Warning—Is Your Phone At Risk From This Chinese Spyware?

Posted by Zak Doffman, Contributor | 7 hours ago | /cybersecurity, /innovation, Cybersecurity, Innovation, standard | Views: 11


Google’s Android is now under serious threat from China. It’s the greatest threat to the world’s leading mobile OS since its inception. And if there was any doubt as to how critical this is, it’s serious enough that U.S. lawmakers have now stepped in.

As I reported last week, rumors in China suggest its largest phone manufacturers are plotting to collaborate on an alternative to Android. Xiaomi and BBK Group — the company behind OPPO, Vivo, and OnePlus — might join with Huawei, which has already departed Android’s stable, on a Google-free alternative.

Absent Huawei this might be fanciful, but China’s leading technology company already has an Android alternative. HarmonyOS started life as an IOT architecture and then expanded to phones when U.S. sanctions kicked in five years ago. It’s sleeker than Android and is arguably less bloated. It’s also right-sized for today’s devices.

ForbesGoogle Is Deleting All Your Location Data—Do Not Miss Deadline

I warned this would happen back in 2020, as the obvious, eventual outcome from an America/China splinternet China playing the long game. If Android does eventually lose BBK in addition to Huawei, then it will be decimated. Only Samsung will remain as a leading OEM within the fold. Pixel is an also-ran when it comes to sales volumes.

Cue America’s lawmakers. “We write to highlight the threat of HarmonyOS and the imperative of multilateral collaboration and diplomacy to prevent HarmonyOS’s proliferation,” the House Select Committee on the Chinese Communist Party warned the U.S. Secretaries of Defense and Commerce and the Chairman of the FCC.

The politicians warned that Huawei’s HarmonyOS is “an alternative to the current leading mobile operating systems developed by Google (Android) and Apple (iOS)” as well as Microsoft’s Windows. “Given the serious national security and geopolitical implications associated with foreign adversary operating systems, it is critical that HarmonyOS be thoroughly scrutinized and that we work with our allies and partners to prevent it from becoming embedded in devices across the world.”

The letter cites China’s National Intelligence Law, warning that “HarmonyOS could provide a direct channel for data collection, potential cyber exploitation, and digital authoritarianism.” Huawei’s OS is open source, but “future updates or patches to the system, could contain backdoors and vulnerabilities designed to facilitate espionage.”

Xiaomi is Android’s largest OEM bar Samsung, and alongside the BBK’s brands has sold hundreds of millions of phones outside China. Add Huawei into the mix and you have a readymade, third global mobile OS. All those phones could be upgraded with a new OS — which is what we have seen with Huawei’s install base.

ForbesHacking Disaster Warning—Delete All These Emails On Your PC

The Committee says the U.S. “should fully examine HarmonyOS’s architecture and codebase” and ensure “our allies and partners around the world are aware of Huawei’s, and thus the CCP’s, control over HarmonyOS, including its updates and patches.”

I have approached Huawei for any response, but such allegations have been dismissed by China’s closest mirror to Apple and Google in the past. While the security threat to Americans and others is open to debate, its competitive threat to Google and Android in particular is not. America still controls the world’s two mobile ecosystems, but if China takes a third route that will change, and there will be no going back.

“Unlike operating systems subject to U.S. regulatory jurisdiction, HarmonyOS is controlled by a sanctioned and red-flagged entity. Huawei is on the Commerce Department’s Entity List, the FCC’s Covered List, and the U.S. Department of Defense’s list of Chinese Military Companies,” the politicians point out. “Simply put, in the universe of bad actors, Huawei is as bad as it gets.”



Forbes

Leave a Reply

Your email address will not be published. Required fields are marked *