Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Wednesday, April 14th, 2021

    Time Event
    6:34p
    The FBI Is Now Securing Networks Without Their Owners’ Permission

    In January, we learned about a Chinese espionage campaign that exploited four zero-days in Microsoft Exchange. One of the characteristics of the campaign, in the later days when the Chinese probably realized that the vulnerabilities would soon be fixed, was to install a web shell in compromised networks that would give them subsequent remote access. Even if the vulnerabilities were patched, the shell would remain until the network operators removed it.

    Now, months later, many of those shells are still in place. And they’re being used by criminal hackers as well.

    On Tuesday, the FBI announced that it successfully received a court order to remove “hundreds” of these web shells from networks in the US.

    This is nothing short of extraordinary, and I can think of no real-world parallel. It’s kind of like if a criminal organization infiltrated a door-lock company and surreptitiously added a master passkey feature, and then customers bought and installed those locks. And then if the FBI got a court order to fix all the locks to remove the master passkey capability. And it’s kind of not like that. In any case, it’s not what we normally think of when we think of a warrant. The links above have details, but I would like a legal scholar to weigh in on the implications of this.

    8:19p
    Upcoming Speaking Engagements

    This is a current list of where and when I am scheduled to speak:

    The list is maintained on this page.

    << Previous Day 2021/04/14
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org