News: 1601557213

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Huawei's UK code reviewers say Chinese mega-corp is still totally crap at basic software security. Bad crypto, buffer overflows, logic errors...

(2020/10/01)


UK.gov security researchers examining Huawei source code have so far verified just eight firmware binaries out of more than 60 used across Britain's mobile phone networks, according to the GCHQ-backed agency's annual report.

The Huawei Cyber Security Evaluation Centre (HCSEC) – mostly run by GCHQ offshoot the National Cyber Security Centre (NCSC), though it is also staffed by some Huawei personnel – sighed that the Chinese company has made "limited" progress on [1]last year's recommendations to toughen up its act.

Code reviewers found "evidence that Huawei continues to fail to follow its own internal secure coding guidelines. This is despite some minor improvements over previous years." In addition, "The Cell" said it had found more vulnerabilities during 2019 than it had in previous years – though Huawei was keen to paint this finding as "proof the review system is working", something NCSC guardedly agreed with.

"NCSC does not view the increase in vulnerabilities as an indicator of a further decline in Huawei's product quality, but it certainly does not indicate any marked improvement or transformation," said the agency in its report.

There was nothing in the report suggesting the Chinese state had planted intentional backdoors in code – though there was plenty to suggest that Huawei simply isn't taking the task of building robust and secure software and firmware with requisite seriousness.

Vulns uncovered by HCSEC researchers poring through the source code of Huawei's mobile network equipment firmware included "unprotected stack overflows in publicly accessible protocols, protocol robustness errors leading to denial of service, logic errors, cryptographic weaknesses, default credentials" as well as "many other basic vulnerability types".

Is this a backdoor?

Binary equivalence is the dark art of checking that a firmware binary supplied to HCSEC for evaluation is the same as the firmware deployed in production across Britain's mobile phone networks. While HCSEC verified during 2019 that eight builds examined in the lab were the equivalent of their production counterparts, The Register understands there are around 60 Huawei firmware builds in total lurking around Blighty's mobe networks.

"Huawei have committed to delivery of binary equivalence across officially released versions of all carrier products sold into UK from Dec 2020," said the report, which then warned that Huawei sees providing binary equivalence assurance as a "bespoke" task for each firmware version instead of an ongoing process: "Consequently, the NCSC does not have confidence that binary equivalence will be sustainable."

Huawei chairman says tech giant's goal is ‘survival’ as it battles ‘non-stop aggression’ [2]READ MORE

Even more concerning was what happened when serious vulnerabilities were found, with the report warning of "high CVSS scores" which The Register understands were generally in the region of 7-9 with the occasional 10. Scoring methods and what they mean are explained by the US National Vulnerability Database [3]here .

"During 2019, HCSEC identified critical, user-facing vulnerabilities in fixed access products," said the report. "The vulnerabilities were caused by particularly poor code quality in user-facing protocol handlers and the use of an old operating system. The vulnerabilities were a serious example of the issues that are more likely to occur given the deficiencies in Huawei's engineering practices, and during 2019 UK operators needed to take extraordinary action to mitigate the risk."

Part of that risk rests on the Huawei Real Time Operating System (RTOS), based on "an externally maintained Linux distribution" to replace a legacy RTOS that used open-source code from the west. This presents a problem: "NCSC investigated Huawei's plans to manage and maintain Huawei RTOS during 2019 and found that the plans for RTOS were not practically sustainable."

Nothing to see here, all routine... cough cough

A Huawei spokesman told The Register : "This latest report highlights our commitment to a process that guarantees openness and transparency, and demonstrates HCSEC has been an effective way to mitigate cyber security risks in the UK. The report again concludes that the NCSC 'does not believe that the defects identified are a result of Chinese state interference'."

He added: "Huawei has faced the highest level of scrutiny for almost 10 years. This rigorous review sets a precedent for cyber security collaboration between the public and private sectors, and has provided valuable insights for the telecoms sector. We believe this mechanism can benefit the entire industry and Huawei calls for all vendors to be evaluated against an equally robust benchmark, to improve security standards for everyone."

Huawei has previously made calls for other vendors such as Cisco and Nokia to be subject to the same public HCSEC-style scrutiny as it must undergo, even [4]launching a sort-of equivalent in Brussels last year to try and lead the way.

Former NCSC chief Ciaran Martin, under whose watch today's HCSEC report was compiled, told Parliament's Science and Technology Committee yesterday: "There are ongoing concerns about the quality of Huawei's security performance at a technical level, rather than concerns [about] hard evidence of Chinese state interference. That's an ongoing process of remediation. The [5]US sanctions are very tightly defined, they do impact new deployments so that's why there's a bar on new deployments and as part of [6]the package announced in July , contingency plans were made to ensure the existing stuff could be serviced."

The report's detailed findings will be eagerly lapped up by the Anglosphere's Five Eyes spying alliance, whose pre-eminent member, the USA, has made no secret that it wants Huawei completely gone from the western world's communications infrastructure. ®

Bootnote

One line of the HCSEC report assured the world: "There were no failures in the DV process this year." DV stands for Developed Vetting, one of the most in-depth forms of security clearance used by the British state. El Reg was unable to verify what happened with HCSEC staffers' DV clearances in previous years.

Get our [7]Tech Resources



[1] https://www.theregister.com/2019/03/28/hcsec_huawei_oversight_board_savaging_annual_report/

[2] https://www.theregister.com/2020/09/23/huawei_in_survival_mode/

[3] https://nvd.nist.gov/vuln-metrics/cvss

[4] https://www.theregister.com/2019/03/05/huawei_brussels_code_inspection_facility/

[5] https://www.theregister.com/2020/05/18/huawei_guo_ping_us_sanctions_response/

[6] https://www.theregister.com/2020/07/14/huawei_ban_uk/

[7] https://whitepapers.theregister.com/

Can we do this for all manufacturers

ComputerSays_noAbsolutelyNo

While the increased scrutiny directed at Huawei was sort of collateral damage of the trade bickering between the Beloved Leader of the Alternative Western World and China, ...

could we do this with every manufacturer of critical infrastructure?

Imagine a world, in which we can proof that our power distribution systems can not be hacked by some script kiddies from Elbonia.

Ok, I'll show myself out.

Re: Can we do this for all manufacturers

alain williams

Just provide the source code and be done with it. Huawei makes its money selling hardware, by opening its code (even if that is just to its large telco customers) it would increase trust that it does not have back doors.

I doubt that their algorithms are vastly better than the competition.

If it does not want to do that then publish the complete hardware specs and customers could install their own firmware ... OK: something would need to be obtained, but once done, and shared with telcos world wide, we could have something robust.

The same should apply for Nokia, Cisco, etc.

Re: Can we do this for all manufacturers

JetSetJim

> Huawei makes its money selling hardware

No it doesn't. Hardware is (was?) almost given away to get the footprint in the networks - certainly in the access networks. S/w licensing is then their revenue model, as each year 3GPP helpfully come up with new features, bells & whistles (and Gs) that Huawei can charge through the nose to implement in their software and deploy into the networks.

In terms of their development practise - it's "sell it, build it asap, chuck it through the door with minimal testing, let the field engineering/support teams debug it". It's designed and built by very talented people, but it's rushed, and as the old adage goes: "fast, good & cheap - pick any two".

Re: Can we do this for all manufacturers

Charlie Clark

I'm not sure how that would help. Just having the code does not automatically solve the problem. I'm all for open source but seeing as the source is provided in this instance it doesn't help.

Also, it's worth noting that static code analysis only goes so far in flagging up bugs.

Re: Can we do this for all manufacturers

Charlie Clark

could we do this with every manufacturer of critical infrastructure?

should ve could we do this with every manufacturer publisher of critical infrastructure software? FTFY

Otherwise you have to define which infrastructure is critical and there is no reason why the manufacturers of consumer electronics, cars or anything else should be able to get away with their current practice to seeing if anyone notices when things break.

Lets hope

Chris the bean counter

We exploited a few of the vulnerabilities in the Chinese network

Huawei's attitude seems very odd

John Smith 19

They submit (even fund) this fairly public process where there vulnerabilities are revealed in public.

But seem to make little (any?) effort to improve their processes to cut down issues and improve quality.

Is this the price they feel they have to pay to get into the UK market?

The European market?

Of course no one can check what's really happening inside those chips.....

So this could be the illusion of security, rather than the real thing.

Not sure about this...

Commswonk

Quite apart from the fact that Huawei kit is currently off the UK's Christmas present wish list why are we doing their work for them in drawing the equipment's vulnerabilities to their attention? OK; if the NCSC says to Huawei there are n* vunerabilities that we have found without providing any specifics then all well and good, but as things stand we seem to be risking handing information about our specialists' abilities to find those vulnerabilities to a foreign entity whose intentions are not always necessarily benign, or might not be in the future. Just seems a bit wrong to me...

* Where n is an integer!

Re: Not sure about this...

doublelayer

They're reviewing it anyway, so why not point out the problems? If they're hiding them from the public, that would be a problem, but they're not. They point out that there are many problems, and from the sound of it, the problems they have identified aren't exactly hidden. Even a very malicious version of Huawei can't get much out of that report other than that NCSC will read code sent to them and has some technical people in it. Meanwhile, if they actually changed some of this, it would mean that networks in the U.K. using Huawei infrastructure would be more secure.

Looks at the USA

Blackjack

So... who are most the companies having all those big leaks in recent years? Americans you say?

Pot calling kettle.

Pittsburgh Driver's Test

(8) Pedestrians are

(a) irrelevant.
(b) communists.
(c) a nuisance.
(d) difficult to clean off the front grille.

The correct answer is (a). Pedestrians are not in cars, so they are
totally irrelevant to driving; you should ignore them completely.