Feeds

BT network 'vulnerable to Chinese attack'

Spy chiefs warn over Huawei gear in 21CN

The Essential Guide to IT Transformation

Spy chiefs have reportedly briefed ministers that Huawei hardware bought by BT could be hijacked by China to cripple the UK's communications infrastructure.

At a meeting in January, Alex Allan, chairman of the Joint Intelligence Committee, told the Home Secretary that while BT had taken steps to secure its network, "we believe that the mitigating measures are not effective against deliberate attack by China", the Sunday Times reports.

Huawei, led by former People's Liberation Army (PLA) research chief Ren Zhengfei, is a major supplier to BT's ongoing multi-billion-pound 21CN network upgrade. It will see all voice and data traffic carried by the same packet-switched equipment. In 2005 the Chinese firm won contracts to provide access nodes and optical equipment for the core of the new network.

At the meeting, ministers were told that the UK government had "not paid sufficient attention to the threat [from Huawei] in the past". At the time of the 21CN deal, feted by Huawei executives as offering "significant benefits for the UK", GCHQ reportedly warned that the BT network was used by government departments, the military and intelligence services, and would be a prime target for any future Chinese attack.

Despite consistent denials, western intelligence services believe Huawei has close ties to the Chinese military. Fears in Washington over the alleged relationship last year scuppered its attempt to acquire US telecoms equipment maker 3Com.

Huawei's bid partner, the investment firm Bain Capital Partners, pulled out when a Congressional committee indicated it would block the $2.2bn takeover. Security chief raised particular concerns about 3Com's TippingPoint division, which is closely involved in secure US government networks.

Now it seems UK intelligence officials believe there is a risk that China may have used its influence on Huawei to ensure 21CN is vulnerable to a remote attack. The risk is reportedly deemed "low", but a secret Whitehall report says "the impact would be very high".

They reportedly want the Chinese components of 21CN to be replaced with more trusted equipment, but ministers are reluctant to act, citing competition law. Huawei beat British firm Marconi to supply BT.

Patricia Hewitt, who now sits on BT's board, declined to intervene in the deal as trade and industry secretary in 2005.

At January's meeting, ministers were told security advice given to BT has cut the risks to 21CN from malicious hackers but the unspecified measures would not mitigate built-in vulnerabilities. Intelligence officials reportedly said they could not offer specifics on a potential Chinese strike, as they had "only limited understanding of our adversaries' attack capability".

China has made great efforts to become a major commercial technology player. As well as hosting manufacturing and research facilities for many of Huawei's western rivals, last year the Pentagon noted strengthening ties between Chinese firms and the PLA. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.