Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Why Huawei Has Congress Worried
Newest First  |  Oldest First  |  Threaded View
dburgess00
50%
50%
dburgess00,
User Rank: Apprentice
10/10/2012 | 10:07:21 PM
re: Why Huawei Has Congress Worried
The concern here is not design flaws or security shortcomings, but about deliberate back doors. The most dangerous vulnerabilities will not be revealed through testing, but only through a complete tear-down and reverse-engineering of every device. The real answer is for the telecom industry to understand that closed, locked-down, proprietary systems are inherently untrustworthy. Open source is a safer way. http://openbts.blogspot.com
tkomperda606
50%
50%
tkomperda606,
User Rank: Apprentice
10/10/2012 | 3:30:31 AM
re: Why Huawei Has Congress Worried
The U.S. government didn't intervene when the U.S. Telecom Industry was going down the tubes and U.S. Companies like Lucent and Tellabs were losing money and laying thousands of people off. These jobs are gone forever and there are still people from that industry that are out of work. The Chinese moved in and cleaned up what remained (from an economic standpoint)and now we're getting the public all alarmed about a security issue. I'm not saying that there aren't hacking and espionage initiatives to be concerned with (with all of the major powers like China, U.S. Russia, Israel, other parts of Asia, etc.), but this is more so a situation where China is kicking our ass once again from an economic perspective. We continue to give up our leadership positions in various industries and technologies and other countries are more than happy to come in and improve their economic situation to our detriment. Then our politicians proclaim that we need to generate more jobs! Or, that we should be concerned about spies!
Dudeman44
50%
50%
Dudeman44,
User Rank: Apprentice
10/9/2012 | 6:06:57 PM
re: Why Huawei Has Congress Worried
This isn't a financial issue, it's a security concern. So we can't show proof of these two companies spying on others via their Chinese designed and built network devices, do we want to be the first to find out after it's installed? It's too late then.

Example: years ago, the U.S. needed a new embassy built in Moscow, and we trusted local, (then Soviet) contractors to build it. Before it was completed, American teams inspected, it was so riddled with bugs and spy devices built into the floors, walls, ceilings, fixtures, etc., that it had to be torn down and rebuilt by American teams sent over there. Do we want to learn from history, or not? Same exact situation here, only much worse if it ever got deployed nationally. How could anyone be so naive as to think the Chinese government would let a once in a lifetimre opportunity like this to pass by.

In all fairness, if the shoe were on the other foot and Cisco was invited to build out China's or Russia's telecom infrastructure, you can bet the CIA would to exactly the same thing...
greg-imm
50%
50%
greg-imm,
User Rank: Apprentice
10/9/2012 | 1:32:38 PM
re: Why Huawei Has Congress Worried
when will we realize the Chinese are trying to be the financial powerhouse of the world and that we are so greedy we are giving it to them for short term gain? Our corporations are so bent on making the next quarter's goals that they are selling the US out. We are not just giving away our leadership position in the world, we are shoveling it out to them as fast as we can for the almighty buck. When we will look a little past the end of our greedy little noses and start investing in our own country at the expense of the investors.


Commentary
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Tim Sadler, CEO and co-founder of Tessian,  6/17/2021
Edge-DRsplash-10-edge-articles
7 Powerful Cybersecurity Skills the Energy Sector Needs Most
Pam Baker, Contributing Writer,  6/22/2021
News
Microsoft Disrupts Large-Scale BEC Campaign Across Web Services
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7862
PUBLISHED: 2021-06-24
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.
CVE-2021-21737
PUBLISHED: 2021-06-24
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10 B860H V5.0, V83011303...
CVE-2021-25923
PUBLISHED: 2021-06-24
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
CVE-2021-25655
PUBLISHED: 2021-06-24
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
CVE-2021-25656
PUBLISHED: 2021-06-24
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).