« Video on the net - TV networks try to control it, telcos try to profit | Main | Using OPML to do a Cornell Notes style outline »

March 02, 2006

Schneier on Greek wiretapping, Blaze on US wiretapping

Bruce Schneier writes about a wiretapping scandal in Greece:

Schneier on Security: More on Greek Wiretapping:

The attackers managed to bypass the authorization mechanisms of the eavesdropping system, and activate the "lawful interception" module in the mobile network. They then redirected about 100 numbers to 14 shadow numbers they controlled. (Here are translations of some of the press conferences with technical details. And here are details of the system used.)

There is an important security lesson here. I have long argued that when you build surveillance mechanisms into communication systems, you invite the bad guys to use those mechanisms for their own purposes. That's exactly what happened here.

In a related note, Matt Blaze is going to be talking at Stanford about holes in the US CALEA in-band signalling used to control domestic wiretaps:

Topic: Signaling Vulnerabilities in Law-Enforcement Wiretap Systems

Speaker: Matt Blaze
University of Pennsylvania

About the talk:

Telephone wiretap and dialed number recording systems are used by
law enforcement and national security agencies to collect
investigative intelligence and legal evidence. This talk will
show how many of these systems are vulnerable to simple,
unilateral countermeasures that allow wiretap targets to prevent
their call audio from being recorded and/or cause false or
inaccurate dialed digits and call activity to be logged. The
countermeasures exploit the unprotected in-band signals passed
between the telephone network and the collection system and are
effective against many of the wiretapping technologies currently
used by US law enforcement, including at least some ``CALEA''
systems.

Both of these are via Dave Farber's "interesting people" list.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/2735/4372294

Listed below are links to weblogs that reference Schneier on Greek wiretapping, Blaze on US wiretapping:

Comments

Post a comment

If you have a TypeKey or TypePad account, please Sign In

My Photo

Subscribe to Vacuum

  • Subscribe with Bloglines

    See also my other blog, Superpatron, for library patrons and libraries.

Once the search has begun, something will be found

  • Google Custom Search

Vacuum archives

  • archives of vacuum - include things hosted on other sites. (not linked yet TBD checking style now) 1999: 1 2 3 4 5 6 7 8 9 10 11 12 2000: 1 2 3 4 5 6 7 8 9 10 11 12 2001: 1 2 3 4 5 6 7 8 9 10 11 12 2002: 1 2 3 4 5 6 7 8 9 10 11 12 2003: 1 2 3 4 5 6 7 8 9 10 11 12 2004: 1 2 3 4 5 6 7 8 9 10 11 12 2005: 1 2 3 4 5 6 7 8 9 10 11 12 2006: 1 2 3 4 5 6 7 8 9 10 11 12 2007: 1 2 3 4 5 6 7 8 9 10 11 12

Call me!

  • Call me!

upcoming.org

What I'm up to

mybloglog


Blog powered by TypePad
Member since 08/2003