US Government Tells Officials, Politicians To Ditch Regular Calls and Texts (reuters.com) 23
The U.S. government is urging senior government officials and politicians to ditch phone calls and text messages following intrusions at major American telecommunications companies blamed on Chinese hackers. From a report: In written guidance, opens new tab released on Wednesday, the Cybersecurity and Infrastructure Security Agency said "individuals who are in senior government or senior political positions" should "immediately review and apply" a series of best practices around the use of mobile devices.
The first recommendation: "Use only end-to-end encrypted communications." End-to-end encryption -- a data protection technique which aims to make data unreadable by anyone except its sender and its recipient -- is baked into various chat apps, including Meta's WhatsApp, Apple's iMessage, and the privacy-focused app Signal. Neither regular phone calls nor text messages are end-to-end encrypted, which means they can be monitored, either by the telephone companies, law enforcement, or - potentially - hackers who've broken into the phone companies' infrastructure.
The first recommendation: "Use only end-to-end encrypted communications." End-to-end encryption -- a data protection technique which aims to make data unreadable by anyone except its sender and its recipient -- is baked into various chat apps, including Meta's WhatsApp, Apple's iMessage, and the privacy-focused app Signal. Neither regular phone calls nor text messages are end-to-end encrypted, which means they can be monitored, either by the telephone companies, law enforcement, or - potentially - hackers who've broken into the phone companies' infrastructure.
Where there's a will... (Score:1)
...there's a way!
"Bad actors" can still employ the [in]famous James Bond style attacks.
I know this for I have been to Washington and know how vulnerable government officials can be. Do folks remember Lewinsky?
I am sure she could have garnered lots of valuable intel by using her MO.
Hahahaha, that will work! (Score:1)
I mean the only thing typical politicians can do well is yammering at others. Some, like Trump, are even functional analphabets, how do you expect anybody like that ever to do without a phone to talk to people?
Security for me, but not for thee (Score:5, Insightful)
Re: (Score:2)
Basically was gonna say something like this.
Funny how when its "national security" using encryption is of utmost importance, but for general population, please no, we can't have everyone using it, as that would be supporting criminal behavior.
Re: (Score:2)
Re: (Score:2)
but for general population, please no, we can't have everyone using it
The general population is already using it.
No one I know still uses SMS. We use WhatsApp, Viber, Telegram, all with E2E security.
Government is on the trailing edge, as usual.
Let's understand this for what it is. (Score:2)
This is the first time the US Government has advocated for non-PSTN or unencrypted email communications that can otherwise be tapped. ...from the Department of Silver Linings
Re: (Score:2)
For "senior goverment politicans and officials"
The rest of us? They want us to continue using compromised networks with limited encryption so the same "law enforcement" that may monitor them can monitor them.
It's for them. Not us. They will argue it's national security for them. They will argue we have no right to that level of privacy on a data network...for security.
Well, not the FBI (Score:4, Interesting)
Why yes, yes we would all benefit from secure telecommunications. However...
FBI Calls Apple's Expansion of End-To-End Encryption 'Deeply Concerning' [slashdot.org]
FBI Chief Calls Unbreakable Encryption 'Urgent Public Safety Issue' [slashdot.org]
Top FBI Attorney Worried About WhatsApp Encryption [slashdot.org]
And that was just within the first minute of searching. See also the entire /. database of articles where "FBI" and "encryption" are both mentioned.
Re: (Score:2)
Many already surmised that we were victims of warrantless snooping. So we went with end2end encryption, like Signal, which also works with voice. Other apps have varying degrees of side-channel exploits.
The real head-desk is that many now also use MFA, which means for them, a text message with a code. That code is now vulnerable, as text messages are essentially open for snooping (and always have been).
This means that most MFA is useless for those using texts, because unless the text is encrypted (Signal w
Re: (Score:2)
Re: (Score:2)
Why only senior government officials and politicians? Wouldn't *everybody* benefit from secure communications?
And how senior? Trump wouldn't stop using his iPhone, in favor of the secure one Presidents usually use, during his first administration -- before this guidance. What makes anyone think he'd change this time around? And if his communications aren't secure, ...
Re: (Score:2)
While some call detail records were taken that cover a large number of individuals, the only direct targeting that has been reported is senior government officials. Nothing wrong with protecting yourself but maybe the threat isn't very real.
Maybe you are thinking that there are more people in China than the US so they can actually listen to all of our calls at the same time? No one cares what you ordered for breakfast.
Re: (Score:2)
If you're a spy, people who have access to a broad array of sensitive information are the most attractive targets. This is either a senior non-technical officials, or they technically sophisticated junior workers -- your Chelsea Mannings and Edward Snowdens.
Each of these types of people represent a qualitatively different vulnerability that requires a different approach to securing. You don't have to tell a low level tech with access to lots of highly sensitive information to use end-to-end encryption, h
Re: (Score:2)
Wouldn't *everybody* benefit from secure communications?
Everyone else is already using secure communications.
No one I know still uses SMS.
It's all on WhatsApp, Viber, or other E2E secure channels.
The Cone of Silence (Score:2)
Sometimes the old ways are best.
Wait... (Score:2)
Salt Typhoon also compromised the private portals, or backdoors, that telephone companies provide to law enforcement to request court-ordered monitoring of phone numbers pursuant to investigations. This is also the same portal that is used by U.S. intelligence to surveil foreign targets inside the United States.
Didn't the hackers use a backdoor that the Federal agencies forced the telecoms and others to install? Simple solution to a simple problem.
If it's such a problem fix it for everyone. (Score:2)
Yes, this is clearlly the solution... (Score:2)
Rather than remove the backdoors that enable the hackers, we're just move all communications to third-party services. Sounds like a textbook case of throwing out the baby with the bathwater,
Soon to be Truth Social only (Score:2)
in a few months
FOIA (Score:2)