4 ms·
tldr: 1) LTE uses broadcast messages to do push notifications. These are unencrypted and unauthenticated. Researchers can trigger them silently by spamming you
by rmac 11y ago
tldr:
1) LTE uses broadcast messages to do push notifications. These are unencrypted and unauthenticated. Researchers can trigger them silently by spamming you on Facebook, and triangulate your location since the LTE network only sends the pages to the geographic location you are in.
2) LTE supports crash reports that can potentially include your GPS coords. A rouge base station can request these from your phone without setting up an encrypted channel due to shitty baseband implementations.
3) something about denial of service
the excellent paper is here: http://arxiv.org/pdf/1510.07563v1.pdf http://arxiv.org/pdf/1510.07563v1.pdf
- TorKlingberg 11y agoI'd like to add a few things: 1) This is really a fundamental limitation of all encryption: It hides what you are sending, but not the fact that you are sending something. Paging in mobile networks is a broadcast message that basically just says "Device with ID XXXX, please wake up and check in with the network". If you can cause pages (by calling, texting or with Facebook messages) then you can see in what area the pageing is sent, and you can find out the ID (TMSI) of the device. 2) It is not a crash report, but a connection failure report. 3) During the initial connection, before encryption is started, an rogue transmitter can send a connection rejection message to the phone, pretending to be the network. The phone will not try 4G/3G again and downgrade to 2G. The attacker can then break the weak 2G authentication and make the phone believe that it is a real base station. The last part is what an IMSI catcher / Stingray device does.
- Natanael_L 11y ago1) but you can hide who it is sent to, such that only timing attacks are plausible (see Tor and every VPN)