Live data from Hacker News

Huawei was able to eavesdrop on Dutch mobile network KPN: Report

nltimes.nl

121–130 of 148 posts

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#121

Earlier quoted context omitted.

Hackers could always claim they were security testing :) If that would have been the case, it would have been the first thing they'd mention though.

It was? Those words came from the report done by the security testing team.

Copy the lines + link that state that please. That's not my observation.

Note: i'm a native dutch speaker. So no translation required.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#122

Earlier quoted context omitted.

It was? Those words came from the report done by the security testing team.

Copy the lines + link that state that please. That's not my observation. Note: i'm a native dutch speaker. So no translation required.

From the original link

>The Capgemini report stated that Huawei staff, both from within KPN buildings and from China, could eavesdrop on unauthorized, uncontrolled, and unlimited KPN mobile numbers.

That quote clearly comes from the security testing team's report. It's not clear from the quote provided to me who is responsible for the "Uncontrolled and unauthorized access," but we know there was an ongoing security audit at the time mentioned.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#123
post #113

Earlier quoted context omitted.

I agree that there is a lot of spin on these stories: efforts to paint bad and sloppy network security decisions as evidence of actual malice. I am sympathetic to the national security agencies who are likely driving this reporting, though. Giving untrusted foreign companies access to your communications infrastructure is generally a bad idea, and the evidence (from Western countries’ own actions) is that this kind o…

> Right now all of the incentives for that company are to gain the trust of customers during these early stages when everyone is looking for a reason to throw up protectionist barriers. What makes you think these are "early stages"? AFAIK many telcos already use Huawei 4G equipment, though I can't find actual numbers for that. I'd say Huawei/China is already well positioned to abuse any backdoor access they have. The…

Part of what made the US hit the panic button was that Huawei was poised to be the premier maker of 5G equipment all over the world.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#124

Earlier quoted context omitted.

Copy the lines + link that state that please. That's not my observation. Note: i'm a native dutch speaker. So no translation required.

From the original link >The Capgemini report stated that Huawei staff, both from within KPN buildings and from China, could eavesdrop on unauthorized, uncontrolled, and unlimited KPN mobile numbers. That quote clearly comes from the security testing team's report. It's not clear from the quote provided to me who is responsible for the "Uncontrolled and unauthorized access," but we know there was an ongoing security a…

Capgemini did the audit, not Huawei who had uncontrolled access.

It should be clear that unauthorized access is not from those doing the audit, but from Huawei. Why is that so hard to understand? Lol

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#125
post #113

Earlier quoted context omitted.

I agree that there is a lot of spin on these stories: efforts to paint bad and sloppy network security decisions as evidence of actual malice. I am sympathetic to the national security agencies who are likely driving this reporting, though. Giving untrusted foreign companies access to your communications infrastructure is generally a bad idea, and the evidence (from Western countries’ own actions) is that this kind o…

> Right now all of the incentives for that company are to gain the trust of customers during these early stages when everyone is looking for a reason to throw up protectionist barriers. What makes you think these are "early stages"? AFAIK many telcos already use Huawei 4G equipment, though I can't find actual numbers for that. I'd say Huawei/China is already well positioned to abuse any backdoor access they have. The…

>What makes you think these are "early stages"? AFAIK many telcos already use Huawei 4G equipment, though I can't find actual numbers for that. I'd say Huawei/China is already well positioned to abuse any backdoor access they have. The move to 5G could only expand this.

We're at the peak of a massive international debate regarding the role of Huawei in Western communications networks. This is a debate that has already led to bans and restrictions on the deployment of Huawei equipment in 5G networks [0-3]. 5G buildouts are happening right now, and hence the political purchasing decisions (with a multi-decade impact) are happening now. I suspect that's why we're seeing things like TFA.

It seems to me that this would be the worst possible time for Huawei to get caught doing something unambiguously malicious. Right now Western networks could remove Huawei if they wanted to, or if politicians ban it. Ten years from now -- assuming Huawei "wins" in most Western nations -- it will be vastly more difficult to replace that equipment. If we imagine a 2035 where Huawei has dominated the US/European 5G market, I suspect that their European competitors will also be much weaker (or will have abandoned the field entirely), meaning that there really isn't much of an alternative.

So TL;DR I can't say that there is a good time to get caught spying, but there definitely is a bad time: and it's right now.

[0] https://www.bbc.com/news/newsbeat-47041341 [1] https://www.telecompaper.com/news/dutch-mps-call-for-more-cl... [2] https://www.reuters.com/article/us-france-huawei-5g-security... [3-N] Just search on " 5g Huawei debate"

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#126

Earlier quoted context omitted.

From the original link >The Capgemini report stated that Huawei staff, both from within KPN buildings and from China, could eavesdrop on unauthorized, uncontrolled, and unlimited KPN mobile numbers. That quote clearly comes from the security testing team's report. It's not clear from the quote provided to me who is responsible for the "Uncontrolled and unauthorized access," but we know there was an ongoing security a…

Capgemini did the audit, not Huawei who had uncontrolled access. It should be clear that unauthorized access is not from those doing the audit, but from Huawei. Why is that so hard to understand? Lol

Why should it be clear? What evidence do you have? I can't read the report, you could easily find where they say "Huawei was responsible for the unauthorized access" that for some reason the articles don't directly quote.

Instead you're acting like I'm being dumb for not making baseless assumptions. The articles aren't titled "Huawei eavesdropped on KPN" for a reason.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#127

Earlier quoted context omitted.

I agree that Huawei is not the worst issue to criticize China on. But, you don't need "proof" of a spying to recognize that it's high risk to put someone in a high-trust role if they are beholden to competing interests. The competing interests themselves are enough to establish the existence of risk. You're right that many people who outsourced to China previously wrote off all these risks as unimportant and later cr…

> outsourced to China previously wrote off all these risks as unimportant and later cried foul when their IP was stolen Give me one concrete example from a reputable source. I'll PayPal you $20 (gift option) look my profile to get my contact information.

User kube-system delivered concrete examples from reputable sources further down the thread. Could you now please post concrete proof of having sent your paypal gift?

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#128
post #88

Earlier quoted context omitted.

Understand that feeling but Huaweis existence is born from corporate espionage stealing IP from Nortel networks in the 00s. Not a great starting point for a company and it really doesn’t take much of a stretch to see the concern about Chinese party wanting to spy on the rest of the world given the lack of freedom of their own people...

> it really doesn’t take much of a stretch to see the concern about Chinese party wanting to spy on the rest of the world given the lack of freedom of their own people Perhaps not, but I try not to believe things just because they confirm my existing biases.

I agree - it is a dangerous precedent to set. I do think that with large infrastructure purchases and installations you really have to go in with open eyes -- it's very difficult to undo those kind of purchases. Probably make sense to use trusted providers.

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#129

Earlier quoted context omitted.

Capgemini did the audit, not Huawei who had uncontrolled access. It should be clear that unauthorized access is not from those doing the audit, but from Huawei. Why is that so hard to understand? Lol

Why should it be clear? What evidence do you have? I can't read the report, you could easily find where they say "Huawei was responsible for the unauthorized access" that for some reason the articles don't directly quote. Instead you're acting like I'm being dumb for not making baseless assumptions. The articles aren't titled "Huawei eavesdropped on KPN" for a reason.

Unauthorized access was detected from China outside of the procedure.

With that access they could have done anything ( eg. eavesdropping ).

Follow up requests are currently happening by the Dutch government ( other related news from today).

KPN also mentioned: currently they have no access. While the report states: they had access.

KPN mentioned that Huawei's employees with access were employed by KPN. Wick could be correct, but it didn't explain access from China since those employees are employed in the netherlands.

A bit of wordplay going around. That's true.

--

Capgemini:

Huawei blijkt zich buiten de procedure om vanuit China toegang tot de kern van het netwerk te verschaffen. Veiligheidsmensen van KPN weten dat dit gebeurt, maar doen niets. ‘Ongecontroleerde en ongeautoriseerde toegang vanuit China heeft na 28 oktober 2009 daadwerkelijk plaatsgevonden’, vermeldt het rapport in april 2010. [...] De onderzoekers [van Capgemini] vragen het Chinese bedrijf daarom wie bij de gegevens kan en hoe de versleuteling is geregeld. ‘Pas na lang aandringen’ is Huawei bereid ‘duidelijkheid te verschaffen’. Huawei blijkt een uiterst zwakke versleuteling toe te passen en zelf het sleutelbeheer te doen. Capgemini: ‘Daarmee zijn nummers die onder de tap staan bekend bij Huawei’.

Edit: couldn't respond below. Source is the origin of all foreign news articles, it's the original newspaper that is in possession of the Capgemini report: https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...

( Google cache is possible as a workaround fyi)

Re: Huawei was able to eavesdrop on Dutch mobile network KPN: Report

#130

Earlier quoted context omitted.

Why should it be clear? What evidence do you have? I can't read the report, you could easily find where they say "Huawei was responsible for the unauthorized access" that for some reason the articles don't directly quote. Instead you're acting like I'm being dumb for not making baseless assumptions. The articles aren't titled "Huawei eavesdropped on KPN" for a reason.

Unauthorized access was detected from China outside of the procedure. With that access they could have done anything ( eg. eavesdropping ). Follow up requests are currently happening by the Dutch government ( other related news from today). KPN also mentioned: currently they have no access. While the report states: they had access. KPN mentioned that Huawei's employees with access were employed by KPN. Wick could be…

Where is this Capgemeni statement from? It's extremely strange that they make several accusations yet the only part that's actually from the report is the same quote mentioned before. The [...] also moves on to a completely new topic.

Overall, it says the same "Huawei could have done something" as the other sources I've seen.

Post reply on HN