Security

Salt Typhoon forces FCC's hand on making telcos secure their networks

Proposal pushes stricter infosec safeguards after Chinese state baddies expose vulns


The head of America's Federal Communications Commission (FCC) wants to force telecoms operators to tighten network security in the wake of the Salt Typhoon revelations, and to submit an annual report detailing measures taken.

Jessica Rosenworcel, outgoing chair of the US telecoms regulator, has proposed rules that would require the nation's carriers to safeguard their infrastructure against illicit access or interception of communications in an effort to bolster them against cyberattacks.

The proposal centers on a draft Declaratory Ruling that puts a new interpretation on section 105 of the Communications Assistance for Law Enforcement Act (CALEA) as requiring telcos to take action to lock down their networks.

This particular legislation was passed 30 years ago during the presidency of Bill Clinton and ensures telcos have the ability to comply with wiretapping requests from law enforcement. Section 105 requires a carrier to make certain that any interception of communications can only be carried out with lawful authorization.

The FCC also wants these network service providers to submit an annual certification attesting they have created, updated, and implemented a cybersecurity risk management plan.

"The cybersecurity of our nation's communications critical infrastructure is essential to promoting national security, public safety, and economic security," Rosenworcel said in a statement. "As technology continues to advance, so do the capabilities of adversaries, which means the US must adapt and reinforce our defenses."

If adopted, the Declaratory Ruling would take effect immediately, according to the FCC. The agency is to also seek comment on security risk management requirements for communications providers, as well as other ways to boost the resilience of communications systems and services.

The urgent call for action follows discovery that China-backed cyber baddies entirely compromised telecommunications infrastructure in the US and elsewhere via the so-called months-long Salt Typhoon campaign which affected at least eight operators in the US alone.

It was reported last month that a great many devices within US telcos were targeted by the attackers, allowing them to establish a persistent presence that may require the replacement of "literally thousands and thousands and thousands" of switches and routers.

The attackers are believed to have compromised the wiretapping systems used by law enforcement in at least some instances, hence the focus on the CALEA legislation being taken by the FCC to address the issue.

It isn't just the US alone that is affected, as The Reg reported at the end of November. The same vulnerabilities which left American telecoms networks wide open to foes are likely replicated worldwide and are a result of regulatory failures and a lax attitude to security by companies.

The situation is so dire the US Cybersecurity and Infrastructure Security Agency (CISA) issued guidance this week including advice on using encrypted messaging to protect information – a notable shift from governments constantly trying to erode encryption so they can snoop on communications themselves. ®

Send us news
4 Comments

More victims of China's Salt Typhoon crew emerge: Telcos just now hit via Cisco bugs

Networks in US and beyond compromised by Beijing's super-snoops pulling off priv-esc attacks

Robocallers who phoned the FCC pretending to be from the FCC land telco in trouble

Don't laugh: The $4.5m fine proposed for carrier Telnyx shows how the Trump administration will run its comms regulator

Wallbleed vulnerability unearths secrets of China's Great Firewall 125 bytes at a time

Boffins poked around inside censorship engines – here's what they found

Acer signals 10% laptop price hike in US, blames Trump's extra China tariff

Analyst tells El Reg to expect more of this across hardware brands

India's top telco plans cloud PCs for its 475 million subscribers

PLUS: China bans AI leaders from visiting USA; Acer data leak suspect cuffed; and more

Microsoft warns Trump: Where the US won't sell AI tech, China will

Rule hamstringing our datacenters is 'gift' to Middle Kingdom, vice chair argues

Three charged in Singapore with alleged link to illicit shipments of Nvidia GPUs to China

Accused face up to 20 years in prison

As China embraces Big Tech again, Alibaba plans vast spend to push for artificial general intelligence

Plus: Samsung exec jailed for selling DRAM secrets; ASUS launches sweetly scented mouse; Toyota’s smart city nears opening; and more

Fujitsu worries US tariffs will see its clients slow digital spend

PLUS: Pacific islands targeted by Chinese APT; China’s new rocket soars; DeepSeek puts Korea in a pickle; and more

Xi know what you did last summer: China was all up in Republicans' email, says book

Of course, Microsoft is in the mix, isn't it

Ampere bets on Arm to muscle into Intel's telco territory

Chipmaker touts high-core, low-power Altra processors as the future of 5G and AI inferencing

China's Silver Fox spoofs medical imaging apps to hijack patients' computers

Sly like a PRC cyberattack