British Intelligence Responds To Slashdot About Man-in-Middle - TopicsExpress



          

British Intelligence Responds To Slashdot About Man-in-Middle Attack ift.tt/eekxlt Nervals Lobster writes The GCHQ agency, Britains equivalent of the National Security Agency, reportedly used fake LinkedIn and Slashdot pages to load malware onto computers at Belgian telecommunications firm Belgacom. In an emailed statement to Slashdot, the GCHQs Press and Media Affairs Office wrote: We have no comment to make on this particular story. It added: All GCHQs work is carried out in accordance with a strict legal and policy framework which ensure that our activities are authorised, necessary and proportionate, and that there is rigorous oversight, including from the Secretary of State, the Interception and Intelligence Services Commissioners and the Intelligence and Security Committee. Meanwhile, LinkedIns representatives suggested they had no knowledge of the reported hack. We have read the same stories, and we want to clarify that we have never cooperated with any government agency, a spokesperson from the social network wrote in an email to Slashdot, nor do we have any knowledge, with regard to these actions, and to date, we have not detected any of the spoofing activity that is being reported. An IT security expert with extensive knowledge of government intelligence operations, but no direct insight into the GCHQ, hypothesized to Slashdot that carrying out a man-in-the-middle attack was well within the capabilities of British intelligence agencies, but that such a retail operation also seemed somewhat out of character. Based on what we know theyve done, they are doing industrialized, large scale traffic sweeping and net hacking, he said. They operate a wholesale, with statistical techniques. By statistical I mean that they send something that may or may not work. With that in mind, he added, its plausible that the GCHQ has software that operates in a similar manner to the NSAs EGOTISTICAL GIRAFFE, and used it to redirect Belgacom employees to a fake download. However, the story has been slightly garbaged into it being fake [LinkedIn and Slashdot] accounts, as opposed to network spoofing. Read more of this story at Slashdot.
Posted on: Mon, 11 Nov 2013 15:48:46 +0000

Trending Topics



Recently Viewed Topics




© 2015