Re: Another Pseudo Secure Encryption Bites The Dust - Thank Goodness
none <[email protected]> Fri, 3 Mar 2023 02:24:35 +0100 (CET)
| Newsgroups | alt.computer.security,alt.privacy.anon-server |
|---|---|
| Organization | dizum.com - The Internet Problem Provider |
| Message-ID | <[email protected]> |
On 02 Mar 2023, rat <[email protected]> posted some news:[email protected]: > On 02 Mar 2023, Grant Taylor <[email protected]> posted some > news:[email protected]: > >> On 3/2/23 1:24 PM, The Stuff of Legend wrote: >>> Gentlemen, this is fairly old news. The EncroChat servers were >>> breached by the French authorities as early as 2019, using a >>> technique similar to that used to gain access to the BlackBerry >>> network a couple of years earlier. >> >> Nothing about what you shared indicated that authorities /broke/ or >> /cracked/ the encryption used. >> >> Getting inside the network another way is completely independent of >> the encryption used. >> >> xkcd 538 -- Security -- comes to mind >> - https://xkcd.com/538/ > > All it takes is a tech inside a DC cage with a USB drive. Plug it in, > the OS does the rest when it reads the drive file system. Takes less > than a minute to compromise a system. Pull the drive on the way out > and nobody is the wiser. > > A COLO looks impressive on the outside and even more internally. But > techs are badged to work in them to save time getting in and out. > There are blind spots and it is not uncommon for equipment grid / cage > locations to be misidentified on access requests. > > Familiarity breeds contempt and opens doors. There are cameras above some cages but many of those team members monitoring activity have no direct view of a tech working inside a cabinet or rack. They can see when a server is pulled out in front for example because that is where the cameras are aimed, but any access of port or USB connections on the back of the server are not visible.