Hackers are stealing years of call records from hacked cell networks
techcrunch.com
techcrunch.com
1. Researcher says CDR contains all the raw data you send. False. It contains call detail records. Not your internet traffic. Not your Facebook calls. Not your icloud or WhatsApp messages.
2. The researchers here fail to share who was targeted and share almost no verifiable data to confirm what they found. Anyone could claim to have found a hack like they claim and get credit without providing any details to draw a big headline.
Seems like marketing not research.
Cybereason doesn't need the marketing. Everyone in infosec knows who they are and if they say they found this I'd say it's legit.
Remember, you don't own your call detail records, the telco does, its not legally your data and never has been. (in the United States anyhow)
The GDPR applies to any information about an identified or identifiable natural person.
So, in a word, yes.
However: Data ownership is a red herring. It doesn't matter who owns what data, what matters is if they have the legal authority to process that data.
I wonder if EE got hit I could see some interesting interviews with BT security happening :-)
They're bound by the GDPR no matter what... it's just that having a legal obligation to process data is a legal basis for processing (it'd be silly for it not to be).
If you're interested in why they process data, just ask your them. They have to tell you what legal basis they use to process your data.
Collected in a mobile network, there's usually a record for each event of a mobile phone. Authenticating to the network, attaching to the network. Doing a location update, sending/receiving an SMS, switching routing/tracking area, handover between cells and so on.
The carriers are not executing well on the concepts you describe, despite the feasibility of what you are proposing. Https everywhere is breaking things for the carriers. Tracking flows and reversing them for all customers is a non-trivial state management and storage problem.
Most TLS (TLS up to 1.2) will tell anybody who is watching that you visited foo.example.com including the SNI foo.example.com your browser sent to tell the server which name it was looking for and the certificate the server provided to prove it is really foo.example.com. But it will encrypt bar and baz and quux isn't sent over the wire it's just used internally by the browser and any Javascript.
That's the difference between "dotancohen looked at webMD" and "dotancohen looked at this article about sexually transmitted infections in men who have sex with men".
In TLS 1.3 the certificate is encrypted, a snooper can still see you asked for foo.example.com but not whether this server in fact presented a certificate for that name.
eSNI (currently under active development as an addition to TLS 1.3) encrypts that part where your browser asks for foo.example.com, since your browser also did a DNS lookup for foo.example.com we need to encrypt that too for it is make any real difference which is being done under DPRIVE.
For entities that fall under the jurisdiction of the Federal Communications Commission (the “FCC”), “[e]ach carrier that offers or bills toll telephone service shall retain for a period of 18 months such records as are necessary to provide . . . billing information . . ..” (47 C.F.R. § 42.6).
https://morningconsult.com/2017/04/25/tech-groups-push-fcc-u...
You can meet those legal requirements while (a) deleting all records after 18 months have passed and (b) storing all 'archive' records (e.g. between 30 days and 18 months) on a separate system that's only used for these specific requirements and has all access (which should be rare and narrowly specific, unlike daily business) logged.
It's true that we can talk to friends and family with internet services.
But for businesses we use our phones. Personally I don't think I would affected if my call records were given to anyone or leaked.
But I can think of scenarios where it could be really damaging to someone.
Like imagine a celebrity was having cancer treatment they didn't want people to know. Their call.records get leaked to a tabloid who infer their calls to a clinic mean that they have cancer and run an article.
I can imagine that would be a painful experience.
The fact that this is legal is really troubling.
As an example, suppose a cell phone appears at the local supermarket/grocery store every weekday from 9 AM to 5 PM. If you conclude that phone is owned by an extremely avid supermarket shopper rather than a store manager, you're ignoring the persistence over time dimension.
If you claim that it's more likely a cashier rather than a store manager (because there are more cashiers than managers), you're on much firmer ground than if you claim it's more likely a shopper than a store manager just because there are wildly more shoppers than managers.
I do go in a few times a month around four or five times, but god only knows what google probably thinks.
You may be personally affected by your elected representatives or people in positions of power in industry being blackmailed into making certain decisions.
So you may not be directly "personally affected", but you can certainly be indirectly "personally affected".
Did you receive spam from your contacts or recently dialed numbers? Maybe it's something new..
'I have nothing to hide from the government' yeah what about the mafia, criminals and such that could/will access the data?
https://techcrunch.com/2018/06/25/nsa-att-intercept-surveill...
What do you mean passed on it? It's being covered broadly. TechCrunch is only one publisher carrying the story.
https://www.wsj.com/articles/global-telecom-carriers-attacke...
https://www.cnbc.com/2019/06/25/hackers-hit-telecommunicatio...
https://www.wired.com/story/chinese-hackers-carrier-metadata...