UK cyber agency launches review of Huawei presence in 5G networks

The United Kingdom’s cybersecurity agency is reviewing the impact that new U.S. sanctions on Chinese telecommunications company Huawei could have on Britain’s deployment of 5G technology. The review by the National Cyber Security Centre is welcome news for U.S. officials who have lobbied their U.K. counterparts to ban Huawei gear out of concerns over espionage. And it’s a potential change of fate for Huawei’s business in the U.K. after officials decided in January to allow the telecom giant’s equipment in up to 35% of the country’s 5G deployments — albeit not in the most sensitive parts of those networks. “Following the U.S. announcement of additional sanctions against Huawei, the NCSC is looking carefully at any impact they could have to the U.K.’s networks,” the NCSC said in a statement to CyberScoop on Tuesday. “The security and resilience of our networks is of paramount importance.” Prime Minister Boris Johnson’s office, according […]

The post UK cyber agency launches review of Huawei presence in 5G networks appeared first on CyberScoop.

Continue reading UK cyber agency launches review of Huawei presence in 5G networks

US Commerce Department tightens screws on Huawei export controls

The U.S. Department of Commerce on Friday said it was tightening regulations to prevent Huawei from using U.S. software to make semiconductors abroad, the latest move by officials to crack down on a Chinese telecommunications giant they deem a national security threat. The new regulations are an effort to “narrowly and strategically target Huawei’s acquisition of semiconductors that are the direct product of certain U.S. software and technology,” the Department of Commerce said in a statement. Huawei has been circumventing previous restrictions on using U.S. technology to make semiconductors, which are key to its smartphone business, Commerce officials alleged. The updated export controls go further in forcing foreign companies that use U.S. chipset technology to get a license before selling that technology to Huawei. A Huawei spokesperson did not immediately respond to a request for comment. The new export controls are one of a series of stringent measures the Trump administration […]

The post US Commerce Department tightens screws on Huawei export controls appeared first on CyberScoop.

Continue reading US Commerce Department tightens screws on Huawei export controls

Federal agencies recommend U.S. bar China Telecom over cybersecurity concerns

Several federal agencies recommended Thursday that U.S. regulators block a Chinese state-owned telecommunications firm from providing service to American customers. The Departments of Justice, Defense, and State urged the Federal Communications Commission to take action against China Telecom, a subsidiary of a Chinese state-owned telecommunications company, over cybersecurity and national security concerns, according to a Justice Department statement. The departments said the FCC should revoke China Telecom’s licenses to operate in the U.S. because, as a Beijing-based firm, China Telecom can “provide opportunities for [China] to engage in malicious cyber activity enabling economic espionage and disruption and misrouting of U.S. communications,” the department says. China Telecom has acted as a “common carrier,” meaning it connects domestic and international networks, since 2007. The U.S. government in recent years has warned that Chinese companies may not be able to refuse Beijing’s intelligence requests. This recommendation comes after U.S. intelligence officials have warned for years that the Chinese government could leverage another […]

The post Federal agencies recommend U.S. bar China Telecom over cybersecurity concerns appeared first on CyberScoop.

Continue reading Federal agencies recommend U.S. bar China Telecom over cybersecurity concerns

Commerce Department proposes rules for implementing Trump’s supply-chain security order

The Department of Commerce on Tuesday outlined how it might implement a White House order that gives the department broad leeway to ban foreign parts in U.S. IT and communications supply chains because of security concerns. Secretary of Commerce Wilbur Ross will “adopt a case-by-case” approach to determining what components will be banned, drawing on assessments from the Department of Homeland Security and the Office of the Director of National Intelligence, the department said in a statement. Under the proposal, before making a final decision to exclude a foreign company from U.S. digital supply chains, the Commerce Secretary would notify the company, giving it the opportunity to address security concerns and avoid a ban. The secretary would send an unclassified ruling to the parties explaining the decision and make that public when appropriate. The proposal is a key step toward making a more stringent national policy governing U.S. supply chains a […]

The post Commerce Department proposes rules for implementing Trump’s supply-chain security order appeared first on CyberScoop.

Continue reading Commerce Department proposes rules for implementing Trump’s supply-chain security order

Trump administration looks to throttle Chinese surveillance companies’ business with U.S.

The U.S. Commerce Department made moves Monday to limit the activities of eight Chinese companies in the U.S., citing human rights abuses and surveillance against Uighurs and other Chinese Muslim minorities. The department said it is adding the companies to its Entity List, which identifies people, businesses or other organizations for “engaging in activities contrary to U.S. national security and/or foreign policy interests.” Although the department names human rights abuses as the primary concern in its latest action, some of the eight companies have also come under federal scrutiny in recent months for security issues. Just two months ago the Trump administration issued a rule to bar federal purchases of telecommunications equipment from two of the companies added to the list this week, Hangzhou Hikvision Digital Technology Co. Ltd., a former Chinese government research arm, and Dahua Technology. Those earlier moves were done in accordance with the 2019 National Defense Authorization Act. Another company added to the Entity List this week, Xiamen […]

The post Trump administration looks to throttle Chinese surveillance companies’ business with U.S. appeared first on CyberScoop.

Continue reading Trump administration looks to throttle Chinese surveillance companies’ business with U.S.

NIST is preparing guidance on how to share .zip files in a more secure way

Do you ever wonder if the files you’re sending over the internet are safe from hackers’ prying eyes? The search for how to share files in a more secure way could soon be over. The U.S. National Institute of Standards and Technology is now preparing to instruct the public, as well as government agencies, on the best ways to protect .zip files sent over the internet, according to a letter obtained by CyberScoop. While there’s no timeline for when the final advice could be made public, NIST says its motivation is to produce “easy-to-understand guidance” on how to compress many files into a single place while protecting all of that data with strong encryption. James Schufedier, director of the Congressional and Legislative Office at NIST, explained more in a July 22 letter to Sen. Ron Wyden, D-Ore. “The need to improve practices for securing sensitive data that is shared over the Internet is one of […]

The post NIST is preparing guidance on how to share .zip files in a more secure way appeared first on CyberScoop.

Continue reading NIST is preparing guidance on how to share .zip files in a more secure way

As defense bill approaches finish line, future of Chinese company ZTE hangs in the balance

When House and Senate negotiators sit down next week to iron out their differences in the annual defense bill, the fate of Chinese telecom giant ZTE will be a key issue. Select lawmakers from both chambers are headed to a conference committee to reconcile the House and Senate versions of the National Defense Authorization Act (NDAA) for fiscal 2019. One notable discrepancy is ZTE-related language: Broadly speaking, the Senate version calls for stricter rules that would curtail the Chinese company’s ability to do business in the U.S.. The House NDAA would restrict the Department of Defense and its contractors from procuring equipment from Chinese telecoms ZTE and Huawei. The Senate version, taking stock of ZTE’s continuous flouting of U.S. sanctions, would explicitly block ZTE from doing business in the country writ large. The Senate’s version of the NDAA, with the ZTE ban tucked into it, passed with broad bipartisan support, 85-10. […]

The post As defense bill approaches finish line, future of Chinese company ZTE hangs in the balance appeared first on Cyberscoop.

Continue reading As defense bill approaches finish line, future of Chinese company ZTE hangs in the balance

Senators want Commerce to help U.S. firms ditch ZTE

A bipartisan trio of senators have asked the Department of Commerce to clarify that U.S. companies are welcome to remove products from their networks made by controversial Chinese telecom company ZTE. Republican Sens. Tom Cotton, Ark., and Marco Rubio, Fla., along with Sen. Chris Van Hollen, D-Md., say they strongly support the department’s April “denial order” barring ZTE from buying U.S. technology components for seven years. However, the senators are concerned that the order is ambiguous to the point of hindering the removal of ZTE gear from U.S. infrastructure. On Monday, they wrote Secretary of Commerce Wilbur Ross asking his department to issue guidance and waivers to help U.S. companies clear their networks of ZTE software and hardware. U.S. officials have long warned that the Chinese government could leverage technology built by ZTE and fellow Chinese telecom Huawei to spy on Americans – accusations the companies deny. The Commerce Department […]

The post Senators want Commerce to help U.S. firms ditch ZTE appeared first on Cyberscoop.

Continue reading Senators want Commerce to help U.S. firms ditch ZTE

House panel rejects call for cyberthreat report on ZTE amid Trump deal

On the heels of a reported U.S. deal with embattled Chinese telecom company ZTE, American lawmakers rejected a Democratic measure that would have directed the Department of Homeland Security to provide more information on any cybersecurity risks posed by the international tech company. The top Republican and Democrat on the House Homeland Security Committee sparred over the utility of the resolution, which would have tasked DHS with providing any documentation it has on cyber risks introduced by the use of ZTE products on federal, state and local government networks. The Republican-led panel voted 16-11 against the measure. Instead, lawmakers will get a classified briefing from officials at DHS, the FBI and the Defense Department on June 13 about the  national security risks posed by ZTE and Huawei, another Chinese technology giant. Texas Republican Michael McCaul, the committee’s chairman, announced the briefing at a committee markup Wednesday on Capitol Hill. U.S. […]

The post House panel rejects call for cyberthreat report on ZTE amid Trump deal appeared first on Cyberscoop.

Continue reading House panel rejects call for cyberthreat report on ZTE amid Trump deal

DHS’s diagnostics open door to collaboration among agencies, says Commerce official

A funny thing happened when the CIO Council at the Department of Commerce sat down to figure out how to deploy the new tools coming from the Department of Homeland Security’s Continuous Diagnostics and Monitoring, or CDM, program. Rod Turk, the department’s CISO and acting CIO, said people on the council —which brings together the CIOs from all the various agencies and bureaus that make up Commerce — started asking questions. “Questions like, ‘Why do we have multiple Security Operation Centers and Network Operation Centers?’ … We have three SOC’s just in [the Commerce headquarters building] … What can we do  more efficiently?” recalled Turk, who said he’s sat on the council for about eight years. Turk spoke at a breakout session on CDM on Thursday at the 2017 McAfee Security Through Innovation Summit hosted by FedScoop and CyberScoop. Under the governmentwide CDM program, DHS pays for cybersecurity tools and services that monitor the IT networks […]

The post DHS’s diagnostics open door to collaboration among agencies, says Commerce official appeared first on Cyberscoop.

Continue reading DHS’s diagnostics open door to collaboration among agencies, says Commerce official