โŒ

Reading view

There are new articles available, click to refresh the page.

EU telcos ask: Huawei going to afford to replace Chinese equipment?

Replacing telecoms kit supplied by so-called high-risk vendors could cost European telcos up to โ‚ฌ40 billion ($45.5 billion), with additional impacts on network performance and future investment plans. This is the warning in a report from GSMA Intelligence, the research arm of the mobile comms industry's global trade body, the GSMA. It refers to plans by the European Commission to address potential threats to EU security posed by IT and telecoms kit from third-country sources. The proposed Cybersecurity Act 2 (CSA2) regulatory framework includes provisions requiring member states to rip out and replace critical equipment supplied by designated high-risk vendors (HRVs) in their telecoms infrastructure, as reported by The Register earlier this year. When the Commission says "high-risk vendors," it means China-based suppliers such as Huawei and ZTE, as identified in a speech by former European Commissioner Thierry Breton several years ago. According to the GSMA, it comes down to the increasing importance of digital infrastructure to economies and life in general, and so the Brussels policymakers are placing a greater emphasis on security and resilience. However, huge uncertainty remains over the cost of replacing HRV equipment - hence the mobile trade body's decision to investigate. There's also the challenge of doing it on a large scale within a tight timeframe: mobile operators would have just three years to remove the targeted equipment, while deadlines for other networks and assets could differ. The GSMA's own figures, based on a survey of seven EU operator groups, produce an estimate of โ‚ฌ30 billion to โ‚ฌ40 billion. This includes costs for mobile networks, fixed networks, and transport networks, such as optical backbones and subsea cables. Taking a midpoint estimate of โ‚ฌ35 billion, mobile networks would account for โ‚ฌ19 billion, fixed infrastructure for โ‚ฌ5 billion, and transport elements for โ‚ฌ11 billion. The report also warns of impacts beyond just the rip-and-replace cost. Banning those high-risk suppliers will restrict competition in the telecoms equipment marketplace, likely resulting in higher costs for operators. The GSMA says its analysis uses an approach favored by the European Commission itself, which relies on diversion ratios, measuring the proportion of sales lost by one firm that might be captured by another, combined with information on margins. Cutting to the chase, it believes that equipment prices could rise 24 percent - in part because the market for mobile kit is already highly consolidated, with Huawei accounting for a sizable chunk of it. Fixed network gear could see increases of up to 19 percent, and GSMA estimates transport network equipment prices may go up by a more modest 10 percent. Based on anticipated investment between 2027 and 2030, this would result in an incremental cost to network operators of about โ‚ฌ8.5 billion ($9.7 billion), according to the report. Facing these additional costs, network operators will review their investment and market strategies and respond by either increasing access charges for customers or scaling back spending on network upgrades and service improvements โ€“ possibly both. The GSMA warns that the broader economic costs to the European economy would likely be wider than its estimated impact on the telecoms businesses. "High-quality, affordable network infrastructure serves as a foundational, general-purpose technology that underpins productivity gains, innovation and economic growth. Slower or more expensive 5G/6G deployment will hinder the EU's ability to meet its ambitious Digital Decade 2030 targets," it states. The GSMA references a KPMG study (caveat: produced in collaboration with the China Chamber of Commerce to the EU) that claims these policies could lead to cumulative economic losses of up to โ‚ฌ370 billion ($422 billion) across the EU region between now and 2030. But if you need other evidence, just consider the UK's situation. It forced operators to remove Huawei kit from the country's 5G networks in response to pressure from the first Trump administration, which threatened to cut Britain out of intelligence sharing if it didn't comply. This was despite an investigation finding no technical justification for such a ban. The result is that the UK's 5G networks are among the worst in Europe when it comes to performance and quality of service. This has been directly linked with the decision to replace Huawei kit, when British operators should instead have been putting cash toward ramping up their 5G rollouts. To add insult to injury, some telecoms networks in the US itself are still using Huawei equipment, refusing to replace it unless the government coughs up the cash. And just a few years ago, it was reported that Huawei was the supplier of nearly 60 percent of the installed network kit operating Germany's 5G infrastructure. Some may argue that it is long overdue for EU member states to bite the bullet and purge their national networks of any potential security threat. But the question is, how much is Europe prepared to pay for it? ยฎ

China advances plans for national single-stack IPv6 network, and its own surveillance-friendly version of the protocol

Chinaโ€™s Cyberspace Administration on Tuesday issued a plan for wider adoption of IPv6 between now and 2030, and for more work on a non-standard set of services that Beijing calls โ€œIPv6+โ€. The Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030) contains the usual promises to increase use of IPv6. Beijing wants 900 million users to be connected over IPv6 by 2027, and for the protocol to carry 38 percent of network traffic. China also wants all connected devices to be IPv6-enabled by 2027. โ€œBy 2030, IPv6 will be widely and deeply integrated with all sectors of the economy and society, building a technologically advanced, open, innovative, self-driven, and secure IPv6 industrial ecosystem,โ€ the regulator wrote. โ€œThe number of active IPv6 users will reach 950 million, and IPv6 will account for 42 percent of network traffic.โ€ The Administration also expects that by 2030, โ€œNew networks will be prioritized for IPv6 addresses by default, accelerating the evolution towards IPv6 single-stack, and promoting the formation of a network service and application system dominated by IPv6.โ€ News that China is planning for the day it runs a single-stack internet will excite some, notwithstanding the fact that IPv6 has proven less important than its creators hoped. The most interesting part of the new plan is the call for more work on IPv6+ โ€“ a set of enhancements to IPv6 that allows those who send information to embed metadata describing content into packets and even suggest the route it should take. As Think Tank the Mercator Institute for China Studies last year observed, IPv6+ โ€œhas obvious appeal for authoritarian regimes looking to control their citizens,โ€ because a carrier could read metadata and act on it. One possible action could be to allow network operators to identify traffic they would like to charge extra to carry, an idea telcos like because they feel it is unfair that they bear the burden of investing in last-mile infrastructure to deliver content from the likes of Netflix and YouTube. Reading metadata could also enable censorship: Beijing already blocks a lot of content, and if dissidents had to identify themselves in packets, theyโ€™d be easier to find and block. The Institute also notes that Chinaโ€™s telco equipment companies have implemented IPv6+ and exported kit that runs it to several nations. Thatโ€™s worrying because China already tried to create a protocol called โ€œNew IPโ€ that also included surveillance-friendly features. China tried to have the International Telecommunications Union sign off on New IP, despite the Internet Engineering Task Force maintaining existing IP protocols. That effort failed, but Beijing is pressing ahead with its efforts to spread its own version of IP at home and abroad. The new plan doesnโ€™t suggest that Beijing abandon vanilla IPv6. Indeed, it calls for Chinese participation in global standards development. But the document also says China will work on โ€œnational IPv6 standards and accelerate the development of national IPv6 standards in key areas.โ€ ยฎ

NTP server that traveled back in time caused massive Aussie mobile outage

Australian telco Telstra has revealed the cause of the recent incident that caused widespread connectivity problems across its mobile networks, inculding outages to Australia's 000 emergency services line, plus outages to electronic payments services and transport networks. The carrier explained itself in a submission [PDF] to a Senate inquiry into outages affecting Australiaโ€™s emergency services which initially investigated an outage at Telstra's main rival, Optus. The Optus incident is linked to multiple deaths after people could not reach emergency services. Telstra's submission reveals that the carrier's attempt to address a known resilience problem was the instigating incident. That problem was a faulty backup power feed in the chassis used to house a network time protocol (NTP) server. A few minutes before midnight on July 7, a Telstra techie started work to replace that chassis. By 3:38 AM on July 8, the worker had finished the job and powered up the server. The NTP server included a GPS card that Telstra says โ€œdid not operate as expectedโ€ when the server came back online. โ€œWe now believe this occurred because of an intentional design change that had previously been made to the equipment to fix an earlier fault [which] had not been properly documented,โ€ the submission states. โ€œThis meant the maintenance team was not aware of the way the device would behave when restarted.โ€ Telstra also admitted it had not applied a software update to the device, despite knowing of its availability in early 2026. โ€œHad that software update been completed or had the design change been properly reviewed and documented post the earlier incident, and reflected in the maintenance procedure, the outage may not have occurred,โ€ the submission states. The outage did happen because once the NTP server came online it reset its clocks to the year 2006. The server then did what NTP servers do: publish that time to myriad other machines across the network. Once those machines received the incorrect time, other kit on the Telstra network compared digital certificates and decided something dodgy was going on โ€“ so denied connections. Just one of Telstraโ€™s three NTP servers had this problem, but enough bad timing info made it onto the carrierโ€™s network to cause chaos. The telco isolated the bad box at 7:11 AM, and by 10:30 AM had identified all network components that used the bad time information the naughty NTP box broadcast. That wasnโ€™t the end of the matter, because as valid time information rippled across the network, some equipment didnโ€™t close IP sessions. Customer devices therefore couldnโ€™t reconnect to the network unless rebooted. The carrier has described the outage as โ€œclearly unacceptable.โ€ โ€œIf maintenance work can trigger this kind of outage, it suggests our controls were not good enough. We are accountable for that, and our investigation will address why that design change was not documented, why the software update was not completed, and what needs to change in our controls so known risks are captured, prioritised and closed before they can affect customers.โ€ The carrier has done the usual thing by promising to conduct deep and lengthy self-reflection, submit itself to further flagellation at more inquiries, co-operate with a probe by the relevant regulator, and to do what it takes to prevent similar incidents. ยฎ

Hands off our VPNs, privacy groups tell UK ministers

Privacy campaigners, browser makers, and VPN providers have united to warn the UK government against restricting virtual private networks, saying age-gating the technology would weaken online security while doing little to stop kids dodging social media bans. The Open Rights Group on Tuesday published an open letter signed by more than 20 organizations, including the Electronic Frontier Foundation, ExpressVPN, the Internet Society, Mozilla, Mullvad, Proton, and the Tor Project. It urges ministers to rule out age verification and other restrictions on VPN services. The coalition argues that VPNs have become important infrastructure for a broad range of users, from businesses and journalists to abuse survivors and ordinary users trying to protect themselves on public Wi-Fi. Requiring users to prove their age would undermine the privacy VPNs are intended to provide. "Restricting VPNs would undercut the security and privacy of millions, without making children safer," the letter reads. "Age-gating VPNs would require everyone to surrender sensitive personal information simply to access tools designed to protect privacy." It's hardly a new fight. Mozilla spent much of spring arguing that ministers were chasing the wrong target, warning that breaking VPNs would do little to fix Britain's age-check problem while making the internet less private and less secure for everyone else. The open letter suggests plenty of others have since reached the same conclusion. The intervention comes as ministers prepare to introduce a ban on social media for under-16s, arguing that VPNs aren't the loophole many critics assume. The government's own research backs that up, showing that while about one in four 11 to 17-year-olds said they'd used a VPN, only 7 to 10 percent did so to bypass age checks. Most simply lied about their age instead. The coalition highlights similar figures from Ofcom, which it says makes a poor case for tightening access to VPNs. "Ofcom's research found that only around 3 percent of children had used VPNs to access content meant for older audiences," the letter says. "Evidence from Australia shows children are much more likely to get around age checks by not being asked, giving false information, or even drawing on a mustache." The signatories instead want ministers to tackle what they describe as the "root causes of online harms," rather than making people prove who they are before they can use privacy tools. The letter argues that strong enforcement of platform obligations, better parental controls, investment in digital literacy, and privacy-by-design requirements would do more to protect children than requiring VPNs to be behind age checks. Whether the government is persuaded may depend on whether it views VPNs as a niche loophole used by a small minority of teenagers โ€“ as its own research suggests โ€“ or as the next obstacle to enforcing its online safety agenda. ยฎ

The US government warns that Russia state hackers are coming after your router

The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.

Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.

Proxy networks: The go-to tool

โ€œRussian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,โ€ the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.

Read full article

Comments

ยฉ Getty Images | BernardaSv

โŒ