Security

Salt Typhoon forces FCC's hand on making telcos secure their networks

Proposal pushes stricter infosec safeguards after Chinese state baddies expose vulns


The head of America's Federal Communications Commission (FCC) wants to force telecoms operators to tighten network security in the wake of the Salt Typhoon revelations, and to submit an annual report detailing measures taken.

Jessica Rosenworcel, outgoing chair of the US telecoms regulator, has proposed rules that would require the nation's carriers to safeguard their infrastructure against illicit access or interception of communications in an effort to bolster them against cyberattacks.

The proposal centers on a draft Declaratory Ruling that puts a new interpretation on section 105 of the Communications Assistance for Law Enforcement Act (CALEA) as requiring telcos to take action to lock down their networks.

This particular legislation was passed 30 years ago during the presidency of Bill Clinton and ensures telcos have the ability to comply with wiretapping requests from law enforcement. Section 105 requires a carrier to make certain that any interception of communications can only be carried out with lawful authorization.

The FCC also wants these network service providers to submit an annual certification attesting they have created, updated, and implemented a cybersecurity risk management plan.

"The cybersecurity of our nation's communications critical infrastructure is essential to promoting national security, public safety, and economic security," Rosenworcel said in a statement. "As technology continues to advance, so do the capabilities of adversaries, which means the US must adapt and reinforce our defenses."

If adopted, the Declaratory Ruling would take effect immediately, according to the FCC. The agency is to also seek comment on security risk management requirements for communications providers, as well as other ways to boost the resilience of communications systems and services.

The urgent call for action follows discovery that China-backed cyber baddies entirely compromised telecommunications infrastructure in the US and elsewhere via the so-called months-long Salt Typhoon campaign which affected at least eight operators in the US alone.

It was reported last month that a great many devices within US telcos were targeted by the attackers, allowing them to establish a persistent presence that may require the replacement of "literally thousands and thousands and thousands" of switches and routers.

The attackers are believed to have compromised the wiretapping systems used by law enforcement in at least some instances, hence the focus on the CALEA legislation being taken by the FCC to address the issue.

It isn't just the US alone that is affected, as The Reg reported at the end of November. The same vulnerabilities which left American telecoms networks wide open to foes are likely replicated worldwide and are a result of regulatory failures and a lax attitude to security by companies.

The situation is so dire the US Cybersecurity and Infrastructure Security Agency (CISA) issued guidance this week including advice on using encrypted messaging to protect information – a notable shift from governments constantly trying to erode encryption so they can snoop on communications themselves. ®

Send us news
4 Comments

FCC to telcos: By law you must secure your networks from foreign spies. Get on it

Plus: Uncle Sam is cross with this one Chinese biz over Salt Typhoon mega-snooping

FCC boss urges speedy spectrum auction to fund 'Rip'n'Replace' of Chinese kit

Telcos would effectively fund grants paid to protect national security

China to probe US chip subsidies as export curbs rattle allies

Beijing investigating claims of unfair competition in mature semiconductors

Charter, Consolidated, Windstream reportedly join China's Salt Typhoon victim list

Slow drip of compromised telecom networks continues

Encryption backdoor debate 'done and dusted,' former White House tech advisor says

When the FBI urges E2EE, you know it's serious business

FCC net neutrality rules dead again as appeals court sides with Big Telco

No more back-and-forth: Rosenworcel tells Congress the issue needs legislating

Biden said to weigh global limits on AI exports in 11th-hour trade war blitz

China faces outright ban while others vie for Uncle Sam's favor

Akamai to quit its CDN in China, seemingly not due to trouble from Beijing

Security and cloud compute have so much more upside than the boring business of shifting bits

More telcos confirm China Salt Typhoon security breaches as White House weighs in

Intrusions allowed Beijing to 'geolocate millions of individuals, record phone calls at will'

Microsoft invites Chinese software vendors to sell on its marketplace and through its partners

Good luck getting buyers and resellers excited about that

When food delivery apps reached Indonesia, everyone put on weight

PLUS: Salt Typhoon and IT worker scammers sanctioned; Alibaba Cloud’s K8s go global; Amazon acquires Indian BNPL company

Donald Trump proposes US government acquire half of TikTok, which thanks him and restores service

Incoming president promises to allow ongoing operations for 90 days just as made-in-China app started to go dark