China targeted and might have held for months access to the infrastructure used to do wiretaps on the AT&T and Verizon networks.

This is a huge "told you so" moment for the cryptographic community that has been saying that such infrastructure does present a huge risk to national security. China reportedly used this capability for intelligence collection, obviously without a warrant ...

https://www.wsj.com/tech/cybersecurity/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b?st=C5ywbp&reflink=desktopwebshare_permalink

@fj
The WSJ is somewhat inaccessible to me.

Are the compromised systems at the Lawful Interception level or the NSA Room 614A level?

@zl2tod @fj "lawful" intercept level. On the other stuff the providers themselves have no access and it would never become public knowledge if it was breached. The CIA and NSA would keep that under wraps and probably not even report it to the intelligence committee.

@HackyScientress @zl2tod @fj

Remember:

And yes, AFAICT this applies to all #Telcos which have to provide "#LawfulInterception" #Backdoors if not put #Govware in their core systems.

  • And yes, speaking as an insider, this can happen in.any juristiction where said #API|s and systems are mandatory.

So like all #EU / #EFTA & #G20 members!

  • I've yet to hear of any nation that doesn't demand such tech to be installed capable of both targeted and/or #BulkSurveillance.

-Just because laws demand a #judge to sign a #warrant doesn't mean said judge is actually in control or able to prevent someone from using it without permission!

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] OFC #Cyberfacists will demand #cyberfacism. - #Backdoor Integration *is the illicit activity*! - #Wiretapping *is the illicit activity*! - #CustodialKeys *are the illicit activity*! - #KYC *is the illicit activity*! Sadly this shite is [mandatory in every juristiction I know of]( https://infosec.space/@kkarhan/113292738181126901 )...

Infosec.Space