Telcos face £100k-a-day fines unless they obey new UK.gov rules on how to deploy Huawei 5G gear in their networks
- Reference: 1606217233
- News link: https://www.theregister.co.uk/2020/11/24/telecommunications_security_bill/
- Source link:
A new law being laid in Parliament today will allow the government to write binding security rules that shut so-called "high risk" vendors' equipment out of parts of networks – and could even dictate how their existing equipment can be used within telcos' networks.
Oliver Dowden, Culture Secretary, aka Secretary of State for Digital, Culture, Media and Sport, boasted in a canned statement: "This groundbreaking bill will give the UK one of the toughest telecoms security regimes in the world and allow us to take the action necessary to protect our networks."
As well as targeting gear with backdoors, the new laws will also let regulators including Ofcom target telco equipment running poorly written firmware. Such firmware is said to be widespread in Huawei's network equipment, as [1]revealed in 2019's Huawei Cyber Security Evaluation Centre report and [2]reinforced in this year's follow-up .
National Cyber Security Centre technical director Dr Ian Levy said in a canned statement: "The roll-out of 5G and gigabit broadband presents great opportunities for the UK, but as we benefit from these we need to improve security in our national networks and operators need to know what is expected of them. We are committed to driving up standards and this bill imposes new telecoms security requirements, which will help operators make better risk management decisions."
The new Bill will, the Ministry of Fun** told the press, be written as a framework allowing civil servants to create legally binding codes of practice without Parliamentary oversight. It said these requirements will be set out in secondary legislation, but are likely to involve companies acting to:
securely design, build and maintain sensitive equipment in the core of providers' networks which controls how they are managed;
reduce the risks that equipment supplied by third parties in the telecoms supply chain is unreliable or could be used to facilitate cyber attacks;
carefully control who has permission to access sensitive core network equipment on site as well as the software that manages networks;
make sure they are able to carry out security audits and put governance in place to understand the risks facing their public networks and services; and
keep networks running for customers and free from interference, while ensuring confidential customer data is protected when it is sent between different parts of the network.
In a statement, BT told us: “The security of our networks is paramount. We therefore welcome the UK government’s establishment of clear security standards for the UK telecoms industry. We’ll continue to work closely with the NCSC and other Government bodies to develop these standards further.
"As we outlined in July, we’re working to the latest Government guidelines around the exclusion of Huawei from 5G networks, and we’ve recently signed agreements with [3]Nokia & [4]Ericsson that will allow us to deliver on these commitments.”
All new purchases of Huawei mobile network equipment for UK networks will be [5]banned from the end of this year under existing laws. By the year 2027 all "high-risk vendor" kit will be stripped out of Britain's networks altogether.
Frantic at the notion of being shut out of a lucrative, Western market, Huawei has been busy commissioning [6]study after [7]study "proving" that kicking it out of Britain's telco networks would be bad for the economy.
If the UK government is genuinely concerned about the perceived secuirty risks of integrating Huawei kit, and not acting on ongoing pressure from the US administration, it is no small wonder that telcos in Britain have until 2027 to eradicate Huawei from their networks.
Huawei sent us a statement from UK veep, Victor Zhang: "It’s disappointing that the government is looking to exclude Huawei from the 5G roll out. This decision is politically-motivated and not based on a fair evaluation of the risks. It does not serve anyone’s best interests as it would move Britain into the digital slow lane and put at risk the Government’s levelling up agenda."
Speaking on behalf of members of Mobile UK - a trade assoication which includes Vodafone, Three, EE and O2 - director Hamish MacLeod, said: "Network security and resilience have always been a top priority for the UK’s mobile network operators. We support the framework for the Telecoms Security Bill and will continue to work closely with the Government to ensure the objectives of the Bill are fulfilled and to build on the already robust security measures mobile operators have in place." ®
Get our [8]Tech Resources
[1] https://www.theregister.com/2019/03/28/hcsec_huawei_oversight_board_savaging_annual_report/
[2] https://www.theregister.com/2020/10/01/huawei_uk_security_code_review_panel/
[3] https://www.theregister.com/2020/09/29/ee_picks_nokia_for_5g_ran/
[4] https://www.theregister.com/2020/10/28/ee_ericsson_5g_ran/
[5] https://www.theregister.com/2020/07/14/huawei_ban_uk/
[6] https://www.theregister.com/2020/11/18/huawei_report_uk_economy/
[7] https://www.theregister.com/2020/09/09/huawei_report/
[8] https://whitepapers.theregister.com/
A slippery slope?
"...allowing civil servants to create legally binding codes of practice without Parliamentary oversight. "
Hmm, do I detect the thin end of a wedge?
What's the point of having an expensive Parliament if the government can side-step it to avoid accountability and rule by diktat?
There might be good reasons for introducing such Draconian powers, but then there always are. No, like them or loath them, we need MPs to keep government honest. Just like Joanna Cherry MP and others did last year with the illegal proroguing of parliament.
OMG !
Politicians attempting to define technical architecture and functionality of network components....
Please tell me this is April 1st? No? Then please let me wake up and the nightmare is over.
Re: OMG !
Politicians attempting to define technical architecture and functionality of network components..
More civil servants rather than politicians. And it's not necessarily a bad thing, eg-
* carefully control who has permission to access sensitive core network equipment on site as well as the software that manages networks;
* make sure they are able to carry out security audits and put governance in place to understand the risks facing their public networks and services; and
* keep networks running for customers and free from interference, while ensuring confidential customer data is protected when it is sent between different parts of the network.
Except perhaps the last one, which may not play nicely with 'net neutrality, or lawyers. Rest is (or should be) pretty much best practice for telcos.
Access could be tricky, but prevent someone bimbling along and accessing craft terminals/console ports. Or just stealing cards from core switches/routers. But devils are in the details. So will 'preventing access' mean kit is locked in a rack? Or will it need to be in an access controlled area? Or no local control plane access permitted?
All of that is arguably a Good Thing(tm) but may present implementation issues, if 'core access' applies to kit collocated in common areas inside shared datacentres. Retrofitting those so telco kit is caged, or just all in a more secure telco-only room will be expensive in most of the popular datacentres. Disallowing craft/console access will obviously make the life of a field engineer FUN!
Datacentres already have their own security/access procedures, some good, some not so good, so a common standard, ie named staff, photo ID, confirmation via NOC is all good. Like one location where I'd dance for the NOC's security camera before they'd unlock the door. Luckily they controlled ingress, not egress. But I guess access restrictions could include requiring staff be vetted, which is already a thing for some sites, but may cause problems if extended to any ops staff with access. Especially I guess when those functions are outsourced & off-shored.
Same applies to audit. It's best practice, but sometimes challenging to tell ops types that they can't just jump onto a router and go ham. Which should then be part of telco's change management processes, ie all changes be logged, approved and tracked. Additional challenges come from good'ol SDN, which extends control plane functionality to customers, but most vendors I've seen have gotten better at providing capabilities to track & audit those changes.
Last one is potentially the most FUN. So touches on SLA's and potentially vague assurances wrt security and data integrity for customer traffic. So will this mean an Ofcom levied fine for network outages? The ICO already has power over breaches, so there's a possibility for bunfights there. But 'secure' is more vague, ie will that mean encrypting core links? That's possible, but by no means cheap on core switches that handle Tbps of data.
But the proposals in the Bill aren't that suprising, ie it's pretty much taking stuff from CESG's Manual of Protective Security and applying those to public networks. BT and many of the other big telcos would (or should) have systems & procedures in place given the public sector customers they manage.
That's what happens when you have breakable crypto...
Suddenly it's a real pain when your broken crypto stream passes through foreign routers...
Security?
"If the UK government is genuinely concerned about the perceived security risks"
If it was really about security then *all* vendors would have to submit their code for audit by GCHQ.
Re: Security?
-- So that GCHQ can find the backdoors for their own use!!
Surely you do not expect GCHQ to close any backdoors that they might want to use for themselves.
Icon for what should happen to crooked politicians (approx 99.99% of them!) ======>
Shades of the Charge of the Light Brigade and against Balaclava Clad Foe and Phantoms of Troubles.
Are Parliamentarians [Roundheads] plotting or preparing for a Revolutionary Civil War against or with leading Cavaliers, and is it worldly wise of them in an age in which they have no chance of effective overall command and control?
Is someone in Westminster spiking the Honourable Members' mineral waters? Or is there another valid excuse for their perceived madness and destructive badness?
>>allowing civil servants to create legally binding codes of practice without Parliamentary oversight.
Looks like the backdoor is being taken out of the equipment and left in government, where it rightfully belongs. No one is hacking this country without greasing the right palms.
For Huawei, you ask? of course not, it's an open equal opportunity backdoor.
Bitcoin preferred. Updated codes of practice within 3 months of payment. Speed it up with a "National security concerns" add-on, hide it from everyone with complete anonymity guaranteed, ask for details.
Pie in the sky where pigs do fly .....
Looks like the backdoor is being taken out of the equipment and left in government, where it rightfully belongs. No one is hacking this country without greasing the right palms. .... Anonymous Coward
Where it rightfully belongs, AC ? :-) That's FCUKing priceless. Who told you that porkie?
Why?
Nobody will die if an apprentice telecoms operator uses the wrong credentials to login to a maintenance terminal.
Nobody will die if a switch fails to get a bios flash.
Nobody will die if a software patch fails.
So why the draconian measures? Cui bono? Who is this helping?
As well as targeting gear with backdoors
So that;s Cisco & Juniper out of the running as well then is it? I assume this will apply to all networking kit used for 5G, not just the wireless bits.