Interesting how this 3 day old story is getting twisted more and more. Can we stick to the facts?
Huawei was used for outsourcing, Huawei obviously has root access. If you outsource your IT to a company with known ties to a foreign government you can't complain about them having sensitive access.
So if anyone accessed from China, it must be huawei? You do know China has 1.4B people. And hackers often use zombie machines to attack. But clearly didn't matter to you.
Huawei was the only one that circumvented the password policy from KPN, which is the telecom provider of > 50% of phone infrastructure in the Netherlands ( including government).
The audit was from 2009 and was an internal security audit that got leaked. It's specifically about Huawei.
Yeah I guess this is like having Kaspersky and then complaining that data was exfiltrated to the FSB or something. Or you know, know who you are dealing with when you outsource.
Who is the 'they' in your comment? The Capgemini report underlying all this, in no unclear terms, states that Huawei abused their access; with unmonitored and unauthorized access from China.
Additionally, it concludes that Dutch telecom act was violated by Huawei by being able to access the numbers being tapped by Dutch security services.
All statements in the original news article are backed up by the Capgemini report. Of course this report could be wrong, but then it's curious why KPN decided to keep this report a secret, apart from sharing the results with Dutch intelligence (AIVD).
Either way, I have a hard time seeing how any of this is 'spin'.
I don't need to spin anything. I hereby oppose Huawei having this kind of unlimited and unchecked access in past present and future.
The only part that is unclear, and may never be clear, is whether this authority has been abused. However I oppose them (or anyone) having the authority in the first place.
Huawei had employees onsite in the netherlands for access. Unauthorized full network access happened from China.
I do agree it's again here and shouldn't be anymore. But don't claim it's normal, the audit reported it as not.
KPN even hid the report for 10 years, because it was afraid of it's contents to go public.
Ps. Yes, i speak dutch, so I read the original article on Volkskrant.nl . More information is probably getting out soon as it's being inquired currently by their government.
Comments
Interesting how this 3 day old story is getting twisted more and more. Can we stick to the facts?
Huawei was used for outsourcing, Huawei obviously has root access. If you outsource your IT to a company with known ties to a foreign government you can't complain about them having sensitive access.
Just because you have a root access, it doesn't mean you can just make yourself at home and grab any data you want.
And it doesn't mean that they did.
Capgemini report states that unchecked and unauthorized from China happened after October 28 2009; as reported by the journalist that broke this news: https://twitter.com/huibmodderkolk/status/138335058865459200...
So if anyone accessed from China, it must be huawei? You do know China has 1.4B people. And hackers often use zombie machines to attack. But clearly didn't matter to you.
You're ascribing conclusions to me that I didn't draw; its the Capgemini report that states it was Huawei. I'm just the messenger.
Huawei was the only one that circumvented the password policy from KPN, which is the telecom provider of > 50% of phone infrastructure in the Netherlands ( including government).
The audit was from 2009 and was an internal security audit that got leaked. It's specifically about Huawei.
Just because a policy on passwords or root access was broken, it doesn't mean that it was nefarious (as implied here - eavesdropping etc.).
It's explicitly forbidden when working with a large telecom provider in the EU
Yeah I guess this is like having Kaspersky and then complaining that data was exfiltrated to the FSB or something. Or you know, know who you are dealing with when you outsource.
I don't think the people complaining are the ones who chose to give root access to a company with known ties to a foreign government.
Then why do they spin it as if Huawei abused their access? Surely they could just make their opposition known without all the wink wink going on.
Who is the 'they' in your comment? The Capgemini report underlying all this, in no unclear terms, states that Huawei abused their access; with unmonitored and unauthorized access from China.
Additionally, it concludes that Dutch telecom act was violated by Huawei by being able to access the numbers being tapped by Dutch security services.
All statements in the original news article are backed up by the Capgemini report. Of course this report could be wrong, but then it's curious why KPN decided to keep this report a secret, apart from sharing the results with Dutch intelligence (AIVD).
Either way, I have a hard time seeing how any of this is 'spin'.
I don't need to spin anything. I hereby oppose Huawei having this kind of unlimited and unchecked access in past present and future.
The only part that is unclear, and may never be clear, is whether this authority has been abused. However I oppose them (or anyone) having the authority in the first place.
Huawei had employees onsite in the netherlands for access. Unauthorized full network access happened from China.
I do agree it's again here and shouldn't be anymore. But don't claim it's normal, the audit reported it as not.
KPN even hid the report for 10 years, because it was afraid of it's contents to go public.
Ps. Yes, i speak dutch, so I read the original article on Volkskrant.nl . More information is probably getting out soon as it's being inquired currently by their government.
Now it's not only "true", it's sufficient to be the evidence of national threats (again)
https://foreignpolicy.com/2021/04/30/huawei-china-business-r...