China May Be Reading Your Emails

A recent academic report claims that China has been routinely and systematically hijacking internet traffic from the United States, Canada, Europe and other countries through security flaws in the deep structure of the internet. 

To put it simply, somebody in Beijing may be receiving and reading your emails before you do, as well as capturing your passwords and other personal data from websites you visit.

China’s Maxim – Leave No Access Point Unexploited: The Hidden Story of China Telecom’s BGP Hijacking,” by Chris C Demchak of the US Naval War College and Yuval Shavitt of Tel Aviv University. 

The report alleges that a voluntary US-China 2016 agreement, which aimed to stop military forces from hacking commercial enterprises for economic gain, has appeared to reduce Chinese Internet theft against western targets. 

However, as the report also notes, China’s technological development still continues to be “dependent on massive expropriation of foreign R&D.”

An ‘innocuous player’

As Chinese companies such as Huawei and ZTE are viewed with suspicion in the West, the Chinese government has chosen what the researchers call “a seemingly innocuous player” to reroute, or hijack, internet traffic. The so-called “innocuous player” is state-owned China Telecom, a telecoms giant with close to 300,000 employees.

To understand how China Telecom has been able to divert internet traffic to China and copy it, as the report claims, it is necessary to delve briefly into the obscure world of the internet’s foundational infrastructure.

Essentially, China Telecom has numerous Points of Presence (PoP) in the US and Europe. Think of a PoP as a delivery system that ensures that “packages” sent via the internet reach their intended destinations as efficiently as possible. They are delivery services that connect all the smaller networks that comprise the overall internet.

The small networks are called autonomous systems and could be anything from banks and tech giants to your local Internet Service Provider.

On the other hand, overseas telecoms are barred from operating PoPs in China. The country has just three gateways, in Beijing, Shanghai and Hong Kong. This protects China’s domestic traffic from foreign hijacking.

Meanwhile, enter Border Gateway Protocol (BGP), the key Internet routing protocol for connecting the innumerable autonomous systems that comprise the internet.

Insecure protocol

“BGP is a notoriously insecure protocol used to route internet traffic,” comments Cory Doctorow, a respected technology pundit. Doctorow continues: “By design it is dynamic and responsive, moving traffic away from congested routes and onto those with more capacity: this flexibility can be exploited to force traffic to route through surveillance chokepoints.”

BGP was developed in 1989 – when the internet was generally perceived as an emergent technology bringing the world closer together. It was also the same year that the internet first began to be used in China. In fact, the country did not start to fully implement the internet, and on a negligible scale, until 1994, when China was still widely regarded as a benign backwater.

China is rightly no longer regarded as benign or a backwater, and its hijacking activities are difficult to detect. China Telecom has multiple points of presence (PoPs) in North America and Europe and rerouting traffic via ultra-fast fiber-optic cables causes delays to be almost unnoticeable.

All the same, the report is not exactly news. BGP exploits are probably more common than is largely realised and are probably used by all state players capable of doing so, notably Russia.

But China is regarded as a particularly egregious player. In 2010, for example, the US-China Economic and Security Commission reported to the US Congress on such “hijacks” in a 300-page report that included information on an incident in which 15% of global Internet traffic suddenly started to pass through Chinese servers en-route to its intended destinations, according to Ars Technica, a technology-focused news website.

Malicious Intent 

This would be less problematic if all internet traffic were highly encrypted. Unfortunately, some of it is not. But as the researchers also note: “If diverted and copied for even small amounts of time, even encrypted traffic can be broken.”

In the meantime, the attacks continue and will likely continue to do so. The researchers describe the hijacks as “repetitive,” suggesting “malicious intent.”

Events documented by the report include a six-month period from February 2016, when traffic from Canada to South Korea was “hijacked by China Telecom and routed through China” and a similar incident in which traffic from several locations to the US to “a large Anglo-American bank headquarters in Milan, Italy was hijacked by China Telecom to China.”

If there is any key takeaway from reports such as this, it is that the internet, which has revolutionised modern life, was built on trust. We now live in untrusting times.

Asia Times:

You Might Also Read:

China Compromises Tech Companies With Malicious Microchips

« Why Has The US Not Been Hit With A Devastating Cyber Attack?
China Has “taken the gloves off” In Hacking Attacks »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CSR Privacy Solutions

CSR Privacy Solutions

CSR Privacy Solutions is a leading provider of privacy regulatory compliance programs for small and medium sized businesses.

Avansic

Avansic

Avansic is a leading provider of e-discovery and digital forensics services to attorneys, litigation support teams, and business communities.

Romanian Association for Information Security Assurance (RAISA)

Romanian Association for Information Security Assurance (RAISA)

RAISA promotes and supports information security activities and creates a community for the exchange of knowledge between specialists, academic and corporate environment in Romania.

Sqreen

Sqreen

Sqreen is a web application security monitoring and protection solution helping companies protect their apps and users from attacks.

exceet Secure Solutions

exceet Secure Solutions

exceet Secure Solutions is your experienced specialist for Internet of Things (IoT), Heath Telematics, electronic signatures and timestamps and IT security.

Anect

Anect

Anect is a leading provider of ICT security and services for hybrid and cloud solutions.

ISEC7 Group

ISEC7 Group

ISEC7 Group is a global provider of mobile business services and software solutions. The company was one of the first movers in mobilising company and business processes.

Nextcloud

Nextcloud

Nextcloud offers offers solutions to the combined need of security and ubiquitous access to data and collaboration technology.

Fortress Information Security

Fortress Information Security

Fortress Information Security is one of the largest cyber security providers of supply chain risk management and vulnerability risk management in the US.

DataPassports

DataPassports

DataPassports is a data-centric security and privacy solution that enforces privacy and security from end-to-end with transparent protection of data at the source.

SAIFE

SAIFE

SAIFE has adapted a Software Defined Perimeter approach and paired it with a Zero Trust model that defines access by the user, their device, and where they are located.

Internet 2.0

Internet 2.0

Internet 2.0 is a Cyber Security technology company with a core focus on developing affordable but sophisticated cyber security solutions.

LogicalTrust

LogicalTrust

LogicalTrust security testing specialists find the weakest points in your company and show you how to fix them step-by-step, as well as how to improve your security.

KnoTra Global

KnoTra Global

KnoTra Global is a next-generation Managed Service provider with a portfolio of services including Cybersecurity Solutions, Network Management, IT Leadership, and Day-to-Day Helpdesk and IT services.

Hack-X Security

Hack-X Security

Hack-X Security provide IT risk assessment and Digital Security Services. We are a trusted standard for businesses that must protect their data from cyber-attacks.

FatPipe Networks

FatPipe Networks

FatPipe’s network optimization solutions along with robust native security and SASE-based protection provides organizations all they need for super network performance and security.