News: 1666978326

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Federal bans aren't stopping US states from buying forbidden Chinese kit

(2022/10/28)


Only a "handful" of US states have stopped buying Chinese technologies deemed by the government to pose security threats, according to a report from a Washington policy research group.

The Georgetown University think tank paper, [1]published this week , says that "thousands" of public officials are still purchasing prohibited tech from "Huawei, ZTE, and other Chinese companies" and that most state and local governments simply haven't bought into existing federal actions by making any changes to their procurement policies.

The policy paper landed just hours before reports that senior Biden administration officials [2]are weighing up whether to institute further controls on Chinese technology.

[3]

The authors say only five states — Florida, Georgia, Louisiana, Texas, and Vermont — have put in place measures to limit the procurement of foreign information and communications technology and services (ICTS) on national security grounds, stating that even these existing policies sometimes contain loopholes that would allow "untrustworthy" tech to slip into government networks.

[4]

[5]

Citing public government procurement records provided by GovSpend, the Georgetown report says "at least 1,681" state and local entities purchased equipment and services prohibited at the federal level under Section 889 (see boxout) between 2015 and 2021.

Measures regulating buying foreign ICTS on the grounds of national security:

[6]Section 889 of the 2019 National Defense Authorization Act , which prohibited federal agencies from using equipment and services from five Chinese tech companies (including Huawei and ZTE) or working with contractors that use covered equipment.

Title 2 of the SECURE Technology Act, which created a federal council to analyze supply chain security threats and recommended orders to remove or exclude certain technologies from federal networks.

The [7]ICTS rule , which allows the US Department of Commerce to block both public and private procurement and use of "certain foreign ICTS."

The [8]Secure and Trusted Communications Networks Act , which permits the FCC to restrict the purchase of certain ICTS using federal funds.

They note that while the total value of these purchases was only around $45.2 million, the purchases are "significant in terms of potential risk. Each piece of covered equipment represents a potential entry point into users' networks, regardless of its cost."

The report's authors say the threats the US is legislating against fall into three categories: baked-in backdoors (or the possibility of the later insertion of security holes), human vulnerabilities, and economic risks.

Huawei and other Chinese companies on the list have always denied the existence of "hidden bugs" that would let attackers in, and the report concedes that one wouldn't really need backdoors installed at the government's behest when run-of-the-mill software bugs are an easier – and cheaper – way for most bad actors to get into a network, whether it's in prohibited Chinese companies' software or local software made by local people. The US government has previously claimed it has evidence of such backdoors.

[9]

"State and local governments must take foreign technology threats seriously even if they do not face the same risks as federal agencies like DOD," the authors write. "Even if governments are not targeted directly, the ICTS they deploy might be used to compromise nearby critical infrastructure."

The second category the report posits is a little more interesting: it proposes that techies hauled in to do maintenance and upgrades might be "compromised by a foreign adversary, they could potentially install malware, exfiltrate data, or conduct other nefarious activities on their behalf."

[10]EU infosec agency unveils 5G vendor security licensing scheme despite years of Huawei ambiguity

[11]Chips for Huawei are fried: TSMC stops shipping parts to Middle Kingdom mega-maker this September

[12]UK smacks Huawei with banhammer: Buying firm's 5G gear illegal from year's end, mobile networks ordered to rip out all next-gen kit by 2027

[13]USA adds two more Chinese carriers to 'probably a national security threat' list

The third is the obvious – as "Chinese companies gain market share, the United States and its allies may find themselves relying on their biggest geopolitical competitor for access to key technologies," and the authors note that as America began to put the federal laws into place, "some Chinese firms, like Huawei, commanded markets with no viable US competitors in the first place."

The US also curbs the export of American tech deemed a national security risk to China, but nevertheless, 2,652 export licenses for restricted tech to China were granted by the Commerce Department in 2020, 94 percent of the total requested, according to an [14]August report in the WSJ – with America shipping a wide array of semiconductor, aerospace, and AI/ML tech to China.

In order to solve the problem of state spending on prohibited tech, the think tank recommends the Feds publish a "master list" of untrustworthy foreign ICTS covered by various federal rules and laws, as well as kick in with help for "rip and replace" programs for problematic equipment bought by state organizations, similar to the FCC's 2020 rip and replace program for private operators. Congress coughed up about $1.9 billion for that project, dubbed the [15]Secure and Trusted Communications Networks Reimbursement Program , whose initial focus was on "ripping and replacing" equipment from Huawei and ZTE in the nation's comms network. The first wave of applicants, it adds, asked for "more than $5.6 billion in reimbursements."

[16]

The US government has also put pressure on its allies to exclude hardware from Huawei and other Chinese companies from 5G network buildouts across the world with claims that it is a security risk. Huawei has always denied these claims, and maintains a presence in both 4G core and RAN network infrastructure of many countries.

The UK, which came under enormous pressure from its ally to do so, [17]earlier this month issued formal legal notices to operators instructing them to remove Huawei technology from the country's 5G networks by the end of 2027. However, network operators have already gained some reprieves as they say they cannot meet a January deadline to remove Huawei tech from their core networks (much of the country's 5G installation sits on top of a 4G core that is still full of Huawei kit). The nation's biggest telco, BT, says it expects the removal and replacement of Huawei equipment in its networks to cost about $658 million.

Meanwhile, China's feeling some pain too. Its semiconductor imports dropped 12.4 percent in the month of September, according to [18]official customs data published by the country.

This could get very pricey. ®

Get our [19]Tech Resources



[1] https://cset.georgetown.edu/publication/banned-in-d-c/

[2] https://www.nytimes.com/2022/10/27/business/the-biden-administration-is-weighing-further-controls-on-chinese-technology.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y1xQ94t9ElXAvcFX1v-q8gAAAQM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1xQ94t9ElXAvcFX1v-q8gAAAQM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1xQ94t9ElXAvcFX1v-q8gAAAQM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2019/03/07/huawei_sues_us_equipment_ban/

[7] https://www.commerce.gov/issues/ict-supply-chain

[8] https://www.theregister.com/2022/07/18/scrp_shortfall/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y1xQ94t9ElXAvcFX1v-q8gAAAQM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/02/04/5g_security_eu_uk_stc_reports/

[11] https://www.theregister.com/2020/07/16/tsmc_huawei_chips/

[12] https://www.theregister.com/2020/07/14/huawei_ban_uk/

[13] https://www.theregister.com/2022/09/21/fcc_puts_pacific_network_and/

[14] https://www.theregister.com/2022/08/17/china_us_export_ban_truth/

[15] https://www.theregister.com/2021/11/01/fcc_huawei_replace/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y1xQ94t9ElXAvcFX1v-q8gAAAQM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.theregister.com/2021/07/29/huawei_announces_its_latest_flagship/

[18] https://www.theregister.com/2022/10/24/china_chip_imports_down_124/

[19] https://whitepapers.theregister.com/



Perhaps the buyers

VoiceOfTruth

think the biggest source of vulnerabilities is good ol' apple pie American companies like Microsoft and Cisco. Maybe they didn't have problems with Huawei, but they still now today being clobbered with holes in MS and the like.

Getting a bit old

martinusher

The "threat to national security" notion has been wearing a bit thin lately because members of the Administration now openly state that the purpose of their restrictive measures is to kneecap Chinese competition. So what's a procurement person to do? Go without or pay extra for kit of dubious provenance (which may well be re-badged and significantly marked up Chinese kit anyway) or just carry on with what they were doing anyway?

Funny how posts about Huawei always attract flies to the forums.

Anonymous Coward

Our usual apologists show up to post the usual empty objections about sanctions against them and the other big Chinese telco and networking players.

Bonus points for working in the usual noise about how the us are hypocrites and Cisco and the US brands are just as bad as far as supply chain issues.

The world most of the rest of us live in plays by different rules. Yeah, if you are a Chinese running cisco gear i'd take a close look at it as well as your outbound network traffic. Ditto for Huawei or ZTE gear on other jurisdictions. Even if the box was fine when it left the factory it could have been messes with before it got to you. A bigger and more likely risk is that in the looming conflicts that the supply and support of gear for either could be cut off with little or no notice. As a company I don't want to be saddled with gear that may never receive another essential update, has no support or warranty, and may be at higher risk of "to who it may concern" attacks on whole brands and classes of gear once open electronic conflict flares up.

Even if these things aren't compromised today, are you equipped to audit the updated that come out in the future? I appreciate that risk management is part of my job, and that has a part to play in the bottom line, especially for essential services. So there are vendors I am avoiding solely becuase the money saved, or access to a few bells and whistles, isn't as important as something I can set up and park in the corner without losing sleep over for few years.

And for those that have been whingeing about this solely on the basis of "Choice" or economics, there is a bigger picture to this conflict including ethnic cleansing, genocide, and forced sterilizations. So if they are slapping sanctions on these companies it came from somewhere, and I am not putting that low a price on my conscience either.

How can you govern a nation which has 246 kinds of cheese?
-- Charles de Gaulle