News: 1627533269

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Over 100 Taiwanese political figures' messages leaked outta LINE app

(2021/07/29)


Law enforcement agencies in Taiwan are investigating a cyberattack on over 100 local political figures and dignitaries who used the messaging app LINE.

A [1]statement issued Wednesday by LINE confirmed the attack and stated the company took measures to protect its users and reported the incident to relevant law enforcement agencies.

"LINE has been actively and cautiously fighting against global cybercrimes and attacks," the statement reads, adding "Data security and user privacy is one of our most important issues, and we will continue to take necessary responses to this incident."

[2]

Taiwanese news outlet [3]Liberty Times reported that LINE's Taiwan Headquarters discovered user content, mainly pertaining to politicians and officials, had been extracted last week.

[4]

The attack worked by turning off " [5]Letter Sealing " encryption functions on the targeted users' accounts.

[6]Tencent suspends signups to WeChat, citing 'security upgrade' and need to comply with Chinese laws

[7]Early Skype developer Jaan Tallinn splashes cash in latest funding for Matrix-based instant messenger Element

[8]SolarWinds backdoor gang pwns Microsoft support agent to turn sights on customers

[9]We've been shown time and again that strong encryption puts crims behind bars, so why do politicos hate it?

LINE, the most popular instant messenger and online call service in Taiwan, advised concerned users to check that the Letter Sealing function was activated on their app. When on, [10]the function encrypts text messages, location information and voice and video calls.

This incident is not the first time LINE's security has been brought into question. In March, [11]infosec concerns led Japanese government officials to stop using the app when it was found that Chinese contractors had access to personal data. ®

Get our [12]Tech Resources



[1] https://linecorp.com/zh-hant/pr/news/zh-hant/2021/3841

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQJ8NzmrCAp64oWaTBZW3AAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://news.ltn.com.tw/news/politics/paper/1463246

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQJ8NzmrCAp64oWaTBZW3AAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://help.line.me/line/ios/pc?contentId=20004441

[6] https://www.theregister.com/2021/07/28/tencent_suspends_new_wechat_accounts/

[7] https://www.theregister.com/2021/07/27/element_seriesb_thirty_million_pounds_funding/

[8] https://www.theregister.com/2021/06/26/in_brief_security/

[9] https://www.theregister.com/2021/06/14/kiloscrote_nab_strong_encryption/

[10] https://help.line.me/line/?contentId=50000087

[11] https://www.theregister.com/2021/03/24/line_blocks_china_server_access/

[12] https://whitepapers.theregister.com/



Get that encryption outta here!

Anonymous Coward

Firstly, "outta" in a headline not otherwise impersonating colloquial speech? Whatcha playin at Reg?

Secondly, the real security vulnerability is being able to turn off encryption in the first place. Why would such an option exist?

On a tous un peu peur de l'amour, mais on a surtout peur de souffrir
ou de faire souffrir.
[One is always a little afraid of love, but above all, one is
afraid of pain or causing pain.]