4 ms·
From the article: "if hackers gained access to service providers’ core routers, it would leave them in a powerful position to steal information..." Sorry for t
by MassPikeMike 2y ago
From the article: "if hackers gained access to service providers’ core routers, it would leave them in a powerful position to steal information..."
Sorry for the newbie question, but isn't most internet traffic end-to-end encrypted, these days? So what information would the hackers, or for that matter the "lawful intercept" system , have been able to steal? I do see how accessing routers would let intruders launch malwares, spoof other sites for phishing attacks, etc.
- nashashmi 2y agoMeta data of how many packets are going between two parties, when its going, and who else is getting the data at the same time. It is like the pizza traffic story at 10 pm.
- eightysixfour 2y agoOn top of what you mentioned, they would have access to significant metadata, unencrypted traffic, and it is worth assuming that government agencies have the resources to acquire certificates and MITM high value information.
- hiatus 2y ago> have the resources to acquire certificates and MITM high value information. Isn't that mitigated by certificate transparency?
- ls612 2y agoFor WebPKI yes it should be.
- eightysixfour 2y agoObviously this all depends on your threat model at the end of the day, but if assuming a state level actor, I don’t think it is that far fetched to assume they can acquire the original certificate.
- davisr 2y agoTLS encryption means absolutely nothing. The very system of using certificate authorities is flawed by design. NSA has no trouble performing MITM. Go search 'NSA FLYING PIG'. https://www.cnet.com/tech/tech-industry/nsa-disguised-itself-as-google-to-spy-say-reports/ https://www.cnet.com/tech/tech-industry/nsa-disguised-itself...
- blablabla123 2y agoYeah but I imagine the ice is getting thin. Sure, use of key pinning on the web failed - but for instance banking apps commonly use it. Once monitoring Certificate transparency logs gets more traction, things like that could get noticed.
- davisr 2y agoHow does the use of certificate pinning mean anything when a FISA court can demand the keys and issue a gag order to prevent public disclosure?
- gruez 2y ago1. AFAIK no government, even authoritarian ones, coerced a CA to misissue a certificate. There have, however, been plenty of other ways governments are able to get certificates, like seizing the domains/servers. 2. Even if they did, chrome has enforced certificate transparency, so a gag order on the CA/CT provider would simply result in the certificate being rejected.
- hulitu 2y ago> 1. AFAIK no government, even authoritarian ones, coerced a CA to misissue a certificate. As far as you and i know. Those things are not public. Helps with espionage (see Crypto AG).
- blablabla123 2y agoSure, but then it isn't related to the CA system anymore and any action from them wouldn't be under the radar anymore. Also this problem would apply to any key like gpg. Well, as long as it's not in a Hardware security module. Of course they could also seize that but at some point it becomes logistically impractical, at least for mass surveillance.
- tguvot 2y agoin case that wiretap system related to telephony, etc - plain voice data can be obtained
- jeroenhd 2y agoInformation that someone can gather from access to telecom network hardware includes all SMS traffic (not Signal/iMessage/etc. of course), the contents of every call you make (not over Signal/iMessage/etc.), 2FA codes, the domain of most websites you visit (sniffing TLS certificates, though ECH should hopefully reduce that at some point), and of course your phone's current location at all times; with beamforming technologies like mmWave, that location can be accurate to centimeters or less. If access is wide-spread, you could even figure out who's communicating with who over encrypted messengers by watching for packet timings. Target A communicates with the Signal server and milliseconds later Target B receives a push notification? And then seconds later the inverse happens? That's probably proof enough that two people are communicating. I doubt lawful intercept systems have the ability to inject any traffic, but it's very useful to know the exact make, model, modem version, and OS version of a phone before sending malware like Pegasus to a device, and telco infrastructure knows most of that. As for phishing, knowing what services your target uses can be very useful. Spoofing numbers isn't very hard, and if you've been receiving calls from your local real estate agent for a while, you won't notice as much when you an imposter uses a spoofed number. The more niche and offline the business you're pretending to be, the less likely you'd consider a phishing attempt suspicious.