• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

3

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

3

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
Tech

Huawei’s Perception Problem Deepens as U.K. Spies Identify Security Risks

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
March 28, 2019, 12:27 PM ET

Huawei’s telecommunications equipment software is riddled with severe security flaws, according to a report from the company’s oversight board in the U.K.

On the plus side, the British spies in charge of the oversight say they don’t “believe that the defects identified are a result of Chinese state interference.” However, the bugs are serious enough to cause telecoms networks to stop functioning if they are exploited. And given the amount of pressure the Chinese manufacturer currently finds itself subjected to—particularly from the U.S.—the report’s timing could not be worse for Huawei.

Suspicion over Huawei’s ties to the Chinese state is nothing new, but it’s the world’s top telecoms equipment vendor and its products are widely used. Facing concerns in the U.K., the company agreed in 2010 to set up a lab there called the Huawei Cyber Security Evaluation Centre (HCSEC,) where Huawei employees would help representatives of GCHQ—the U.K. equivalent of the U.S.’s National Security Agency (NSA)—examine the equipment and its software very closely. Huawei has recently set up other cybersecurity labs in Germany and Belgium, but those only give access to network operators, not intelligence agencies.

Each year, the HCSEC board issues a report on how that scrutiny is going, and the latest report came out Thursday. It was pretty damning.

One major problem is that Huawei can’t prove that the code it submitted for review is exactly the same code running in its equipment. According to the report, Huawei’s software development process is so complex and antiquated that it makes it hard for the British spies to analyze the bugs. All this has been raised with Huawei before, but the company’s plan for dealing with it was “unacceptable” to the spies and U.K. network operators, the report stated, adding that the GCHQ representatives were “not confident that Huawei is able to remediate the significant problems it faces.”

It gets worse: “Given both the shortfalls in good software engineering and cyber security practice and the currently unknown trajectory of Huawei’s R&D processes… it is highly likely that security risk management of products that are new to the U.K. or new major releases of software for products currently in the U.K. will be more difficult [and] that there would be new software engineering and cyber security issues in products HCSEC has not yet examined.”

In other words, the oversight board isn’t brimming with confidence about the new-fangled 5G equipment that Huawei is trying to sell into the U.K.

Aerial photograph of the GCHQ, Government Communications Headquarters.
An aerial photograph of the Government Communications Headquarters, also known as GCHQ, in Cheltenham Gloucestershire. (Photograph by David Goddard/Getty Images)
David Goddard—Getty Images

According to the report, Huawei’s shoddy security practices mean attackers with knowledge of the flaws could “affect the operation of the network,” or even cause the network to crash. They might also be able to access people’s data as it passes through the network—though the network operators’ security controls should limit opportunities for such attacks. Again, the HCSEC board does not believe this is the work of Chinese spies.

“We understand these concerns and take them very seriously,” Huawei said in response to the report, adding that the identified issues “provide vital input for the ongoing transformation of our software engineering capabilities.”

But what does the report mean in effect?

The issue here is one of perception. As Johns Hopkins cryptography guru Matthew Green noted in a Twitter thread: “Many people are saying that other manufacturers probably have the same defects as Huawei. I bet they’re right. This isn’t really the point, though.”

Yes, Huawei is subject to a unique level of scrutiny, which has exposed a level of software vulnerability that might also be found in competing products. But, as Green said, those other equipment vendors “aren’t trying to achieve the unique feat that the U.K.-Huawei partnership is: namely make a not-fully-trusted partner into a trusted one.”

While this is potentially true of other vendors, particularly those that are just spinning up and have immature codebases, those vendors aren’t trying to achieve the unique feat that the UK-Huawei partnership is: namely make a not-fully-trusted partner into a trusted one. 8/

— Matthew Green (@matthew_d_green) March 28, 2019

It’s worth noting that, while some countries such as Australia have banned Huawei’s equipment due to potential Chinese intelligence ties, others have blocked it due to concerns about security flaws that might be fixable. New Zealand’s GCSB spy agency, for example, effectively blocked Huawei’s 5G equipment from the country by telling telecoms operator Spark that it couldn’t use it, but the country’s government subsequently said the door was still open if the concerns could be mitigated.

The fact that New Zealand has shunned Huawei, even if temporarily, while the U.K. continues to allow the company’s products to be rolled out, suggests that such decisions are at least partly political. With that in mind, it is perhaps not surprising that the European Union—at odds with the Trump administration over trade and defense—has decided to ignore the U.S.’s demands that all its allies avoid Huawei’s equipment like the plague.

The EU is instead going more the U.K. route, calling for increased product testing and certification, and Huawei has praised this approach as being more proportionate than the American stance. It had better repay the favor by fixing its software soon, because reports such as that issued this week just give the U.S. more ammunition.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Bridgit Mendler speaks on stage at Fortune Brainstorm Tech 2026 in Aspen, Colorado.
Startups & VentureBrainstorm Tech
The space economy’s next frontier is in ground infrastructure, Northwood Space CEO says
By Sebastian HerreraJune 10, 2026
55 minutes ago
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
Commentarydata sovereignty
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
By Leonard LimJune 10, 2026
5 hours ago
Microsoft co-founder Bill Gates (C) arrives for a closed-door interview with the House Oversight Committee on Capitol Hill in Washington, DC, on June 10, 2026.
LawBill Gates
Gates testifies on Epstein: previous Fortune investigation reveals payments to his ex-girlfriend, $1M Microsoft deal
By Eva Roytburg, Joey Cappelletti, Hannah Schoenbaum and The Associated PressJune 10, 2026
6 hours ago
How the World Cup is a high-stakes stage for Big Tech’s AI push
NewslettersCIO Intelligence
How the World Cup is a high-stakes stage for Big Tech’s AI push
By John KellJune 10, 2026
7 hours ago
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits capabilities for AI researchers and developers
AIAnthropic
Anthropic accused of ‘secret sabotage’ as Claude Fable 5 silently limits capabilities for AI researchers and developers
By Sharon GoldmanJune 10, 2026
9 hours ago
A 5-week course and a guaranteed job: Meta commits $115 million to solve the skilled-trades shortage stalling its AI build-out
Future of WorkMeta
A 5-week course and a guaranteed job: Meta commits $115 million to solve the skilled-trades shortage stalling its AI build-out
By Jacqueline MunisJune 10, 2026
9 hours ago

Most Popular

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
2 days ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
2 days ago
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
Economy
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
By Nick LichtenbergJune 9, 2026
1 day ago
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
Energy
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
8 hours ago
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
Investing
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
By Eva RoytburgJune 9, 2026
1 day ago
Current price of oil as of June 9, 2026
Personal Finance
Current price of oil as of June 9, 2026
By Joseph HostetlerJune 9, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.