Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

China Hacked America's Surveillance System. The Backdoor Was the Front Door.

In 1994, the US government required every American telecom carrier to build a surveillance backdoor into its network. In 2026, China's Ministry of State Security used that backdoor to compromise the FBI's wiretap system, access the identities of active surveillance targets, and harvest metadata from more than a million Americans. Nine carriers breached. One "major incident." Thirty-two years of warnings vindicated in a single intrusion. The mandated backdoor was not a security feature. It was the attack surface.

February 17: Inside the wiretap

On February 17, 2026, network security analysts inside the Federal Bureau of Investigation detected abnormal activity in a system called DCS-3000, known internally as Red Hook. It is an unclassified component of the Digital Collection System Network — the FBI's centralized platform for managing court-authorized wiretaps and surveillance orders issued under the Foreign Intelligence Surveillance Act across American telecommunications carriers. Red Hook handles pen register and trap-and-trace data: the phone numbers people call, the routing information that reveals where calls originate and terminate, the timestamps that show when communications occur, and the identities of individuals under active federal investigation.

Someone who was not supposed to be there was inside.

The intrusion was classified as a "major incident" under the Federal Information Security Modernization Act — one of the most serious designations available in the federal cybersecurity framework, reserved for breaches that compromise national security systems or the personally identifiable information of more than 100,000 individuals. The FBI notified Congress. The attribution, when it came, was not surprising to anyone who had been paying attention: Salt Typhoon, a cyber-espionage group linked to China's Ministry of State Security.

What Salt Typhoon accessed was not a random collection of data. It was the operational map of American surveillance — a catalog of who the FBI is watching, who those targets are calling, and how the bureau's investigations are structured. For an intelligence adversary, this is among the most valuable information an opponent can possess. It tells you not only what your adversary knows, but what they are trying to learn. If you are a Chinese intelligence officer running agents inside the United States, this data tells you which of your people have been identified and which remain invisible. If you are running a source inside a US government agency, you now know whether that source's phone number appears in the FBI's active target list. The intelligence value is not incremental. It is catastrophic.

The front door to America's surveillance system had been open, and China walked through it.


The nine telecoms

The DCSNet breach was not Salt Typhoon's first operation inside American infrastructure. It was the latest.

Between 2019 and 2024, Salt Typhoon breached nine United States telecommunications companies: AT&T, Verizon, T-Mobile, Charter/Spectrum, Lumen Technologies, Consolidated Communications, Windstream, and two others that have not been publicly identified. The scope of the campaign was extraordinary. Metadata from more than one million users — call timestamps, text message routing data, source and destination IP addresses, phone numbers — was accessed. The highest concentration of compromised data was in the Washington, DC, metropolitan area, a fact whose implications for national security intelligence need little elaboration. The capital's political class, its lobbyists, its staffers, its intelligence officials — their calling patterns, their contacts, the timing and duration of their communications — were harvested by a foreign intelligence service over a period of years.

The attack vector in the telecom breaches was the same one that would later give Salt Typhoon access to DCSNet: the intercept architecture mandated by the Communications Assistance for Law Enforcement Act.

CALEA, signed into law by President Clinton in 1994, requires every telecommunications carrier operating in the United States to build intercept capabilities into its switching infrastructure. The law mandates that carriers must be able to isolate and deliver the communications of any targeted subscriber to law enforcement upon presentation of a valid court order. In practice, this means every American telecom carrier maintains what amounts to a permanent, built-in surveillance access point — a door that exists specifically so that the government can walk through it.

Salt Typhoon walked through it instead.


A thirty-two-year warning

CALEA was controversial from the moment it was proposed. When the Clinton administration pushed the legislation in 1993 and 1994, a coalition of technology companies, civil liberties organizations, and security researchers raised a specific objection: any intercept capability built into telecommunications infrastructure would inevitably become a target for adversaries. A backdoor, they argued, does not check credentials. It is a structural vulnerability, and any sufficiently sophisticated attacker would eventually find and exploit it.

The FBI, the Department of Justice, and their congressional allies dismissed these warnings. The intercept architecture would be properly secured, they said. Access controls would prevent unauthorized use. The benefits of lawful access to criminal communications outweighed the theoretical risks.

Thirty-two years later, China's Ministry of State Security has provided the empirical test of that theory. The results are unambiguous.

The technical mechanism of the breach is instructive. Salt Typhoon did not need to break encryption. It did not need to crack passwords or exploit zero-day vulnerabilities in the carriers' core switching equipment. It compromised a commercial ISP vendor — one of the third-party companies that provide infrastructure services to the carriers — and used that access to reach the CALEA-mandated intercept access points. The backdoor was not a secret passage in a fortified wall. It was a door in the wall, with a lock, and someone picked the lock.

This is the fundamental problem with mandated access: the security of the system depends not only on the security of the door itself, but on the security of every vendor, contractor, subcontractor, and maintenance pathway that connects to it. In a modern telecommunications network, that supply chain includes hundreds of companies. Any one of them can be the entry point. Salt Typhoon found one. The next attacker will find another.

This is not a novel observation. It is the central finding of the landmark 1997 paper "The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption," signed by virtually every major figure in the cryptographic research community. The paper concluded that building government access into communications infrastructure introduces vulnerabilities that cannot be adequately mitigated. Twenty-nine years later, the paper reads less like a warning and more like a prophecy.


The director's warning

The dramatic irony of the DCSNet breach is difficult to overstate.

In 2024, FBI Director Christopher Wray testified before Congress that Chinese cyber operations represented the defining threat to American critical infrastructure. He warned that Chinese-linked hackers had pre-positioned themselves inside US systems — power grids, water treatment facilities, telecommunications networks — in what he described as preparation for potential conflict. The warnings were forceful, specific, and dire.

What Wray did not disclose in those hearings, and what would not become public until after his departure, was that Salt Typhoon had already breached the CALEA infrastructure at multiple US carriers at the time of his testimony. The FBI was warning America about Chinese penetration of critical systems while its own surveillance system was already compromised.

Wray's successor, Kash Patel, confirmed the DCSNet breach after taking office but has not publicly addressed the structural question: if the legally mandated intercept architecture was the attack surface, should that architecture continue to exist?


The cover-up compound

In February 2026, Senator Maria Cantwell, ranking member of the Senate Commerce Committee, publicly stated that AT&T and Verizon are blocking the release of security reports related to the Salt Typhoon breaches. The carriers have not denied this. They have declined to comment.

The implications are significant. If the carriers are withholding security assessments from Congress, neither legislators nor the public can fully evaluate the extent of the compromise, the adequacy of remediation efforts, or whether Salt Typhoon has been removed from the networks it penetrated. Security researchers who have studied the breaches warn that Salt Typhoon likely remains inside US telecom networks — that the group has established persistent access mechanisms that have not been fully identified or removed. The carriers' refusal to release their security reports makes independent verification impossible.

There is also the matter of congressional staff email. Investigators have indicated that Salt Typhoon may have accessed email accounts belonging to staff members of Congress through the telecom compromises. If confirmed, this would mean a Chinese intelligence service gained access not only to the FBI's surveillance targeting information but also to the internal communications of the legislative body responsible for overseeing that surveillance.

The 72 members of Congress who signed a letter calling for investigation into warrantless data purchases by federal agencies now face a more uncomfortable question: the government's own legally mandated surveillance infrastructure may have given a foreign adversary access to their own communications. The entity tasked with accountability cannot get the security reports. The entity that built the backdoor cannot determine who walked through it. The carriers that were breached are blocking the investigation into their own breach. Every layer of the system designed to provide oversight is failing simultaneously.


The surveillance you can buy

The Salt Typhoon breach is dramatic because it involves classified wiretap systems, nation-state hackers, and the FBI's most sensitive operational data. But a report published one day before this article — on April 11, 2026 — by the University of Toronto's Citizen Lab reveals something more structurally unsettling: you do not need to hack a surveillance system when you can buy one.

The report documents a tool called Webloc, developed by Israeli intelligence firm Cobwebs Technologies, now sold by Penlink following a 2023 merger. Webloc tracks the movements, locations, and personal characteristics of device owners across 500 million devices using data that mobile applications collect ostensibly for advertising purposes — location pings, movement patterns, home addresses, workplaces, and up to three years of historical location data. No warrant is required. No court order. No hack. Just a purchase order.

The customer list spans American law enforcement: ICE, the US military, the Texas Department of Public Safety, the New York City District Attorney's offices, the LAPD, the Dallas Police Department, Baltimore PD, Tucson PD, Durham PD, Elk Grove, Pinal County, and DHS West Virginia. The FBI alone paid $27 million for 5,000 licenses for Babel Street's Locate X, a comparable product. Webloc operates through 198 active servers — 126 in the United States, 32 in the Netherlands, 17 in Singapore, 8 in Germany, 8 in Hong Kong, and 7 in the United Kingdom.

The infrastructure runs on a simple economic logic: free apps need revenue, revenue comes from advertising, advertising is more valuable when it is targeted, and targeting requires location data. The entire global ad-tech ecosystem — billions of dollars in annual revenue — is built on the continuous collection and sale of precisely the data that intelligence agencies need to conduct surveillance. The advertising industry did not merely enable surveillance. It built the infrastructure, optimized it for scale, and made it available to anyone with a budget. The government does not need to mandate backdoors to track its citizens. The ad-tech industry already built the front door, and it is open to every buyer.


Hungary votes today under surveillance

The international reach of these tools is not theoretical. Today — April 12, 2026 — Hungary holds elections under what may be the most extensively documented surveillance apparatus ever deployed against a European democracy's own electorate.

Cobwebs Technologies — the same company that built Webloc — completed license renewals with Hungarian domestic intelligence in March 2026, weeks before the election. Hungary is the first confirmed EU member state to deploy Webloc against its own population. Researchers say the deployment blatantly violates the EU's General Data Protection Regulation. No enforcement action has been taken.

The surveillance goes deeper than ad-tech tracking. Opposition leader Peter Magyar has alleged that the Orban government deployed Candiru — military-grade spyware built by another Israeli firm — against his Tisza Party. Investigative journalist Szabolcs Panyi was charged with espionage ahead of the election. The government's attempts to build its own OSINT surveillance systems, a multi-million-euro project called Quvasz headed by former counterintelligence colonel Tamas Berki and connected to Antal Rogan, the head of the Prime Minister's Cabinet Office who oversees both intelligence and propaganda, was a technical failure — so it bought proven tools from the private surveillance market instead. The Washington Post reported that Russia proposed staging an assassination attempt to influence the election outcome. Russian disinformation operations have been documented running alongside the surveillance apparatus.

This is what the surveillance market produces: tools built for law enforcement in democracies, sold to intelligence services that deploy them against opposition parties, journalists, and voters on election day. The same Cobwebs technology tracking 500 million devices for American police departments is tracking Hungarian citizens as they go to the polls.


The United Kingdom builds the next attack surface

The pattern extends to other democracies that are not merely purchasing surveillance tools but building surveillance infrastructure into the fabric of public space.

The United Kingdom announced in early 2026 that it will expand its live facial recognition deployment from 10 mobile vans to 50, deployed to every police force in England and Wales. The government allocated 26 million pounds for the national facial recognition system, 11.6 million pounds specifically for live facial recognition technology, and 115 million pounds over three years for a National Centre for AI in Policing. The expansion is part of a government white paper on police reforms that includes the creation of a "British FBI" — a National Police Service. The expansion was announced before the government's own 12-week public consultation on facial recognition use had concluded. NEC Corporation, the contractor, is the same firm whose technology has been linked to operations in Israel.

The UK is also the country that served Apple with a secret Technical Capability Notice under the Investigatory Powers Act — an order that forced Apple to withdraw Advanced Data Protection from UK users on February 21, 2025, eliminating end-to-end encryption for iCloud data. In February 2026, Signal announced it would withdraw from Sweden rather than comply with a proposed law requiring backdoor access to encrypted messaging. The announcement was understood as a direct statement about Salt Typhoon: this is what happens when you mandate backdoors.

The UK is building, simultaneously, a nationwide biometric surveillance network and a legal framework that compels companies to weaken encryption. Eighty percent of the British public told pollsters they are "comfortable" with police use of facial recognition — but only 55 percent trust police to use it "responsibly." That gap between comfort and trust is the space where surveillance infrastructure expands before accountability catches up. The UK is constructing the next DCSNet — a centralized surveillance infrastructure with mandated access points that will, if history is any guide, eventually be compromised by the same adversaries it was designed to monitor.


The architecture of the problem

The instinct, in the wake of the Salt Typhoon breaches, is to call for better security — stronger access controls, more rigorous vendor vetting, improved monitoring of the intercept infrastructure. These are reasonable measures, and some of them will be implemented. But they address the symptom rather than the disease.

The disease is architectural. Any system that maintains a permanent access point for law enforcement maintains a permanent access point for anyone who can compromise the access controls. The history of computer security is unambiguous on this point: access controls fail. They fail because of human error, because of supply chain compromises, because of zero-day vulnerabilities, because of insider threats, and because sufficiently resourced adversaries — like a nation-state intelligence service — will invest whatever is necessary to find the weakest link.

The FBI's position has always been that lawful access is essential. Wiretap orders serve legitimate law enforcement purposes. Court-authorized surveillance has disrupted terrorist plots, dismantled criminal organizations, and produced evidence that has secured convictions in cases where no other evidence existed. These claims are not fabricated. The question raised by Salt Typhoon is not whether wiretaps have value, but whether the architectural cost of maintaining universal intercept capability across all telecommunications infrastructure exceeds the law enforcement benefit — and whether that cost is paid not by the FBI but by every American whose metadata was harvested, every surveillance target whose identity was exposed, and every intelligence operation that was compromised when China walked through the door that CALEA required to exist.

The only communications system that cannot be breached through a mandated backdoor is one that does not have a mandated backdoor.


The tools that have no front door

End-to-end encryption, where only the communicating parties hold the keys, eliminates the centralized access point that Salt Typhoon exploited. There is no intercept architecture to compromise because there is no intercept architecture. Signal uses end-to-end encryption by default for every message and every call. The server never holds the plaintext. A court order served on Signal's infrastructure produces nothing useful because Signal's infrastructure has nothing useful to produce. When a grand jury subpoenaed Signal's records in 2021, the company turned over two data points: the date the account was created and the date it last connected. That was everything Signal had.

Decentralized communication networks go further. Tor distributes traffic across thousands of volunteer-operated relays, so that no single node can observe both the origin and destination of a communication. There is no central switching infrastructure where intercept equipment can be installed. The CALEA model — where a carrier maintains a permanent wiretap capability at a central intercept point — is architecturally impossible on a network where there is no central intercept point.

Decentralized VPN architectures like URnetwork route connections through networks of residential nodes rather than centralized server infrastructure. There is no single carrier to serve a court order on, no central switching facility where CALEA-mandated equipment can be installed, no third-party vendor whose compromise gives an attacker access to the entire network. The architecture is distributed by design. The kind of centralized interception that CALEA mandates — and that Salt Typhoon exploited — is geometrically impossible on a network where the traffic flows through thousands of independent nodes with no centralized aggregation point.

These are not theoretical architectures. They exist. They work. They are used by millions of people. And they succeed precisely because they were built without the feature that the US government spent thirty-two years demanding: a door that the government could walk through. Salt Typhoon proved that when you build a door, you do not get to choose who walks through it.


The lesson the policy hasn't learned

The Salt Typhoon breach of DCSNet should have ended the debate about mandated backdoors. It provided the definitive empirical proof that the security community had warned about for thirty-two years: a mandated access point was discovered and exploited by an adversary, compromising the very surveillance operations it was designed to support. The backdoor did not make America safer. It made America's intelligence operations visible to China.

But policy does not move at the speed of evidence. As of April 2026, there is no serious legislative effort to repeal or reform CALEA. The FBI has not publicly reassessed its position on mandated access. AT&T and Verizon are blocking the security reports that would allow Congress to understand the full scope of the breach. The carriers continue to maintain their intercept architecture because the law requires them to. The UK is expanding its own surveillance infrastructure. Hungary is deploying ad-tech surveillance tools against its electorate on election day. And Salt Typhoon, according to the researchers who track its operations, likely remains inside the networks it compromised.

The advertising industry has built a parallel surveillance system that tracks 500 million devices without any legal mandate at all — just the market incentive to collect and sell location data. The governments that spent decades demanding backdoors into encrypted communications now face the reality that the advertising ecosystem built something more comprehensive than anything CALEA ever produced, and it is available to any buyer with a purchase order.

The front door is still open. The backdoor is still mandated. The only communications that China could not intercept were the ones that were never interceptable in the first place — encrypted end to end, routed through decentralized infrastructure, carried on networks where the backdoor was never built.

The question is not whether the next breach will happen. It is whether anything will change before it does.


Sources (3)

Sources: FBI congressional notifications and FISMA incident reports (February-April 2026); Senate Commerce Committee statements (Senator Cantwell, February 2026); Nextgov and Politico reporting on DCSNet/Red Hook breach; Bloomberg, NBC News, and Wikipedia reporting on Salt Typhoon telecom compromises (2019-2026); Citizen Lab, "Webloc" report (April 11, 2026) on Cobwebs/Penlink ad-tech surveillance; VSquare, OCCRP, Bloomberg, and Washington Post reporting on Hungary Orban surveillance apparatus and April 2026 elections; Biometric Update, The Gazette, and Al Jazeera on UK facial recognition expansion; Signal withdrawal announcement (Sweden, February 2026); Congressional letter on warrantless data purchases (72 signatories); cybersecurity researcher assessments of Salt Typhoon persistent access; Abelson et al., "The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption" (1997).

Further Discussion

The Backdoor IS the Vulnerability

Every government that mandates surveillance backdoors is building its adversaries' attack surface. In 1994, the Communications Assistance for Law Enforcement Act required every American telecom carrier to build wiretap capability into its network — a lawful intercept architecture designed so the FBI could monitor suspects with a court order. For thirty-two years, cryptographers warned that a door built for one government is a door available to every government. On February 17, 2026, the FBI discovered that Salt Typhoon — a threat actor linked to China's Ministry of State Security — had walked through that door. The breach compromised DCS-3000, known as Red Hook, the unclassified system the FBI uses to manage court-authorized wiretaps. Phone numbers, routing data, and the identities of individuals under active investigation were exposed. The same group had already breached nine major telecom carriers — AT&T, Verizon, T-Mobile, and six others — accessing metadata from over a million users, concentrated in the Washington, D.C. area. Congressional staff emails may have been compromised. And in February 2026, Senator Maria Cantwell revealed that AT&T and Verizon had intervened to block the release of security reports documenting how deeply their networks were penetrated. The UK's Investigatory Powers Act demands the same architecture. Sweden's Riksdag is considering it. Australia's Assistance and Access Act already has it. Every one of these mandated backdoors is a future Salt Typhoon waiting to happen. The lesson of DCSNet is not that the FBI failed to secure its wiretap system. It is that wiretap systems cannot be secured, because the architectural requirement — a door that law enforcement can open — is indistinguishable from a door that a foreign intelligence service can open. The only communications that Salt Typhoon could not intercept were the ones that were never interceptable: end-to-end encrypted, with no lawful intercept infrastructure to exploit, on networks where the backdoor was never built.

We Already Have the Surveillance Infrastructure. We Just Call It Advertising.

The FBI's DCSNet breach is dramatic because it involves classified wiretap systems and Chinese state hackers. But the Citizen Lab report published one day earlier — on April 11, 2026 — reveals something more structurally disturbing: you don't need to hack a surveillance system when you can buy one off the shelf. Webloc, a geolocation tool built by Cobwebs Technologies and now sold by Penlink, tracks 500 million mobile devices using data that apps collect for advertising. Location, movement patterns, home addresses, workplaces, daily routines — three years of history, updated in near-real-time. No warrant required. No court order. No hack. Just a purchase order. The FBI paid $27 million for Babel Street's Locate X — 5,000 licenses. ICE uses Penlink. Fifteen police departments across the United States — LAPD, Dallas, Baltimore, Tucson, Durham — use the same tools. Hungarian intelligence deployed Webloc weeks before today's parliamentary elections, making Hungary the first confirmed EU country to conduct mass ad-tech surveillance on its own citizens. This is not a bug in the advertising ecosystem. It is the advertising ecosystem working as designed. Every app that requests location permission feeds data into a real-time bidding pipeline that was never built with privacy constraints, because privacy is not a feature advertisers pay for. The FBI doesn't need a CALEA backdoor to know where you are. Your weather app already told them. The government doesn't need to hack your phone. The ad industry already built the front door, optimized it for scale, and priced it for bulk purchase. Salt Typhoon exploited a legal mandate. The advertising industry built something worse: a surveillance architecture that requires no mandate at all.

Comics

#1The Backdoor IS the Vulnerability
#2We Already Have the Surveillance Infrastructure. We Just Call It Advertising.