Bonum Certa Men Certa

ISPs and National Media Blame Internet Users for 'Weak Passwords' (Only LAN Users Have Access) While National Spy Agencies Mandate Back Doors and Microsoft Windows Causes Most of the Distributed Denial of Service Attacks, Data Breaches, Ransomware Etc.

posted by Roy Schestowitz on Nov 01, 2023,
updated Nov 01, 2023

Networking

THE corporate and national media do a "trick or treat" (or bait-and-switch) on us, offering us so-called 'advice' on 'security' [1, 2] when it fact it's a mindless blame game that distracts from states colluding with the likes of Microsoft to back-door everything. Microsoft and the NSA actively collaborate to ensure the NSA knows how to penetrate not only Windows but also all the "clown computing" junk. This isn't about your security, it is about control, and not control by you but over you.

You are nobody to these people and corporations. Heck, they even keep their communication protocols secret from you, unless you bring many patents to the table and sign and NDA (with plenty of oppressive conditions other than the secrecy).

As per the links above, we spoke to Sompi recently over in IRC (the logs contain the full, raw thing). He's from Finland and he made some inquiries to figure out how bad the situation had become.

Hours ago he said: "Most of those router boxes that the ISPs here give their customers for "free" are boot locked to their factory firmware. And also those routers that cost actual money to the customer but the ISP sells them as a "referred choice" [...] So those devices are unsecure by design and SuPo is quiet about them..."

He made some calls to find out more. SuPo (the Finnish spy agency) won't say much, but companies might drop clues, even accidentally.

"A Finnish company Telewell makes routers that at least claim to be free from any backdoors," he said, "but their firmware is closed source so they cannot prove it. The devices are boot locked to their own firmware, but with a little soldering they can be forced to boot OpenWRT, but currently their 5G implementation does not work with OpenWRT. The routers are manufactured in Taiwan and the firmware is written in Germany and in Finland. I called Telewell and asked. Older Telewell devices could run OpenWRT out-of-the box, they were not boot locked. But Telewell added boot restrictions to those new devices because some people failed with the firmware change and the device stopped working and then they were sent to warranty..."

Wi-fi Internet RouterThen there's the issue with the underlying protocols. Including Wi-Fi (similar problem with patents, consortia, secrecy, and oppressive NDAs, where back doors are to be hush-hush rather than tackled), not just xG and transport layer stuff.

As Sompi put it: "The 5G implementation in those Telewell routers is 100% closed and even Telewell itself does not know what data it sends to the mobile cell tower. Telewell only knows the API that is used for interfacing with the 5G chip."

"So basically the 5G chip can spy everything that is not encrypted. And here the landline network was demolished because "we don't need it anymore, 5G is the future!!!1" and every 5G implementation is closed source, and the 5G specification is so complex that it is impossible to create a new implementation from scratch. So now we are stuck with these closed implementations of closed network protocols. AFAIK, the 5G specification does not even specify the format of the network packets. It mostly only specifies various use cases, which is normally not the meaning of a specification."

Well, for phonecalls we are now forced to use TCP/IP (they changed everything to fibre this past February); it's not really a phone per se but a device that uses the Net. They charge for its use like it's an old phone, but it's not. That costs the ISP mere pennies. The profit margins are outrageous.

"Of course the landlines were not secure in their own right, without an actual encryption protocol used as a payload," Sompi said, "but the protocols were at least 100% open for everyone to implement them themselves. I'm not 100% sure of that, but it seems that no-one actually knows how the 5G works, except the engineers that work for those megacorporations which have made their own 5G implementations. I tried to find information about the packet structures of the 5G specification but couldn't find any information about it. The specification seems to be mostly devoid of any actual low-level information about how the 5G technology itself is made to work. So you cannot make your own 5G implementation and use it to connect to other devices."

It's all about patents and NDAs. And NSA, too (or NATO partners like SuPo and GCHQ).

One person told us about "Windows boxes," as "they are the entirety of the botnet problem" rather than people not using a strong password on their router (SuPO barks up the wrong tree, blaming the victims). Such passwords are a weakness only within the remits of the LAN, e.g. family members who might 'break in' (or just physically grab your laptop and use saved passwords in an open/live browser session).

"Yle whines about DDoS in the reports but never ever mentions the Windows botnets which lie behind the attacks," the person retorted.

Curiously enough many of these firms leverage Linux and/or Free software to spread back doors-infested products (inside almost every household) and they do not even bother obeying the software licences. As one person told us: "Scans of the Technicolor branded routers here suggest very strongly OpenWRT though all the details are obfuscated..."

Technicolor became a massive patent troll, just like the Finnish former-giant Nokia, which was left worthless after Microsoft had destroyed it. So combine software patent litigation (even in courts that are illegal and constitutional like the UPC), GPL violations, and wide-open back doors. You're starting to get a not-so-rosy picture of what companies get away with in the darkness. "Modern" computing and networking seem like a bugfest, often by intention and by design. "keep out, peasants, our back doors are good for you!"

Sompi added this older article about Telia. "Basically," he said, "changing the WiFi password of the routers was made using a web service that was hosted remotely by Telia. That web service ran a PHP script that utilized an ISP backdoor in the customer's router and changed its WiFi password via an SSH connection. The researchers set up a normal SSH server using that backdoor port and the PHP script in Elisa's server tried to log in to it, and the researchers got the universal router credentials of all Telia routers of that model. Then they sent a report of everything to Telia and Telia threatened the researchers for doing something illegal. And it is possible that those security flaws are still unfixed. The Finnish state-owned phone company Sonera was also bought by Telia (or actually it was given for free by certain corrupted politicians). Telia also got the Finnish landline network in that process and immediately started demolishing it."

Telia is a Swedish company and Sweden is quite notoriously a spying 'outpost' of the US, without any loyalty to Russia (not in its vicinity), even before the invasion of Ukraine.

Telia Company Logo

Other Recent Techrights' Posts

Audio: Julian Assange Tells US Judge That Espionage Act and First Amendment Contradict One Another, But Pleads Guilty (to Save His Life)
Have a listen to Julian Assange and the judge in Saipan
How to Help Pay Assange Debt (£520,000 Plane Bill and Beyond)
Budget travel was not permitted
Wikipedia Co-Founder (Not Wales) Expresses Support for Wikileaks Founder Julian Assange, Says Assange Will Probably Continue
probably exactly the sort of thing that the US prosecutors did not want
Windows in Åland Islands: From 100% to Less Than Half
Åland Islands lost the sense of urgency to move to GNU/Linux
Not Just Slow News But Also Late News (Julian Assange Landing in Thailand)
Why did AP take so long (nearly a week) to release these?
[Meme] Smart Alec Poettering
How many Microsofters can the Debian Project withstand?
Getting Rid of Microsoft Does Not Go Far Enough
Microsoft already has many problems. One day Microsoft won't exist anymore. But that does not guarantee users' freedom.
Alyssa Rosenzweig's LibrePlanet Talk About Freeing the Apple GPU
Alyssa Rosenzweig is the graphics witch behind the reverse-engineered drivers for the Apple GPU. She previously led Panfrost, the free drivers for Arm Mali GPUs powering devices like the Pinebook Pro. She graduated in 2023 with a Computer Science degree from the University of Toronto and now writes free software full-time.
Links 30/06/2024: LLMs Under Fire and Dictatorship of the Old
Links for the day
 
What Richard Stallman (RMS) Thinks of Paying With Cash or 'Cashless Society'
RMS: Don't be tracked
No Discrimination Allowed Against People Who Pay With Cash
City of Philadelphia on cash
Anthony Albanes: Assange's "arrival home ends a long running legal process. [...] We'll have meetings about AUKUS and other arrangements over coming days as well."
Official transcript
4.04 Linux Not Found, No Such Agency (NSA)
The CoCs never failed Microsoft
Julian Assange Turns 53 in a Couple of Days, Give Him the Gift of Freedom From Debt
Julian Assange turns 53 on Wednesday
IBM's Abandonment of Disabled People (Orca and Wayland Incompatibility) Has Basically Killed Their "DEI" Channel (Room)
The "DEI" channel (Matrix room) as been silent for 4 days
[Meme] Just Because You Throw Money at Lawyers Doesn't Mean You'll Win
Welcome to the second half of 2024
Paulo Henrique Santana (Collabora) on the Debian Brazil Community
There was similar material in DebConf22
Making the Wikileaks Site More Active Again (and Gradually Exiting "X" or Other Social Control Media)
As soon as Assange got kidnapped the Wikileaks Web site reached a near-standstill
Marco Calegaro on Hacking Art Into a Community
talk by Marco Calegaro
Links 01/07/2024: Chokecherry Leaf and Agile Manifesto
Links for the day
Johannes Åsgård on Making the Raspberry Pi More Free With librerpi
Johannes (also known as dolphinana)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 30, 2024
IRC logs for Sunday, June 30, 2024
200 This Week
Monday started with 40 articles/pages and this is #200
Press Complicity and Public Apathy All Along Enabled 14 Years of Illegal, Arbitrary Detention and Coercion Into Plea Bargain of Julian Assange on Brink of Death
They basically blackmailed him into letting the US 'win' the argument
At the End Journalism a Crime (If It Involves Accessing or Gaining Access to Documents Marked "Confidential" or "Classified" by Those Looking to Hide Their Misconduct/Crimes)
At least in the US, especially where the imperialism is at stake
Links 30/06/2024: Tensions in Korea and Japan, Criminalisation of Sleeping Outdoors
Links for the day
100% Slop/Spam From linuxsecurity.com
This is the kind of stuff that's killing the Web faster
Gemini Links 30/06/2024: Murdoch and Ideal OS
Links for the day
In the First 6 Months of 2024 Thailand Moved to GNU/Linux, Not to Windows Vista 11
maybe users moved from Vista 10 and 11 to GNU/Linux, seeing where Microsoft was heading with forced hardware "upgrades"
Eko K. A. Owen, New Outreach and Communications Coordinator for the FSF
Nice to see many new additions to the FSF's team
Microsoft Has Slaves and Enablers, Not Partners
Obligatory meme too
Tobias Platen Covered Freedom-To-Play Games in LibrePlanet 2024
Freedom-To-Play games using Taler
[Meme] Opening a 'Webapp' With 'Only' 4 GB of RAM
Until 2020 none of my PCs ever had more than 2 GB of RAM
Destination 'Five Percent'
We reckon GNU/Linux can break the 5% barrier some time by the end of this year, even without counting Chromebooks
A Crisis of Online Journalism
Almost a week ago a journalist was forced to plead guilty for an act of journalism
Germany One of Many Countries Where Microsoft's Bing Lost Market Share After All That LLM Nonsense (Bing Chat and Further Rebrands/Renames)
openai.com traffic plunged 60% last month
Microsoft’s Latest Antitrust Scrutiny
4 new stories
Microsoft Layoffs, Mass Plagiarism, and More
outrage included
[Meme] Walking Outside the Guardrails of the Walled Gardens Built by Monopolies
So-called "advertiser-unfriendly" material was never a problem for Wikileaks
GNU/Linux Climbed 0.25% This Month (in statCounter)
Around midday on Tuesday we'll start seeing preliminary data for July
Ilya Gulko Introduces Pollyanna
"Pollyanna is a web framework that makes it easy to create your own libre social space, such as a social network or blog."
'FSFE': Underage Labour, GAFAM Fronting, and Identity Theft to Undermine the FSF's Current Fundraiser
looking to raise funds at the same time as the FSF
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 29, 2024
IRC logs for Saturday, June 29, 2024
Links 29/06/2024: Astronauts at Risk, Ukraine Updates
Links for the day
Fedora and Red Hat Leftovers
mostly redhat.com
Microsoft is Now Googlebombing or Spamming 'Open Source' and 'Linux' to Promote Proprietary Surveillance, Azure
Notice the title and the image, what's being promoted etc.
Seychelles: GNU/Linux Doing OK
Seychelles cannot be considered poor
This War Crime Footage, Nothing Political Per Se, Is What They Made Julian Assange Plead Guilty To (War Criminals Not Convicted, Only Those Who Expose Them)
Wikileaks' Julian Assange: Exposing the US Military Crimes
Gemini Protocol Isn't Even Remotely "Dead"
"Lupa knows of 505,000 (half a million!) working Gemini URLs at present, up from about 425,000 this time last year"
About 10 New Free Software Foundation (FSF) Members Per Day
The total changed from 46 to 47 while typing the article
20 Years Passed, Let's Go Even Faster Now
We are hoping to bring more original stories
Vista 11 Adoption Unusually Low in Germany and It's Going Down, Not Up
This is not happening only in Germany
Kevin Korte on Computers Being Allowed to Make Decisions Based on Cryptic Algorithms and Proprietary/Secret Data
It uses buzzwords where none are needed
[Meme] Garbage In, Garbage Out (linuxsecurity.com)
It is neither Linux nor security, just chatbot-generated slop
Microsoft-Invaded CISA Spreads Anti-Free Software FUD (as If Proprietary Software Has No Memory Safety Issues), Brittany Day Uses Chatbots to Amplify and Permutate the Microsoft FUD
linuxsecurity.com became an anti-Linux spam site
Microsoft Laying Off Staff in an Act of Retaliation and Union-Busting
retaliatory layoffs at Microsoft
Gemini Links 29/06/2024: Content Drowning in 'Goo' and LLM Slop
Links for the day
Windows Lost Almost 92% Market Share in Egypt
From over 99% to just over 7%
In Ecuador, GNU/Linux Adoption Surged From Under 1% to Over 4% in About 3 Years
Not even counting Chromebooks
LibrePlanet: Cultivating Backups (of Recordings)
an appeal to recover some of these talks
Microsoft/Windows Machines Are Turned Off (or Windows Deleted/Decommissioned) in Web Servers, as the "Market Share" Collapse Continues
Taking full history into account, this is a decrease of over 90% in some cases
Corwin Brust Hosting Freedom: A Behind-the-scenes Tour With the GNU Savannah Hackers
"the "smiling faces" behind it."
Android at 90% or More in Chad
Windows below 2%
David Wilson: Cultivating a Welcoming Free Software Community That Lasts
"a feeling of shared ownership for all users."
Julian Assange Might Continue Wikileaks, But Certainly Not Yet (Recovery Time Needed)
And probably at a symbolic capacity only
Bringing in 12 Santas and Taking 13 Out (Old Interview With Julian Assange)
Julian Assange's life inside the Ecuadorian embassy
Neil Plotnick on GNU/Linux in the High School Classroom
uploaded to the LibrePlanet instance of MediaGoblin
Asia Appears to be Fastest to Adopt GNU/Linux
the home of a considerable majority of the world's population
Alexandre Oliva's LibrePlanet 2024 Talk About "Software Enshittification"
in spite of technical difficulties encountered while recording
What They Used to Do With Mono They Now Do With Systemd (Lower and Deeper Down Than Userspace)
Now we have a project started primarily by Red Hat (and managed by Microsoft GitHub, which is proprietary) being managed by Microsoft and primarily serving Microsoft and IBM
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, June 28, 2024
IRC logs for Friday, June 28, 2024