NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business / Companies / Telecommunications

Juha Saarinen: The real reason Huawei shouldn't be in 5G networks

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
2 Apr, 2019 04:01 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

A report out of the UK details a large amount of amateur-hour engineering flubs by Huawei. Photo / AP

A report out of the UK details a large amount of amateur-hour engineering flubs by Huawei. Photo / AP

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

COMMENT:

Big clues as to the real reason for Western countries' reluctance and outright bans on Huawei supplying equipment to 5G networks dropped last week when a report that's hugely embarrassing for the Chinese tech giant was published in Britain.

READ MORE:
• GCSB ban: Huawei NZ boss outlines two possible ways back in

The report from oversight board for Britain's Huawei Cyber Security Evaluation Centre makes it clear that clever, secret backdoors in the Chinese company's equipment is the least of anyone's worries.

Instead, it's old, unsafe and bug-infested software, bad coding practices, and little or no effort by Huawei to sort out some seriously deficient processes and practices.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Ironically, the UK centre was set up as a transparency effort so that British signals intelligence bureaux could review source code that Huawei uses for its gear and other technologies because the Chinese wanted to show that they had nothing to hide.

The report details a large amount of amateur-hour engineering flubs by Huawei. There's use of coding functions deprecated decades ago because they're notoriously unsafe and easy to exploit for hacks.

Even the freshest newbie coders will know not to use those functions because the documentation for them warns, in big fat letters, not to do that.

Huawei's fixes for those security issues was, in some parts of code, to "redefine a safe function to an unsafe one, effectively removing any benefit of the work done to remove the unsafe functions in the source code," the HCSEC oversight board wrote.

Where did that code with the unsafe functions go?

Discover more

Business

Comment: How YouTube became the internet cesspit

26 Feb 04:00 PM
Opinion

Juha Saarinen: Breaking up tech giants won't be easy

12 Mar 01:10 AM
Business

Juha Saarinen: Should we all just switch off?

19 Mar 04:00 PM
Business

When computer updates turn into Russian roulette

26 Mar 04:00 PM

Huawei uses it for its Evolved Node B processing boards that are part of LTE 4G mobile networks.

These are public facing and the HCSEC oversight board noted that they handle communications with untrusted interfaces and that would be expected to be coded in a robust and defensive manner — especially since the operating system used for them lacks mitigations against attacks.

Advertisement
Advertise with NZME.

Open source developers are usually quick to patch security bugs and release new versions of their code — it's unpaid and under-appreciated work that everyone should be grateful for — and upgrade their installations.

Not so with Huawei. HCSEC's oversight board points to Huawei's use of the popular OpenSSL cryptographic library that's used to secure data traffic, saying it found multiple versions of the code, some of which had vulnerabilities dating back to 2006.

The board said Huawei continues to use an ancient real time operating system (RTOS) that's close to being put out to graze by the vendor the company got it from.

A Linux-based replacement is in the works, but HCSEC is not confident Huawei will deliver it. And either way, much of the gear it runs on doesn't have enough processing power and memory capacity for the upgrade.

Ergo, telcos would need buy new gear for the upgraded OS, which they wouldn't be happy about.

The HCSEC was set up in 2010, and last week's report by the oversight board is the fifth annual one.

Advertisement
Advertise with NZME.

You can sense of how exasperated the spooks from Britain's National Cyber Security Centre and Government Communications Headquarters have grown over the years with Huawei, after trying to persuade the Chinese to fix their dangerously buggy code and end bad security practices, but not getting anywhere.

Long story short, Huawei's lack of engineering competency, as described by the oversight board, means there's no need for backdoors in the company's gear. If it's that full of security holes, attackers can waltz through with very little effort.

To Huawei's credit, the company has accepted the criticism of its software engineering and cyber security processes. It has promised to invest $2 billion over five years "in a company-wide transformation that will contain and mitigate the concerns raised by the oversight board".

We'll see how that goes but the report doesn't say how telcos and internet providers buying Huawei gear missed the lack of engineering quality over so many years.

Sure, Huawei customers probably don't always get to see source code and not all know how to analyse it.

However, when you connect to network equipment for regular work and check version numbers and dates of the software tools that are on them, it's pretty easy to tell that "uh oh, this is old and buggy stuff that really needs updating or we'll be hacked".

Advertisement
Advertise with NZME.

In other words, both Huawei and its customers have some explaining to do before they can be trusted.

Especially for the upcoming 5G networks that will be much more pervasive than 3G/4G ones with massive Internet of Things deployments and self-driving vehicles.

The Brits are now seeking a long-term remediation plan to help get its telcos and internet providers out of the mess.

This is to manage having Huawei equipment deployed in their networks and to ensure that the reviewed source code matches what's being built into production environments as currently the HCSEC is not sure that's the case.

If that doesn't happen, things could become dire for Huawei in the UK market.

"NCSC made clear that without such a plan, there could be no long-term confidence in Huawei's technology or Huawei's ability to support operators in its secure use long-term," the report concludes.

Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Telecommunications

Premium
Business|markets

Spark auctioning half its data centre business to fund $1b expansion push: report

01 May 12:09 AM
Premium
Business|economy

‘A sense of invisibility’: Business leader survey finds lack of Government leadership

28 Apr 08:00 PM
Lifestyle

Half of Kiwi adults overwhelmed by phone notifications, study reveals

21 Apr 05:00 PM

One tiny baby’s fight to survive

sponsored
Advertisement
Advertise with NZME.

Latest from Telecommunications

Premium
Spark auctioning half its data centre business to fund $1b expansion push: report

Spark auctioning half its data centre business to fund $1b expansion push: report

01 May 12:09 AM

Surf's up for the telco as its capital-raising effort comes to the sharp end.

Premium
‘A sense of invisibility’: Business leader survey finds lack of Government leadership

‘A sense of invisibility’: Business leader survey finds lack of Government leadership

28 Apr 08:00 PM
Half of Kiwi adults overwhelmed by phone notifications, study reveals

Half of Kiwi adults overwhelmed by phone notifications, study reveals

21 Apr 05:00 PM
Premium
Spark follows Air NZ in deal with Indian outsourcer

Spark follows Air NZ in deal with Indian outsourcer

17 Apr 02:00 AM
Connected workers are safer workers 
sponsored

Connected workers are safer workers 

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP