Explore top 10 tips to secure your open-source projects now. Read More
×U.S. authorities are on high alert as they investigate an alleged Chinese state-sponsored hack targeting major U.S. telecommunications companies. This attack has reignited debate about encryption backdoors , an ongoing contention among security practitioners. . To help you understand this incident and the security implications of encryption backdoors, I'll discuss these recent attacks, lawmakers' reactions, the role of encryption backdoors in this threat, and why many security professionals—including us at LinuxSecurity.com —oppose their usage. Understanding This Hack Federal authorities have quickly investigated a cyberattack known as Salt Typhoon, linked to China-backed hackers. According to an anonymous U.S. official, these attackers targeted multiple U.S. telecommunications firms, including Verizon, AT&T, and Lumen Technologies. They compromised systems explicitly used by government intelligence collection capabilities such as wiretaps. The implications of this breach extend far beyond corporate walls, posing potential threats to national security. Chinese hackers compromised telecom systems and breached U.S. intelligence systems used for lawful surveillance, such as wiretapping. Investigators are meticulously studying the depth to which hackers have penetrated these networks and whether these criminals have extracted sensitive data. Lawmakers' Reaction to This Incident This incident has sparked significant concern among U.S. lawmakers, with Senator Ron Wyden of Oregon leading the charge by calling upon both the Justice Department and Federal Communications Commission (FCC) to implement stringent security standards for telecom companies' wiretapping systems. He specifically mentioned an outdated regulatory framework as he expressed disappointment over how the DOJ dealt with cyberattacks, which he considered negligent. Wyden suggested setting baseline cybersecurity standards that can be enforced through fines while conducting annual third-party cybersecurity auditsby an independent firm. He also advocated for full transparency regarding data breaches among Congress, investigators, and the public, holding negligent corporations responsible - an approach that signals a shift toward corporate accountability rather than prosecuting foreign hackers who rarely find justice in U.S. court systems. What Are Encryption Backdoors? Encryption backdoors are built into encrypted systems to give authorized authorities access to encrypted data for regulatory or national security reasons. Still, if discovered, they can potentially be exploited by malicious actors. Encryption is at the core of modern cybersecurity, protecting sensitive information from unintended access and modification. Robust encryption protocols also facilitate secure communications, safeguard individual privacy, and enhance national security. Examining the Pros & Cons of Encryption Backdoors Encryption backdoors offer both advantages and drawbacks. On one side, they can improve national security by aiding law enforcement with lawful surveillance operations and efficient investigations by providing necessary access to encrypted data. On the other hand, however, they could threaten national security. Encryption backdoors may help ensure compliance in critical infrastructure sectors like telecom and finance; however, their advantages come with potential drawbacks that should not be ignored. Backdoors introduce inherent vulnerabilities into systems, rendering them insecure without discriminating between good and bad actors. Unauthorized individuals could exploit them to access sensitive data. Recent hacks by China have illustrated how malicious actors can exploit backdoors to access data via backdoors, thus endangering national security and corporate confidentiality. Encryption backdoors can potentially erode public trust in cybersecurity and privacy efforts, discouraging users from adopting encryption technologies. Finally, exploited backdoors may lead to security breaches with substantial financiallosses, legal liabilities, and damage to corporate reputations. What Is the Security Community's Stance on Encryption Backdoors? Security experts have long opposed encryption backdoors as contrary to encryption's very purpose. China-backed hacks prove that backdoors can be dangerous. By exploiting backdoor access mechanisms, hackers can gain entry to systems considered secure by encryption. Leading cybersecurity experts advocate for solid encryption without any backdoors. Vital, unbreakable encryption is critical for protecting against sophisticated cyber threats, ensuring personal privacy, and maintaining national security systems' integrity. Responsible encryption involves designing systems to minimize risks without including backdoors. Our Final Thoughts: The Potential Risks of Encryption Backdoors Outweigh Their Advantages Recent attacks targeting U.S. telecom companies highlight the vulnerabilities posed by encryption backdoors. Although intended for national security and regulatory compliance purposes, backdoors present vulnerabilities that malicious actors can exploit—even state-sponsored hackers—looking for vulnerabilities they can use to breach national security and regulatory compliance. As digital ecosystems mature and cyber threats grow increasingly sophisticated, robust encryption without backdoors remains essential to safeguard sensitive information, maintain personal privacy, and fortify national security systems from unintended access. Instead of compromising encryption standards, policymakers should improve cybersecurity protocols, revise regulatory frameworks, and hold corporations accountable for their security practices. Encryption backdoors may seem beneficial regarding law enforcement and regulatory compliance, yet their inherent risks far outweigh their perceived advantages. This is demonstrated by China-backed hacks, such as those perpetrated against our digital infrastructures by hackers armed with access devices from China. Robust encryption without backdoorsmust be implemented for optimal digital security. . The U.S. investigation into hacking by Chinese operatives raises tensions, impacting corporate regulations, international alliances, and public trust in technology security.. Telecom Cybersecurity, Encryption Backdoors, Cybersecurity Legislation, National Security Issues. . Brittany Day
Let me fill you in on a stealthy threat to Linux systems that has flown under the radar for nearly three years! A remote access trojan dubbed "Krasue" has been silently infiltrating Linux systems like yours, primarily targeting telecommunications companies since 2021. . It operates through a sophisticated rootkit including seven variants, each drawing its foundation from different open-source projects. This tricky technique allows the malware to adapt to different Linux kernel versions, making this malware highly difficult to detect and remove. Security researchers have said that the primary objective of the Krasue RAT is to maintain access to the host system. Krasue’s deployment strategy is unknown; possible approaches include credential brute-force assaults, exploiting vulnerabilities, or disguising distribution through unreliable sources that pretend to be trustworthy packages or binaries. So what can you do to stay safe against threats like Krasue? Ensure you have applied the latest patches released by your distro(s) to fix known vulnerabilities that malicious actors could exploit, and subscribe to our newsletters to stay updated on the latest security news, trends, and advisories impacting you. It's a dangerous digital world these days - stay informed and proactive to remain ahead of cybercriminals! . An advanced malware named Krasue targets Linux, exploiting vulnerabilities for remote access. Stay alert and secure!. Krasue RAT, Linux Intrusion, Cybersecurity Threats, Stealthy Malware. . LinuxSecurity.com Team
IBM has spoken out against Australia’s controversial ‘anti-encryption’ laws, claiming they undermine previous work to strengthen the country’s defenses. The vendor giant has urged the federal government to review the Telecommunications (Assistance and Access) Act 2018, which passed last year and effectively compels technology companies to build ‘backdoors’ into their encrypted data. What is your opinion on these anti-encryption laws? Learn more: . In a submission to the government’s 2020 cyber security strategy consultation, IBM said the laws “undermined” previous work by the government to create a “regulatory environment that promotes strong cyber security without constraining innovation or digital commerce.” It added that without review, the law has “potentially damaging” consequences for cyber security in Australia. “Strong and ubiquitous encryption is essential for now and into the future,” the vendor’s submission argued. The link for this article located at ARNnet is no longer available. . Tech giant IBM raises concerns over Australia’s encryption legislation, calling for a reassessment to bolster cybersecurity and foster innovation.. Anti-Encryption Laws,Cybersecurity Strategy,IBM Submission,Telecommunications Act,Australia Regulation. . Brittany Day
The first Open Networking Summit was held in October 2011 at Stanford University and described as “a premier event about OpenFlow and Software-Defined Networking (SDN)”. Here we are seven and half years later and I’m constantly amazed at both how far we’ve come since then, and at how quickly a traditionally slow-moving industry like telecommunications is embracing change and innovation powered by open source. . Coming out of the ONS Summit in Amsterdam last fall, Network World described open source networking as the “new norm,” and indeed, open platforms have become de-facto standards in networking. The link for this article located at Linux.com is no longer available. . Coming out of the ONS Summit in Amsterdam last fall, Network World described open source networking . first, networking, summit, october, stanford, university, described. . Brittany Day
In the 1960s and 70s, technically savvy enthusiasts sought to game telecommunications systems to make free calls, keeping telecom engineers on their toes. . That practice, known as phreaking, involved such luminaries as Steve Jobs, Steve Wozniak and John Draper, known as Cap'n Crunch, who used a whistle from a cereal box to meddle with AT&T's long-distance trunk lines. . Phreaking, a blend of "phone" and "freaking," emerged in the late 20th century as a subculture exploring and manipulating telephone networks.. Phreaking, Android Hacking, Telecommunications Techniques, Historical Cybersecurity. . LinuxSecurity.com Team
Critics of the U.S. National Security Agency's bulk collection of U.S. residents' telephone records should offer a better way to track terrorists and protect the country against attacks, the agency's director said Wednesday.. The NSA's bulk collection of U.S. telephone records is the "least intrusive" way to track suspected terrorists' communications with people in the U.S., General Keith Alexander said, defending the NSA's mass data collection and surveillance programs to the U.S. Senate Judiciary Committee. The link for this article located at Network World is no longer available. . The NSA defends its bulk telephone record collection, calling it the least intrusive method for tracking terrorists.. mass data collection,national security,NSA surveillance,data privacy. . LinuxSecurity.com Team
In "Exploding the Phone," Phil Lapsley writes an entertaining and educational history of the people who hacked the original phone networks. Lapsley talked to CNET about his book.. Imagine a day when it cost an arm and a leg to use the phone, especially for long-distance calls. Then imagine that buried deep within the telephone network infrastructure was a flaw -- a hole that allowed those who were aware of it, and capable of exploiting it, to make all the free calls they want. The link for this article located at CNET is no longer available. . Explore the captivating saga of phone phreaking and its impact on communication networks in Phil Lapsley's engaging narrative.. Phone Phreaking, Hacking History, Telecommunications Security. . LinuxSecurity.com Team
Before smartphones and iPads, before the internet or the personal computer, a misfit group of technophiles, blind teenagers, hippies, and outlaws figured out how to hack the world. There it was again. Jake Locke set down his cup and looked more closely at the classified ad. It was early afternoon on a clear spring day in Cambridge in 1967. Locke, an undergrad at Harvard University, had just gotten out of bed. A transplant from southern California, he didn The link for this article located at Wired is no longer available. . In an era before the internet's explosion, a distinct cadre of outsiders unraveled the secrets of innovation amid the turbulence of 1970s social upheaval.. Hacking, Telecommunications, Technological Innovation, History Of Technology. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.