On The Insecurity of Telecom Stacks in the Wake of Salt Typhoon

51 points by ibotty


jbauer

Nice work by Soatok again.

At this point I think we’re more surprised when folks actually end up doing the right thing as opposed to the behaviour seen from the software vendor here. As long as some baseline of security standards and practices are not enforced by regulation, organisations primarily incentivised by money are just going to continue on doing things like this with little to no repercussion. I suppose that’s nothing new though, it’ll probably take something catastrophic for regulators to get around to it—and even then there’s no guarantee.