Live data from Hacker News

PRC Targeting of Commercial Telecommunications Infrastructure

fbi.gov

31–40 of 157 posts

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#32

Earlier quoted context omitted.

Yes, they leveraging CALEA mandated infrastructure. https://www.techdirt.com/2024/10/16/wyden-calea-hack-proves-... https://www.wyden.senate.gov/imo/media/doc/wyden_letter_to_f... https://en.wikipedia.org/wiki/Communications_Assistance_for_...

Can you imagine if the proponents of the Clipper Chip had actually won the argument? Yeesh. This is inexcusable.

[deleted]

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#33

Whenever I see these news & FBI releases about Chinese state-sponsored hackers breaching systems in America, I wonder whether the same thing happens over there: American malware and hacker groups attacking & laying landmines in China's internet infrastructure, although the Chinese may not publicize these exploits because their system opts to maintain an air of invincibility.

I think its kind of hard to imagine its not totally complementary in this respect. Even just being rational, if we have no qualms spying on our European allies, it seems a safe bet to assume we would be doing that and much more to China too. https://www.bbc.com/news/world-europe-57302806

Considering how deeply infiltrated German intelligence services were/are by Russia, it's hard to feel bad about spying on them.

At least the Dutch are competent.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#35
I was working with MISP[0], an open-source threat intelligence sharing platform, and came across a really interesting dataset from the Australian Strategic Policy Institute on China's technology research institutions[1]. I liked the data so much I built a quick cross-filter visualization on top of it to help explore it[2].

The data offers a fairly comprehensive and interesting perspective on China's research priorities and organization, I can't speak to the effectiveness of the programs themselves, but it does make me concerned that we are falling far behind in many areas, including cyber security.

[0] https://www.misp-project.org/

[1] https://raw.githubusercontent.com/MISP/misp-galaxy/refs/head...

[2] https://www.layer8.org/8541dd18-ff05-4720-aac7-1bd59d3921dd/

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#36
post #22

Earlier quoted context omitted.

Yes, they leveraging CALEA mandated infrastructure. https://www.techdirt.com/2024/10/16/wyden-calea-hack-proves-... https://www.wyden.senate.gov/imo/media/doc/wyden_letter_to_f... https://en.wikipedia.org/wiki/Communications_Assistance_for_...

Wyden is so good on this stuff.

He's getting up there in years, I hope he hangs out a while longer. We could use more senators like him.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#37

> and the copying of certain information that was subject to U.S. law enforcement requests pursuant to court orders Is this legal speak for saying, "They're using our backdoors without our permission."?

No it is not, because these are not backdoors, the entities legally own the data users have provided them and the courts require them to share the data for investigative purposes. When the FBI pressed Apple to break its encryption, it would not had been a backdoor, but simply a different product that Apple would've offered. A backdoor would be a secret exploit that circumvents encryption, or other security methods.

You've probably conflated the saying "going through the backdoor" with the noun backdoor, which is an understandable mistake to make.

Conflating the two is even easier when the backdoor is morally questionable i.e. When someone purposefully installs a wooden backdoor on a bankvault and says it's so that we don't need to go through the whole rigmarole of opening the main vault-door. Yes it allows them to do their job of checking what's in safety deposit boxes easier but the door itself is an evil.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#38
post #37

Earlier quoted context omitted.

No it is not, because these are not backdoors, the entities legally own the data users have provided them and the courts require them to share the data for investigative purposes. When the FBI pressed Apple to break its encryption, it would not had been a backdoor, but simply a different product that Apple would've offered. A backdoor would be a secret exploit that circumvents encryption, or other security methods.

You've probably conflated the saying "going through the backdoor" with the noun backdoor, which is an understandable mistake to make. Conflating the two is even easier when the backdoor is morally questionable i.e. When someone purposefully installs a wooden backdoor on a bankvault and says it's so that we don't need to go through the whole rigmarole of opening the main vault-door. Yes it allows them to do their job…

"Using our backdoors" is what was said, not "going through the backdoor". Backdoors have a very specific meaning in computer security. US law enforcement is not using backdoors to access the data of US companies.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#39

Whenever I see these news & FBI releases about Chinese state-sponsored hackers breaching systems in America, I wonder whether the same thing happens over there: American malware and hacker groups attacking & laying landmines in China's internet infrastructure, although the Chinese may not publicize these exploits because their system opts to maintain an air of invincibility.

At least you have CIA openly recruit spies on Twitter: https://x.com/CIA/status/1841468925378171381 I think only CIA and mossad have the confidence to do it this way.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#40
post #37

Earlier quoted context omitted.

No it is not, because these are not backdoors, the entities legally own the data users have provided them and the courts require them to share the data for investigative purposes. When the FBI pressed Apple to break its encryption, it would not had been a backdoor, but simply a different product that Apple would've offered. A backdoor would be a secret exploit that circumvents encryption, or other security methods.

You've probably conflated the saying "going through the backdoor" with the noun backdoor, which is an understandable mistake to make. Conflating the two is even easier when the backdoor is morally questionable i.e. When someone purposefully installs a wooden backdoor on a bankvault and says it's so that we don't need to go through the whole rigmarole of opening the main vault-door. Yes it allows them to do their job…

A backdoor bypasses legitimate access mechanisms. Whether it is a backdoor or not depends fully on whether you believe lawful intercept is a legitimate access mechanism. And I think the law is on the side of it being not a backdoor.
Post reply on HN