Security

Salt Typhoon forces FCC's hand on making telcos secure their networks

Proposal pushes stricter infosec safeguards after Chinese state baddies expose vulns


The head of America's Federal Communications Commission (FCC) wants to force telecoms operators to tighten network security in the wake of the Salt Typhoon revelations, and to submit an annual report detailing measures taken.

Jessica Rosenworcel, outgoing chair of the US telecoms regulator, has proposed rules that would require the nation's carriers to safeguard their infrastructure against illicit access or interception of communications in an effort to bolster them against cyberattacks.

The proposal centers on a draft Declaratory Ruling that puts a new interpretation on section 105 of the Communications Assistance for Law Enforcement Act (CALEA) as requiring telcos to take action to lock down their networks.

This particular legislation was passed 30 years ago during the presidency of Bill Clinton and ensures telcos have the ability to comply with wiretapping requests from law enforcement. Section 105 requires a carrier to make certain that any interception of communications can only be carried out with lawful authorization.

The FCC also wants these network service providers to submit an annual certification attesting they have created, updated, and implemented a cybersecurity risk management plan.

"The cybersecurity of our nation's communications critical infrastructure is essential to promoting national security, public safety, and economic security," Rosenworcel said in a statement. "As technology continues to advance, so do the capabilities of adversaries, which means the US must adapt and reinforce our defenses."

If adopted, the Declaratory Ruling would take effect immediately, according to the FCC. The agency is to also seek comment on security risk management requirements for communications providers, as well as other ways to boost the resilience of communications systems and services.

The urgent call for action follows discovery that China-backed cyber baddies entirely compromised telecommunications infrastructure in the US and elsewhere via the so-called months-long Salt Typhoon campaign which affected at least eight operators in the US alone.

It was reported last month that a great many devices within US telcos were targeted by the attackers, allowing them to establish a persistent presence that may require the replacement of "literally thousands and thousands and thousands" of switches and routers.

The attackers are believed to have compromised the wiretapping systems used by law enforcement in at least some instances, hence the focus on the CALEA legislation being taken by the FCC to address the issue.

It isn't just the US alone that is affected, as The Reg reported at the end of November. The same vulnerabilities which left American telecoms networks wide open to foes are likely replicated worldwide and are a result of regulatory failures and a lax attitude to security by companies.

The situation is so dire the US Cybersecurity and Infrastructure Security Agency (CISA) issued guidance this week including advice on using encrypted messaging to protect information – a notable shift from governments constantly trying to erode encryption so they can snoop on communications themselves. ®

Send us news
4 Comments

Blocking Chinese spies from intercepting calls? There ought to be a law

Sen. Wyden blasts FCC's 'failure' amid Salt Typhoon hacks

China gorging on silicon before Uncle Sam slams the door

Chip imports up more than 14% this year in anticipation of fresh restrictions

China preps another rocket that Beijing hopes will become its workhorse

Long March-8A improves payload by forty percent and comes just a month after Long March 12 debut

Trump administration wants to go on cyber offensive against China

The US has never attacked Chinese critical infrastructure before, right?

US reportedly mulls TP-Link router ban over national security risk

It could end up like Huawei -Trump's gonna get ya, get ya, get ya

China's Salt Typhoon recorded top American officials' calls, says White House

No word yet on who was snooped on. Any bets?

China's homebrew Bluetooth alternative is on the march as Beijing pushes universal remotes

'Star Flash' is said to include 5G tech and leave rival wireless protocols struggling in the crack of a sofa

FCC throws open 6 GHz band to unlicensed low-power gizmos

Good news for techies pushing 'education, healthcare, and entertainment' gadgets in the US

Supreme Court to hear TikTok's appeal against law that would force it to shut, or sell

Will consider free speech arguments just nine days before the clock runs out

How Chinese insiders are stealing data scooped up by President Xi's national surveillance system

'It's a double-edged sword,' security researchers tell The Reg

China strikes back with Nvidia antitrust probe as US tightens tech chokehold

Beijing cites GPU giant's Mellanox merger conditions from four years ago

How Androxgh0st rose from Mozi's ashes to become 'most prevalent malware'

Botnet's operators 'driven by similar interests as that of the Chinese state'