China

Vodafone Says It Found Hidden Backdoors in Huawei Equipment (bloomberg.com) 166

For months, Huawei has faced U.S. allegations that it flouted sanctions on Iran, attempted to steal trade secrets from a business partner and has threatened to enable Chinese spying through the telecom networks it's built across the West. Now Vodafone Group has acknowledged to Bloomberg that it found vulnerabilities going back years with equipment supplied by Shenzhen-based Huawei for the carrier's Italian business. From the report: While Vodafone says the issues were resolved, the revelation may further damage the reputation of a major symbol of China's global technology prowess. Europe's biggest phone company identified hidden backdoors in the software that could have given Huawei unauthorized access to the carrier's fixed-line network in Italy, a system that provides internet service to millions of homes and businesses, according to Vodafone's security briefing documents from 2009 and 2011 seen by Bloomberg, as well as people involved in the situation.
United States

US Will Rethink Cooperation With Allies Who Use Huawei (reuters.com) 230

Washington does not see any distinction between core and non-core parts of 5G networks and will reassess sharing information with any allies which use equipment made by China's Huawei, a U.S. cybersecurity official said on Monday. From a report: "It is the United States' position that putting Huawei or any other untrustworthy vendor in any part of the 5G telecommunications network is a risk," said Robert Strayer, deputy assistant secretary for cyber, international communications and information policy at the State Department. "If other countries insert and allow untrusted vendors to build out and become the vendors for their 5G networks we will have to reassess the ability for us to share information and be connected with them in the ways that we are today," he said. Further reading: UK To Let Huawei Firm Help Build 5G Network.
Businesses

LG Halts Phone Manufacturing In South Korea For 2019, Relocating To Vietnam (cnet.com) 40

LG, the South Korean electronics and phone company, is relocating their mobile production facility in South Korea for the year, and focusing instead on one of its plants in Haiphong, Vietnam. CNET reports: Though LG overall is profiting, its mobile division posted a $172 million loss in the second quarter of 2018. And while smartphone sales are down globally, things are especially difficult for LG. Its last couple of flagship phones didn't take off, and it still must compete against bigger companies like Samsung, Huawei and Apple, too. With the relocation, the company does not plan to downsize its phone business, however. The move is to make LG "much more competitive for the global market," said LG senior director of global corporate communications Ken Hong. "Korea will continue to be the hub for smartphone R&D, design, quality assurance, etc." As reported by Reuters, the factory in South Korea mostly makes premium phone models, which would include devices like the LG G8 ThinQ or the upcoming V50 ThinQ, and manufactures about 10% to 20% of LG's total smartphones. In addition to South Korea and Vietnam, the company also has factories in China, Brazil and India.
Privacy

UK Minister: Huawei Leaks 'Unacceptable', Criminal Investigation Possible (reuters.com) 77

The UK Culture Secretary Jeremy Wright said on Thursday he could not rule out a criminal investigation over the "unacceptable" disclosure of confidential discussions on the role of China's Huawei in 5G network supply chains. From a report: Huawei, the world's biggest producer of telecoms equipment, is under intense scrutiny after the United States told allies not to use its technology because of fears it could be a vehicle for Chinese spying. Huawei has categorically denied this. Sources told Reuters on Wednesday Britain's National Security Council (NSC) had decided to bar Huawei from all core parts of the country's 5G network and restrict its access to non-core parts. The leak of information from a meeting of the NSC, first reported in national newspapers, has sparked anger in parliament because the committee's discussion are supposed to be secret. "We cannot exclude the possibility of a criminal investigation here," Wright said, speaking in response to an urgent question on Huawei in parliament. "I do not think that the motivation for this leak matters in the slightest. This was unacceptable and it is corrosive to the ability to deliver good government."
United Kingdom

UK To Let Huawei Firm Help Build 5G Network (bbc.co.uk) 64

AmiMoJo writes: The UK government has given Chinese telecoms giant Huawei the go-ahead to supply equipment for the UK 5G data network. The company will help build some "non-core" parts such as antennas. But the plans have concerned the home, defense and foreign secretaries. The U.S. also wants its allies in the "Five Eyes" intelligence grouping -- the UK, Canada, Australia and New Zealand -- to exclude Huawei. Huawei said it was "pleased that the UK is continuing to take an evidence-based approach to its work," adding it would continue to work cooperatively with the government and the industry.
Government

The CIA Accuses Huawei Of Being Secretly Funded By China's State Intelligence (reuters.com) 147

"U.S. intelligence has accused Huawei Technologies of being funded by Chinese state security, The Times said on Saturday."

Long-time Slashdot reader hackingbear shares a story from Reuters: The CIA accused Huawei of receiving funding from China's National Security Commission, the People's Liberation Army and a third branch of the Chinese state intelligence network, the British newspaper reported, citing a source. Earlier this year, U.S. intelligence shared its claims with other members of the Five Eyes intelligence-sharing group, which includes Britain, Australia, Canada and New Zealand, according to the report...

The accusation comes at a time of trade tensions between Washington and Beijing and amid concerns in the United States that Huawei's equipment could be used for espionage. The company has said the concerns are unfounded... top educational institutions in the West have recently severed ties with Huawei to avoid losing federal funding.

Iphone

Mass Production of iPhones To Start In India 110

Apple is poised to begin mass production of iPhones in India this year, according to Foxconn Technology Group Chairman Terry Gou. This marks a big shift for the largest assembler of Apple's handsets that has long concentrated production in China. Bloomberg reports: Gou said that Prime Minister Narendra Modi has invited him to India as his Taiwanese company plans its expansion in the country. Apple has had older phones produced at a plant in Bangalore for several years, but now will expand manufacturing to more recent models. Bloomberg News reported this month that Foxconn is ready to start trial production of the latest iPhones in the country before it starts full-scale assembly at its factory outside the southern city of Chennai.

India has become the fastest-growing smartphone market in the world, while China stagnates and Apple loses share to local competitors such as Huawei Technologies Co. and Xiaomi Corp. Apple has been a minor player in India, in part because of its high prices, but local manufacturing would help the Cupertino, California-based company avoid import duties of 20 percent. It's not yet clear how Apple's steps into India will affect its China operations. China has been the company's most important manufacturing base for years, home to Foxconn's biggest facilities and hundreds of other partners.
Android

Google, Huawei Agree To Pay Owners of Faulty Nexus 6P Devices Up To $400 (theverge.com) 10

Google and Huawei have preliminarily agreed to settle a class action lawsuit from Nexus 6P users who say their devices experienced a bootlooping issue that caused the phones to shut down randomly, regardless of the battery level. Pending court approval, the companies would be liable to a $9.75 million settlement for the class action that began in April 2017, which may result in payments of up to $400 for participating plaintiffs. The Verge reports: The lawsuit alleged that Google, which contracted the design and manufacturing of its early Android smartphones to third-party companies, and Huawei, one of the chosen companies, breached the device warranty since the companies were aware of the issue, but did not respond to the bug. The plaintiffs also said the companies continued selling the faulty devices while failing to acknowledge the issue. If the court approves the settlement at the next hearing on May 9th, Nexus 6P users in the U.S. who purchased the device on or after September 25th, 2015 would be eligible to claim reimbursement.

The proposal currently states that those who are eligible for the settlement could be paid up to $400 for their faulty device, while those who received a Pixel XL in a prior warranty exchange program would only be eligible for up to $10. Those who submit proper documentation for the bug will receive the most settlement money, while those without may be eligible for up to $75. For full details on submitting a claim, check out the as-filed longform notice document, which explains the process that will go into effect following court approval.

Australia

US Firm Wins Bid To Block Huawei From Subsea Pacific Cables (theregister.co.uk) 33

An anonymous reader quotes a report from The Register: An American company is to build a series of undersea cables linking Australia to China after the Aussie government put its foot down and kicked Huawei off the contract. Building on our reports from last year that Australia had blocked Huawei from building a 4,000km cable between Australia, Papua New Guinea and the Solomon Islands, U.S. company TE Subcom has reportedly won the deal to build the link.

"All options for meshing the Pacific Islands are good for the development of the economies of these countries," Keir Preedy, chief executive of the Solomon Island Submarine Cable Company, told Reuters. The company is developing the Solomons' new cable. In addition to the Aus-PNG-Solomons route previously announced, TE Subcom will build a cable spur to Hong Kong -- Chinese territory. "It is due for completion in 2022 and also includes a possible trans-Pacific branch to Los Angeles," the newswire stated.

United States

US Conducted Secret Surveillance of China's Huawei, Prosecutors Say (reuters.com) 106

U.S. authorities gathered information about Huawei through secret surveillance that they plan to use in a case accusing the Chinese telecom equipment maker of sanctions-busting and bank fraud, prosecutors said on Thursday. From a report: Assistant U.S. Attorney Alex Solomon said at a hearing in federal court in Brooklyn that the evidence, obtained under the U.S. Foreign Intelligence Surveillance Act (FISA), would require classified handling. The government notified Huawei in a court filing on Thursday of its intent to use the information, saying it was "obtained or derived from electronic surveillance and physical search," but gave no details. The United States has been pressuring other countries to drop Huawei from their cellular networks, worried its equipment could be used by Beijing for spying. The company says the concerns are unfounded. Brian Frey, a former federal prosecutor who is not involved in the Huawei case, said FISA surveillance, which requires a warrant from a special court, is generally sought in connection with suspected espionage.
China

MIT Cuts Funding Ties With Huawei, ZTE Citing US National Security Concerns (scmp.com) 102

Following similar moves by Stanford, University of California Berkeley and University of Minnesota, Massachusetts Institute of Technology announced that it is cutting ties with Huawei and ZTE, citing U.S. national security concerns. "At this time, based on this enhanced review, MIT is not accepting new engagements or renewing existing ones with Huawei and ZTE or their respective subsidiaries due to federal investigations regarding violations of sanction restrictions," Richard Lester, MIT's associate provost, and Maria Zuber, the school's vice-president for research, said in a letter to faculty on Wednesday. The South China Morning Post reports: MIT's move is part of a broader effort to strengthen its vetting of research partners, which may affect relationships with other entities in mainland China, Hong Kong, Russia and Saudi Arabia. "Most recently we have determined that engagements with certain countries -- currently China [including Hong Kong], Russia and Saudi Arabia -- merit additional faculty and administrative review beyond the usual evaluations that all international projects receive," the letter said.

The Protect Our Universities Act, introduced last month by Representative Jim Banks, an Indiana Republican, would establish a task force, led by the U.S. Department of Education, to maintain a list of "sensitive" research projects, including those financed by the defense and energy departments and U.S. intelligence agencies. The proposed body would monitor foreign student participation in those projects. Students with past or current Chinese citizenship would not be allowed access to the projects without a waiver from the director of national intelligence. The Act also calls for the intelligence director to create a list of foreign entities that "pose a threat of espionage with respect to sensitive research," and stipulates that Huawei and ZTE be included.

Security

Huawei Laptop 'Backdoor' Flaw Raises Concerns (bbc.com) 95

A flaw in Huawei Matebook laptops, found by Microsoft researchers, could have been used to take control of machines. From a report: The "sophisticated flaw" had probably been introduced at the manufacturing stage, one expert told BBC News. Huawei is under increasing scrutiny around the world over how closely it is tied to the Chinese government. The company, which denies any collusion with Beijing, corrected the flaw after it was notified about it in January. Prof Alan Woodward, a computer security expert based at Surrey University, told BBC News the flaw had the hallmarks of a "backdoor" created by the US's National Security Agency to spy on the computers of targets. That tool was leaked online and has been used by a wide variety of hackers, including those who are state-sponsored and criminal gangs. "It was introduced at the manufacture stage but the path by which it came to be there is unknown and the fact that it looks like an exploit that is linked to the NSA doesn't mean anything," Prof Woodward said.
Sony

Sony To Slash Smartphone Workforce 50% By 2020 (nikkei.com) 51

Sony is cutting up to half its smartphone workforce as sales shrink in the face of stiff global competition. From a report: The job cuts come as the global smartphone industry suffers one of the severest downturns of recent years. Worldwide shipments are expected to decline for the third straight year in 2019 to about 1.3 billion units, according to U.S. research company IDC. Sony's share of the smartphone market has fallen sharply in recent years -- from more than 3% in 2010, according to the research portal Statistica -- to less than 1% currently. It has struggled to compete against leaders Apple, Samsung Electronics and Huawei Technologies, all of which are racing to develop new 5G devices. The decision to scale back its smartphone workforce, which could see up to 2,000 of the total 4,000 jobs cut by March 2020, is part of a move to reduce fixed costs in the business, and also includes procurement reform.
Businesses

Huawei Tops $100 Billion Revenue For First Time Despite Political Headwinds (cnbc.com) 39

An anonymous reader quotes a report from CNBC: Huawei's revenue grew 19.5 percent in 2018, surpassing $100 billion for the first time, despite continuing political headwinds from around the world. Sales came in at 721.2 billion yuan ($107.13 billion) last year. Net profit reached 59.3 billion yuan, higher by 25.1 percent compared to a year ago. The revenue growth was faster than that seen in 2017, but the net profit rise was slightly slower.

Huawei's numbers are a bright spot for the firm, which has faced intense political pressure. The U.S. government has raised concerns that Huawei's network gear could be used by the Chinese government for espionage. Huawei has repeatedly denied those allegations. Sales in its carrier business, which is its core networking equipment arm, reached 294 billion yuan, slightly below the 297.8 billion yuan recorded in 2017. The real driver of growth was the consumer business, with revenue for that division rising 45.1 percent year-on-year to reach 348.9 billion yuan. For the first time, consumer business is now the biggest share of Huawei's revenue.

Security

Huawei's Equipment Poses 'Significant' Security Risks, UK Says (cnbc.com) 131

The U.K. government warned on Thursday Huawei's telecommunications equipment raises "significant" security issues, posing a possible setback to the Chinese tech firm as it looks to build out 5G networks. From a report: In 46-page report evaluating Huawei's security risks, British officials stopped short of calling for a ban of Huawei's 5G telecommunications equipment. But the assessment cited "underlying defects" in the company's software engineering and cybersecurity processes, citing "significantly increased risk to U.K. operators." The findings give weight to warnings from U.S. officials who have argued Huawei's networking equipment could be used for espionage by the Chinese government. Huawei has repeatedly said it does not pose any risk and insists it would not share customer data with Beijing. In a statement Thursday, Huawei said it takes the U.K. government's findings "very seriously."
Android

New Huawei Phone Has a 5x Optical Zoom, Thanks To a Periscope Lens (arstechnica.com) 88

An anonymous reader quotes a report from Ars Technica: Huawei officially announced the Huawei P30 Pro smartphone today. While it has a new Huawei-made SoC, an in-screen optical fingerprint reader, and lots of other high-end features, the highlight is definitely the camera's optical zoom, which is up to a whopping 5x. Not digital zoom. Real, optical zoom. Space, of course, is at a premium in smartphones. Imagine a smartphone sitting face down, and you would have to fit a vertical stack of the display, the CMOS sensor, and the lens all in about an 8mm height. There is just not a lot of room. But what if we didn't have to stack all the components vertically? The trick to Huawei's 5x optical zoom is that it uses a periscope design.

From the outside, it looks like a normal camera setup, albeit with a funky square camera opening. Internally, though, the components make a 90-degree right turn after the lens cover, and the zoom lens components and CMOS sensor are arranged horizontally. Now instead of having to cram a bunch of lenses and the CMOS chip into 8mm of vertical phone space, we have acres of horizontal phone space to play with. We've seen prototypes of periscope cameras from Oppo, but as far as commercial devices go, the Huawei P30 Pro is the first. While the optical zoom is the big new camera feature, there are four total cameras on the back of the P30 Pro. A 40MP main camera, a 20MP wide angle, the 8MP 5X telephoto, and a Time of Flight depth-sensing camera. The main 40MP camera uses a 1/1.7 inch-type sensor that, when measured diagonally, would make it 32 percent larger than the 1/2.55 inch-type sensors in the Galaxy S10 or iPhone XS.
The P30 Pro also has a new "RYYB" pixel layout, which swaps out the two green pixels in most CMOS "RGGB" sensors for yellow pixels. "Huawei claims it can capture 40 percent more light, as the yellow filter captures green and red light," Ars Technica reports. "Of course, this will make the color wonky, but Huawei claims it can correct for that in software."

Other specifications include a Kirin 980 octa-core processor with 6GB or 8GB RAM, up to 512GB storage, IP68 water and dust resistance, NFC, wireless charging, 40W wired charging, and a 4,200mAh battery. It starts at a price of $1,125.
Security

Microsoft: Windows 10 Devices Open To 'Full Compromise' From Huawei PC Driver (zdnet.com) 112

According to ZDNet, researchers at Microsoft have discovered a buggy Huawei utility that could have given attackers a cheap way to undermine the security of the Windows kernel. From the report: Microsoft has now detailed how it found a severe local privilege escalation flaw in the Huawei PCManager driver software for its MateBook line of Windows 10 laptops. Thanks to Microsoft's work, the Chinese tech giant patched the flaw in January. As Microsoft researchers explain, third-party kernel drivers are becoming more attractive to attackers as a side-door to attacking the kernel without having to overcome its protections using an expensive zero-day kernel exploit in Windows. The flaw in Huawei's software was detected by new kernel sensors that were implemented in the Windows 10 October 2018 Update, aka version 1809.

The kernel sensors are meant to address the difficulty of detecting malicious code running in the kernel and are designed to detect user-space asynchronous procedure call (APC) code injection from the kernel. Microsoft Defender ATP anti-malware uses these sensors to detect actions caused by kernel code that may inject code into user-mode. Huawei's PCManager triggered Defender ATP alerts on multiple Windows 10 devices, prompting Microsoft to launch an investigation. [...] The investigation led the researcher to the executable MateBookService.exe. Due to a flaw in Huawei's 'watchdog' mechanism for HwOs2Ec10x64.sys, an attacker is able to create a malicious instance of MateBookService.exe to gain elevated privileges. The flaw can be used to make code running with low privileges read and write to other processes or to kernel space, leading to a "full machine compromise."
Long-time Slashdot reader shanen writes: Though the story features Huawei, there doesn't seem to be anything specific to that company there. Just innuendo that you can't trust Chinese companies, eh? "Don't throw your computer into that Chinese briar patch!" Anyway, the sordid reality is that Microsoft is the root of all evils in the Windows platform. If increasing security had been half as important as maximizing profits, then we'd be in a much better world today. All complicated software is buggy, but adding complexity for no good reason is just begging for more problems. Here's a crazy solution approach: Any OS feature that isn't used by a LARGE majority of the users should be REMOVED from the OS. Maybe that isn't strong enough. Maybe the OS should be strictly limited to what absolutely needs to be there. Guard those eggs carefully!
Wireless Networking

Trump Blockade of Huawei Fizzles In European 5G Rollout (bloomberg.com) 280

An anonymous reader quotes a report from Bloomberg: Last summer, the Trump administration started a campaign to convince its European allies to bar China's Huawei from their telecom networks. Bolstered by the success of similar efforts in Australia and New Zealand, the White House sent envoys to European capitals with warnings that Huawei's gear would open a backdoor for Chinese spies. The U.S. even threatened to cut off intelligence sharing if Europe ignored its advice. So far, not a single European country has banned Huawei. Europe, caught in the middle of the U.S.-China trade war, has sought to balance concerns about growing Chinese influence with a desire to increase business with the region's second-biggest trading partner. With no ban in the works, Huawei is in the running for contracts to build 5G phone networks, the ultra-fast wireless technology Europe's leaders hope will fuel the growth of a data-based economy.

The U.K.'s spy chief has indicated that a ban on Huawei is unlikely, citing a lack of viable alternatives to upgrade British telecom networks. Italy's government has dismissed the U.S. warnings as it seeks to boost trade with China. In Germany, authorities have proposed tighter security rules for data networks rather than outlawing Huawei. France is doing the same after initially flirting with the idea of restrictions on Huawei. Governments listened to phone companies such as Vodafone Group Plc, Deutsche Telekom AG, and Orange SA, who warned that sidelining Huawei would delay the implementation of 5G by years and add billions of euros in cost. While carriers can also buy equipment from the likes of Ericsson AB, Nokia Oyj, and Samsung Electronics Co., industry consultants say Huawei's quality is high, and the company last year filed 5,405 global patents, more than double the filings by Ericsson and Nokia combined. And some European lawmakers have been wary of Cisco Systems Inc., Huawei's American rival, since Edward Snowden leaked documents revealing the National Security Agency's use of U.S.-made telecom equipment for spying.

Operating Systems

Huawei Says It Has a Backup OS In Case It's Cut Off From Android (engadget.com) 85

Huawei has built its own operating system for phones, tablets and computers in case tensions between Huawei and the U.S. escalate even further than they already are. "The OS has been rumored for years, but Huawei confirmed its viability with the South China Morning Post, saying it could be used if the company were cut off from Android or Windows," reports Engadget. "It's seen as a last resort, but given the current discord between the U.S. and Huawei, it's not entirely surprising that the company has a plan B." From the report: Huawei began building the OS in 2012, after the U.S. banned Chinese telecom equipment maker ZTE from using American products and services. This was reportedly seen as a way to prepare for "worst-case scenarios." Now, with Huawei suing the U.S. government and the U.S. saying it might punish Germany if the country works with Huawei on its 5G networks, those worst-case scenarios might not be too far-fetched. At the moment, this doesn't change much. Android and Windows are still the company's first-choice. "We fully support our partners' operating systems -- we love them and our customers love them," a company spokesperson told South China Morning Post. Still, given the state of the U.S.-Huawei relationship, this contingency plan could be significant.
The Internet

America's Latest Effort To Thwart the Growth of China's Huawei is Playing Out Beneath the World's Oceans (wsj.com) 107

A new front has opened in the battle between the U.S. and China over control of global networks that deliver the internet. This one is beneath the ocean. [Editor's note: the link may be paywalled; syndicated source.] From a report: While the U.S. wages a high-profile campaign to exclude China's Huawei from next-generation mobile networks over fears of espionage, the company is embedding itself into undersea cable networks that ferry nearly all of the world's internet data. About 380 active submarine cables -- bundles of fiber-optic lines that travel oceans on the seabed -- carry about 95% of intercontinental voice and data traffic, making them critical for the economies and national security of most countries. Current and former security officials in the U.S. and allied governments now worry that these cables are increasingly vulnerable to espionage or attack and say the involvement of Huawei potentially enhances China's capabilities.

Huawei denies any threat. The U.S. hasn't publicly provided evidence of its claims that Huawei technology poses a cybersecurity risk. Its efforts to persuade other countries to sideline the company's communication technology have been met with skepticism by some. Huawei Marine Networks, majority owned by the Chinese telecom giant, completed a 3,750-mile cable between Brazil and Cameroon in September. It recently started work on a 7,500-mile cable connecting Europe, Asia and Africa and is finishing up links across the Gulf of California in Mexico. Altogether, the company has worked on some 90 projects to build or upgrade seabed fiber-optic links, gaining fast on the three U.S., European and Japanese firms that dominate the industry. These officials say the company's knowledge of and access to undersea cables could allow China to attach devices that divert or monitor data traffic -- or, in a conflict, to sever links to entire nations.

Slashdot Top Deals