Security Risks of Chinese-Made Connected Devices in Western Markets

A new report from the Center for European Policy Analysis raises alarms about the security risks posed by Chinese-made connected devices sold in Western countries. It highlights vulnerabilities in port cranes and buses, emphasizing the need for a unified risk assessment methodology. The report warns that these devices could compromise sensitive data and infrastructure, urging allied nations to adopt a common framework to mitigate potential threats. With concerns over malicious software updates and unauthorized access, the findings call for careful scrutiny of Chinese technology in critical sectors. Discover the implications of these findings and the proposed strategies for safeguarding national security.
 | 
gyanhigyan

Growing Security Concerns Over Chinese Devices

Representational Image

New Delhi, Sep 17: A recent report highlights the increasing security threats posed by Chinese-manufactured connected devices, ranging from port cranes to buses, sold to Western nations if not properly assessed for risks.


The Center for European Policy Analysis (CEPA) report indicates that cranes from Chinese manufacturer ZPMC, used in American ports, are equipped with cellular modems that can circumvent firewalls, potentially gathering sensitive information and disrupting cargo operations.


Additionally, Yutong buses delivered to Oslo are reported to have connected battery and power management systems that could allow the manufacturer to disable the buses remotely, according to the findings.


"Chinese connected vehicles are embedded with cameras, microphones, and location sensors that collect data. Apps provided by Chinese companies, like Hikvision’s Hik-Connect, transmit phone and SIM card identifiers to servers in China," the report elaborates.


The publication advises EU allied nations to refrain from implementing counterproductive sovereignty measures and to strategize a collective response that mitigates risks associated with private purchases of Chinese consumer products.


Concerns were also raised regarding Chinese apps that send phone and SIM identifiers to Chinese servers, as well as connected vehicles and cameras that gather sensitive data, which could be used to expose critical infrastructure and military movements.


A seemingly innocuous purchase, such as a Chinese-made solar inverter by a family, could escalate into a significant threat if the manufacturer gains the ability to alter the functionality of numerous devices, thereby jeopardizing the power grid.


The International Energy Agency has cautioned about potential blackouts resulting from malicious software updates to inverters, with connected devices capable of causing disruptions across borders before grid operators can regain control, the report states.


The report calls for allies to implement a unified assessment framework known as Digital Strategic Exposure (DSE) to evaluate risks associated with devices, cloud services, subcontractors, and jurisdictions, aiming to minimize "dangerous digital leverage."


"With DSE, Europe would establish a legally sound basis for excluding Chinese products when risks are unmanageable, without unnecessarily excluding American technologies. Partners could align their reasoning without disclosing confidential information," it concludes.