Huawei Criticised for Potentially Compromising UK Infrastructure with Old Third-Party Software
Huawei is using software that will be unsupported from 2020, in hardware that will be used for years to come
Huawei is drawing ire in the UK over its use of third-party software in its products, which will come to end-of-life long before the hardware itself does.
As reported last month, the Oversight Board of the Huawei Cyber Security Evaluation Centre (HCSEC) - a company-funded body that examines and test Huawei products to be used by UK telcos - said that ‘security critical third-party software used in a variety of products' are not ‘subject to sufficient control'.
It added that Huawei hardware contains third-party software, including security-critical components, that will cease long-term support in 2020, even though the Huawei products in question will be in service for much longer.
The Oversight Board is a government organisation that publishes an annual report about HCSEC's work.
A Reuters report says that Huawei buys the software in question from Wind River Systems, based in the USA - where, ironically, the Chinese vendor has also been facing increased scrutinyover security concerns.
Three sources told Reuters that Wind River Systems is responsible for developing the VxWorks operating system, and that it will not receive security updates and patches past 2020. As British telecom operators will still be using the Huawei hardware with VxWorks at that point, their networks could become vulnerable to attack.
The sources did not suggest that the software itself is a security risk - only the upcoming lack of support.
A Wind River spokesperson told Reuters that the company often helps customers to upgrade to newer versions. A Huawei spokesperson said the vendor would address ‘any areas for improvement' that are raised by the British authorities (although the Oversight Board's report does not specifically mention VxWorks).
Huawei supplies equipment to UK telcos including BT and Vodafone.
- Senior Identity and Access Management Consultant (IDAM)
- €70,000 - €85,000
(Security Consultant, Technical Consultant, Consultant, IDAM, CyberArk, RSA, Cyber, Security, Germany) Location: Frankfurt *Candidates must be EU based (Germany preferred) as our client are unable to provide sponsorship* Senior Identity and Access Management consultant (IDAM) subject matter expert is needed to lead and drive technical and or business transformation projects in a client facing position for a prestigious consultancy in Frankfurt, Germany. A broad technical knowledge across Identity and access management is essential. Technical hands-on experience with one or more of the following Ping, Forgerock, Cyberark, RSA Aveksa is highly desirable. A successful individual will be client facing and MUST be able to effectively engage, consult and provide advice to complex client engagements. The position will give the Senior Identity and Access Management consultant the opportunity to work with top tier clients with the view of making a meaningful strategic difference. If you are passionate about your industry and specialise in the IDAM space and are looking for a new challenge to step up, apply today and speak with the Security team. Call DCL Search & Selection on 0208 663 4030 and find out about more of our cybersecurity jobs. Reference: TC7528 (Security Consultant, Technical Consultant, Consultant, IDAM, CyberArk, RSA, Cyber, Security, Germany)
- Business Development Manager (IoT Connectivity Solutions)
- Up to €120,000 plus bonus and benefits
Experienced Business Development Manager is required for an expanding Service Provider to sell/position their IOT connectivity solutions into the Manufacturing Sector within the German market. This is a great opportunity to join a key player within this space, who have a number of successful projects for you to reference, they have the skills and the network but now needs the key person to help take the message to market You need to have proven sales experience within the mobile cellular IOT connectivity space and ideally knowledge of the manufacturing sector, this is a true consultancy role, you will be comfortable working with other sales team within the business but also able to directly approach key customers yourself. Great opportunity to join an expanding business as they grow their German Presence Ref: RA7259 (IoT Sales Jobs, IoT Sales, IoT Sales Executive, IoT Business Development Manager)
- Services Manager (Telecommunications)
- Up to £75,000 plus benefits and bonus
Service Manager with telecommunications experience is required for a tier 1 service provider. You will be responsible for managing a number of key global account, acting as the voice of the customer within the business. Your key objectives will include: Responsibility for overall service relationship with the customer To enhance the customer experience To protect and grow customer revenues You will be working within a global business where you will be managing different services from different parts of the globe and therefore must be able to demonstrate where you have ideally worked within a similar environment. You will be a key member of the service management team responsible for a number of key accounts. You must have experience as a Service Manager from either a telecom/telecommunications or hosting business dealing with services to corporate accounts, you will need to have knowledge around telecom/telecommunications solutions. Ref: RA7255
- Infrastructure / Forensic Lab Manager
- Up to £40,000 Base
Infrastructure / Lab Manager needed to join a consulting business near London Bridge. MUST be commutable on a daily basis. The Infrastructure / Forensic Lab Manager will be responsible for the upkeep, performance, security/patching etc of the hardware/software used by the consultants across the UK business. Broad IT experience covering both on-prem - Cloud (Azure) environments, Hyper V, Security Information and Event Management tools (such as SPLUNK). Specific experience with Forensic / eDiscovery Labs (Relativity / Nuix) is highly desirable. The Infrastructure / Forensic Lab manager will be a key hire within the technical team being the escalation point for any internal IT issues. Experience liaising with remote/international stakeholder is essential. All details kept in the strictest of confidence. Apply today and or contact Chris.Holt@dclsearch.com *For this position candidates must be UK based and our client is unable to sponsor candidates outside of the EU* Ref: CH7533 (Forensics Jobs, Digital Forensics Jobs, Forensics Lab Manager)