5G: The outsourced elephant in the room
berthub.eu
berthub.eu
Even now, you likely have 3, 4 or 5 national mobile operators in any one country. They negotiate their own roaming agreements in order for you to get roaming access. It's all driven by these kinds of relationships predicated on trusting other networks.
In IT, we are rapidly moving towards zero trust (due to the internet), but circuit switched (legacy) voice is still all designed to be sent over private circuits between operators who trust each other.
The legacy protocols (see SS7), used to route calls between operators are functional, but also lack access control and authentication, as it's assumed only trusted parties are on the network and able to use them. Those assumptions are no longer valid, and there's a huge challenge in dealing with this - hence SMS and call interception and rerouting attacks to steal 2FA tokens etc.
I guess all of the big telcos have some homegrown ossified hacky "solution" that also serve as a minimal kind of "firewall" for SS7. (Basically I imagine that there's a lot of hardcoded rules for phone numbers, country codes and operators. Sure, they probably are an opposite of a problem for national intelligence services, after all it's easier to go by unnoticed in the noise, but they at least help with a total BGP-like hijack of a whole country code by an operator.)
There are product-based SS7 protocol firewalls available that try to detect the "patterns" of signalling used to do "bad things", and block and report them.
Part of the problem with SS7 is that it's complex, and you can't easily restrict who says what - if you port your number from Operator A to Operator B, your number prefix still sits in A's range, and calls are signalled to Operator A. They can then tell you to try Operator B. B may then need to tell you the user is roaming and how to reach them. But yes, current firewlls leave a lot to be desired!
There's a number of good talks from CCC about SS7 - one is https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271...
As you say, this is the legacy system, but it's still a huge problem for them!
Hopefully with the (slow) move to 4G and IMS calling, we can turn the page on SS7 attacks soon.
Not in all networks as far as I'm aware. UK is an annoying example of not having a central database of ported numbers (with ACQ), where a redirect is setup in the old network. I once ported my number in the UK and had huge issues receiving international calls or 2FA codes, it took me ages to work out and only got it sorted by leaving the number entirely and getting a new one.
Otherwise, like here in Germany, it's done with a proper database and the call never passes through the old network.
Yes, because it's a centralized meta-control plane of/for BGP. But no, because after all IP address space is already centrally managed anyway: IANA -> RIRs (-> LIRs), but not really, because each AS decides what to do with RPKI data.
So it's much better than parsing RIPE plain text query reults, and it's the correct fix for hijackings.
"Real-world censorship resistance" is not in the threat model for the current Internet at the RPKI/BGP/RIR level, but it's very much in scope for high-level protocols like DNS, TLS, HTTP (as privacy concerns).
See https://tools.ietf.org/html/rfc4593 and https://tools.ietf.org/html/rfc7132 Regular ("in-band") DoS or tampering attacks on RPKI databases and CAs (certificate authorities) are of course taken into consideration - even by nation states. Though these particular RFCs don't offer a particularly systematic and ironclad solution. (The problem is punted to users: "just use (stale data and) caches, decide for yourself what to do if the central DB is unavailable".) Likely there's some other RFCs that offer better answers with - hopefully - more operational detail.
Building a truly global efficient/high-bandwidth/low-cost "infinitely" censorship resistant Internet is (very) hard. Currently traffic passes through various networks, those "autonomous systems" have the capability to direct (and filter, eg. null route) traffic. Source routing in theory might help with working-around bad AS-es, but even detecting such AS-es seems hard theoretically. And on top of all that there's the economic aspect. (How would the network/users/operators incentivize each other to work around bad ASes?)
Hence IPsec and site to site/road warrior VPN - the underlying connectivity is regarded as untrusted by any sane user.
In telecoms, anyone on the SS7 network can make a request to find a given number, or say the number is available and can be reached by routing via their network.
That's only a small piece of the puzzle in network security generally, but is sure better than how SS7 works right now.
[1] https://news.ycombinator.com/item?id=26469738
[2] https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
[3] https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...
Edit...added [3] above. Apparently, it's a $16 service, not $15: https://sakari.io/pricing/
And if you have access to SS7, you can do it without the middle-man $15 service!
These systems are really designed for use in a world where only trusted actors have any access to the system! That's clearly not true with all these third parties exposing functionality to the general public!
[1] https://www.ptsecurity.com/upload/ptcom/PT-SS7-AD-Data-Sheet...
This doesn't really seem to make things any worse. Surely it's easier to have $15 than it is to have access to SS7.
- Major players are using phone numbers to de-dup people. Use your million phone numbers to bypass such verifications and aggregate more power than intended. You could sell the accounts directly or monetize them individually (e.g., social media like farms, turning cloud free trials into dogecoin, ...).
- Way too many services believe that if you control a phone/email you must be the account holder. Banks, 401k managers, and other critical pieces of infrastructure are more than happy to harvest your phone number for "added security" and proceed to weaken the security on your account by allowing anyone with control of that phone number to hijack the account.
- Unique phone numbers are valuable in their own right. Individual numbers have max message rates and other garbage, but with an army of phone numbers you can, e.g., send out the same scam message to most phone numbers, see who bites, and use that to build a curated list of a hopefully much smaller set of numbers to target with real people.
- If you have any extra information like a plausible contact graph you can use that to impersonate people for viral marketing or something (kind of like how the Marco Polo app texted your entire contact list without your permission). I'm pretty sure permissions are way more locked down than they were when apps used to just use your phone directly, but if you control the phone number and have that contact info then you could pull off a similar marketing trick still today.
- Just snooping on the information is probably valuable. I'm struggling to imagine how you'd monetize it directly (some kind of insider trading?), but 1M person-hours worth of intercepted texts can't be worth <=$0 I don't think.
This is a targeted attack.
> Individual numbers have max message rates and other garbage, but with an army of phone numbers you can, e.g., send out the same scam message to most phone numbers
As I read this, it involves sending messages from random numbers, not reading messages that get sent to random numbers?
> I'm struggling to imagine how you'd monetize it directly (some kind of insider trading?), but 1M person-hours worth of intercepted texts can't be worth <=$0 I don't think.
Data can easily be worthless if it takes effort to process and doesn't produce much value. This is a common case; "if the data exists, it must be valuable" is not a particularly strong argument.
Insider trading doesn't really work, since by hypothesis you have no idea who the people are whose messages you're reading. (If you know, then you're performing a targeted attack.) There's no "inside" as far as you're concerned.
Kind of. If you have a dump of email/phone combos lying around then it's just a dragnet operation against vulnerable institutions.
If you're pointing out that you said "random" phone numbers, I think it's worth mentioning that the techniques mentioned in this thread can let you target your favorite million numbers, but even just having a pool of a random numbers is still valuable -- for any account you want to compromise you have a 1/10k chance of controlling the number needed. That's an annoying cost but not prohibitive even for accounts only worth pennies on average.
> As I read this, it involves sending messages from random numbers, not reading messages that get sent to random numbers?
Send and receive (since you need to know which people would respond to obvious scams). As I say that though, I don't think there's much if any benefit over the other SMS spoofing scams which just use a link as the payload.
> "if the data exists, it must be valuable" is not a particularly strong argument.
True, but that wasn't _quite_ the implied argument. People mostly view phones as private, and in 1M person hours you're likely to capture admissions of crimes, cheating, and all kinds of things. If for no other reason than pure blackmail those should have value to an adversary; the question at hand is more about how much value exists and how hard it will be to find and exploit. Private comms are qualitatively different from, e.g., the twitter firehose.
> Insider trading doesn't really work, since by hypothesis you have no idea who the people are whose messages you're reading.
I don't think that's actually a requirement. If somebody confidently asserts they're personally doing [important thing] tomorrow (as opposed to you just sniffing a text saying they think doge is going up) then that can be a strong signal that [important thing] is going to happen. Since most texts probably aren't actionable on the stock market, you probably won't get many such signals, so you can probably afford to actually look up the owners for any matches you get to double-check your hunches.
I still don't think that'd be super easy to turn a feed of texts into insider trading (some ballpark math suggests you might not get much if any actionable intelligence in a reasonable period of time even if you could sift through it), hence my lack of confidence when I proposed it, but there aren't any fundamental barriers that would prevent texts from a pool of randomly selected numbers from being indicative of stock movements.
There's some good CCC talks on the subject if it's of interest.
Literally anyone with a printer and a pen can forge any signature and have a fairly high degree of success in the porting process.
The further you go into the architecture of the "trust based" PSTN, SS7, traditional Telco stuff... The more you will see the total lack of modern cryptography, PKIs, zero trust network modeling, etc.
I'll admit that my perspective is skewed by working in backbone IP network engineering for a mid sized ISP. We occasionally have reason to interact with some pstn related stuff. All of the real technical innovation, security advances and such have been taking place in the ISP world for the past 25 years, not the Telco world.
Too much of SS7 comes from a world where anyone can do anything - there's no legitimate reason in 2021 for an arbitrary network to be able to request a user's network location and cell ID, but the protocols support it. SS7 firewalls try to plug the gaps, but ultimately you just innovate in how you try to get the network to hand over what you want, and eventually you'll find a way the firewall doesn't spot. Cat and mouse continues.
Telco networks are "zero trust", just not in the right way(!)
Funny you say that as x509 was an ITU standard. But yes, PSTN is terribly broken, with mobile bolted on.
Why not refuse to peer with networks that peer/sell to bad actors? Before we had ML based email filters that kind of “hold upstreams responsible” strategy worked pretty well.
With third party access often "leased" via legitimate-ish providers though, it's hard to really do this without cutting countries or territories loose. Small countries often have operators that give SS7 access, to raise some extra revenue they can't get from their (small and population limited) subscriber-base.
Most voice installed for the last 10 years is already over IP. If it doesn't start in the CPE, then it starts at the curbside or lot where a DSLAM or equivalent generate dial tones, pack it onto IP packets and send it over a fiber connection.
Does that mean that all systems are compromised? No, because there are risks associated with tapping in to these systems. Partly it depends on if they have access to the systems, but mostly on the possible blow-back if they get caught.
Example: Swedens FRA (NSA equivalent) could in theory ask Ericsson (a Swedish company), to install a backdoor. But, Sweden has a fairly free press, and there are good chances that someone would leak this information. If it got leaked it would be a major scandal that could go as far as toppling the government and destroy one of Swedens most important export companies. Its very risky, and its a risk no one wants to take, so the parts made in sweden are probably not compromised.
China, on the other hand has almost no risks associated with adding backdoor. No free press, hard suppression of whistle blowers, and since most foreign intelligence services already assume the equipment is compromised, there is no real reputational damage either. I assume they are all compromised, why wouldn't they be?
The US is somewhere in between.
Sometimes companies are compromised by intelligence services, but much more often I think its employees. Why try to change Tim Cooks stance on privacy, when all you need to do is find one Apple employee, willing to take a sack of money to "do their country a great service"?
That's so wrong it hurts! All our press are dependent on government "presstöd" aka handouts.
The complaint was that a grant from the government makes the press less free to criticise the government.
If the grant is clearly and legally bound to be determined according to a set of objective and publicly available metrics I do not see that it would be such a big problem.
Of course a vindictive government could do what they can to negatively affect the press outlet in question but similarly could a supporting public affect them.
In any case it can all be accounted and prepared for as long as the process is objective and transparent.
If the country is a democratic one to begin with, the grants do more good by insulating the press from commercial powers than they do bad in this way, in my opinion.
https://rsf.org/en/our-supporters
They have the CIA vehicle for regime change as one of their sponsors, the amusingly named National Endowment for Democracy that specializes in overthrowing non-white democracies and regime change.
https://en.wikipedia.org/wiki/National_Endowment_for_Democra...
https://williamblum.org/chapters/rogue-state/trojan-horse-th...
They also don't mind white regime change, NED, along with NATO, the US DoS, and a couple of other rather relevant names, where openly sponsoring [0] "Yat's our man" [1], who ended up becoming PM of Ukraine after Euromaidan escalated into a full blown coup.
[0] https://web.archive.org/web/20200328203654/https://openukrai...
Which is why the intelligence services never do the hacking themselves. Instead, they buy the data off the "dark web", from the hackers whole stole and the information brokers who trade in it. If they have to do that, that is. In the US at least, agencies can just buy data on the open market. Supposedly "anonymized", but I'm pretty sure everyone reading this knows that protection is flimsy.
- Buy exploits on the market, with the US govt being the biggest buyer.
- Buy data off legitimate advertising and intelligence companies
- Hire people to find bugdoors
- Hire people to infiltrate all sorts of companies and extract information or plant bugdoors
- Convince or coerce companies to plant bugdoors in their own products
- Do the hacking themselves, plant hardware backdoors and so on
Unsurprisingly, they use all available methods.
Bart Gellman's book says that Snowden warned him not to be the only person in possession of the leaked data prior to publication, as the US intelligence community would kill him (Gellman) instantly to prevent the publication of the information contained therein.
This was the biggest takeaway from the book, for me: the US military will assassinate US citizens (journalists!) in the middle of New York City without due process or a trial to prevent them from carrying out journalism.
We expect this kind of cloak and dagger shit from the CIA, but it pays to think about it in clear terms: the US military can and will assassinate US citizens engaging in constitutionally protected activity in the middle of Manhattan with no consequences whatsoever.
https://en.wikipedia.org/wiki/Anwar_al-Awlaki
https://en.wikipedia.org/wiki/Abdulrahman_al-Awlaki
The potential murder of Gellman was stated by Snowden, who was trained by the CIA, and was stated on more than one occasion.
A US State Department document made available by the National Security Archive on 10 April 2010 reveals that a démarche protesting Pinochet's Operation Condor assassination program was proposed and sent on 23 August 1976 to US diplomatic missions in Uruguay, Argentina, and Chile to be delivered to their host governments but later rescinded on 16 September 1976 by Henry Kissinger, following concerns raised by US ambassadors assigned there of both personal safety and a likely diplomatic contretemps. Five days later, the Letelier assassination took place.[8]
Documents released in 2015 revealed a CIA report dated 28 April 1978, which showed that the agency by then had knowledge that Pinochet ordered the murders.[9] The report stated, "Contreras told a confidante he authorized the assassination of Letelier on orders from Pinochet."[9] A State Department document also referred to eight separate CIA reports from around the same date, each sourced to "extremely sensitive informants" who provided evidence of Pinochet's direct involvement in ordering the assassination and in directing the subsequent cover-up.[9]
During the tenure of Richard Downie at the William J. Perry Center for Hemispheric Defense Studies, a U.S. Southern Command educational institution located at the National Defense University, the alleged (and as yet unproven) role of Jaime Garcia Covarrubias, a Chilean professor who was head of counterintelligence for DINA in the 1970s, in the torture and murder of seven detainees was revealed inside the center. His alleged role was first brought to Downie's attention in early 2008 by Center Assistant Professor Martin Edwin Andersen, a senior staff member who earlier, as a senior advisor for policy planning at the Criminal Division of the U.S. Department of Justice, was the first national security whistleblower to receive the U.S. Office of Special Counsel's "Public Servant Award."[10] In an October 1987 investigative report in The Nation, Andersen broke the story of how, in a June 1976 meeting in the Hotel Carrera in Santiago, Kissinger gave the bloody military junta in neighboring Argentina the "green light" for their own dirty "war."[11]
It really diminishes your point when that is compared to an airstrike on foreign soil.
We don't say that the FSB attempting to execute Skripal in a UK shopping mall doesn't count because it was in the UK. Murder is murder.
The claim that the IC would assassinate Gellman in New York was made by someone who used to be an actual CIA operative and went through their training.
Not that he’s necessarily wrong, but it seems like a leap to go from Snowden saying something he believes, to a certainty that “the US military can and will assassinate US citizens in the middle of manhattan”.
After CIA training, he worked in Geneva under diplomatic cover, in 2007 to 2009.
It is much more realistic that what happened was a true "Burn after reading moment" https://www.youtube.com/watch?v=pabA320p9B0
He wrote about some of the things that happened in Geneva, I encourage you to read them. Even sysadmins for the CIA need to know some stuff about how the game works.
This feels like a strawman to cling to the idea that being a US citizen means that the CIA won't assassinate you for being inconvenient, which has been literally and directly claimed, at least twice, by someone from the actual CIA.
Indeed, the reason you even know the name Jason Bourne, or the reason those movies work, is because of the generation-long history and reputation of the US military intelligence services to break the law flagrantly in many countries with no meaningful consequences. We don't have to suspend disbelief to engage with the idea that there is a section of government with staff who can kill anyone they deem needs killing.
And for US, google Cloud Act.
Isn’t it common knowledge that the US and China is spying on everyone? The main difference is that China is not a military ally, and its government spying, which is unfettered, supports its private enterprise that is government financed and owned. US govt spying is unfettered. US corporate spying far more restricted because US businesses are bound by Federal and State laws, and it’s not centrally coordinated, instead US businesses are autonomous entities. And though US corporate spying on customers is rampant, it is also transparently written into usage contracts. US corporate spying is obviously for profit, and since the US and Europe are strategically tied through NATO, it’s not on the same threat level. China and its axis ally Russia, clearly bump up against the West because our political systems are fundamentally opposite, democratic vs autocratic.
What this translates to is Chinese investors are agressively running around buying into key strategic businesses, advised by data gathering in coordination with its government, with a view to maintaining control, which reflects how the country is managed itself.
American investors are running around buying/competing against business in coordination with data rich parent company entities, with a view to making money. But because it’s a democratic country where laws preserve autonomy even against the government, it’s a free for all and anyone can play, even Chinese owned American companies. Which is a reflection of how the US is managed itself.
This is also how Europe is managed, so I do believe Chinese control of telcos is a bigger threat to Europe’s way of life.
This is a speck of misapprehension that slipped in to your otherwise great writeup. Governments don't naturally conflict because they have different forms and they don't make automatic friends when they are similar. The US is presently allied with many autocracies. Middle-aged Europe was uniformly feudal, and constantly at war. Pre-WWII America was strictly isolationist and despite being a democracy had a fairly sized pro-Hitler element. Governments conflict when they have something to conflict over.
US leadership fundamentally doesn't care about human rights abuses in China more than Chinese leadership cares about abuses against black people in the US. They don't care about bringing democracy in a country when their next move is to make sure "the right" leader is appointed. They don't care about freedom of speech when they can block it as needed under any pretense. And they don't care about any of the principles they advocate if those principles get in their way, they will all happily ally with someone embodying the exact thing they're fighting against if it server their interest of maintaining or growing their power.
And getting to the point addressed above, they care about the image of the company they forced to introduce backdoors only as far as they can be punished by the bigger power, or if they can't sell it as fighting the terrorists (or scare word of the day). Case in point, Sweden and Ericsson wouldn't get away with it because their sphere of influence is a stone's throw away and the US would crucify them. China and Russia can mostly get away with it because their influence extends far enough that they have enough of a "friendly audience" for which they can sell a story. The US can get away with it everywhere else because even if Cisco is backdoored through and through, the US is the dominant superpower and is able to pressure allies to "see things" their way, and they can also sell everything as "the fight against ...".
Superpowers see advancing their interests by any means as a matter of survival and this takes precedence over anything else. They'll do what needs to be done and deal with the fallout after. And if you live long enough to move through these different regimes you start seeing the pattern immediately, only thing that changes is the "feel good" story the people are served with.
It's difficult to disentangle that from the unpopularity of war. Since democratic regimes are harder to get to do things, because you have to convince more than one person, the null hypothesis would be that autocratic regimes have a higher propensity for belligerence, especially in societies predating the invention of propaganda.
But in a totalitarian regime, consent of the governed did not matter much. Expressions of pacifism would land you in a concentration camp really quick.
Democracies care a little more about what the average Joe thinks, even though they are far from perfect in this regard and consent can be sorta-kinda manufactured.
Most democracies are in general against war for practical reasons, wars are a drain away from stuff at home that's important for them as people. US citizens may be "less likely" to want that but only because recent history has saturated them with the justification that the war is against regimes with "different values". It's an easy sell for people who are never to keen on going beyond that. So it would mostly be a matter of repackaging the justification. Some democracies can afford both the wars and the "moral repackaging" for their citizens.
But people also misunderstand democracy and what it means. The fact that the interests of the majority are respected might also mean that the minority is suffering a great deal. How well are black people's interests represented in the US?
One the other hand in democracy you are allowed to give a tiny endorsement to a person or party for a leadership position in the hope that they will represent your interest while others are buying "priority" over you for this representation with far more than a vote. You're not seeing this as less of a democracy so people are not judging political systems based on their actual implementation but rather by picking and choosing on particular values.
Russia is ostensibly a democracy, albeit one where the leadership is somewhat predetermined a very small minority. USA is a democracy albeit one where the leadership is somewhat representing the interests of a very small minority. I'm sure a war between these two is not seen as such a remote possibility in terms of people's preference.
Reasonably well it would seem from the outside. 11% of congress is "black", which is roughly in line with population and there seem to be hundreds of laws and programs aimed at helping them. And there's also lots of media attention to their problems and struggles.
People treated well don't need lots of media attention to remind those treating them well that black lives matter, in 2021. I'd say that for a democracy that's a pretty bad track record that isn't improving fast enough. Democratic majority decisions sometimes leave the minority far behind.
That picture turns to the opposite when looking at statistics of jail and prison inmates representation, or when looking at how the wealth in the country is racially divided and whole neighborhoods still racially and economically segregated.
In that context BLM is not really a new thing, it's just the most modern manifestation of a rather old and still very on-going issue [0].
[0] https://en.wikipedia.org/wiki/List_of_ethnic_riots#United_St...
A group can have plenty of political representation and institutional and legal support and still struggle for other reasons (e.g. historic oppression or cultural problems depending on whether you lean left or right).
Though on second thought there still are a few laws with racist intent on the books aren't there? Though they're being undone at a decent clip.
The US electoral system may have it’s flaws, but to compare it to Russia is absurd.
How many opposition leaders has the US government tried to murder recently?
The statement was clearly about the relationship each country has with democracy, comparing not to each other but to what democracy should be. There's value in evaluating things against what they should be, not against an arbitrarily worse thing. It's the only way to see the flaws and look to improve.
The reality is that countries you call "democracies" are allies of the United States, while countries you call "dictatorships" are enemies. If a democracy is to be an enemy, the first course of action is to first make it stop being a democracy. Then if it goes your way there's nothing to be worried about, and if the chaos installs someone you don't like then you're not fighting a democracy.
The Chinese government has popular support. So were many others the US invaded or overthrew - some were even democracies. It doesn't matter, as we saw with the Iraq war any inconvenient facts will not make it into the narratives and any lies will be disseminated as needed.
Because if you criticise the Chinese government you disappear for a few months at best. If you’re unlucky you’re never seen again.
> countries you call "democracies" are allies of the United States, while countries you call "dictatorships"
That’s an extraordinarily bold claim and I think you should have to back it up with some evidence. Which of the countries that are called dictatorships do you think are unjustly labeled as such?
Wasn't too long ago that being considered too far on the left in the US was a professional and social death sentence.
Was neither too long ago that anybody who opposed illegal wars of aggression, torture, and state-sponsored assassinations, was deemed a "treacherous terrorist supporter" who might as well have flown the planes into the towers themselves, the earlier versions of that involved sending armed soldiers to violently break up peaceful student protesters ala Kent State.
Heck, "race riots" are a regular thing in the US to this day, yet somehow not considered political, nor the countless black activists that were jailed, left to live in exile, or straight up assassinated in the US [0], somehow none of that is considered "political" [1].
Add in the reality how the US has not just the biggest prison population, but also the highest incarceration rate on the planet, and it comes across as a bit tone-deaf to constantly evoke how in the "evil not US countries" people are allegedly getting vanished in droves, but never ever in the US [2].
[0] https://digitalcommons.law.yale.edu/cgi/viewcontent.cgi?arti...
[1] https://www.theguardian.com/world/2018/may/11/rakem-balogun-...
[2] https://www.businessinsider.com/more-than-80-percent-of-the-...
Laughable considering cordial relationship between US and Vietnam. The latter political system is basically a clone of China.
The main difference is that US law is exported to the rest of the world's population and Chinese law is not.
If Julian Assange leaked Chinese intelligence/war-crime-evidence he would be at home raising his kids right now.
- no need for backdoors since Huawei, Ericsson & Nokia are full to the brim with bugdoors (Huawei tops the chart here since many years already and as anyone involved in Inter-Operability-Testing (IOT) at the NEV will confirm).
- no need for "compromising networks" when you have the actual vendor (Huawei, Nokia, Ericsson often their subcontractors) sitting totally legally in your ISP's network and being paid for responding to the alarms raised and escalated by O&M.
- even the attacks against 3/4/5G become academic in the discussion of nation state threat actors when they can operate and exploit simply as an insider of the system. These weaknesses (as outrageous as they are) are useful but it's a different threat model
If I was I was a intelligence agency in a country where there is a risk of blow-back, like in Europe or the US, I might prefer to use exploits. That way you haven't compromised your own country infrastructure (as much) and the risk of leaks is much lower since you dont have to work with an outside entity. A government agency forcing a domestic company to add backdoors, looks much worse if it gets out, then an agency using existing bugs.
If I'm a Intelligence agency in a country that doesn't care about blow-back like China or Russia, why bother finding and using an exploit, when you can call up the vendor and have them design the system with your use-case in mind? You dont have to worry about someone fixing the bug you have spent man years making exploitable, and you can make sure the backdoor can only be used by you. Its way more convenient and cost effective.
China is now suffering fron Huawei blowback in quite a few western countries.
I think Huawei, would have experienced almost the same blowback even if they didn't have any backdoor. Western intelligence experts, would have advised against using Huawei without any evidence of backdoors, simply because they know they would have put in backdoors if they where in the position of china, and they assume the Chinese aren't incompetent.
The blow back also serves a political purposes for everyone around. Western politicians/military gets to say "We need to protect ourselves against scary China!". And China's propaganda machine gets to say "Look at the terrible racist west treating us unfairly, by accusing us of bad things without evidence!".
[0] https://www.vpro.nl/argos/lees/onderwerpen/cryptoleaks/2020/...
[1] https://www.ceesjansen.nl/en/cryptography/
[2] https://www.tandfonline.com/doi/full/10.1080/02684527.2020.1...
“There is a root backdoor in the telnetd of Ericssons AXE backdoor”
https://www.schneier.com/blog/archives/2006/03/more_on_greek...
https://www.schneier.com/blog/archives/2020/04/another_story...
The article in Dutch on Philips Telecommuncations (which became Lucent later on):
https://www.volkskrant.nl/nieuws-achtergrond/nederland-luist...
https://www.schneier.com/blog/archives/2007/07/story_of_the_...
https://www.schneier.com/blog/archives/2006/02/phone_tapping...
https://theintercept.com/2015/09/28/death-athens-rogue-nsa-o...
https://www.theguardian.com/commentisfree/2015/sep/30/athens...
and all time favorite:
The "Back doors" in AXE are a slightly different thing. Many countries have laws that says that law enforcement have the right to wiretap phone calls under some circumstances. This means that telcos want and ask for this feature so that they can comply with the law. The telcos are aware of the systems capability because they need it to be there. Anyone who reads the law can see that the telcos has to facilitate wiretapping, but they obviously dont want to advertise it, so its an open secret.
Its quite different if you deliver a solution, with a hidden back door that the customer dont know about or have asked for, for the benefit of the intelligence service in the country of manufacturing. Enabling a nation to wiretap illegally in countries where they do not have jurisdiction.
How does Linus ability to go public make it more dangerous for intelligence services?
That implies intelligence services approaching him with such an offer would put themselves in danger of consequences just for asking, when that's evidently not true: There were no consequences for the NSA for asking Linus, there were no consequences for the NSA in the vast majority of cases it was caught doing something it shouldn't do.
It's also not true that in the "free society" is some binary thing: In the US National Security Letters are a very real thing, outfits affected by them are legally not allowed to publicize it. By any definition of this "free society keeps intelligence services in check" logic that should not be a thing, but it is, just like many other legal tools to suppress the free and open reporting about "national security" issues.
If this became known the subjects of interest would stop using those networks. Only the low level criminals would be dumb enough to get caught.
Any country that is serious about cyber security needs to develop and maintain its own communication network.
This is quite misleadingly written: telcos are not shipping reams of CDRs to some cubicle farm in Haifa or Chongqing.
Yes, almost every telco outsources its billing software to other companies, notably Amdocs (founded in Israel, now HQ's in the US). However, billing info is some of the most sensitive data a telco has for both privacy and commercial reasons, so that software always runs in a closed environment from where it cannot dial home. Historically that's been on-prem, it's slowly moving to the Cloud but even there it's going to be firewalled off very carefully.
While it's true that the installations are on-prem (having been to quite a few of those), Amdocs business model isn't about dropping code and going away: They are so embedded with your typical deployment that there's plenty of opportunity to exfiltrate data. Sending every CDR to Haifa? Probably not: The Sysadmins on your typical large telco are iffy, but not that iffy.
And carefully firewalled? The talent was never great, and the security practices were never all that serious: I've been handed production shells that I had no business having, because it was convenient at the time. Once again, I'd say that the best argument to claim that there's no data exfiltration is that the people writing the code aren't good enough to do this under the customer's nose.
Once a managed provider steps in, they want to "own" the configuration. You end up with the operator itself actually having to raise tickets with the MSP to change things on their own network.
All this becomes a huge issue if there's a major outage, as the MSP might not have enough access to actually get in and do anything.
Most telecoms networks are run (to some significant extent) by a managed service provider, in my experience. When O2 UK had a major core outage due to an Ericsson certificate expiry inside the core, it wasn't O2 engineers that found and fixed the issue; it was Ericsson engineers.
The margins as an operator don't make it easy to keep around the deep technical skills to be an expert in the network you own.
In Europe you'll likely see far lower per-user pricing due to competition. You'll typically have 3 or 4 operators with physical networks, and a number of virtual operators providing white labelled service over the underlying networks.
A standard target ARPU (average revenue per user) would probably be around 15 GBP per user per month. You'll likely get to that via contract users who you try to get on 22 GBP per month or thereabouts, and pay as you go users whose ARPU is far lower (maybe 8 or 10?)
Compared with the US, consumer prices paid are incredibly cheap - expect unlimited calls and SMS, and many gigabytes of data. If you shop around you'll get even cheaper still. In the UK you'd be able to get unlimited 4G or 5G data for 25 GBP per month.
Clearly the US has a much larger geography to cover, but there's definitely more competition leading to downward price pressure in Europe, in my view.
Once, I found out a contractor was so used to opening and closing tickets for themselves that they were actually gaming the system and using it as a way to correct payements for their services. Each payement went through at least two accounting services and yet it worked. Interesting discussions followed :-). They are still there.
[0]https://berthub.eu/articles/posts/how-tech-loses-out/
This article hits the nail on its head, and i can see it happening all around us, not only in the telcom/tech world. Boeing is a prime example for instance, but also the general death of manufacturing in the western world has resulted in this.
Europe in general has a fetish with subcontracting IT to the point where only the contractor’s can do it. Sometimes it’s the contractors’s contractor’s contractor who is the only one who can do anything.
in the short term this does not matter, because the company stays profitable, but long term this is resulting in a system in which no one has complete ownership and responsibility of their systems, which makes doing changes and innovating nearly impossible.
For instance, when I worked in US govt, best as I could tell all the real work was done by contractors and the govt employees sat around on their asses all day.
Headquartered in Switzerland, its German office was mainly just Product managers writing requirements. Most of them would do endless paper work and all technical work is outsourced to multiple contractors. One of the requirements of the Product managers was to handle all these contractors so that things run smoothly. Many of the product managers had PhD degrees or Masters doing this nonsense. Finally the wonder why the cost of their products are so high.
I have noticed that it is better in the United States where a lot of medical companies have a lot of in house technical experience.
(EDS won the northen countries, BTW, and I think things were marginally better with them, but either way, things soon reverted back to a more flexible arrangement because product development was severely hampered and most OpCos ended up rebuilding their IT systems)
The IBM guy is probably connecting to Vodaphone through some AT&T managed tunnel.
Regarding the articles statement of providers wanting an "all-in-one" solution, I have seen that in person, where management forced it, found it was horrible and then gave in and let us build the mixed vendor solution that worked well. I've personally mixed enode-b's from 2 different vendors to 3 different vendors SGW's and a different vendors PGW with no issues.
The "One Throat To Choke" idea doesn't work if your business depends on that throat to operate so you end up with the vendor calling the shots instead of the business.
On the whole, the technical standards should allow the kind of interoperability you described. That's the kind of fun real-world engineering that techies love. The bean-counters don't, because it's more devices needing support packages, it's more suppliers on the books, and ultimately it's probably (slightly) less profit than buying a single box.
I've seen big household name operators in Europe stop even pretending they're doing the work, and straight up pass on contact details and a mobile number for the person at their tier-1 vendor partner, so you can liaise directly with them.
It seems in these "5G" days even more than before, operators are retreating into the business of connectivity service, and leaving more and more for their vendor partners to do. When you're not even hiding the fact to a client that they may as well speak directly to the vendor, that says it all(!)
but it sounds soooooo good in meetings !
woah. as a EU citizen, i'm terrified. i wanted to say surprised, but after a moment's thought, turns out it's only a moderate misalignment of expectations.
Once I asked for a one day snapshot of all mobile data for a cooperative R&D project. The saga went on for months with repeated requests at various hierarchical levels, but to no avail.
It's not that they refused, but I guess that the guys in charge simply were unable to get the requested information from the subcontractors.
Of course I work for a subcontractor too.
>> In reality, most service providers have not been operating on this model for decades. Driven by balance-sheet mechanics and consultants, service providers have been highly incentivised to outsource anything that could possibly be outsourced, and then some.
>> In a modern telecommunications service provider, new equipment is deployed, configured, maintained and often financed by the vendor. Just to let that sink in, Huawei (and their close partners) already run and directly operate the mobile telecommunication infrastructure for over 100 million European subscribers.
I think it's quite a safe bet that no operator in China went that way by buying and outsourcing from/to Western companies.
How much time and people it will take to AT&T to do all the work on it sown ?
Market and customers require faster pace.
About as many people as are currently working on it, probably. The work does, in fact, get done by real live humans. That they work for a contractor only adds humans in the middle. Also the money to pay them is present; it just flows through a few extra contractor accounts first.
If it's not and you hire extra people in order to work on this deployment, than when job is done, you end up with extra few thousands of employees that have nothing to do and you need to fire them. In this case it's easier, faster and cheaper to outsource the work than doing hiring of thousands of people, training them and then firing them when job is done...
Are there enough carriers that the contractors stay busy 100% of the time or do they just hire and fire people as needed?
I get why contract gigs can be mutually beneficial but it seems like either the demand is there for full-time trained technicians to do a particular job, or there isn't. If there isn't, then it does it really matter who does the hiring/firing?
I think what I always figured was that most deployments are rolling and there will always be new tech to train on and then deploy every few years, which sounds fairly sustainable as a full time labor force. I haven't ran a telco before obviously.
Usually telecoms RFI pretty much entire project from third party vendors (or few of them, on order to reduce risks), with very long list of requirements covering everything from software integration to hardware deployment. Vendors will bring teams of their own engineers for "higher level jobs" and a whole bunch of "licenses" subcontractors to do actual track rolls. In case it's a complicated project, like upgrade to 5G, vendor most likely can't provide entire solution by itself, so it will be a "consortium" of vendors that stich up complete solution that is organized by vendor that answers RFI. In this case each vendor may have it's own subcontractors who may have their own subcontractors etc...
End of the day, it’s more to do with accounting stuff like fixed asset inventory, risk management and keeping salaries and benefits low. It’s easier to fire a contractor or hire a shittier/cheaper one than deal with a bunch of employees. IMO, saving hard dollars isn’t a driver.
This is an outraging but very widely spread phenomenon. No industry is spared from the MBA hawks. Everything now is rent-seeking and moat building. Innovation has been packaged away and can only happen when the market makers say it can.
What can an engineer do about that?
Lots!
- Name the companies in question
- Stop working for them, and start working for companies that favor engineering expertise
- As a consumer, advertise the good companies and call bullshit on the bad ones
- Raise awareness about these practices among your elected political representatives and their constituencies
If all of their skilled engineers leave, the bad company cannot run only on the basis of MBAs juggling balance sheets. Unfortunately most of my fellow engineers are far more likely to sit around blaming “the MBAs” over drinks than take any of the above actions.
The MBAs can just outsource the work.
Quote from the author: “Currently, the impact on real-world applications of this network slicing attack is only limited by the number of slices live in 5G networks globally. The risks, if this fundamental vulnerability in the design of 5G standards had gone undiscovered, are significant. Having brought this to the industry’s attention through the appropriate forums and processes, we are glad to be working with the operator and standards communities to highlight this issue and promote best practice going forward.”
PDF can be downloaded from here: https://info.adaptivemobile.com/5g-network-slicing-security
How trustworthy is this? There seems to be a lot of inside information, where did they get it from? Does anyone have corroborating links? All article links are either general, or US specific.
The sector is a pretty "closed shop" though, full of trade secrets and "proprietary" things. Underneath it all though, actually it's fairly simple once you get your head around it.
If you work closely with an operator, even as a client, you'll see examples of this - the number of people brought to meetings from the vendor, versus from the operator. Who answers the questions.
For a public example, see the Telefonica O2 outage in the UK (and Japan, I believe) due to an Ericsson certificate outage, and how much of a role Ericsson played in this. (https://www.theregister.com/2018/12/06/ericsson_o2_telefonic...)
Press releases also give bits and pieces away:
https://www.ericsson.com/en/press-releases/2019/11/orange-op...
https://www.mobileeurope.co.uk/press-wire/9588-three-uk-join...
Although they might not give the level of detail you're looking for, it should hopefully corroborate things.
I’ve pointed it out in previous discussion that China doesn’t need back doors to western 4G/5G infrastructure, because it’s their people operating it.
But as with much other technologi our politicians are ignorant and forgetful.
It’s much worse to have a potentially hostile foreign state running core infrastructure than potentially have them install a back door.
The whole industry is in a deepening downward spiral. Outsourcing and subcontracting is rampant, layoffs left, right and center. The combination of non-functional requirements that would make even senior FAANG fellows dizzy - left to be done by stressed out graying veterans or naive greenhorns, who leave the industry after 2-3 years for 50-100% raises elsewhere for the same skillset. Due to the monopsony power of the large operators, the vendors barely break even on their deliveries. There's no institutional knowledge buildup, nobody to take up the baton after the veterans retire, the vendors gave up pretending they care about being a nice place to work. If you're a techie, stay away from the telecom industry.
How trustworthy ? It depends. Operators in developing countries those day might completely outsource buildout and management of their network to Huawei because they frankly have best end to end portfolio I think.
With operators in rest of the world, especially those that are "well established" reality is more complicated. Telecom networks having a lot of moving parts and require a lot of domain specific knowledge or proficiency with hundreds or thousands types of hardware and multitude of heavily customized per telecom needs software systems. For some of those things work might indeed be outsourced but in many cases outsourced work performed by people who function as company employees in day to day: i.e. they work in telecom office building, have employee badges, pass background checks, etc. Essentially this type of outsourcing is deeply embedded within telecom itself for a most part
Not that that’s everything but I would tend to trust Bert. Certainly, based on his tracks record, I don’t think he’d deliberately mislead.
Personally, I left the industry in 2006 and it was already very close to what's described in this article. I was working for a tier-1 vendor, sitting in the carrier's offices coordinating field work, and saw every facet of these interactions. (Technically I wasn't even working for the vendor, I was working for a contracting firm that had temped me out to the vendor, so it's even more abstract.) Institutional knowledge was held by project managers on the vendor's side at least as much as by the carrier's own staff.
Talk to literally anyone in the industry. I'd be surprised if you can find a single one who says it's not as bad as this article suggests.
> The host service provider often has no detailed insight in what is going on, and would have a hard time figuring this out through their remaining staff. Rampant outsourcing has meant that most local expertise has also left the company, willingly or unwillingly.
100% reflects my experience working in Huawei BR a few years ago. Carriers are mostly customer facing companies and very limited technically.
Our customer (million + subscribers BR carrier) often hadn't the slightest idea how their own network was built and worked.
Banning Huawei is absolutely impossible, at least in Brazil.
If you think this is bad in some place like the UK, you should see how ISPs and mobile network operators are set up in some countries in the developing world, where the vendor has fully captured the Telco as basically a hostage to its technical services.
This is what happens when you have a mixture of institutional corruption, kickbacks and bribes, lack of local technical resources to develop a domestic network engineering talent pool, and a vendor that knows how weak the client entity's negotiating position is.
Network engineering talent is incredibly hard to come by in most regions of the world, especially if you consider that ISP networking deals with arcane technologies not really used in most "enterprise" networks. (BGP in various ways, MPLS is a big one, and arcane transports like SONET or DWDM solutions).
Sure, one might be able to learn how to configure BGP, how ip works etc from their laptop using GNS3 or a couple of second hand routers/switches, but learning how to design networks at scale is completely different beast.
Most people seem to enter the field by getting hired as tech support at a NOC and working their way up from there, which is kind of a grind compared to some more lucrative positions available to people who posses the technical talent.
I sometimes wonder what will happen if we have no one left to maintain the systems so many layers of software and systems depend upon.
Even to get some simple logs from a base station you need to either ask an Ericsson engineer or, worse, wait for the Telco employee with the relevant knowledge to find time to do it. Telco employees with such knowledge are very few compared to the amount of workload they have to do, so it is hard to get them to dedicate time to help you.
Now, in theory, it's pretty much possible to run operator based on leased lines (many operators actually run over leased lines anyway, in many countries and they don't own physical fiber networks due to regulations or other reasons), and interfaces with antennas/enodebs that are "virtualized" (to support multiple operators at once) or even using cloud-ran while deploying rest of software stack "in cloud".
the only light point in an otherwise depressing read
Tech sovereignty has become such a thing. And the bad news is that we have lost. I’ll leave others to debate why, but we can’t manufacture our own chips, we cant make our own telco networks, and the cloud systems that provide back end services are almost lost.
The state of play here is dire for the US and it’s strategic partners. I’d say that surveillance is less worrying than the simple fact that a potential future adversary has an off switch for these things that they can toggle at will: no more chips, no more telco products and no more cloud services - now, let’s have that South China Sea conversation one more time...
Before I "left" there was certainly a trend towards outsourcing and large "swaps" of radio gear (Nortel-Ericsson in my case, and Motorola-Huwawei at a direct competitor, to quote only two examples), but there was no way in $UNDERWORLD that we would let a vendor have direct access to our gear unsupervised (be it Cisco, Ericsson, whatever). Remote troubleshooting was possible, but usually via jump boxes and VNC (only very seldom we would let anyone VPN in, and even then it was only to sub-sections of the network). Nothing left our O&M network. Nothing came in, either, because upgrades were rolled out from internal servers.
And it is still very much the same thing today. Although there are outsourcers and vendors who work alongside core staff in my telco customers (like myself now), we don't have access to anything but lab or dev environments, and even then mostly with MFA and very stringent limitations.
Outsourced staff _does_ do field service of various kinds, and they do have access to base stations, DSLAMs and various other physical infrastructure, but that's usually done with (usually much cheaper) local technicians and not vendor staff. There are certifications for those.
The reality is that most telco services are being "automated out" and moved to virtualized stacks that are easier to manage. And yes, VoIP on the core (no more SS7 if anyone can help it) and Kubernetes everywhere...
But what I found to be really weird was the notion of outsourcing billing. Besides being a GDPR nightmare (and I'm in Europe, like the author, so I find it doubly unsettling), that was only done "off-prem" when all companies involved were in the same group (which was customary when fixed and mobile operators were separate). These days billing is, comparatively, greatly simplified (thanks to flat fees, real-time billing systems for prepaid and streamlined bundles), so the only data that actually leaves the BSS core goes to the (smaller and smaller) printing facilities.
So I would take it all with a massive dollop of salt.
Talking of phone network security one thing that does piss me off is my phone company just transferred my phone number of 10 years to fraudsters who presumably called customer support with some sob story. You'd think they could have some standards to stop that like at least sending an email to your usual address saying "There's been transfer request - you good?"
>Since the early 2000s at least, most billing has been outsourced. This works by sending all Call Detail Records (CDRs) to a third party, often from Israel or China. A CDR stores who called whom and for how long. More data might be attached, for example the location of the customer, or where the customer was roaming abroad etc.
Don't know about software from China, but the one that we sold doesn't send anything back to Israel. There are a lot of rules and restrictions upon CDRs and we had a bunch of training with regards to it. Everything is running on client site, usually on hardware deployed by us at their data centers and managed by dedicated team of people who relocate to live next to the client in order to provide 24/7 support of the systems on site
>Typical service providers have hundreds of thousands of network elements. Surprisingly perhaps, many of these are actually maintained manually (!). Thousands of networking engineers labour to keep all this infrastructure operating well.
This is a mix of half-truths and lies.
None of the operators have thousands of people to manually configure day-to-day network stuff. Operators have rather sophisticated automation systems (aka OSS) that deal with provision and configuration of everything in their networks. Or almost everything. Any given operator whose life span is a decade or two today has a boatload of equipment (thousands of different types of hardware from same amount of vendors). In many cases this equipment was bought and deployed 10 or 20+ years ago. Companies that made it do not exist for many years. This hardware can't be replaced with anything, because nobody does this type of systems anyway. Those systems tend to have proprietary interfaces and in many cases can be managed only through Element Manager which can be managed only manually through some ancient windows or java application.
>Meanwhile, modern large scale internet companies (like Google, Netflix, Facebook) have automated all such maintenance. Automation in this context means that no configuration states are edited manually but instead, entire networks get provisioned and configured from central templates.
>With such automation, small teams of engineers can control and operate vast networks with relative ease - especially if good use is made of continuous integration and real life testing.
I also worked for a while in one of FAANGS. They have it easy: all the hardware with modern with nice interfaces. You can actually automate it. Also their networks are much-much smaller compared to mid-sized telecom, much simpler and much more homogeneous. Automation that FAANG I worked for was a joke compared to automation systems that run telecom networks. My job was near network engineering team and during conversations they admitted that what they have is crap. I believe that at one point of time they considered to buy telecom level OSS system but bailed out because they couldn't get a source code .
Am I the only one noticing that the obvious solution is to stop using closed-source tools for such delicate infrastructure that’s meant to serve the general population?
I honestly can even grasp how we got into this mess in the first place: publicly funded software for public infrastructure that has such delicate security implications should obviously be open source only.
It’s not just telcos...
What are the current / purposed patent licensing terms of NR-U; finalised and related with 3GPP Rel 16 are going to be? Specific to standalone NR-U ( As in MultiFire in 4G. ) which could compete with WiFi 6e.
Which providers are using and which are not using Huawei?
But what if there is a remote kill switch - taking down a cellular network could cause a whole heap of problems in the 21st century.
Full disclosure: employee, soon investor
[edit: also, they are hiring]
Which will win?
?
Or, more likely, does the future hold a coming broadband internet connectivity price war?
?
And if so...
...who will be the "last IP address standing"?
?
I'm going to have to train my bot senses. I got conned. Any tips? Mindlessly reading me is not prepared...
If you read critically with a view of "what are they actually saying?", you tend to spot this fairly quickly. The ending with some irrelevant babble gave the game away a bit though.
It seems that these text generation bots are pretty good, as you say, at generating some basic level chatter about a topic in a manner that can sound convincing. Somewhat like a "talk-show style TV news pundit" can - I'm reminded of the various times they're tricked into giving their commentary on things that haven't happened yet, and they happily (blindly) oblige, because they're more interested in being seen to be an expert than in actually having something to say.
I think the more confident and critical you are in reading, the raider it is to detect the nonsense through internal inconsistencies - many of these text generation systems really struggle to produce an internally consistent argument.
Edit: ok, I think you meant to reply to another comment which is currently flagged/dead. It looked like you were referring to the linked article itself.
Bottom line is that outsourcing should only be possible if it was not possible to create a product locally or companies should pay any difference in tax locally, so that people who got put out of jobs because of this can at least get benefits.
And finally I don't understand why even discussing doing any deals with China does not amount to farting in a room.