Sandvine put on America's export no-fly list after Egypt used network tech for spying
(2024/02/27)
- Reference: 1709065358
- News link: https://www.theregister.co.uk/2024/02/27/sandvine_us_entity_list/
- Source link:
The US Commerce Department has blacklisted Sandvine for selling its networking monitoring technology to Egypt, where the Feds say the gear was used to spy on political and human-rights activists.
The Canadian IT appliance and software maker, along with China's Chengdu Beizhan Electronics, was added to America's Entity List, which places export restrictions on those organizations and essentially bans US companies from doing business with them without special permission from Uncle Sam. The Dept of Commerce adds outfits to the list that are deemed a threat to American national security or foreign policy interests.
Chengdu made the naughty list for apparently acquiring and attempting to acquire US goods on behalf of China's University of Electronic Science and Technology, which was already on the Entity List. Chengdu could not be reached for comment.
We take allegations of misuse very seriously
Sandvine earned its spot for supplying "deep packet inspection technology to the Government of Egypt, where it is used in mass web-monitoring and censorship to block news as well as target political actors and human rights activists," according to the Americans
When asked about these allegations, and the export restrictions, a Sandvine spokesperson told The Register the biz hopes to clear up the situation: "Sandvine is aware of the action announced by the US Commerce Department. We are committed to working closely with government officials to understand, address and resolve their concerns. Sandvine solutions help provide a reliable and safe internet, and we take allegations of misuse very seriously."
[2]Citizen Lab says Sandvine network gear aids government spyware
[3]The spyware business is booming despite government crackdowns
[4]US adds Euro spyware makers to export naughty list
[5]Uncle Sam to clip wings of Pegasus-like spyware – sorry, 'intrusion software' – with proposed export controls
The networking business has, for years, been accused of helping authoritarian regimes censor and spy on dissidents.
In 2018, Citizen Lab [6]claimed Sandvine PacketLogic devices were used to deliver nation-state malware to "hundreds" of internet users in Turkey and Egypt. The deep-packet inspection boxes, placed on the networks of Türk Telecom and Telecom Egypt, allegedly redirected users to malicious websites where they inadvertently downloaded spyware, cryptocurrency mining scripts, and other software nasties.
[7]
More recently, in September last year, Citizen Lab claimed the Canadian biz sold technology to [8]help install Predator spyware on the phone of Ahmed Altantawy, an Egyptian politician running for president.
[9]
Altantawy was the victim of a similar cyberattack in 2021 that also used Sandvine's technology, according to Citizen Lab.
Predator's developer [10]Cytrox , which is now called Intellexa, was [11]added to the Entity List in July 2023. ®
Get our [12]Tech Resources
[1] https://public-inspection.federalregister.gov/2024-03674.pdf
[2] https://www.theregister.com/2018/03/09/citizen_lab_claims_sandvine_hardware_used_to_enable_government_spyware/
[3] https://www.theregister.com/2024/02/07/spyware_business_booming/
[4] https://www.theregister.com/2023/07/18/us_sanctions_commercial_spyware/
[5] https://www.theregister.com/2021/10/20/us_intrusion_software_rules/
[6] https://www.theregister.com/2018/03/09/citizen_lab_claims_sandvine_hardware_used_to_enable_government_spyware/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zd5pmFv6RYB9IAK2HkZsugAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.thestar.com/business/technology/canadian-tech-company-allegedly-implicated-in-foreign-spying-received-millions-from-ontario-government/article_ddadd556-9836-587d-8b56-e58e9ef8c936.html
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zd5pmFv6RYB9IAK2HkZsugAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/05/27/predator_analysis_talos/
[11] https://www.theregister.com/2023/07/18/us_sanctions_commercial_spyware/
[12] https://whitepapers.theregister.com/
The Canadian IT appliance and software maker, along with China's Chengdu Beizhan Electronics, was added to America's Entity List, which places export restrictions on those organizations and essentially bans US companies from doing business with them without special permission from Uncle Sam. The Dept of Commerce adds outfits to the list that are deemed a threat to American national security or foreign policy interests.
Chengdu made the naughty list for apparently acquiring and attempting to acquire US goods on behalf of China's University of Electronic Science and Technology, which was already on the Entity List. Chengdu could not be reached for comment.
We take allegations of misuse very seriously
Sandvine earned its spot for supplying "deep packet inspection technology to the Government of Egypt, where it is used in mass web-monitoring and censorship to block news as well as target political actors and human rights activists," according to the Americans
[1]PDF
in a notice published in the Federal Register on Tuesday. The listing applies to Sandvine's Canadian head office as well as its branches in India, Japan, Malaysia, Sweden, and the United Arab Emirates.When asked about these allegations, and the export restrictions, a Sandvine spokesperson told The Register the biz hopes to clear up the situation: "Sandvine is aware of the action announced by the US Commerce Department. We are committed to working closely with government officials to understand, address and resolve their concerns. Sandvine solutions help provide a reliable and safe internet, and we take allegations of misuse very seriously."
[2]Citizen Lab says Sandvine network gear aids government spyware
[3]The spyware business is booming despite government crackdowns
[4]US adds Euro spyware makers to export naughty list
[5]Uncle Sam to clip wings of Pegasus-like spyware – sorry, 'intrusion software' – with proposed export controls
The networking business has, for years, been accused of helping authoritarian regimes censor and spy on dissidents.
In 2018, Citizen Lab [6]claimed Sandvine PacketLogic devices were used to deliver nation-state malware to "hundreds" of internet users in Turkey and Egypt. The deep-packet inspection boxes, placed on the networks of Türk Telecom and Telecom Egypt, allegedly redirected users to malicious websites where they inadvertently downloaded spyware, cryptocurrency mining scripts, and other software nasties.
[7]
More recently, in September last year, Citizen Lab claimed the Canadian biz sold technology to [8]help install Predator spyware on the phone of Ahmed Altantawy, an Egyptian politician running for president.
[9]
Altantawy was the victim of a similar cyberattack in 2021 that also used Sandvine's technology, according to Citizen Lab.
Predator's developer [10]Cytrox , which is now called Intellexa, was [11]added to the Entity List in July 2023. ®
Get our [12]Tech Resources
[1] https://public-inspection.federalregister.gov/2024-03674.pdf
[2] https://www.theregister.com/2018/03/09/citizen_lab_claims_sandvine_hardware_used_to_enable_government_spyware/
[3] https://www.theregister.com/2024/02/07/spyware_business_booming/
[4] https://www.theregister.com/2023/07/18/us_sanctions_commercial_spyware/
[5] https://www.theregister.com/2021/10/20/us_intrusion_software_rules/
[6] https://www.theregister.com/2018/03/09/citizen_lab_claims_sandvine_hardware_used_to_enable_government_spyware/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zd5pmFv6RYB9IAK2HkZsugAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://www.thestar.com/business/technology/canadian-tech-company-allegedly-implicated-in-foreign-spying-received-millions-from-ontario-government/article_ddadd556-9836-587d-8b56-e58e9ef8c936.html
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zd5pmFv6RYB9IAK2HkZsugAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/05/27/predator_analysis_talos/
[11] https://www.theregister.com/2023/07/18/us_sanctions_commercial_spyware/
[12] https://whitepapers.theregister.com/
Deep packet inspection technology
t245t
Deep packet inspection only works if the router/firewall transparently replaces the website cert with a local one. Which kind of defeats the whole point of end-to-end encryption.
Yorick Hunt
Ah, knocking off another Cisco competitor... Who's going to be next?
Pot Kettle
Yet Another Anonymous coward
Doesn't the USA sell M1 Abrams tanks to Egypt?
Obviously tanks could never be used to violate human rights
Intersting to see where the gear was sourced
Did their sales team get caught with their hand in the cookie jar? Did the sale get washed thought a shell company? Or was the box a bootleg clone? Did the company notify their countries intelligence service and give them backdoor access, and if so were they under a gag order?
Pretty much all of these have played out in different repressive regimes over the years, so we will have to see what details emerge. Sandvine is one of the old guard DPI/traffic management companies, so getting slapped on the entity list is a bit of a surprise. Wonder if we will see a follow up story about fallout for that.
Probably a few TLA's around the world that had or have their gear installed.