News: 1618836355

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Huawei could have snooped on the Dutch prime minister's phone calls thanks to KPN network core access

(2021/04/19)


Huawei was able to snoop on the Dutch prime minister's phone calls and track down Chinese dissidents because it was included in the core of the Netherlands' mobile networks, an explosive news report has claimed.

Dutch national daily [1]Volkskrant (behind a pay wall) reported over the weekend that mobile operator KPN, which used Huawei-supplied equipment in the core of its network, discovered the full extent of the Chinese company's doings in 2010 after it commissioned Capgemini to write an outsourcing risk analysis report .

[2]

Not only could the prime minister be eavesdropped on by Huawei, along with millions of other customers, said KPN as it quoted the report, but it could also identify people being snooped on by the Dutch state as well.

Thanks to Capgemini's analysis, seen by Volkskrant, KPN learned to its horror that Huawei had "unauthorised and uncontrolled access" to the core of KPN's 3G and 4G networks. The report's contents were so explosive that senior execs feared for the company's future if its contents got out at the time.

[3]

"Huawei employees could listen to all conversations, even those of then Prime Minister [Jan] Balkenende," reported the newspaper, following up today with sources saying that Huawei still has admin-level access to [4]the core of its 4G network as part of a network management outsourcing deal.

KPN, a former state-owned telco, roughly comparable to Britain's BT, had around 6.5 million subscribers in 2009 according to local reports.

KPN described Volksrant's reporting as "harsh" in comments made to The Register , saying: "The purpose of the analysis was specifically to survey the risks and address these internally, so as to improve the security and integrity of KPN's systems and to facilitate diligent decision making."

It added that it had not detected any data thefts from its network and that its planned outsourcing of network management to Huawei was cancelled as a direct result of the Capgemini report, describing attitudes to mobile network security as "different nowadays from what they used to be in the past."

KPN said it decided "to not pursue further outsourcing of maintenance" of its core mobile network following receipt to the report. "With respect to the systems and proces risks identified in the aforementioned analysis, a remediation and improvement plan was drawn up and implemened in 2010."

A Huawei spokeswoman strenuously denied any wrongdoing, telling The Register it had "no access to lawful interception data" with Gert-Jan van Eck, COO of Huawei Netherlands, saying: "The allegation that the Prime Minister could be overheard by us is completely untrue and an underestimation of the security of the interception environment. It just isn't possible."

"We have never been held liable by the government authorities about unauthorized acts," added Huawei, which makes curious reading after translation from Dutch to English.

Capgemini merely said: "For reasons of client confidentiality we do not comment on past, present or future client engagements."

The Register understands that Huawei's potential level of access was known within British governmental circles and was one of the reasons why the Chinese firm was shut out of the core of 4G networks in the UK.

An NCSC spokesperson told us: "Huawei's presence in the UK is subject to detailed oversight. This form of detailed oversight is the best way to manage risks posed by existing Huawei products in the UK's national telecommunications infrastructure."

Huawei's potential to act as an espionage arm of the Chinese state triggered a lot of wailing and gnashing of teeth in the US, with both political pressure and [5]associated sanctions hitting deployments in other countries.

[6]

It has long maintained the stance that it is just like any other Western private company, but this came under fire after China's Faroe Islands ambassador [7]threatened to withdraw a trade deal if the autonomous Danish territory rejected Huawei-supplied 5G equipment. At the time, in late 2019, China's UK and French ambassadors then both weighed in to [8]loudly declare that Huawei was nothing to do with the Chinese state , which fully and vocally supported it. ®

Get our [9]Tech Resources



[1] https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle-gesprekken-van-mobiele-kpn-klanten-afluisteren-inclusief-die-van-de-premier~bd1aece1/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YH2pGtFTAL@gYRT@6rTCWwAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YH2pGtFTAL@gYRT@6rTCWwAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.volkskrant.nl/nieuws-achtergrond/huawei-beheert-nog-steeds-de-kern-van-het-mobiele-netwerk-van-kpn~bbe353c2/

[5] https://www.theregister.com/2021/01/20/huawei_former_ncsc_chief_parliament/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YH2pGtFTAL@gYRT@6rTCWwAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2019/12/11/china_threatened_denmark_huawei_5g_free_trade_deal/

[8] https://www.theregister.com/2020/02/10/china_backs_huawei_ambassadors_uk_france/

[9] https://whitepapers.theregister.com/

Lawful ?

Khaptain

"no access to lawful interception data"

Does this mean that they didn't have the keys to the backdoor used by our governements or that they only had acces to unlawful interception data ?

Re: Lawful ?

I ain't Spartacus

Khaptain,

I think it's a reference to one of the allegations that Huawei could see the list of numbers under investigation by Dutch police and intelligence services. Not reported specifically in this piece, but apparently in the original Dutch news piece.

Whether that's access to just the list, or to actual call and intercept data I don't know.

The allegation they could listen to any call by anybody was separate.

Anonymous Coward

And people said it was an unjustified witch hunt against Huawei...

Anonymous Coward

Yeh why would Huawei put a backdoor into KPN's network? oh right Dutch authorities require it for their "lawful intercept".

And why would that include the Dutch PM phone? Ahhh yes, "lawful intercept" includes him too.

And why can you set the lawful intercept without any technical mechanism from the courts? Because the good guys trust the good guys to the point where trust is assumed.

And why would Huawei's kit store those intercept settings on Huawei's kit? Ahh yes because how the fook otherwise would it know what to intercept!

And why would Huawei's kit have access to the intercept files Huawei writes....oh right, that's a dumb question, of course they need to write those files.

And why would, you, KPN, give Huawei network access to their own switches on your site when you control that network access? Because KPN outsourced maintenance of the servers remotely to Huawei.

The Dutch backdoored their phone system, and there is the potential that the vendor of the hardware can misuse the backdoor which apparently has no technical checks on it and can be remotely set.

At some point, you're going to have to recognize why pier to pier encryption is essential, and opposing it, or backdooring it, weakens your own security and undermines your own country.

Dutch comms is badly compromised, the UK situation is far worse, courtesy of GCHQ and 5-eyes.

See this?

https://www.justsecurity.org/71279/trump-pushed-cia-to-give-intelligence-to-kremlin-while-taking-no-action-against-russia-arming-taliban/

This is how close you came to losing democracy right across the west. Courtesy of you lot in Cheltenham.

Grauenwolf

Yes, this is part of a witch hunt.

They outsourced the maintenence to Huawei and were then surprised that Huawei has access to their systems?

That's like letting a plumber into your house, then complaining that the plumber had access to your water pipes.

Sil

1. These are still no more than allegations.

2. The US is known to have hardware modified IT/communication systems ordered by external foreign parties.

3. How many times have there been flaws found in Cisco systems giving full rights to the system?

In the mean time

Anonymous Coward

US agencies have been caught listening on German Chancelor's phone converstations and it didn't seem to have any impact. Oh, and they're still able to do that unless of course Huawei equipments stand in their way.

Something tell me that this is actually the problem: Huawei equipments might be aware of those TLS snooping and this would give the Chinese governement an advantage.

Re: In the mean time

Yet Another Anonymous coward

>listening on German Chancelor's phone converstations and it didn't seem to have any impact.

That's because they couldn't understand it, sounded like total gibberish.

Re: In the mean time

Yet Another Anonymous coward

Although to be fair it's tricky for certain American leaders to understand a language where words can be more than 140 characters

Re: In the mean time

Yet Another Anonymous coward

We were conquered by France and a 1000years later we can just about ask the way to the station (but not understand the answer)

Re: In the mean time

I ain't Spartacus

Well actually conquered by the Normans, who happened to have earlier conquered a bit of Northern France. France itself was a very small bit stuck in the middle of a bunch of warring dukedoms. It was centuries before the French crown had conquered and married its way to control of what we now know as France.

And even there, the Normans ruled - but stopped speaking norman french and learned english eventually.

The report actually seems worse than this

I ain't Spartacus

Dear El Reg,

I hope you come back to this story. Saw it this morning, and was hoping for more technical coverage.

The main points of the story appear to be:

They had full network access. Could listen into any call (including the PM's phone) and also had a list of all accounts under intercept/surveillance from both police and intelligence services. Didn't see if they'd actually done this, or if it was even possible to check.

Huawei had also accessed the network from inside China. Don't know if that was in accordance with the network management outsourcing agreement or in breach.

They'd also put in place measures to see subscriber data, and been looking at it. Including for a subsidiary company - and continued to do so even after being told to stop.

Which rather sounds like blackmail, as the company didn't release the report out of fear of exposure. So maybe Huawei played on that? Why otherwise directly ignore an instruction from your client?

Finally the translation I saw alleged that Huwawei were still managing the network, depsite the company's claim they were no longer outsourcing to them.

Re: The report actually seems worse than this

Yet Another Anonymous coward

It's a phone system: everybody from a bloke at the box on the corner with a clip on phone, to anyone in customer server, to anyone with root access to any of the switches, to anybody in the other office who picks up an extension has access.

If you think a prime minister's un-encrypted phone call suddenly becomes secure by having the backhaul supplier being from Finland you are a GCHQ

Re: The report actually seems worse than this

I ain't Spartacus

It's a mobile phone system. 3G and 4G in this case.

I've only seen a quick translation of the Dutch report, which conflates the risk of using Huawei kit with using Huawei as outsourced network management. Assuming no backdoors in Huawei kit - those are two vastly different risks!

But if it's true that Huawei were downloading and subscriber data, even after being told to stop, then that is definitely nefarious - even if everything else alleged is only a risk that they could have - not proof that they did.

On t'other hand, if they had the keys to manage the network, they presumably had at least some abiltiy to cover their tracks and make audit of their actual actions hard to impossible.

Re: The report actually seems worse than this

Grauenwolf

Did you catch the part where they said that Huawei was paid to have that access? It's subtle, but that's what they meant when they were taking about outsourcing. They hired Huawei to work on those systems.

Re: The report actually seems worse than this

I ain't Spartacus

Did you catch the part where they said that Huawei was paid to have that access?

Strangely yes, I can read and everything. Did they hire Huawei to download susbcriber data ( not needed to run the network core) and then refuse to stop after being told to?

That's a concrete accusation of wrongdoing. Much of the other stuff comes from an audit report, and is (as you say) a risk - and no more.

Also the logging into the core network from China, rather than management offices in the Netherlands may or may not be dodgy depending on the contract.

To paraphrase

Anonymous Coward

KPN outsourced management of the core of their network to Huawei, and were then surprised by a report that said Huawei had the access to functions which KPN had given them...

Why is this a surprise or 'explosive' in any way other than for an assessment of the competency of KPN's management?

Was there any evidence that Huawei had actually used the access for 'bad stuff(tm)' ?

Fake News

Grauenwolf

> KPN said it decided "to not pursue further outsourcing of maintenance" of its core mobile network following receipt to the report

Translation: Huawei had access to our systems because he gave it to them so they could perform the maintenence we paid for.

More fake news

Kaufman

Pretty sad when you have to use adverbs like, "potentially" to describe what may or may not have happened more than a decade ago to smear Huawei. I trust Huawei far more than any company from American allied countries such as the 14 eyes which unsurprisingly, Netherlands just happens to be one of them. It's also not blind trust Huawei has proven to be far more transparent than any other company on the planet. So it's of no surprise that they are still churning enough profits despite American sanctions to remain as the largest telecommunications company in the world.

Belgacom and Greece

Anonymous Coward

I will just mention two notorious cases of western countries using western manufacturers to eavesdrop on foreign communications, including government communications.

Of course Huawei could do this. And maybe they did. But every TEM can do this, and 5-eyes seem to make regular use of them to do so. There is nothing surprising about this, and all modern governments are well aware of the issue (even if they fail to convince their politicians to actually use the encrypted comms tools they provide).

Anonymous Coward

Article heavy on the allegations, light on any evidence. Just paraphrasing an article from another media outlet that failed to provide any proof doesn't make for great journalism.

<james> abuse me. I'm so lame I sent a bug report to
debian-devel-changes