The Federal Communications Commission (FCC) moved to close a potential loophole that could have allowed entities on the agency’s Covered List, like Huawei and ZTE, to provide domestic interstate telecom services.
Previously, Section 214 of the Communications Act provided automatic “blanket” authorizations to domestic carriers, meaning they didn’t need individual FCC review. Following a unilateral vote, FCC commissioners agreed to end such authorization, contending it could allow entities whose equipment is deemed an unacceptable risk to U.S. national security to theoretically slip through that process without scrutiny.
FCC Chairman Brendan Carr said the move was about stopping an “end run” around the agency’s Covered List rules.
“From 2019 to 2023, the FCC denied or revoked the international telecommunications authority of five separate entities – all controlled by foreign adversaries – and added these services to the Covered List. These actions followed findings that their services posed unacceptable national security risks," Carr noted. “Nonetheless, many of these entities, and others identified on the FCC’s Covered List, continue to operate or potentially operate in the U.S. by providing services that do not fall under the legal definition of international telecommunications authority.”
The FCC is also looking into stripping existing blanket authorizations from Covered List entities and looking to bar carriers from interconnecting with Covered List entities without FCC approval.
“The nature and scope of physical and cybersecurity threats facing our communications networks today exceed those of any recent era,” Commissioner Olivia Trusty said in a statement. “In response to these growing hostilities, it is imperative that we re-examine policies that permit access to U.S. networks to ensure that frameworks originally designed to promote economic growth are not exploited in ways that jeopardize our national and economic security.”
CES trade body warns router ban could leave devices unpatched and vulnerable
Both Huawei and ZTE, along with Hytera Communications, Hangzhou Hikvision Digital Technology, and Dahua Technology, have been subject to U.S. sanctions since 2019. The FCC then introduced rules in 2022 barring domestic telecom operators from acquiring and using networking and other equipment from China-based vendors deemed to pose a security threat to the nation’s communications network.
In the wake of growing cyberattacks, including the infamous Salt Typhoon incidents, the FCC has doubled down on what it perceives as potential threats to network and national security.
The apex of its efforts is a sweeping ban on imports of foreign-produced routers, with devices containing components produced outside the U.S. unable to be brought into the country over national security fears.
The agency recently expanded the order to cover consumer-grade LTE/5G customer premises equipment (CPE) devices, which use a cellular signal instead of traditional wired broadband to connect to the internet, and Wi-Fi hot spot devices.
But a leading trade association has called out the ban over its implementation practicalities.
The Consumer Technology Association (CTA), which organizes the annual CES event in Las Vegas, said in a regulatory filing that the scope ambiguity is causing industry headaches, with it asking the FCC to clarify exactly which products are caught by the ban.
It also wants the agency to extend the waiver that lets manufacturers push security patches to already-authorized devices beyond the current one-year limit. The group argues that failure to do so would mean a wave of unsupported routers would be sitting in homes with no fix pathway – an ironic potential risk stemming from a banning order whose goal is to prevent vulnerabilities being exploited.
The CTA is also pushing the FCC to allow routine component substitutions, such as swapping out a chip that has gone end-of-life, without triggering full re-authorization, provided the device's overall security posture remains unchanged. Vendors face the prospect of having to routinely apply for status as a trusted consumer router company, with Netgear among the early birds to have been granted this conditional status.
“CTA supports the administration’s goal to protect U.S. networks from equipment and services deemed to pose an unacceptable threat to national security,” the filing reads. “We suggest ways to achieve the administration’s goals while addressing the concerns of industry to continue to bring secure devices to the American public.”
CTA joins a growing chorus of critics of the FCC move, with the Global Electronics Association (GEA) trade group having previously warned that “virtually no consumer router is manufactured entirely within the U.S.”
“The scale of the affected market, more than 100 million devices in active use, tens-of-millions of units imported annually, and a replacement cycle that touches virtually every home and small business, makes implementation far more consequential than the drone precedent that preceded it," GEA stated in a report.
Comments