Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Huawei to meet with German security researcher who disclosed product vulnerabilities

The company plans to engage with security researchers to improve product security

Article comments

Chinese networking and telecommunications equipment manufacturer Huawei plans to send a team of engineers to Germany in order to meet with Felix Lindner, a security researcher who earlier this year disclosed vulnerabilities in the company's products, he confirmed.

The meeting was first revealed by John Suffolk, Huawei's global head of cybersecurity, during an interview, Reuters reported Thursday.

The company is not just interested in fixing the particular flaws reported by Lindner, but in making systemic changes that would make its products more secure in the long term, Suffolk said in the interview.

Felix "FX" Lindner is the technical and research lead at Recurity Labs, an IT security consultancy company based in Germany. This year, he disclosed critical vulnerabilities in Huawei home and small enterprise routers during the Defcon and Hack in The Box security conferences.

He also criticised the company for the lack of transparency when it comes to security issues and the poor quality of code in its products.

"I was surprised to learn that they told the press about this meeting before it actually took place, but it is correct that such a meeting is planned," Lindner said via email. "What Huawei's goals are for the meeting is not known to me yet."

"Unfortunately we are unable to disclose more information apart from what John Suffolk said in the interview," Yingying Li, marketing and communications manager at Huawei in the UK said Thursday via email. "We have set up a comprehensive security assurance system and have it stress tested on regular basis. The company will keep seeking ways to enhance the product security together with our customers and industry peers."

In the interview, Suffolk noted that Huawei has made changes in its approach to security since he joined the company in 2011, which included making it easier for security researchers to report vulnerabilities.

"It is correct that they appointed a Product Security Incident Response Team (PSIRT) and more prominently published how to reach it," Lindner said. "However, other areas still need some work. Security advisories, for example, are not yet widely circulated."

"Currently, all one can see is the apparent willingness to engage, which is a good first step," the researcher said. "Whether this will lead to a serious product security program or not is something time will tell."

Before joining Huawei as its global head of cybersecurity, Suffolk served as the chief information officer of the British government for six years. Back in September, he published a paper in which he outlined Huawei's commitment to cybersecurity.

"The company remains open for a constructive dialogue with all stakeholders, especially in the field of cyber security which is one of our top priorities," Roland Sladek, Huawei's vice president of international media affairs for the EMEA region, said via email.

For the past few years, the company has strongly disputed accusations of having ties to the Chinese military or the country's intelligence services.

A report released earlier this month by the US House of Representatives' Permanent Select Committee on Intelligence said that using equipment from Huawei and fellow Chinese telecom vendor ZTE for US critical infrastructure would pose a national security threat because of the possible ties between the two companies and the Chinese government.

The committee advised the US government, its contractors, as well as private-sector companies to avoid buying networking equipment from the two Chinese vendors.



Share:

More from Techworld

More relevant IT news

Comments

sternhead said: on one hand they claim to observe best security practices have state of the art gear and deny all claims to the contrary otoh theyre seeking out Lindner to discover how their routers and security practices were determined to be crap Dont tell em anything FXThey just want to figure out how to beat the researchers



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *