift/ghost shift” products, rejected manufacturing samples, QA rejects being sold out the back door, etc. If you want some articles about supply chain risk management in China, I’m sure I can dig some up.
Post reply on HN