Experts spoke about a possible violation of communication security in the modern world
- Новости
- Society
- Experts spoke about a possible violation of communication security in the modern world
Retired FSB Major General, Candidate of Law Alexander Perelygin told Izvestia on June 2 that modern smartphones are special technical means of capturing information, and Western companies "hold" key positions in this area. In this regard, these corporations have the opportunity to directly interfere with their performance.
According to Alexander Baranov, a member of the Russian Academy of Cryptography, Doctor of Physico-Mathematical Sciences, communication security in modern realities can be compromised despite the use of end-to-end encryption protocols. The specialist explained that popular services declare the principle of end-to-end encryption, in which public keys are generated directly on subscribers' devices. However, in practice, it is possible to implement a "meeting in the middle" scheme.
"One subscriber does not contact another subscriber, but in the middle with the server, <...> then this information can be opened on the server, and then further transmitted, closed again and transferred to another subscriber," Baranov said.
He added that with this architecture, the server located between the interlocutors is able not only to access the transmitted information, but also to adjust or supplement it during the broadcast.
Kaspersky Lab told Izvestia that attackers use infected mobile devices as powerful data collection platforms capable of recording sound, video and tracking the movements of the owner. According to Igor Kuznetsov, director of the company's global research center, after the device is compromised, the virus turns into a regular application that executes commands from management servers.
"Most of the time, the program that is installed on the phone does not have any clear business logic. She only performs a set of actions that those who control her have requested from her. There are additional modules, such as for audio recording or video recording. But if we look globally at what attackers can potentially do, we need to consider a smartphone, any mobile device, simply as a platform with sensors," the laboratory said.
Despite the hardware limitations of microphones, criminals use specialized filter programs to clean and decrypt the received audio. According to the expert, if it is difficult for an ordinary person to make out recordings made from a pocket, then intruders have tools to improve the sound quality.
The malware also allows you to remotely activate any of the device's cameras for covert video recording.
"The device started recording audio for the next three hours, and it didn't matter if the phone was online, if it had Internet or not.: as soon as the phone was connected, the audio recording was sent to the attacker's server. We started looking and found that all these devices were Apple products," Kuznetsov said about one of the cases of spyware detection.
On the same day, the FSB Central Control Center reported that a large-scale scheme of foreign intelligence agencies to introduce malicious software onto the mobile devices of high-ranking employees had been uncovered in the Russian Federation. It was noted that the purpose of the campaign was to collect data, listen to conversations, as well as conduct acoustic and video monitoring of the situation.
To implement the scheme, the technical capabilities of large international IT corporations had to be used. Presumably, the United Kingdom, the United States, and Canada may be involved.
Переведено сервисом «Яндекс Переводчик»