Wednesday, March 23, 2022


Congress Needs to Fix Major Funding Shortfall in Rip & Replace Program

By Michael O’Rielly

For years now, Congress has been appropriately focused on the national security concerns of our nation’s communications networks and those nation states or groups seeking to do harm to the American government and its people.  From banning specific companies from serving the U.S. market, ensuring the functionality of “Team Telecom”, funding removal and replacement of network equipment, and numerous other measures, Congress has sought to minimize key weaknesses and vulnerabilities in these networks.  Unfortunately, changes required of the private sector as a result of these measures are proving more expensive than originally anticipated.  In particular, applications for reimbursement under the so-called “Rip & Replace” program are now expected to total over $5.6 billion, when only $1.895 billion in Federal funding has been provided for this purpose.  Congress can and should promptly fix this, as the failure to do so would undermine a central national security effort and inappropriately leave communications companies holding the bag for these costs. 

Meeting Congressional Commitments

The principles established by Congress in the Secure and Trusted Communications Networks Act of 2019 are sound.  The applicable House Committee Report notes that “Given the pivotal role that private communications networks serve in connecting U.S. critical infrastructure functions, American networks are appealing targets for foreign adversaries.  The United States, therefore, has a clear interest in mitigating threats posed by vulnerable communications equipment and services.”[i]  A combination of this law and Federal Communications Commission actions effectively does this by requiring a broad swath of certain communications providers’ equipment (and services) capable of being abused to the detriment of U.S. national security, particularly that supplied by Huawei and ZTE, be identified and subsequently removed with cost reimbursements paid for by the government.  Specifically, Section 4 of the law, as amended, establishes a thoughtful mechanism for smaller providers (those with 10 million or fewer customers) and other key entities (e.g., non-commercial educational institutions, health care providers, and libraries) to remove, replace, and dispose of “communications equipment or service that poses an unacceptable risk to the national security of the United States or the security and safety of United States persons”.  In essence, these providers are obligated to remove untrustworthy equipment and be reimbursed for such costs, while minimizing opportunities for waste, fraud, and abuse.

Indeed, the necessity for the reimbursement program is especially strong.  Congress targeted resources to smaller broadband providers that unwittingly purchased cheaper equipment (i.e., Chinese origin), which had the unintended consequence of helping to strengthen the Chinese Government, improve its world influence, and expose U.S. networks for potential manipulation and abuse.  As House Energy and Commerce Subcommittee Chairman Michael Doyle stated on the House floor, smaller providers – unlike their larger brethren – “didn’t get the same heads-up by our government”[ii] of the risks generated by such equipment.  Thus, these entities purchased the troubling equipment without warning and now find themselves in the unenviable position of being told to remove it.  Similarly, Ranking Member Bob Latta stated, “This bill takes into account important concerns we have heard from small, rural providers that were previously unaware of possible security risks when selecting vendors and making purchasing.”[iii]  In other words, the U.S. government did not share, either intentionally or by negligence, vital information on potential threat exposures with smaller providers and now seeks their compliance for the equipment   removal effort.  

To put this in context, Congress and the FCC created the mandates that identified equipment used by certain communications providers be removed.  Applicable communications providers are in little position to ignore this requirement and it should not be seen as voluntary.  As such, the relevant issue, which was already answered once by the FCC and ostensibly by Congress, is whether cost to smaller providers for conducting this work and replacement equipment should be done without sufficient reimbursement.  In fact, when considering funding for the Rip & Replace program on the Senate Floor, Senate Commerce Committee Chairman Roger Wicker said, “Let me also make the point that some things are worth paying for, and protecting Americans, protecting our electronic system, our broadband communications from the Chinese-owned Huawei and ZTE is worth paying for.”[iv]

Any lack of additional funding above the $1.9 billion effectively creates a massive unfunded mandate of approximately $3.7 billion, as existing funding will be prorated to recipients.  Even though the statute prioritizes funding for very small providers (i.e., those with 2 million or fewer customers), this will not resolve the needs of these providers, necessitating prorated reimbursements at significantly reduced rates.  That’s means, smaller providers would be faced with untenable options, including the possibility of going out of business.  The result could be even further reduced broadband service in rural areas.  In the meantime, these companies are facing extreme uncertainty.

It’s important to note that there is history of Congress increasing initial funding levels after a statute has been passed when it was deemed necessary.  Consider the added funding Congress made available under the digital set top box program as part of the analog television conversion process.  In that instance, Congress created a two-step funding stream based on consumer demand for the program.  However, even with this structure, anticipated demand exceeded funding resources  and Congress stepped in to allocate an extra $650 million the program.  Likewise, Congress added additional funding as part of the successful Broadcast Incentive Auction.  Specifically, the initial costs for the repacking of broadcast stations exceeded the Congressional allotment of $1.75 billion.  With more programmatic experience, Congress added an additional $1 billion for the vital reimbursement purposes.  In the end, these added funds were essential to accomplishing the Congressional directives contained in the respective statutory provisions. 

National Security Needs

The risk of not fully funding the replacement costs for untrustworthy equipment is significant.  As House Energy and Commerce Committee Chairman Frank Pallone stated in the requisite House legislative hearing, which helped lead to the statutory provisions, “Communications networks are interconnected and that means that one weak link can harm the whole system.  We must help smaller carriers remove suspect equipment for the good of the entire country.”[v]  Yet, without sufficient reimbursement funds available, there is a high likelihood that smaller carriers will be simply unable to remove the troubling equipment in any scheduled timeline.  Many of these carriers cannot cease operations for a time period to install necessary equipment or conduct the necessary transfer to new equipment while still remaining financially viable.  Absent such equipment replacement, the U.S. would consist of a patchwork of upgraded and replaced networks on one hand and those that aren’t able to do so on the other hand.  Given the interconnected nature of wired and wireless broadband networks, any system that maintains suspect or untrustworthy equipment makes all networked systems more vulnerable to abuse or potential attack.   

To clarify the gravity of this situation, Section 2 of the statute explicitly identifies two threats by not replacing the requisite equipment.  First, such network equipment potentially could be used to route or redirect “user data traffic or permitting visibility into any user data or packets that such equipment or service transmits or otherwise handles.”  This indicates that this suspect equipment is capable of being manipulated for purposes of disrupting user communications or to gain access for some monitoring or perhaps nefarious purpose.  The consequences of these scenarios are potentially cataclysmic.  For example, disrupting communications could lead to a partial or total shutdown of critical user information, especially during emergencies.  Those that have experienced communications blackouts know how damaging this can be.  Moreover, allowing a foreign actor to collect and examine user communications could facilitate the building of extensive dossiers on all Americans or obtain the sensitive communications of our elected leaders.  Second, the statute identifies the possibility that the untrustworthy equipment could be disrupted remotely.  That implies that foreign adversaries could have the means and opportunity from afar and without detection to use weak entry points in the network via this equipment to gain complete control over any connected network.  The harms that could come from such an occurrence are immeasurable.

Timing Important for Broadband Access

Complicating the reimbursement program’s funding issue is the desire from the legislative and executive branches of the Federal government, as well as state and local officials, to see all Americans have access to broadband.  As opposed to those Americans with cost or adoption issues, those without broadband access are disproportionately likely to live in less dense or rural areas of the country.  These places tend to be where smaller broadband companies operate and thrive.  Furthermore, the smaller providers facing the major Rip & Replace program challenges are likely to be some of the same ones that can bring broadband to unserved Americans. 

The problematic Rip & Replace program funding is likely to keep some smaller broadband providers on the sidelines as it comes to expanding out their networks to neighboring areas or expanding to new markets.  Such uncertainty may feed into the rates paid for matching capital, when needed, or the willingness of states and other officials to select these providers as winning grantees for new broadband access money.  Additionally, it means that applications for broadband network access builds will be more expensive and generate fewer submissions.  If policy leaders want to ensure that every American has access to broadband it needs to make sure that those providers likely to bring solutions forward are not financially hamstrung by an underfunded reimbursement program. 

*             *             *

The Rip & Replace program has a sound justification – help protect U.S. national security – and a solid structure.  But it lacks the necessary funds to make it effective.  That is something Congress can rectify, and I hope it does soon.   Absent doing so, we will be left with an under-protected communications network system that leaves Americans more vulnerable to harm and also threatens the viability of rural communications network providers. 

Tuesday, November 30, 2021


U.S. National Security and Trusted Global Manufacturers: Part 1

by Michael O'Rielly

One of the undeniable priorities of the federal government is to preserve the security of the nation – and as a result, the safety and security of the American people – against those who seek to do us harm.  At the same time, national security-based prohibitions and restrictions should not be used like a fishing net to capture unrelated matters or entities.  Their application must be narrowly tailored to only those relevant threats or risks.  Simply put, over-inclusiveness under the guise of national security stifles or stops dead legitimate and positive activities and commerce.  Yet recent telecom debates and the accompanying rhetoric have suggested that some people believe foreign equipment manufacturers are monolithic and all of equal risk to U.S. national security and its companion concern: supply chain breakdowns.  This kind of imprecision can negatively and unfairly impact the market.  Policymakers should carefully differentiate, in their words and when drafting legislative text, between foreign equipment manufacturers that are a real risk to national security and those global manufacturers that are not.  

To unpack the current provider market for telecom equipment, it’s worth understanding some of the past.  Until the mid-1990s, the U.S. had several fairly strong equipment manufacturers headquartered domestically and operating globally.  They supplied much of the old needs of the world’s telecom providers.  Because of a number of factors, including the development of new Internet equipment providers, poor management and decisions, implosion of the long-distance sector, and an overall bursting of the telecom industry stock bubble, U.S. manufacturers faced enormous pressures.  Equipment providers went through a very long and painful rebranding and industry consolidation, leading to some leaving the business and to foreign companies merging with and some ultimately purchasing U.S. providers.  As a result, much of the U.S. market, certainly the wireless sector, is serviced primarily by global telecom equipment providers that are, in fact, headquartered overseas. 

Deriding global equipment providers for being “foreign,” however, does a real injustice to their underlying U.S. roots.  In reality, three of the larger companies – Ericsson, Nokia, and Samsung – are headquartered in U.S.-allied countries.  They partner with U.S. law enforcement and intelligence agencies, as well as global intelligence agencies, as necessary and appropriate.  Moreover, these companies are de facto American, given their massive investments in facilities, workers, and responsibilities in this country.  Research and development is done here; their customer deployments are managed, led, and executed here; and their procedures and operations comply with all U.S. law.  At least one manufactures 5G equipment here.  They should be viewed not as foreign affiliates, but U.S. companies that also have affiliates throughout the world.  Given the unique histories of each of these companies, it’s irrational to think or expect that they would relocate their headquarters to the U.S.  Nonetheless, this is not a reason to treat them as anything other than trusted partners in the fight against risks to U.S. national security. 

The situation involving these trusted equipment providers differs substantially from at least two others.  The first are foreign-based equipment providers that originate or reside in adversarial countries known to directly generate national security risks, or that have obligations because of their headquarters within those foreign governments or regimes.  Because of these relationships, the practices of their host countries, and other considerations, equipment firms from Russia and China have appropriately received additional scrutiny and remediation efforts.  Treating these companies in adversarial countries differently, as U.S. lawmakers have done in recent times, can make sense under the right conditions.

Chinese companies, in particular, can raise certain political and economic tensions, given the Chinese government’s historic involvement in commerce and the operational requirements it imposes.  Added to this is extensive mistrust internationally from decades of sensitive and critical intellectual property and business secret-stealing by Chinese organizations.  Furthermore, financial arrangements and lending practices of the Chinese government, combined with the involvement of Communist Party officials in companies’ activities, produce additional national security concerns. 

The second category worthy of greater review are those equipment providers headquartered in the U.S. that effectively conduct all their work offshore or by foreign operators.  Having a shell of a company in the U.S. claiming to be a domestic provider should cause heightened attention.  At a very minimum, these companies should not be placed on a pedestal.  Yet, these types of companies have been lining up efforts to both receive favorable treatment as “U.S. firms” and impose penalties or competitive disadvantages on trusted global equipment providers.  That twists logic on its head. 

This circumstance is exactly why headquarters location is such a poor measurement of how “domesticated” or “U.S. nationalized” a company supposedly is.  The selection of a location for company headquarters is done for many reasons, like owners’ nationality or tax and legal purposes, and is difficult to determine based on this how exactly ingrained the company may be in U.S. soil or society.  It is also always subjective, as someone must make a judgment call about whether certain functions or services should count as domestic or foreign, and then determine if those rise above some arbitrary level.  In the end, it is a useless exercise, because domestication does not necessarily equal trusted partners and overseas producers don’t necessarily equal greater risk to U.S. national security.  

Instead, whether a firm can be trusted to protect U.S. national security should be the proper determination.  Is the equipment it builds, installs, manages, or sells trustworthy?  In other words, is its equipment properly secure from being used for nefarious or harmful purposes?  Does it alert proper authorities if or when a secure chain is compromised?  Does it provide equipment and service to the U.S. government for sensitive functions?  These are just some of the questions that are relevant when discussing trust, and they get to the heart of whether national security concerns may be raised by an equipment provider or servicer. 

While imprecision may be plaguing recent debates, official congressional actions through the legislative process have actually proven to be thoughtfully constructed and consistent with my points here.  Consider the Secure and Trusted Communications Act of 2019 (P.L. 116-124).  Section 2 requires the FCC to produce a public list, which it has done since, of covered communications equipment or services that “poses an unacceptable risk to the national security of the United States or the security and safety of United States persons.”  In section 8, the law requires the National Telecommunications and Information Administration (NTIA) within the U.S. Department of Commerce to “engage with trusted providers of advanced communications service and trusted suppliers of communications equipment or services.” It specifically defines “trusted” to only be those providers or suppliers, “not owned by, controlled by, or subject to the influence of a foreign adversary.”  This is certainly one direction for addressing national security that avoids a proximity examination of a company’s headquarters to U.S. homeland.  

That law differs substantially from other, misguided legislative efforts.  For example, a Senate amendment filed to the U.S. Innovation and Competition Act (formerly the Endless Frontier Act) would have created a new grant program to promote Open Radio Access Networks, or Open RAN, but limited funding to only companies that are U.S.-headquartered.  Thankfully, the amendment was not offered or approved, partly because it would have raised numerous violations of U.S. obligations to the World Trade Organization, and partly because it is lousy policy.  Likewise, the House is not immune from such wrongheaded efforts.  Report language was added to the House Armed Services Committee’s FY2022 National Defense Authorization Act favoring Open RAN and seeking reports from the U.S. Department of Defense on its efforts “supporting the development of a domestic industrial base for 5G.”  This is a blatant attempt to favor U.S.-headquartered companies at the expense of trusted global telecom equipment providers. 

In the end, the foreign headquarters location debate, and considering ways to inappropriately treat global equipment and service providers, are detrimental to national security by impeding such trusted companies.  These efforts ignore the real threats and seek to promote U.S.-headquartered companies, which typically are mere shells for work done overseas.  That means policymakers must stop drafting and advocating for imprecise or intentionally slanted efforts that focus on the wrong targets.  Congress has proven that it can and should center attention and added scrutiny on non-trusted providers, and the rhetoric leading up to any final law should match this approach. 

*             *             *

The opinions expressed in this document are those of the author and are not intended to be a submission to the Federal Communications Commission (or any other government agency or proceeding) with the intent to influence agency employees in the performance of their official duties in any current or future Commission matter.

Monday, November 29, 2021

Introduction and Welcome

Today, I start a new offering in my private sector consulting and advocacy venture, MPORielly Consulting Inc., with the creation of this new blog feature: TMT and Me.  

I hope this outlet provides monthly value for those seeking real discussions on tech and telecom policy matters that have been my career’s work.  Call it weedy, meaty, or borderline boring, I intend to avoid some of the superficial conversations and dig deeper than most on what’s already in play and what should be happening.  Those who worked with me in the past will remember that even my one-pagers were packed with substance.  Certainly, there will be some easier reads, maybe along the lines of old Dear Colleagues from the Hill days, but the main direction will be thought pieces of various lengths. 

Through a nearly thirty-year professional career, I have been part of almost every policy debate involving telecommunications or technology issues.  The early House committee days became the Senate years and leadership positions.  Eventually I found myself as FCC Commissioner.  The path was unexpected but provided a catbird seat to lessons on how best to analyze issues and maneuver Washington D.C.  Along the way, I melded my conservative principles with a desire to get things done. 

For those interested, the blog shares its name with the title I heard from so many industry analysts over decades.  TMT -- Technology/Media/Telecommunications -- served as the heart of my government portfolio through so many jobs.  It remains a part of me as I extend my FCC blogging experience to this additive role.  Of course, I’ll still be active on other formats (e.g., op-eds, panels, speaking, advising, and etc.) so there will be multiple chances to see my views.   

I wrote an extensive blog collection while at the FCC and found the medium incredibly useful.  Yet, some question whether blogs have become passé has-beens replaced by Instagram or TikTok moments or do they remain old-school enriched content delivery mechanisms for a sugared-up world?  I guess we’ll find out.  It certainly provides a limitless platform to express my thoughts on the current debates in the telecom and tech ecosystems.  And I’ve got a lot to say.

If you’ve made it this far, I thank you and welcome your productive suggestions as I plug along on this adventure (and please keep any trolling or negativity for your local bartender). 

 All my best,




 

P.S. -- The opinions expressed in any blog, as well as any other work, are those of the author and are not intended to be a submission to the Federal Communications Commission with the intent to influence agency employees in the performance of their official duties in any current or future Commission matter.

  MOVING 2.7 GHZ TO THE FRONT OF THE PIPELINE Anyone who has worked in the wireless policy arena knows that one of the toughest challenges...