US recommends encrypted messaging as Chinese hackers linger in telecom networks (arstechnica.com)
from return2ozma@lemmy.world to technology@lemmy.world on 04 Dec 21:12
https://lemmy.world/post/22774069

#technology

threaded - newest

DarkCloud@lemmy.world on 04 Dec 21:44 next collapse

I love how this is painted as hacking when the root cause is an unrestricted number of telco subsideries that pay for access to the system, this then essentially gives them the powers and credentials to monitor, intercept, and clone anyone’s phone and send/receive their messages/calls (Linus Tech Tips teamed up with Derek from Veritasium to show the extent to which it can be done, stealing his identity to intercept texts to and from his wife).

This is a product of the market deregulations of Capitalism. Capitalism is once again a security risk to citizens of free democracies. Shit happens all the time.

Chozo@fedia.io on 05 Dec 00:31 next collapse

That's not what's happening here, though.

xodoh74984@lemmy.world on 07 Dec 05:42 collapse

Gotta love when a comment complaining about something that didn’t happen gets the most upvotes.

Edit: For those curious about what actually did happen

Salt Typhoon exploited technical vulnerabilities in some of the cybersecurity products like firewalls used to protect large organizations. Once inside the network, the attackers used more conventional tools and knowledge to expand their reach, gather information, stay hidden and deploy malware for later use.
Source

The hack revealed in the Linus video is concerning, but only if you’re a targeted individual. This hack was used for mass surveillance, affected way more people, and was achieved by exploiting security vulnerabilities.

The technical deep dive is a pretty interesting read.

xodoh74984@lemmy.world on 07 Dec 05:30 collapse

The hacker known as “capitalism”

jqubed@lemmy.world on 04 Dec 21:47 next collapse

An unnamed FBI official was quoted in the same report as saying that phone users “would benefit from considering using a cellphone that automatically receives timely operating system updates, responsibly managed encryption, and phishing-resistant” multifactor authentication for email accounts, social media, and collaboration tools.

(Emphasis added)

I assume by “responsibly managed encryption” they mean something that still has a backdoor, even though backdoors seem to be a significant part of the problem?

henfredemars@infosec.pub on 04 Dec 21:50 next collapse

I don’t want the encryption equivalent of a TSA approved luggage lock.

uriel238@lemmy.blahaj.zone on 05 Dec 01:10 collapse

And will continue to be.

The industrial espionage sector usually cracks backdoors inside days of first release (unless they find a better exploit).

That was the point of NSA before 9/11 and the Patriot Act. Before it was completely captured.

CCMan1701A@startrek.website on 05 Dec 03:33 collapse

Good thing banks use sms for two factor codes