Who should be worried?
This week the National Cyber and Information Security Agency issued a warning. [[1](https://www.govcert.cz/download/uredni-deska/Varován%C3%AD-NÚKIB-18121 7-podepsane.pdf)] It concerns the use of devices and software from Huawei and ZTE.
"The use of these products represents a security threat" reads the warning.
"The warning was prompted by our findings, including those from our security partners and from our allies. The core issue is the legal and political environment of the People's Republic of China, in which these companies primarily operate. Chinese laws require private companies operating in China to cooperate with intelligence activities, among other things — making it potentially dangerous to allow them into systems critical to the running of the state," says NÚKIB Director Dušan Navrátil.
By the end of the week there was a clarification.
"The warning is not primarily aimed at the ordinary user"
"It is intended in particular for selected entities operating information systems important to the functioning of the state"
"For people who use a mobile phone or router from the mentioned companies for everyday use, we can assume the usual risk associated with using any mobile or network device. We can only recommend following the principles of safe use of these products and the general rules of safe behaviour in cyberspace, which can be found, for example, on the NÚKIB website here: https://nukib.cz/cs/informacni-servis/doporuceni/"
How is an ordinary user supposed to make sense of all this? It's not as straightforward as it seems. From public sources it is known that Huawei's founder previously worked for the Chinese military. [2][3] Which suggests a certain connection to specific individuals or to intelligence services. By itself it means nothing, you might say. However, from a security perspective it's not ideal. Intelligence services by definition pursue certain objectives, and access to such devices or software hands them a very powerful tool. Of course, there is no public evidence.
Now to our public sector — hlídač smluv shows some fairly interesting contracts. Mobile phones are used by the police (South Bohemian Regional Headquarters, Police Presidium), NAKIT, Ministry of the Interior, Ministry of Labour and Social Affairs, Ministry of Regional Development, Ministry of Health, Office of the Government, Czech Social Security Administration, Fire and Rescue Service, University Hospital Brno, Plzeň City Transport and dozens of others — mostly municipalities. Not to mention their presence in the general population. That's already a sizeable potential source of information. From what I managed to find, only Plzeň City Transport uses MDM (Mobile Device Management), so if someone's phone was compromised, lost, or behaving abnormally, the remaining organisations wouldn't be able to do anything about it.
An interesting part is Huawei's presence in laptop contracts. The reason: ProBook and EliteBook series laptops contain an LTE modem from that brand. Where are such laptops? General Directorate of Customs, Czech Television, Czech Radio, Ministry of Finance, Ministry of the Environment, Financial Intelligence Unit, Brno City Council, University of West Bohemia in Pilsen, Operator ICT and others.
We've saved the best for last: the infrastructure elements (routers, switches, firewalls, servers or storage). A fairly significant presence can be found at the Ministry of Justice including regional courts and state prosecution offices. Some of the elements mentioned can also be found at Administration of Basic Registers, Administration of State Material Reserves, Air Navigation Services, Police Presidium, Ministry of the Interior, Road Directorate, Fire and Rescue Service and others.
I mustn't forget Prague Castle Administration — they almost certainly have mobile phones as well as whatever else they want up to a certain financial threshold — according to the current contract [4] that's one million CZK excluding tax.
What can you say? Huawei is represented quite widely in Czech public administration. Not to mention all telecoms operators using their equipment in their networks.
Just do your analysis. Can you trust a given component? Does it have certifications, has it undergone an independent security audit? Can you verify it's not doing something it shouldn't? Once you've answered all of that, decide what you'll do.
One such audit is carried out by the UK's HCSEC — this year's report states: "However, Huawei's processes continue to fall short of industry good practice and make it difficult to provide long term assurance. The lack of progress in remediating these is disappointing." [5]
Personally I would not use this hardware/software if only because there is reasonable doubt. Including mobile phones. The claim that ordinary users face no risk is nonsense. Who is an ordinary user? Such a phone could be used, for example, to gather compromising information, as an entry point for further compromise,...