Microsoft Threat Intelligence
I'd guess the Russian Threat has a longer history than the Microsoft Threat but that neither should be a surprise to anyone.
Russian cyberspies are abusing local internet service providers' networks to target foreign embassies in Moscow and collect intel from diplomats' devices, according to a Microsoft Threat Intelligence warning. Redmond detailed the ongoing cyber-espionage campaign, active since at least 2024, and carried out by a Kremlin-backed …
"Or, use a virtual private network (VPN) service provider like a satellite-based provider, whose infrastructure is not controlled by Russia or other outside entities."
And who wouldn't trust Musk's StarLink to provide great service.... to Russia.
"Or, use a virtual private network (VPN) service provider..."
Or, to begin with, don't use Microsoft products that are notoriously hard to secure. Case in point: how did Microsoft know what went on between computers located at embassies and their local ISPs? Or am I missing something here?
Quite possibly the embassies kept logs and shared some of that data with Microsoft in order to further understand the intrusion? Or they were using some security company specifically to coordinate all of that for them, happily paying for the service in a job that is famously full of espionage?
The point is that it's disingenuous to complain/criticize the actions of a foreign "enemy" government while failing to note that your own/allied governments do the same thing, let alone to a far greater and more pervasive extent, as is straightforwardly the case with the US government and digital surveillance.
The "our glorious homeland / their barbarous wastes" cartoon isn't just a meme about hypocrisy in general, it's specifically calling out ideological hypocrisies related to nationalism and xenophobia, in situations exactly like this one.
Microsoft has had a global intercept program in play for decades. Personally I think it's why they were involved in the creation of the Cloud Act
These are all the Microsoft-in-the-middle attacks? And the same Microsoft that's about to install an OS 'feature' that screenshots every few seconds, and will send data to Microsoft so the screenshots can be OCR'd and any PII or other sensitive data stored for very vague purposes? And the same Microsoft that will presumably be complying with this-
https://www.legislation.gov.uk/ukpga/2016/25/contents
An Act to make provision about the interception of communications, equipment interference and the acquisition and retention of communications data, bulk personal datasets and other information; to make provision about the treatment of material held as a result of such interception, equipment interference or acquisition or retention; to establish the Investigatory Powers Commissioner and other Judicial Commissioners and make provision about them and other oversight arrangements; to make further provision about investigatory powers and national security; to amend sections 3 and 5 of the Intelligence Services Act 1994; and for connected purposes.
Because if Microsoft doesn't, then its Totalitarian Recall 'feature' would be outright illegal in the UK. Or TPTB are fine with it, because they can then obtain warrants to compel Microsoft to turn over any sensitive data that they've collected. I suspect we already know the answer to this one because HMG and other governments with similar legislation to the IPA haven't told Microsoft to cease & desist. And with Totalitarian Recall, it won't matter if people try to use a VPN because Microsoft will just intercept the data before it hits any tunnel.
But such is politics. Pretty much every country has legal provisions for lawful intercept in the telco licences needed to provide ISP or pretty much any communications service. This isn't a uniquely Russian issue.
Sorry, but Tom Clancy already wrote about that ages ago.
Say what you want about Clancy, but I'm pretty sure that no US embassy in Moscow would ever consider using Internet - going through a Russia-controlled provider - for anything like secure communication.
They'd use a US-controlled satellite if they wanted anything near confidentiality.
It doesn't matter who the ISP is if you're using a VPN. Don't need to go so far as to use satellite, just a VPN that will authenticate the remote side using PKE so there's no "middle" attack possible.
I suspect this attack is only being mounted against less capable countries' embassies. No way it will work on the US or any of the larger EU members unless they have criminally incompetent IT staff.
How do you connect to the VPN?
Unless you have your own dedicated wires, taking the signal all the way outside the Russian data network and never once using a Russian wire, switch or router, the VPN is just security theatre. You'd need your own trusted satellites to do it, which might be feasible for the Americans but not many others.
Do you not know the first thing about public key encryption? The only thing Russia could do to the data traversing its networks is block it. It is trivial for both sides of a connection to authenticate each other using shared secrets, so a man in the middle attack would not be possible, and it is encrypted so it can't be read.
Why do you think Russia and China ban VPNs (other than ones on their approved list, and you can guess how they get approved) if it is just "security theater"?
A rhetorical 'question set' that 'can' be answered by anyone who REALLY knows:
Question 1.
Are ALL VPN's safe to use, just because they use PKE ???
Question 2.
Can we 100% trust that current PKE is not compromised by certain entities more usually known via TLA's ???
Question 3.
Can VPN Providers, being in the middle, compromise/weaken the plus points of PKE sufficient to 'aid' the needs of Govts to 'know all' ???
Yes ... I am aware of the so called threat of 'Quantum computing' BUT as of yet it is not PUBLICALLY known if a working Quantum Computer exists that IS capable of utilising the necessary mathematical techniques to 'crack' current PKE.
:)
Depends on the approach. The 'traditional' approach of traversing the entire keyspace looking for a hit is not going to be faster on a quantum computer, but I heard there is an new algoritm for quantum systems that does allow finding a key much quicker. I have no further detail, but I wouldn't be surprised.
If we could build a real quantum computer, with several times more bits than anything we can think of building today, then https://en.wikipedia.org/wiki/Shor%27s_algorithm allows fast finding of factors, which underminds older encryption systems.
"Post quantum" systems are already in use, in your TLS stack, that don't have this flaw.
Are you sure? There is research effort currently towards post-quantum systems which are efficient enough to actually use, but I think you may be mistakenly thinking that elliptic curve Diffie-Hellman is post-quantum. That's not the case: it's still vulnerable to Shor's hidden subgroup attack. Certainly if I run `openssl ciphers -v` it doesn't list anything other than Diffie-Hellman variants and pre-shared keys.
often multiple layers of encryption. connect to a bank using https:. link is over wifi wap 3. tunneled through a vpn encrypting everything going through it. two to three layers of encryption depending on the position of the traveling packet if i'm not mistaken. has to make things hard. certificates add more security as long as they don't use md5.
We get it. USA = good. USA spies = good. Everyone else, if they do the same thing, are bad.
You really think foreign diplomats are not tracked in the USA? Or elsewhere?
It has not been forgotten that the USA spied on Merkel in her own country using equipment installed in the American embassy there.
Will MS tell us how much they assist the American regime spying on foreign diplomats? Just asking.
What on earth has your reply got to do with the point made by the commenter? We can all read the Reg and maintain an open mind, and be critical of it from time to time.
The USA is just as active at spying on both friends and enemies as anyone else. And Microsoft will facilitate if required.
You draw too many wrong conclusions from my comment. I do not despise The Register.
In days gone past, The Register would have been a little more circumspect and perhaps call out MS for hypocrisy. After all, MS is an NSA partner. How far do you think that goes? Probably every foreign diplomat who uses MS in any way is a target, and MS provides al the information they have.
In France just recently when MS admitted under oath that they would break EU law by acceding to demands from the American regime, I would not have let them off the hook. My next logical question would be: Under oath, is MS aiding and abetting or collaborating or assisting in any way spying on anyone at all in France? I can imagine the squirming from MS as they contemplate being locked up by the American regime.
In France just recently when MS admitted under oath that they would break EU law by acceding to demands from the American regime, I would not have let them off the hook.
That's just the joy of doing business in multiple countries. MS is a US corporation and therefore has to abide by US law, or risk huge fines and potentially jail time for their execs. MS also does business in France/the EU, and therefore also has to abide by French/EU law. Which then creates conflicts. So MS can create a French entity that in theory is legally distinct, but the US might disagree and apply pressure at the US parent level.. Which can then lead to diplomatic spats. It gets FUN! when some countries like Germany can have very strict data protection legislation, or 'data sovereignty' requiring German data to stay in Germany.. kinda tricky when MS datacentres were in Ireland.
One feature of embassies used to be the high frequency antenna you see on the roof. ( See https://youtu.be/ii63_EMfpBw?si=oFl6MCGK6_tqcBgJ ) Every embassy needs a reliable, secure, way to phone home such as a short wave link and while I'd guess that this has long been replaced by satellite or internet data link using an encrypted tunnel. Obviously embassy traffic is going to be of great interest to the host country so I'd be very surprised if all traffic wasn't recorded, monitored, analyzed and maybe even decoded and I'd expect the security professionals in these facilities to work on that assumption, even if the host country is 'friendly'. We've come a long way from a hundred years ago or so and the openly stated attitude in the UK was that "Gentlemen don't read each others' mail".
I'm not exactly sure what Microsoft could bring to the table that's new. One hopes that one's embassies are only using Microsoft products for stuff like managing the coffee supply, scheduling office parties and so on with the important stuff being hosted on a somewhat more secure platform.
The UK has been reading other gentlemen's mail since before the UK was a thing (see Francis Walsingham). The quote about other people's mail came from an American, before WWI.
It was the UK's habit of intercepting and reading German diplomatic traffic (a habit I hear they've taken up themselves, quite regularly) that finally brought the USA into WWI. By decrypting the Zimmerman Telegram, and then "allowing" the US to discover its content, the Brits demonstrated Germany's intent to bring Mexico into WWI on the German side, and to thereby threaten the USA's own territory, aiming to discourage the Americans from using German attacks on neutral shipping as a casus belli. When President Wilson found out, war was declared.
Ironic, eh?
That would be good if it were true. See the NSA or the CIA. It was the late Henry Stimson, in 1929, who shut down MI-8.
As for the start of WWI, it is true that Zimmerman note outraged America, but the continued attacks on US-flagged civilian vessels before & after surely were a bigger deal.
Not using Microsoft tat !
I would imagine any nation above Crappistani status would use secure channels for diplomatic communications. I know that AU DFAT system was formally verified well over a decade ago before deployment but obviously couldn't prevent the US from storing their end of an embarrassing communication on some random US army corporal's USB memory stick.
My guess the targetting is much lower - the staff using a less secure site wifi to access the normal internet rubbish. This stuff can be useful and possibly provide leverage to coerce or blackmail the staff at a later date.
It is literally the VERY first job of EVERY spy agency to spy on in-country diplomats. I believe that it was Metternich who, when a diplomat jokingly complained that he was receiving copies of his mail rather than the originals, responded "I will instruct them to be more careful."
(The second job is to set up spy networks in other countries, usually controlled from the embassy.)
It appears that the El' Reg book of style has determined that the proper term for Russians carrying executing their orders in the war is "goon". What is the term for a Ukrainian? "Defender of the Motherland in the Great Patriotic War?"
Warfighters fight wars. It is only when their individual acts go beyond the usual that such opprobrium is appropriate.
As for this particular complaint, Microsoft, you know that Russia is on the Entities List? Maybe you should just turn off all licenses there & come home. Seriously. The ruble isn't worth that much.
Not true: some countries separate spying on in-country diplomats and spying in other countries into two separate agencies. E.g. in the UK it's the job of the Security Service (formerly MI5) to do domestic espionage and counter-espionage, and they would be very upset if the Secret Intelligence Service (formerly MI6) were to try spying at home.
As for everyone mentioning a VPN--ughh, I assume you are NOT talking about a commercial VPN? Those things, all of them, are almost certainly, by law, going to have jacks hardwired to the local TLA. OTOH, it's trivial to set up an ssh server in your home country & connect to that to sftp files over. (If you need help, message me, as long as you are on considered a bad boy by the US, I have very reasonable rates)
…. bears and, er, woods. Every country spies on every other country (and have done since well before there were countries as we know them) and the working assumption is they already inside your wire. So act accordingly.
But what are people doing using random captive portals with anything other than personal devices (and even then don’t)?