frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

China Read the West's Wiretaps for Years

https://shanakaanslemperera.substack.com/p/the-inverted-panopticon
4•CGMthrowaway•1h ago

Comments

123malware321•39m ago
this is quite interesting but it has some weird stuff in there which makes me doubt some of the info. I am wondering if it's missing some links (or I am) or that the info is maybe incomplete or somehow wrong.

For example, it mentions exploits for CISCO devices being a primary entry point into tap systems. makes sense, because afaik these devices hold things like tap bridges which control stuff. (not sure ofc, but some info on it was disclosed 12 years ago.. snmp tap bridges).

Then it goes on and says suddenly: "Salt Typhoon deployed a sophisticated persistence mechanism designed to survive exactly the remediation attempts carriers would eventually undertake. The primary implant, documented by Trend Micro researchers under the name GhostSpider, operated entirely in memory without touching disk, evading traditional antivirus that scans for malicious files"

Afaik, you do not install anti-virus on a CISCO switch or router, or ASA. I've never seen it. The smart install stuff is also network devices, not some kind of app on a user device. So how would anti-virus really be able to see it even if it was on the disk.

Forensic tooling might not be able to find it if its in memory (and the device was powered off... dont do this!) but that's a completely different ballpark.

Wondering if anti-virus and forensic tooling was swapped / confused, or if there is some kind of missing piece of info about a malware that this piece pertains to.

fyi, ghostspider is a windows based malware, so hence i don't see the correlation to the mentions on CISCO popping and getting into the devices that hold taps.

https://www.trendmicro.com/en_us/research/24/k/earth-estries... (mentioned a bit down on the page)

The original article the info in this one relates to https://archive.md/CgRWt#selection-4559.0-4559.257 also doesn't seem so sure about the nature of the breach. it does not mention such specific capabilities.

They mention that us lawmakers / security folks noted: "The hackers also had the ability to “record phone calls at will”, according to Anne Neuberger, who was a deputy US national security adviser at the time." which is one of the more concrete statements. This statement is completely different from 'having access to wiretaps'

As far as I know this used to be done via things like this: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6... which would be very specific access to these cisco devices (so that part _does_ seem to align, the CVE's vs. the capabilities).

It's a very interesting read and pretty well written. Definitely tickles my curiosity, but if anyone has more information related to the specific claims of accessing tap infrastructure rather than telco general infra, this would be welcome!

Waymo Seeking About $16B Near $110B Valuation

https://www.bloomberg.com/news/articles/2026-01-31/waymo-seeking-about-16-billion-near-110-billio...
1•JumpCrisscross•5s ago•0 comments

The Georgia voter data is clean

https://tilores.io/content/Is-Georgias-Voter-Data-Clean
1•Major_Grooves•26s ago•0 comments

Ask HN: What Happened to Prompt Injection?

1•dpflan•2m ago•0 comments

Semi-Autonomous Mathematics Discovery with Gemini: Erdős Problems Case Study

https://arxiv.org/abs/2601.22401
1•tzury•3m ago•0 comments

It took 5 years to merge this PR

https://github.com/matplotlib/matplotlib/pull/9598
1•alexmolas•3m ago•0 comments

LibEventCpp – Single-header library for event-driven programming

https://github.com/nguyenchiemminhvu/LibEventCpp
2•ncmv92•4m ago•1 comments

A Legal Tool for Holding ICE Agents to Account, Hiding in Plain Sight

https://www.nytimes.com/2026/02/02/us/ice-lawsuits-states.html
1•JumpCrisscross•4m ago•0 comments

Show HN: ÆTHRA – A tiny programming language for writing music as code

1•CzaxTanmay•4m ago•0 comments

See what your AI agents see while browsing the web

https://docs.blitzbrowser.com/self-hosted/live-view/
1•sam_march•5m ago•0 comments

Mercury Banking Is Down

https://status.mercury.com/
1•IG_Semmelweiss•7m ago•0 comments

Indian GOVT, RBI in Talks with Alipay+ 2B LINKED2INDIA'S Digital Payments System

https://twitter.com/REDBOXINDIA/status/2018243381286371575
1•koolhead17•7m ago•0 comments

AI MIDI Generator and Editor (Cursor for Music)

https://www.muse.art/home
1•rcarmo•7m ago•0 comments

Is your SaaS going to survive?

https://zainhoda.substack.com/p/is-your-saas-going-to-survive
1•zainhoda•9m ago•0 comments

Resist and Unsubscribe

https://www.resistandunsubscribe.com
2•mooreds•10m ago•0 comments

Proton's new Mail mobile apps: there's more than meets the eye

https://proton.me/blog/next-generation-proton-mail-mobile-apps
1•samuel-freeman•11m ago•0 comments

China's Loongson 3B6000 Benchmarks

https://www.phoronix.com/review/loongson-3b6000-loongarch
2•csmantle•12m ago•0 comments

The rise of one-pizza engineering teams

https://www.jampa.dev/p/the-rise-of-one-pizza-engineering
2•jampa•13m ago•0 comments

Show HN: Context9 – A private-first Knowledge MCP for real-time local doc sync

https://github.com/Prism-Shadow/context9
1•PrismShadow•13m ago•0 comments

Wikipedia Faces a Generational Disconnect Crisis

https://spectrum.ieee.org/wikipedia-at-25
1•purplekohav•14m ago•1 comments

Show HN: ThorVG 1.0 – Fast vector rendering with Lottie and GPU back ends

https://www.thorvg.org/post/thorvg-v1-0-a-new-generation-released
7•hermet•15m ago•2 comments

There's a social network for AI agents, and it's getting weird

https://www.theverge.com/ai-artificial-intelligence/871006/social-network-facebook-for-ai-agents-...
1•ColinWright•15m ago•0 comments

Better Images of AI

https://betterimagesofai.org/
1•jruohonen•15m ago•0 comments

Show HN: Open Deep Research that beat Big Tech now self-verifies claims

https://github.com/IamLumae/Project-Lutum-Veritas
1•LutumVeritas•17m ago•0 comments

Immuable, a full-fledged operating system in OCaml to serve a website

https://github.com/dinosaure/immuable
1•dinosaure•17m ago•0 comments

Gap: Give AI agents secure access to your accounts – without sharing credentials

https://github.com/mikekelly/gap
1•AffableSpatula•17m ago•0 comments

Skin-conformal ultrasonic sensor for cuffless blood pressure sensing

https://www.nature.com/articles/s41378-025-01110-2
1•PaulHoule•19m ago•0 comments

World Language Families

https://dr.eamer.dev/datavis/poems/language/tree.html
1•speckx•19m ago•0 comments

Google accused of aiding IDF aerial footage analysis

https://www.jpost.com/israel-news/article-885271
1•bhouston•21m ago•0 comments

No One Knows How Many Deadly Air Bags Are on U.S. Roads

https://www.wsj.com/business/autos/no-one-knows-how-many-deadly-air-bags-are-on-u-s-roads-46ec160c
1•bookofjoe•21m ago•1 comments

Show HN: Authnkey – Android credential provider with FIDO2 support via NFC

https://github.com/mimi89999/Authnkey
1•wegwerf_4783247•24m ago•0 comments