German defense chat overheard by Russian eavesdroppers on Cisco's WebEx
- Reference: 1709574315
- News link: https://www.theregister.co.uk/2024/03/04/germany_confirms_russia_leak_genuine/
- Source link:
Senior government officials have also confirmed Russian reports that the call was hosted on and tapped via Cisco's WebEx video conferencing platform rather than any kind of secure, military-grade comms.
Roderich Kiesewetter, deputy chairman of the German parliament's oversight committee, [1]said the Bundeswehr leak was possibly caused by a Russian agent inside the [2]WebEx call or the Bundeswehr's implementation of it, but the country is still working on discovering how the intrusion took place.
[3]
Likewise, the ministry released a statement to wider media saying: "According to our assessment, a conversation in the air force division was intercepted. We are currently unable to say for certain whether changes were made to the recorded or transcribed version that is circulating on social media."
[4]
[5]
Cisco has distanced itself from the situation. A spokesperson told The Register : "Cisco does not publicly discuss customer information and we refer your request to the organization in question."
The 38-minute recording was first published by Margarita Simonyan, editor-in-chief at the Russian state-controlled RT news outlet, and has since been shared widely online. It was supposedly handed to her by "sources" in Russian intelligence.
[6]
RT said it identified two of the four German military officials on the call, including the head of Air Force Operations Brigadier General Frank Graefe, and Air Force Chief Lieutenant General Ingo Gerhartz.
RT has since made a number of claims after publishing the call, including that the conversation provides proof that Germany was planning to help Ukraine to destroy the Kerch Bridge that connects Russia to the illegally annexed Crimea.
Discussions also involved a potential delivery of Taurus long-range missiles to Ukraine for use in the attacks and how Germany could supply these without appearing to be directly involved in the conflict.
[7]
Taurus missiles have a range of around 310 miles, far greater than the Storm Shadow cruise missiles supplied to Ukraine by the UK, which have a range of around 155 miles.
Ukraine has long asked Germany to deliver Taurus missiles, but Chancellor Olaf Scholz has repeatedly declined to do so out of fears that the [8]ongoing conflict could escalate.
[9]Ukraine claims Russian military is using Starlink
[10]Iran's cyber operations in Israel a potential prelude to US election interference
[11]Legacy tech shoots down Ministry of Defence's supply chain improvements
[12]Businessman faces 20 years in prison over accusations of illicit chip exports to Russia
Kiesewetter told broadcaster ZDF that more recordings are likely to have been intercepted and could well be released at a later date, all to Russia's benefit.
It's likely the recent release was designed to pressure Germany to drop talks over Taurus missile deliveries.
On Friday, Dmitry Medvedev, deputy head of Russia's Security Council, said via Telegram: "After all, our eternal opponents – the Germans – have again turned into sworn enemies."
"Germany is preparing for war with Russia," he said in a second message on Sunday, both of which were lengthy and included several Nazi-themed slurs against the German military.
Maria Zakharova, spokesperson for Russia's Foreign Ministry, said Germany must "promptly" explain the nature of the audio, adding that a failure to respond will be seen as an admission of guilt.
Scholz said on Saturday that the leak was "a very serious matter" and is now being investigated thoroughly and quickly.
Asked about developments in the investigation, the Bundeswehr told The Register it had nothing further to add, but pointed to defense minister Boris Pistorius's comments on Sunday, calling the leak an act of "information war."
"It is a hybrid disinformation attack. It is about division. It is about undermining our unity," he said. ®
Get our [13]Tech Resources
[1] https://twitter.com/ARD_BaB/status/1764243289576730689
[2] https://www.theregister.com/2023/06/02/cisco_webex_audi_collaboration/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZeZSlysy6rWQvqHIi9piiQAAAYA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeZSlysy6rWQvqHIi9piiQAAAYA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeZSlysy6rWQvqHIi9piiQAAAYA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeZSlysy6rWQvqHIi9piiQAAAYA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeZSlysy6rWQvqHIi9piiQAAAYA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2023/06/01/ukraine_romcom_malware/
[9] https://www.theregister.com/2024/02/12/russian_military_starlink_claims/
[10] https://www.theregister.com/2024/02/07/irans_cyber_operations_in_israel/
[11] https://www.theregister.com/2024/01/23/mod_supply_chain/
[12] https://www.theregister.com/2024/01/19/russia_chip_exports_arrest/
[13] https://whitepapers.theregister.com/
Re: Why?
But the last time the Germans used mil-grade encrypted comms it also went rather badly.
Although if there is one outfit that should have learned the lesson of not trusting your military comms is secure - it's the chaps in Berlin in pointy helmets
Re: Why?
It is weird. There is the BSI which produces bulletins on information security and companies in certain industries that are part of the critical infrastructure are required to follow the relevent information security bulletins. Hard to see Cisco's publically available WebEx getting a pass on this, not just for the hand "dial-in" feature, but also the guaranteed backdoor for friend and ally the USA and its collection of TLAs. Really, the work for secure end-to-end encryption calls has been done and at least two open source products are available and approved for use in Germany…
But the Bundeswehr, along with many armies around the world, is famed for out of date kit and IT practices.
Re: Why?
>But the Bundeswehr, along with many armies around the world, is famed for out of date kit and IT practices.
The Brits have some unbreakable cypher machines to sell them
Re: Why?
What, us? The country of government by Whatsapp?
Re: Why?
Specifically the country that sold all her post-war allies these unbreakable German enigma machines that they had been totally unable to break
Thank God!
They didn't overhear the conversation about what Russian cell phone number, when called, detonates the nuclear warhead secreted in the Kremlin.
Huh?
"It is a hybrid disinformation attack. It is about division. It is about undermining our unity," he said.
And yet it's been confirmed, at least in part. Plus there's some more interesting stuff, like apparently one of the participants was calling in from a Singapore hotel room. And early in the call, participants mentioned sending files via WhatsApp. But the conspiracy theories and disinformation is flying. Some suggest a German leaked this to try and stop Germany doing something stupid. Or an allied nation leaked it for mentioning foreign boots on the ground already.
Or maybe there's some previously unknown vulnerability (or backdoor) that allows people to locate and invisibly join calls that are booked, or are in progress. Methinks this one could get fun as ideally, you'd need some way of knowing the call was happening, ie the participants diaries/schedules were also compromised.. Which could be a much bigger threat.
But other than plotting how to involve the UK in a war crime, one of the aspects was something I'd been wondering about. Taurus is an ALCM, Ukraine doesn't have much in the way of 'A'. So mentioned the number of Su-25s had left, and how they'd need modifications taking months. I guess Russia may try to reduce the number of Su-25's even further.
Re: Huh?
"Or maybe there's some previously unknown vulnerability (or backdoor)"
It's Cisco, of course it's a backdoor, don't you ever read Cisco's CVE entries for authentication bypass after authentication bypass.
Stop buying Cisco shite
Re: Huh?
NSA, CIA, FBI all have keys…
Re: Huh?
Yes, the "misinformation" confirmed as authentic by the German government... Yes that one... Apparently misinformation means "anything inconvenient should the unwashed masses learn of it".
Also, how is referring to the German military with Nazi terms such a slur? They're the ones sending Panzers to burn on the Don steppe... again.
... again
Was that before or after the Soviets allied with the Nazi's, which they did from September 17, 1939 until June 22, 1941?
Re: ... again
which they did from September 17, 1939 until June 22, 1941?
Bad troll. In a modern day context, it's perhaps more interesting that the descendents of actual Nazis are reuniting once again to kill Russians and start a new world war. Some in Ukraine are even flying the same flags and wearing the same insignia. Never again?
Re: ... again
Still repeating Putin's lies about Ukrainian "Nazis" like Zelenskyy. Nevermind that he's Jewish!
Are there nazis in Ukraine? Sure, just like there are in Russia, the UK, the US, and many other places. Would you back Russia attacking the UK to "de-nazify" it? There are probably a lot more nazis in Russia than anywhere else...
Re: ... again
Don't feed the trolls.
Re: ... again
Still repeating Putin's lies about Ukrainian "Nazis"
Those that ignore history are condemned to repeat it. Ukraine's red & black flag, their Galacian division, Azov, Right Sector etc etc. The last being a bit interesting given Yarosh has been hinting at coups again. But I'll just leave this here-
https://www.bbc.co.uk/news/av/43632454
Two reasons to use non-military comms in my experience.
1 - milcoms don't work well enough: UK troops in Bosnia relied heavily on Nokia analogue mobiles because the milcoms weren't reliable enough - usually due to flat or dead batteries.
2 secure milcoms are a bit of a pain and the more senior you are the less pain you can be bothered with. Have to wait for the crypto to be keyed before you make that call? - just use an open channel and speak in "code". Have to walk over to a different part of the compound to send that secure message? - too much effort, use a mobile phone. Have to log in to your MoD PC to join a secure video call? - can't because it's got a proper secure password which I can't be arsed to learn and anyway it's not been charged for ages and I don't know where the 2FA fob is so we'll just do it on zoom and be careful what we say.
Wasn't there a more recent German politician who 'encrypted' his comms at Eu meetings by speaking to his colleagues in a Bavarian(?) accent
The SIPRNet protocols were not ignored
@ [1]Mike 137 : “ the SIPRNet protocols were ignored when Chelsea Manning was exfiltrating the Wiki Leaks files. ”
Manning burned the files to a DVD on a SIPRNet terminal.
[1] https://forums.theregister.com/forum/all/2024/03/04/germany_confirms_russia_leak_genuine/#c_4822374
Paranoia Is Mandatory In 2024!!
The Americans were listening in to Angela Merkel's phone.
The British were listening in to Belgian telecoms (targets unknown).
The NSA is istening in to almost any voice communication in the USA (and maybe elsewhere too).
Oh......and then there's a long tradition of Fort Meade "influencing" the design of Cisco equipment.
So why is anyone surprised when we learn that the Russians have figured out some of the Fort Meade "enhancements" to Cisco products?
....and not just WebEx!!!!
Quote (William Burroughs): "The paranoid is a person who knows a little of what is going on."
Why?
" the call was hosted on and tapped via Cisco's WebEx video conferencing platform rather than any kind of secure, military-grade comms "
There's almost certainly a standard somewhere that requires mil-grade comms for secret conferencing. Why not use it? I suppose for the same reason that the SIPRNet protocols were ignored when Chelsea Manning was exfiltrating the Wiki Leaks files. Standards are fine, but they have to be followed -- particularly where potential international conflict is being discussed.