Normal view

There are new articles available, click to refresh the page.
Yesterday — 22 July 2026Main stream

China advances plans for national single-stack IPv6 network, and its own surveillance-friendly version of the protocol

21 July 2026 at 22:55
China’s Cyberspace Administration on Tuesday issued a plan for wider adoption of IPv6 between now and 2030, and for more work on a non-standard set of services that Beijing calls “IPv6+”. The Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030) contains the usual promises to increase use of IPv6. Beijing wants 900 million users to be connected over IPv6 by 2027, and for the protocol to carry 38 percent of network traffic. China also wants all connected devices to be IPv6-enabled by 2027. “By 2030, IPv6 will be widely and deeply integrated with all sectors of the economy and society, building a technologically advanced, open, innovative, self-driven, and secure IPv6 industrial ecosystem,” the regulator wrote. “The number of active IPv6 users will reach 950 million, and IPv6 will account for 42 percent of network traffic.” The Administration also expects that by 2030, “New networks will be prioritized for IPv6 addresses by default, accelerating the evolution towards IPv6 single-stack, and promoting the formation of a network service and application system dominated by IPv6.” News that China is planning for the day it runs a single-stack internet will excite some, notwithstanding the fact that IPv6 has proven less important than its creators hoped. The most interesting part of the new plan is the call for more work on IPv6+ – a set of enhancements to IPv6 that allows those who send information to embed metadata describing content into packets and even suggest the route it should take. As Think Tank the Mercator Institute for China Studies last year observed, IPv6+ “has obvious appeal for authoritarian regimes looking to control their citizens,” because a carrier could read metadata and act on it. One possible action could be to allow network operators to identify traffic they would like to charge extra to carry, an idea telcos like because they feel it is unfair that they bear the burden of investing in last-mile infrastructure to deliver content from the likes of Netflix and YouTube. Reading metadata could also enable censorship: Beijing already blocks a lot of content, and if dissidents had to identify themselves in packets, they’d be easier to find and block. The Institute also notes that China’s telco equipment companies have implemented IPv6+ and exported kit that runs it to several nations. That’s worrying because China already tried to create a protocol called “New IP” that also included surveillance-friendly features. China tried to have the International Telecommunications Union sign off on New IP, despite the Internet Engineering Task Force maintaining existing IP protocols. That effort failed, but Beijing is pressing ahead with its efforts to spread its own version of IP at home and abroad. The new plan doesn’t suggest that Beijing abandon vanilla IPv6. Indeed, it calls for Chinese participation in global standards development. But the document also says China will work on “national IPv6 standards and accelerate the development of national IPv6 standards in key areas.” ®

Before yesterdayMain stream

NTP server that traveled back in time caused massive Aussie mobile outage

17 July 2026 at 00:48
Australian telco Telstra has revealed the cause of the recent incident that caused widespread connectivity problems across its mobile networks, inculding outages to Australia's 000 emergency services line, plus outages to electronic payments services and transport networks. The carrier explained itself in a submission [PDF] to a Senate inquiry into outages affecting Australia’s emergency services which initially investigated an outage at Telstra's main rival, Optus. The Optus incident is linked to multiple deaths after people could not reach emergency services. Telstra's submission reveals that the carrier's attempt to address a known resilience problem was the instigating incident. That problem was a faulty backup power feed in the chassis used to house a network time protocol (NTP) server. A few minutes before midnight on July 7, a Telstra techie started work to replace that chassis. By 3:38 AM on July 8, the worker had finished the job and powered up the server. The NTP server included a GPS card that Telstra says “did not operate as expected” when the server came back online. “We now believe this occurred because of an intentional design change that had previously been made to the equipment to fix an earlier fault [which] had not been properly documented,” the submission states. “This meant the maintenance team was not aware of the way the device would behave when restarted.” Telstra also admitted it had not applied a software update to the device, despite knowing of its availability in early 2026. “Had that software update been completed or had the design change been properly reviewed and documented post the earlier incident, and reflected in the maintenance procedure, the outage may not have occurred,” the submission states. The outage did happen because once the NTP server came online it reset its clocks to the year 2006. The server then did what NTP servers do: publish that time to myriad other machines across the network. Once those machines received the incorrect time, other kit on the Telstra network compared digital certificates and decided something dodgy was going on – so denied connections. Just one of Telstra’s three NTP servers had this problem, but enough bad timing info made it onto the carrier’s network to cause chaos. The telco isolated the bad box at 7:11 AM, and by 10:30 AM had identified all network components that used the bad time information the naughty NTP box broadcast. That wasn’t the end of the matter, because as valid time information rippled across the network, some equipment didn’t close IP sessions. Customer devices therefore couldn’t reconnect to the network unless rebooted. The carrier has described the outage as “clearly unacceptable.” “If maintenance work can trigger this kind of outage, it suggests our controls were not good enough. We are accountable for that, and our investigation will address why that design change was not documented, why the software update was not completed, and what needs to change in our controls so known risks are captured, prioritised and closed before they can affect customers.” The carrier has done the usual thing by promising to conduct deep and lengthy self-reflection, submit itself to further flagellation at more inquiries, co-operate with a probe by the relevant regulator, and to do what it takes to prevent similar incidents. ®

ZTE's AI new calling builds an open and intelligent telecom ecosystem, transforming from basic voice call to an AI-powered service hub

15 July 2026 at 15:00
ZTE showcased at MWC Shanghai 2026 its groundbreaking AI New Calling solution, together with China Mobile Research Institute (CMCC). Based on the concept of "Calling as a Service", this innovation uses open interfaces to deeply integrate traditional voice calls with artificial intelligence (AI), establishing a dual-engine system powered by "Calling + AI Agents" and "Calling + AI Capabilities". Through an intelligent service portal, it expands the scope of communication applications and converts the conventional closed voice network into an intelligent, open, and flexible AI-integrated network. This enables operators to create a versatile, continuously evolving service ecosystem and unlock new business growth opportunities. Dual engines driving commercial value With real-time AI assistants capable of understanding multimodal intentions, the system automatically handles complex tasks like booking travel and scheduling meetings, providing users with a smooth experience of "automatic recognition, intelligent execution, and task completion" without the need to download additional apps. While enhancing user experience, the integration of calling and AI also generates commercial value. It establishes a powerful service gateway within the calling interface, expanding operators' business horizons to realize "Calling as a Service". Additionally, advanced features such as real-time translation and AI-based fraud prevention improve core call quality, offering unique services that increase customer loyalty and generate additional revenue. Two-layer technological upgrades strengthening the foundation The AI New Calling architecture delivers two key technological advancements: Enhanced Capability Infrastructure: The introduction of an IMS Data Channel (IMS DC) enables multimodal data transmission and lightweight H5 app deployment, overcoming limitations in audio/video interactions and creating a superior calling platform. A new ecosystem is established by launching a plug-and-play AI calling open platform that supports third-party plugin integration for flexible capability use and rapid innovation development. Together, these improvements facilitate the smooth transition from closed voice networks to an intelligent, open, and agile AI+ network, helping operators build a sustainable and evolving communication service ecosystem. Four core capabilities redefining the value of voice call Focusing on essential user needs, ZTE's AI New Calling removes traditional barriers in audiovisual communication by fully embedding AI capabilities throughout the communication process. It redefines the value of calling across four main areas: enhancing efficiency, expanding the ecosystem, improving experience, and embracing technological inclusivity. AI personal assistant: Users can activate a personal AI agent during calls to independently manage meetings, travel plans, and other routine tasks—achieving complete task closure and turning every call into a productive interaction ("calls that get things done"). Super service gateway: The native dialer is transformed into a comprehensive service gateway, providing direct access to frequently used services like business travel and government functions—without requiring app downloads. This allows instant service access at the moment of dialing ("dial and enjoy"). AI clear voice: By combining background noise reduction, voiceprint optimization, and weak-network compensation, AI Clear Voice delivers crystal-clear, high-definition two-way audio even in challenging network environments. Accessible calling services: Utilizing AI integrated within the network, the system offers inclusive features like real-time language translation and proactive fraud detection. These services operate independently of the capabilities of user devices, ensuring truly universal and fair communication for all. Open collaboration to co-build the intelligent calling ecosystem AI New Calling is a strategic path toward the digital and intelligent transformation of voice communication. Its widespread implementation requires collaboration throughout the industry. ZTE is dedicated to driving innovation in communication technologies and facilitating the smooth transition of traditional voice networks into intelligent, open, and flexible AI-powered networks. Moving forward, ZTE will continue to collaborate with partners across the ecosystem to push the boundaries of AI and telecommunications integration, speed up the adoption of AI calling solutions in various industries, and deliver smarter communication experiences to millions of households, collectively shaping the future of digital intelligence in telecom. Contributed by ZTE.

Hands off our VPNs, privacy groups tell UK ministers

14 July 2026 at 07:59
Privacy campaigners, browser makers, and VPN providers have united to warn the UK government against restricting virtual private networks, saying age-gating the technology would weaken online security while doing little to stop kids dodging social media bans. The Open Rights Group on Tuesday published an open letter signed by more than 20 organizations, including the Electronic Frontier Foundation, ExpressVPN, the Internet Society, Mozilla, Mullvad, Proton, and the Tor Project. It urges ministers to rule out age verification and other restrictions on VPN services. The coalition argues that VPNs have become important infrastructure for a broad range of users, from businesses and journalists to abuse survivors and ordinary users trying to protect themselves on public Wi-Fi. Requiring users to prove their age would undermine the privacy VPNs are intended to provide. "Restricting VPNs would undercut the security and privacy of millions, without making children safer," the letter reads. "Age-gating VPNs would require everyone to surrender sensitive personal information simply to access tools designed to protect privacy." It's hardly a new fight. Mozilla spent much of spring arguing that ministers were chasing the wrong target, warning that breaking VPNs would do little to fix Britain's age-check problem while making the internet less private and less secure for everyone else. The open letter suggests plenty of others have since reached the same conclusion. The intervention comes as ministers prepare to introduce a ban on social media for under-16s, arguing that VPNs aren't the loophole many critics assume. The government's own research backs that up, showing that while about one in four 11 to 17-year-olds said they'd used a VPN, only 7 to 10 percent did so to bypass age checks. Most simply lied about their age instead. The coalition highlights similar figures from Ofcom, which it says makes a poor case for tightening access to VPNs. "Ofcom's research found that only around 3 percent of children had used VPNs to access content meant for older audiences," the letter says. "Evidence from Australia shows children are much more likely to get around age checks by not being asked, giving false information, or even drawing on a mustache." The signatories instead want ministers to tackle what they describe as the "root causes of online harms," rather than making people prove who they are before they can use privacy tools. The letter argues that strong enforcement of platform obligations, better parental controls, investment in digital literacy, and privacy-by-design requirements would do more to protect children than requiring VPNs to be behind age checks. Whether the government is persuaded may depend on whether it views VPNs as a niche loophole used by a small minority of teenagers – as its own research suggests – or as the next obstacle to enforcing its online safety agenda. ®

The US government warns that Russia state hackers are coming after your router

13 July 2026 at 17:03

The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors.

Both the Russian and Chinese governments have been compromising routers for years, sometimes in prolonged tugs-of-war to wrest control of devices the other has already commandeered. The US government has occasionally issued covert commands and taken other steps to disinfect routers. Google and other companies have also worked to disrupt the massive botnets that control compromised routers in lockstep. The actions to date are little more than whack-a-mole exercises as the operators simply replace their botnets with new ones.

Proxy networks: The go-to tool

“Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks,” the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.

Read full article

Comments

© Getty Images | BernardaSv

User crippled a network while trying to learn Nmap

13 July 2026 at 02:30
WHO, ME? Welcome to the working week, dear reader, which as always we open with a fresh instalment of “Who, Me?” – the reader-contributed column that offers an education in how not to do things at work. This week, meet a reader we’ll Regomize as “Roger” who told us that a decade or so back he managed teams that designed electronic shop tools and associated test kit. Roger admits he had begun to find the job a little boring, and so he sometimes found himself exploring things not strictly related to the job. Which was how he found Nmap, the popular network mapping tool. “One Friday afternoon, with apparently nothing better to do, I started using Nmap to poke around our internal network,” Roger admitted. He enjoyed the experience, and it sparked an idea: Why not run the tool all weekend, to get a view of the entire company’s network? “It was a mid-sized company, with engineering, sales, marketing, admin, and even a factory,” he told The Register. “I was curious how the IT boffins had the network set up and thought it would be fun to run a massive scan of the network over the weekend and see what turned up.” He therefore set Nmap running and left for the weekend. When he arrived at his desk on Monday, Roger couldn’t help but notice his laptop was missing. The next thing he saw was the company’s head of IT approaching “with a haunted, slightly wild-eyed look in his eyes.” Roger immediately recognized this was not a courtesy visit, and so asked him what had happened to his laptop. The IT boss said he and the company’s Chief Operating Officer had both tried using a VPN to hook up to the office over the weekend but could not connect as the network was utterly fried. Troubleshooting efforts led straight to Roger’s laptop, which they promptly disconnected – at which point the network sprang back to life! Roger then endured an interrogation about his machine. “I played dumb,” he admitted. “It was easy enough for me to do and I didn't even have to pretend because I didn't really understand what was going on.” He eventually mentioned a recent visit to the company’s China office and floated a theory he may have picked up a virus in his travels. “This sent the laptop straight into IT isolation/purgatory, where the poor thing endured nearly a week of relentless virus scanning,” Roger admitted. The tech team couldn’t find anything awry and eventually gave Roger a stern talking-to about taking care while travelling before returning the machine. With Nmap still installed. Have your attempts at self-education ended in tears? If so, don’t leave The Register crying for new submissions to Who, Me? Click here to send us an email instead so we can share your experiences on a future Monday. ®

❌
❌