AT&T, Verizon reportedly hacked to target US govt wiretapping platform
bleepingcomputer.com
bleepingcomputer.com
When was this? As far as I remember (but I'm not that old to be honest), it seems to mostly been about the US government making sure the government has secure communications, while the rest get to fend for themselves.
The FBI did that recently[1]
[1] https://www.malwarebytes.com/blog/news/2024/02/fbi-removes-m...
They've always undermined American security so they could have more information and power.
The goal is to protect the physical and institutional USA (and equivalent for other countries' intel agencies); this requires making sure there's no successful conspiracies, from within or without, to destroy it; this requires all the things we here all agree are bad for digital security, including the security necessary to running e.g. electronic banking ledgers or votes.
I don't have any actual solutions here, that's just a description of the problem space as I understand it to be.
There's a bunch of US agencies sponsoring Tor, presumably to undermine hostile governments, even though there's also US agencies trying to subvert it.
"That there is no safe backdoor" has more or less been the statement of any expert on the topic. In a time we still had experts since security consultants of today are often as shady as the scammers trying to get access to your data/system.
In each case the FBI wanted to keep the breach open as a honeypot so they could investigate the bad actors, regardless of considering the cost to the business of continuing to leak data about their products/customers/employees.
"Security researchers also found that the threat actor attacked hotels, engineering companies, and law firms in Brazil, Burkina Faso, South Africa, Canada, Israel, France, Guatemala, Lithuania, Saudi Arabia, Taiwan, Thailand, and the United Kingdom."
but that isn't in the main article and they don't say where they got that information from?
If we're not going to accept Seymour Hersch's anonymously-sourced claim that the US Navy was involved in the destruction of the Nordstream pipelines, why accept this claim at face value either? For an example of reporting of a major hacking incident not reliant on anonymous government sources, see the OPM hack:
https://www.nytimes.com/2015/06/05/us/breach-in-a-federal-co...
Notably, the WSJ source report doesn't include any mention of reporters attempting to get official statements from the relevant US government agencies and being rebuffed. That smells like plausible deniability of the kind involved in the bogus Iraq WMD leaks.
Sorry for the newbie question, but isn't most internet traffic end-to-end encrypted, these days? So what information would the hackers, or for that matter the "lawful intercept" system , have been able to steal? I do see how accessing routers would let intruders launch malwares, spoof other sites for phishing attacks, etc.
Isn't that mitigated by certificate transparency?
https://www.cnet.com/tech/tech-industry/nsa-disguised-itself...
2. Even if they did, chrome has enforced certificate transparency, so a gag order on the CA/CT provider would simply result in the certificate being rejected.
As far as you and i know. Those things are not public. Helps with espionage (see Crypto AG).
Also this problem would apply to any key like gpg. Well, as long as it's not in a Hardware security module. Of course they could also seize that but at some point it becomes logistically impractical, at least for mass surveillance.
After the PRISM stuff, folks got a lot more savvy with encryption. TLS has been tightened up a lot since then across many fronts (perfect forward secrecy, removing crap roots, certificate transparency, etc).
There's just no way the NSA can be MITMing any reasonable proportion of traffic. Possibly extremely targeted stuff, and sure, there's technically the possibility that Google is handing over keys, but if it was happening at any massive scale, people would now know.
That's why the fight has moved over to metadata now, which is what the three letter agencies are vacuuming up these days.
If access is wide-spread, you could even figure out who's communicating with who over encrypted messengers by watching for packet timings. Target A communicates with the Signal server and milliseconds later Target B receives a push notification? And then seconds later the inverse happens? That's probably proof enough that two people are communicating.
I doubt lawful intercept systems have the ability to inject any traffic, but it's very useful to know the exact make, model, modem version, and OS version of a phone before sending malware like Pegasus to a device, and telco infrastructure knows most of that.
As for phishing, knowing what services your target uses can be very useful. Spoofing numbers isn't very hard, and if you've been receiving calls from your local real estate agent for a while, you won't notice as much when you an imposter uses a spoofed number. The more niche and offline the business you're pretending to be, the less likely you'd consider a phishing attempt suspicious.
Thanks to mobile networks, information can be anything from live internet traffic to live location information of cars and phones. However, I suspect if someone did a hack that juicy, carrier SOCs would've noticed immediately. This type of infrastructure isn't exactly hooked up to a public IP address somewhere.
Snort.
Would it not be a good indicator that it may not be a great idea to begin with?
<< carrier SOCs would've noticed immediately.
I want to believe that. I do. But the longer I live in corporate, the more I think that we are experiencing a serious competency problem across the board.
So, the question of competence or otherwise may be mooted by virtue of simply not having proper visibility.
It's getting from point A to point B, and probably not via sneakernet. The details will make it more or less secure, but I'd be shocked if it's going through anything other than public internet pathways.
These carriers make up the backbone of the internet, but that doesn't mean the internet is the only network they route.
Without going into details, consider that sometimes they are, even with very large providers that you think should know better. Law enforcement’s got to get to them somehow.
And much of the documentation for these systems is publicly available. Search for your favorite enterprise company and for “lawful intercept”.
The thing about CSPs is their core business is edge routing. A majority of their core assets are going to be internet connected routers, and you’d actually be able to collect more data by owning some of those. The additional information you can get from LI (and the reason you often need a clearance to work on LI systems) is information about who law enforcement are running intercepts on.
Also, LI is just a regulatory cost centre for CSPs. It’s hilarious (or scary, depending on your perspective) how poorly those systems are maintained, and how often the break.
We're talking real deal nation-state actors targeting an industry where for the last few decades the only downside of being breached is having to say "oh oops, sorry" and maybe providing a year of credit monitoring. Security is something taken just seriously enough to avoid a ruling of negligence, but no more.
It is very optimistic to assume that carriers would immediately notice a breach by threat actors this sophisticated.
If an external actor can control the wiretapping infrastructure, that doesn't just imply spying on targets; it can also cause some wiretapping evidence on terrorists/spies used by law enforcement can no longer be used.