You are viewing a single comment's thread.

view the rest of the comments →

SeekNuShallFind ago

Source

HCSEC – run by Huawei UK staff and overseen by GCHQ – warned: "Huawei's processes continue to fall short of industry good practice and make it difficult to provide long term assurance."

Concerns centre around two technical issues: the consistency of software builds of networking products from Huawei supplied to UK telecom network operators, and (more particularly) Huawei's management of third-party components imported as part of a product build, both commercial and open source. "Security critical third party software used in a variety of products was not subject to sufficient control," according to an evaluation by GCHQ that followed a technical visit to Shenzhen by NCSC, HCSEC, and the UK telecom operators.

Professor Alan Woodward, a computer scientist from the University of Surrey, told El Reg that Huawei needed to improve its procedures, particularly in assuring the security of its own supply chain.

"The authorities need to be totally convinced about the security of Huawei products before they are incorporated into our critical national infrastructure," Woodward said. "The onus appears to be on Huawei to improve their processes to enable the UK to feel confident in giving the required assurances.

"The supply chain is becoming a classic attack vector so the UK needs to be sure not just about test examples of equipment, but that the processes then used to manufacture the equipment at scale are secure from interference."