Security Risks of Chinese-Made Connected Devices in Western Markets
Growing Security Concerns Over Chinese Devices
Representational Image
New Delhi, Sep 17: A recent report highlights the increasing security threats posed by Chinese-manufactured connected devices, ranging from port cranes to buses, sold to Western nations if not properly assessed for risks.
The Center for European Policy Analysis (CEPA) report indicates that cranes from Chinese manufacturer ZPMC, used in American ports, are equipped with cellular modems that can circumvent firewalls, potentially gathering sensitive information and disrupting cargo operations.
Additionally, Yutong buses delivered to Oslo are reported to have connected battery and power management systems that could allow the manufacturer to disable the buses remotely, according to the findings.
"Chinese connected vehicles are embedded with cameras, microphones, and location sensors that collect data. Apps provided by Chinese companies, like Hikvision’s Hik-Connect, transmit phone and SIM card identifiers to servers in China," the report elaborates.
The publication advises EU allied nations to refrain from implementing counterproductive sovereignty measures and to strategize a collective response that mitigates risks associated with private purchases of Chinese consumer products.
Concerns were also raised regarding Chinese apps that send phone and SIM identifiers to Chinese servers, as well as connected vehicles and cameras that gather sensitive data, which could be used to expose critical infrastructure and military movements.
A seemingly innocuous purchase, such as a Chinese-made solar inverter by a family, could escalate into a significant threat if the manufacturer gains the ability to alter the functionality of numerous devices, thereby jeopardizing the power grid.
The International Energy Agency has cautioned about potential blackouts resulting from malicious software updates to inverters, with connected devices capable of causing disruptions across borders before grid operators can regain control, the report states.
The report calls for allies to implement a unified assessment framework known as Digital Strategic Exposure (DSE) to evaluate risks associated with devices, cloud services, subcontractors, and jurisdictions, aiming to minimize "dangerous digital leverage."
"With DSE, Europe would establish a legally sound basis for excluding Chinese products when risks are unmanageable, without unnecessarily excluding American technologies. Partners could align their reasoning without disclosing confidential information," it concludes.
