News Corp. Hacking Scandal Spreads To Government
wiredmikey writes "The scandal revolving around the News Corporation's now defunct British tabloid, News of the World, has entered a new phase with news that the hacking extended into areas of national security, as detectives working for the Murdoch media empire may have hacked into the computer of a government minister responsible for Northern Ireland. Scary stuff, yet the enterprise security community seems strangely quiet on the topic, aside from showing other journalists how easy it is to do. Potentially, if you know the correct mobile number and you can guess four digits, you too can be listening to your elected leaders' personal messages. The chances are pretty good that it could be their birthday."
Will a contrite Rupert Murdoch make a tearful visit to No. 10? MI5?
Really not surprised, when the people in News International (NI) were going for a story they let nothing get in their way. And the juicier the story, the more Big White Letters on the cover of NotW or Sun. Drunk with it, they were, the idea of digging where they should not and getting away with it.
Another round of review for suitability of the Murdoch Clan by stock holders? Might just be enough to dislodge the old goat and his son.
A feeling of having made the same mistake before: Deja Foobar
Alastair Campbell - (Press Secretary for Tony Blair) not someone who I would normally believe on anything. Wrote a pretty comprehensive witness statement outlining how far the problems goes and how much it affects the running of the country and to be fair he understands the media more than most. It is worth a read - http://www.levesoninquiry.org.uk/wp-content/uploads/2011/11/Witness-Statement-of-Alastair-Campbell.pdf
If this were really happening, what would you think?
About 6 years ago when this all originally flared up, it became clear people were simply not changing their default voicemail pin-codes from the network supplied default. All you needed to do was call the mobile number, listen for which operator it was that was which was responsible for the voicemail, then punch in the default pin-code for that network operator.
At the time, this caused a few MNOs to change their systems so that you could not use remote voicemail until the user had set a new pin-code other than the default. In fact, its sad that operators were not somehow made partially liable for all this in the first place!
They'll can some middle and upper middle management types, but Murdock and his cronies that created and encouraged a corporate culture of amoral lawbreakers will continue to walk off, rich and happy, after a few carefully crafted statements full of empty sentiment, and dropping more guilt on top of the scapegoats of the day.
Of course, if there was less government regulation, the field would be level, and countless competitors would exist to force Murdock's News Corp to actually be honest and... aww, damn it, I can't keep a straight face and finish that crap.
Watching the Leveson inquiry over the last couple of weeks has been one of the most depressing things I've ever done; the lowlight was probably former NOTW journalist Paul McMullen saying the following on the subject of privacy:
In 21 years of invading people's privacy I've never actually come across anyone who's been doing any good. Privacy is the space bad people need to do bad things in.
Privacy is evil; it brings out the worst qualities in people.
Privacy is for paedos; fundamentally nobody else needs it.
Basically the papers are full of amoral arseholes (Not just NI papers either, it's clear that the Daily Mail and others have been up to it as well), the Police and the ICO have been shamefully complicit and the government didn't want to look into it in case it upset Murdoch and he told his papers not to support them any more.
Makes you proud to be British really...
Social Engineering.
I hate to be the bearer of obvious news, but the DEFAULT password on everyones voicemail is usually 1234, 1111 or something. Every place I worked it was the same. Every cell carrier, landline and VoIP... they use the same default password, not random ones.
Plus there are people who have the voicemail password programmed into their cell phone. That sets the stage for hacking the voicemail without doing much at all. Just call in via a landline and try the defaults first, then try their birthday and family birthdays. You'll get most peoples PIN's this way.
The only reason there isn't large amounts of chip+pin/ATM pin fraud is because ATM's eat cards after 3 wrong answers, but if you have access to a POS system to keep trying, keep trying PIN's. Keep buying sticks of gum from gas stations and 711's until you guess the pin.
In voicemail systems, the voicemail retrieval number is easily found, and everyone STUPIDLY puts their full name in the voicemail greeting. NEVER DO THIS. Your voicemail message should not be in your voice, and should not have your full name in it. Better yet, only list the extension. The reason is that you make yourself a voicemail hacking target for social engineering by having your name on the voicemail.
Say I'm a hacker wanting to get the PIN to someone elses voicemail. I keep trying voicemail boxes until I find someone with a name that works their. Next thing I do is get ahold of the technical service desk and ask for them to reset the voicemail PIN and say I'm the person on the voicemail greeting. Oversimplified (if they're doing their job they'll ask for the employee badge number, but oh, that can be socially engineered too.)
When I worked for (CELL PHONE CARRIER), it's easy to reset passwords, just call in, verify the SSN and the password will be reset. Such horrible abuse of personal information.
When I worked for (INTERNET SERVICES), someone tried to social engineer me using the voicemail. Fortunately my name isn't easy to spell. Someone went through the phone directory and left messages asking to be called back to deal with their account. As the customer was in the US and I was not handling US customers it raised a red flag right away.
Would that be any 4 digits, or some particular ones?
Any of these particular digits: 0, 1, 2, 3, 4, 5, 6, 7, 8, 9
This post comes with a double-your-money-back guarantee!
Any offense taken to this post is at your sole discretion.
The government hacks people all the time, but I rarely see outrage about it.
Cite or STFU. That is all.
Actually, no it isn't. The government - or more correctly the police - are quite capable of getting their hands on your data easily, without resorting to "hacking" if they get a court order. They don't need to hack anything.
Besides that, Britain isn't some tin pot dictatorship (yet) where the police are basically there to do what politicians say: ministers have been tried, convicted and sentenced for a number of crimes, so they patently aren't above the law. I've no doubt, however, that they still get away with the same kinds of financial shenanigans that any rich banker or company executive does.
If God forks the Universe every time you roll a die, he'd better have a damned good memory.
Look, it's bad enough that Fox News is owned by a man who allegedly changed his nationality to get around foreign ownership laws of media outlets (how come the Aussies and Brits don't have those laws? That way he'd only influence ONE country's media).
But aren't there laws in the U.S. against the blatant use of the public airwaves to push a particular viewpoint or even "hatemongering" (just as one example: look at the number of times Fox accidentally spelled "Obama", "Osama" and mentioned his middle name "Hussein")? For a detailed look at this bias watch the documentary "Outfoxed".
Even if you were to claim that this is protected free speech (yes but not using public spectrum! Use a satellite like Howard Stern!) couldn't there be a case made for shutting the network down for the public interest? Several recent studies have shown that Fox viewers are not only less informed than viewers of other network/media, but they are less informed than people who WATCHED NOTHING AT ALL (don't know exactly the comparisons, google it).
Until then I didn't know that ignorance could be a negative value. Wow.
Of course, if there is any proof to the allegations that his company spied on Americans, perhaps some form of justice will be done.
The thing people keep ignoring in this ongoing story is how most of the "hacking" happened with the assistance of one or more people working for the government: police officers (some of them have already been nabbed for this) and political appointees, along with the standard-issue public employee bureaucrats.
The official who had his computer "hacked?" BS. He sold the information to someone, and when he got caught, he lied.
That's what happens when you give bureaucrats the power to tap phones and other private communications: they sell it to people who would get arrested for doing it, or who are too dumb to do it themselves.
It's not just NewsCorp, too - half of the tabloids in the UK have been caught in this affair.
At least a decade ago you didn't have it, and I doubt it has changed. All you need is to change your caller id to that of the phone (easy to do), then the voicemail system doesn't ask for your password. It is why you can always check your voicemail from your own phone without entering the password.
You don't need to guess any digits. You spoof the caller id to be the cell phones number. Most people don't bother with a PIN if they call voicemail from their own phone.
1 2 3 4
I randomly generate all of my passwords. http://www.xkcd.com/221/
Check out my lame java blog at www.javachopshop.com
Many countries frown upon spying on government officials, even to the extent of imposing life imprisonment or execution.
Given corporations' statuses as people, it would seem logical to try them based on the laws of the country in which they operate.
I'm not a proponent of the death penalty, so would instead ask that News Corp, if/when found guilty, simply be locked up for life, just as any other "person" would be.
I defy anyone to challenge that logical conclusion.