frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AT&T, Verizon blocking release of Salt Typhoon security assessment reports

https://www.reuters.com/business/media-telecom/senator-says-att-verizon-blocking-release-salt-typhoon-security-assessment-2026-02-03/
75•redman25•1h ago

Comments

delichon•1h ago

  Put not your trust in bloody princes, they can plead expedience. -- James Clavell, Gai-Jin

If I had an internal report on my network's vulnerabilities a senator would be one of the last people I'd voluntarily share it with.
ungreased0675•53m ago
These companies were required by the government to have lawful intercept capability. A bad actor took advantage of that government-required backdoor, and now the government has the shamelessness to grandstand about privacy and security? We need to elect better people.
dmix•48m ago
Is this speculation or has that information come out already?
medina•46m ago
https://www.commerce.senate.gov/2025/12/experts-agree-u-s-co...

> “The Chinese government's espionage operation deeply penetrated networks of at least nine U.S. telecom companies, including AT&T and Verizon,” said Sen. Cantwell. “They exploited the wiretapping system that our law enforcement agencies rely on under the Communications Assistance for Law Enforcement Act -- known as CALEA. These systems became an open door for Chinese intelligence. Salt Typhoon allowed the Chinese operation to track millions of Americans’ locations in real time, record phone calls at will and read our text messages.”

dmix•31m ago
That definitely deserves a congressional investigation then. No wonder they don't want to talk about that.
xnx•29m ago
This quote speaks in past tense, but last I heard the Chinese still had access/control of compromised systems. Do we know if this attack is even over?
gruez•25m ago
>and now the government has the shamelessness to grandstand about privacy and security? We need to elect better people.

Where's "the government [... grandstanding] about privacy and security"? It's getting blocked by the companies, not the government.

>She said Mandiant refused to provide the requested network security assessments, apparently at the direction of AT&T and Verizon.

observationist•13m ago
"US Senator says AT&T, Verizon blocking release of Salt Typhoon security assessment reports"

A US senator is using it for political grandstanding. She is an ineffective twit with no power and no principles, no right under law to receive what she demanded, and she made sure to run to the press with it "see! look, I'm a principled, powerful senator holding those evil corporations feet to the fire!"

The problem is that the vulnerability exploited by salt typhoon is a systemic flaw implemented at the demand of Cantwell and other of our legislative morons.

You cannot have an "only the good guys" backdoor. That doesn't work. People are bad, and stupid, and fallible. You can't make policy or exceptions that depend on people being good, and smart, and infallible.

She's using the inevitable consequence of a system she helped create for her own political benefit. She voted for the backdoor back in 94 against the strenuous and principled objections by people who actually know what they're talking about.

Bobblehead talking points should not serve as the basis for technical policy and governance, but here we are.

SunshineTheCat•18m ago
I agree with you on electing better people, but this is largely a systematic problem with how government works:

1. Propose bill to solve a problem which is either minor or completely misunderstood by the person proposing the bill 2. Pass bill, don't solve original "problem," creates 15 new, actual problems 3. Run on fixing all the new problems they created (and some others that don't exist) 4. Repeat

maltalex•17m ago
The problem isn't the back door. Every telecom company in every country provides access for "lawful intercept". Phone taps have been a thing for decades and as far as I know, require a warrant.

The problem is that telecoms are very large, very complex environments, often with poor security controls. Investing in better controls is hard, time-consuming and expensive, and many telecoms are reluctant to do it. That's not great great since telcos are prime targets for nation state hackers as Salt Typhoon shows.

Hacking the lawful intercept systems is very brazen, but even if the hackers didn't don't go as far, and "only" gained control of normal telco stuff like call routing, numbering, billing, etc. it still would have been incredibly dangerous.

ok123456•51m ago
If they simply implicated an "APT" in wrongdoing, they would have released it, as it would have been unremarkable and fit neatly within the Overton window of hissing-chinese spys justifying an even more expansive national security apparatus and general anti-sino sentiments among the ruling class in Washington.

This leads me to two possible, non-exclusive outcomes: the links to China are tenuous, and the attribution is flimsy (e.g., they accessed a machine at 9 am Beijing time!); or the report implicates the system itself as unauditable by design, which was bound to happen given the design of the intercept tools.

walletdrainer•5m ago
These reports would be useful for any other attacker interested in their infra, it’s obvious why the companies wouldn’t want to release them in this manner.
chaps•2m ago
Once had a call with Comcast's CISO after I found one of their sysadmin's home directories on github. The conversation was about whether they should give me a bounty.

They told me in no unclear terms that if they made a bug bounty program, they'd go bankrupt trying to pay all the bounties.

ISPs love to cover their eyes, ears and nose.

Building an AI voice agent from scratch

https://www.ntik.me/posts/voice-agent
1•nicktikhonov•29s ago•1 comments

Memory-Safe Jule language emerges as C/C++ alternative

https://thenewstack.io/jule-open-source-programming-language/
2•maxloh•2m ago•0 comments

Rejourney Achieves 12 ms Main Thread time with 3x Frame Rate

https://rejourney.co/engineering
2•mrashiddev•2m ago•0 comments

Structural differences found in brains of people with panic disorder

https://medicalxpress.com/news/2026-02-differences-brains-people-panic-disorder.html
1•Brajeshwar•2m ago•0 comments

Manufacturing as Code Is the Future, and the Future Is Now

https://blog.makerrepo.com/blog/2026/01/12/manufacturing-as-code-is-the-future/
1•fangpenlin•2m ago•0 comments

Medieval Widowhood

https://medievalmarginalia.substack.com/p/on-medieval-widowhood
1•dmazin•5m ago•0 comments

Show HN: BB – A persistent message broker for AI agents (MCP, Ed25519, Matrix)

https://bb.org.ai/
2•lthms•7m ago•0 comments

AirPods Pro 4 Could Feature Cameras to 'See Around You'

https://www.macrumors.com/2026/02/09/airpods-pro-4-could-feature-cameras-to-see-around-you/
2•geox•7m ago•0 comments

Safe Drinking Water Is a Basic Human Right That Texas Prisons Fail to Respect

https://truthout.org/articles/safe-drinking-water-is-a-basic-human-right-that-texas-prisons-fail-...
3•wahnfrieden•8m ago•1 comments

Show HN: AI agents play SimCity through a REST API

https://hallucinatingsplines.com
1•aed•9m ago•0 comments

Flotilla: A Discord Alternative Built on Nostr

https://flotilla.social/
2•jonstaab•9m ago•1 comments

Asweraetsytrhxgf

https://gist.github.com/jewe8ham
2•horegsounfra•11m ago•0 comments

Signing JSON Web Tokens: Algorithm Tradeoffs, Performance, and Security

https://ciamweekly.substack.com/p/signing-json-web-tokens-algorithm
1•mooreds•12m ago•0 comments

Show HN: Clelp – A searchable directory of 1,700 AI skills, rated by AI agents

https://clelp.ai
1•jhaugh•14m ago•0 comments

Coolnewapps.com – A place to submit and browse freshly launched apps

https://www.coolnewapps.com/submit
1•avirflux•14m ago•0 comments

A Sigmoid Dialogue (2014) [pdf]

https://aleph.se/papers/A%20Sigmoid%20Dialogue.pdf
1•ath_ray•14m ago•0 comments

Scrapoxy – End of Life

https://scrapoxy.io/
1•mobilio•14m ago•0 comments

Appeal to Meta Leadership on Account Deletions in Russia [video]

https://www.youtube.com/watch?v=2YYHhD7DNZs
1•alexandrutocar•15m ago•0 comments

Towards Understanding What State Space Models Learn About Code

https://arxiv.org/abs/2602.06774
1•belter•17m ago•0 comments

Show HN: OpenMessage – Google Messages Client for macOS with MCP Server

https://openmessage.ai
1•MaxGhenis•17m ago•0 comments

Ask HN: Do provisional patents matter for early-stage startups?

2•gdad•18m ago•0 comments

The Cost of Truth

https://www.samrian.com/blog/cost-of-truth
1•Abdulhafiz_F•21m ago•1 comments

Show HN: Self-hosted WhatsApp archive viewer with chat analytics

https://github.com/sabrieker/whatsapp-archive
1•sabri_eker•21m ago•0 comments

JSONata: A JSON query and transformation language

https://jsonata.org/
1•fanf2•21m ago•0 comments

Vibe coding an RSS feed – how hard can it be?

https://blog.fortrabbit.com/vibe-coding-an-rss-feed/
1•esher•21m ago•0 comments

Writing an LLM from scratch, part 32a – Interventions: training a baseline model

https://www.gilesthomas.com/2026/02/llm-from-scratch-32a-interventions-baseline-model
1•ibobev•23m ago•0 comments

Why Is the Sky Blue?

https://explainers.blog/posts/why-is-the-sky-blue/
2•udit99•23m ago•0 comments

Writing an LLM from scratch, part 32B – Interventions: gradient clipping

https://www.gilesthomas.com/2026/02/llm-from-scratch-32b-interventions-gradient-clipping
1•ibobev•24m ago•0 comments

Child internet safety campaign accused of censoring teenagers' speeches

https://www.theguardian.com/technology/2026/feb/08/childnet-internet-safety-campaign-accused-cens...
2•beardyw•24m ago•0 comments

Writing an LLM from scratch, part 32c – Interventions: removing dropout

https://www.gilesthomas.com/2026/02/llm-from-scratch-32c-interventions-removing-dropout
1•ibobev•24m ago•0 comments