The fun part is they don’t know the extent of the comprise or how long it has been going on.

What happened is that CISA recently published a report stating that they think a lot of US telecommunications equipment has been compromised. It isn’t a one time breach. They know that China has control over a unspecified amount of critical components. The malware China is using is extremely complex and very hard if not completely impossible to detect. China is very good at covering there tracks so even getting a sample of Malware is hard.

Because of all this, CISA is now recommending that people use encrypted messagers.

  • nifty@lemmy.world
    link
    fedilink
    arrow-up
    90
    ·
    1 month ago

    This is why the old guard of tech and privacy was against a lot of the shenanigans you routinely encounter in any app or device. Bonus, the S in IoT stands for security.

  • jas0n@lemmy.world
    link
    fedilink
    arrow-up
    87
    ·
    1 month ago

    Apparently, the hackers exploited the backdoor that was provided for “lawful surveillance” in the 3G spec. Imagine that.

    • manicdave@feddit.uk
      link
      fedilink
      arrow-up
      48
      ·
      1 month ago

      Lol.

      Seven years ago I spent hours trying to explain to my MP that this would happen if they weakened encryption and put in back doors.

      He seemingly couldn’t get his head round the fact that you have to assume foreign adversaries have access to everything in transit and they’re not going to be worried about longer prison sentences designed to make up for weaker security.

      I should send him an email asking if he understands the argument now it’s coming from an American in a suit and not just one of the plebs.

      • Possibly linux@lemmy.zipOP
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        1 month ago

        You absolutely should

        Also include links to the human rights abuse done by the Chinese police. And the fact that South Korea almost just turned into a dictatorship.

    • Possibly linux@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 month ago

      My understanding is that the scope is totally unknown. I’m sure they exploited the crap out of those systems.

      • cannedtuna@lemmy.world
        link
        fedilink
        arrow-up
        13
        ·
        1 month ago

        At first, the F.B.I. and other investigators believed that China’s hackers used stolen passwords to focus mostly on the system that taps telephone conversations and texts under court orders. It is administered by a number of the nation’s telecommunications firms, including the three largest — Verizon, AT&T and T-Mobile. But in recent days, investigators have discovered how deeply China’s hackers had moved throughout the country by exploiting aging equipment and seams in the networks connecting disparate systems.

        https://www.nytimes.com/2024/11/21/us/politics/china-hacking-telecommunications.html

        Doesn’t look like they know (or are willing to share specifics as to) the full scope of the hack, but they seem to have a pretty good idea.

  • Console_Modder@sh.itjust.works
    link
    fedilink
    arrow-up
    32
    ·
    edit-2
    1 month ago

    So what would be an encrypted messenger? Telegram or a Matrix app like Element? Asking cuz I’ve been kinda hinting to my friends that maybe we should move away from Facebook Messenger, but all we do is share memes and YouTube videos… Occasionally we’ll fuck with their stupid AI and make it write all responses in cuneiform or call everyone “shitass”

    Edit: I can’t spell for shit

      • Scrubbles@poptalk.scrubbles.tech
        link
        fedilink
        English
        arrow-up
        11
        ·
        1 month ago

        Note even with all of this they only recommend they use encrypted messaging. We should merrily go along with fb messenger or sms or whatever they swear is good.

        • dzervas@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          1 month ago

          btw messenger isn’t the worst case scenario. 1-1 chats are e2ee.

          it’s still facebook and it sucks, but it’s not as bad as SMS/calls

    • Possibly linux@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      52
      ·
      edit-2
      1 month ago

      It not about one breach

      CISA recently published a report stating that they think a lot of US telecommunications equipment has been compromised. It isn’t a one time breach. They know that China has control over a unspecified amount of critical components. The malware China is using is extremely complex and very hard if not completely impossible to detect. China is very good at covering there tracks so even getting a sample of Malware is hard. They are constantly evolving and adapting it so it is very tricky to pinpoint and clean systems.

      Because of all this, CISA is now recommending that people use encrypted messagers. Usually the government wants unfeathered access to data so that’s how you know it is very bad.

  • hark@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    1 month ago

    I wouldn’t be surprised if CISA, which was created under the Trump administration, is manufacturing consent for escalation with China.