7 ms·
How to Build Your Own Rogue GSM BTS for Fun and Profit
- kevindeasis 11y agoIs there a list of all the HN topics that include the keyword: "How to build your own _____ for fun and profit" Please don't mention the search bar.
- blantonl 11y agoI wouldn't even think about doing this unless you are in a faraday cage environment or other locked down RF environment where you can be absolutely sure you have complete control over all RF emitted by the device and you know exactly which devices are able to connect. Otherwise, in the US expect the FCC and network operators to become intimately familiar with who you are rather quickly. Having random public phones roam onto your rouge cellular network is a public safety risk (potentially no 911 access) as well as any number of laws being directly broken (unlicensed spectrum use, denial of service to legitimate licensed networks etc).
- evilsocket 11y agoabsolutely agree, while writing the post I gave for granted that ppl realized how illegal this is and take appropriate measures.
- brian-armstrong 11y agoIt's a great post but I think it's one of those experiences best enjoyed vicariously
- brian-armstrong 11y agoOh! And also, if this sort of thing interests you, get your ham radio technician's license. There is no morse code requirement and the test questions and answers come from a publically-available pool. It is straightforward to study for (but do read the theory, don't just memorize test answers). Once you have that, you can start operating digital modes on local bands at low power. You'll be amazed how far you can stretch 5W of transmitter.
- baobrien 11y agoI'm pretty sure a technician license grants you the same amount of power and access to the same bands as a general and extra license above 6m.
- brian-armstrong 11y agoYeah, I think you're right. Just for reference, here's all the allocations. They've got fairly verbose rules http://www.arrl.org/frequency-allocations http://www.arrl.org/frequency-allocations
- vvanders 11y agoFWIW MURS is open without a license for digital, although with pretty lower power ceilings.
- gnu8 11y agoAll very good reasons why we should be throwing more police officers as well as the executives and owners of Harris in jail for using these things. It's impossible to manufacture or operate a stingray without breaking the law.
- evilsocket 11y agonever heard about faraday cages?
- deleted 11y ago[deleted]
- woodman 11y ago... now we just need to figure out how to lure the surveillance target into our EM-shielded cage.
- evilsocket 11y agomy point is that it's quite easy to "play" with such things without actually breaking the law
- Semiapies 11y agoThey aren't "playing".
- walrus 11y agoI think you may have misunderstood the comment. In the US, Ireland, and probably elsewhere, police are using rogue cell sites ("Stingrays") for surveillance. The person you replied to is claiming that this is illegal, and the police forces that are doing it should be punished. They weren't talking about people experimenting with setting up Faraday-caged toy cell sites in their basement — there's absolutely nothing wrong with that and it should be encouraged!
- 11y ago
- avip 11y agoSitting in a Faraday cage will not do you much good... Totally agree with the sentiment though. Apply for an experimental FCC license!
- snowpanda 11y agoDo those licenses really exist? Sounds interesting.
- seba_dos1 11y agoThat's how Harald Welte and Osmocomm team was always providing on-site GSM networks on events like Chaos Communication Congress/Camp. However, recently Germany sold out part of spectrum that was used for those licenses, so it became much harder now there. The network on last CCC almost didn't happen, but the provider who bought it (T-Mobile IIRC?) allowed to use it this time anyway. The future is a one big question mark though :(
- k0ngo 11y agoThis. It is also important to note that you may interrupt the service of other people's handsets even if your BTS doesn't allow them to connect, just by operating your SDR with an insufficient clock reference [1]. The handset will re-calibrate it's VCXO to match your SDR, and then won't be able to see the legitimate cell networks. [1] http://openbts.org/w/index.php?title=Clocks http://openbts.org/w/index.php?title=Clocks
- blantonl 11y agoExcellent point. All cell phone sites have a GPS reference clock source for each provider. The clock source is critical for everything from RF tuning to handoff timing between sites. You'll see this type of antenna mounted typically right on top of the equipment housing structure. Each one you see will tell you how many providers are there. http://www.antenna.com/media/GPSL1-TMG-SPI-40NCB-thumb.png http://www.antenna.com/media/GPSL1-TMG-SPI-40NCB-thumb.png (Note that it is small, about 6 inches in height. And different variations abound, but they are typically painted white and mounted right on the structure for LOS view to the sky)
- pjc50 11y agoI suspect the chances of getting caught if you run it intermittently a few times are almost nil. After all, the Stingray devices are illegal and seem to have been used for years.
- MOARDONGZPLZ 11y agoPerhaps, but he was addressing the legality, not the practicality of getting caught. And the points about your project potentially stopping people from calling 911 are also salient. This is just something that isn't worth the risk to most tinkerers like myself to even try.
- peterwwillis 11y agoTalk about over-reacting. Not only is there a legal power maximum for private use of regulated spectrum, but there are plenty of areas of the US where you won't interrupt anyone else's service. If you're really concerned, get a Ham license. There are plenty of areas where you can play with this on low power without pissing off the feds or ILECs. The creators of OpenBTS did this to provide service where it doesn't exist - in the middle of a desert, providing service to 30,000 people over a 7 square kilometer area, for example. It should go without saying that broadcasting a pirate signal in a populated area is a bad idea.
- blantonl 11y agoThis is not an over-reaction in even the slightest way. The barrier to entry for this implementation is a little over $600 USD. If someone brought this solution online in their apartment in midtown Manhattan NYC, they would potentially affect hundreds, if not thousands of devices. Someone who is deploying an OpenBTS in the middle of the desert probably already has a good understanding of their existing RF environment. I'm willing to bet that just about everyone participating here lives in an RF rich environment where if they brought solution online, it would impact someone.
- peterwwillis 11y agoPeople who buy football equipment are aware that you can injure people playing football and generally don't play football in a midtown Manhattan office, for example. People who buy BTS equipment are aware that they are creating a cell tower and it will affect people around them and the police and cell network providers will not be happy with them if that happens.
- CraigJPerry 11y ago> they would potentially affect hundreds Unlikely since the range of this device is about a single small / medium apartment building.
- archimedespi 11y ago
- danellis 11y ago> Having random public phones roam onto your rouge cellular network is a public safety risk So don't let other people on it. Fun story: I worked for a company in the UK making GSM picocells with IP backhaul. One day, due to a misconfiguration, we had a lot of confused people from other offices in the building wondering why their phones were roaming onto a Canadian cell network thousands of miles across the Atlantic. Oops.
- otec 11y agoWhy is it illegal again ?
- sschueller 11y agoI posted this yesterday already: https://news.ycombinator.com/item?id=11403135 https://news.ycombinator.com/item?id=11403135 I thought you can't post duplicate content.?
- milankragujevic 11y agohttps://news.ycombinator.com/newsfaq.html https://news.ycombinator.com/newsfaq.html > Are reposts ok? > If a story has had significant attention in the last year or so, we kill reposts as duplicates. If not, a small number of reposts is ok. > Please don't delete and repost the same story, though. Accounts that do that eventually lose submission privileges.
- brudgers 11y agoI've heard the moderator, dang, say that the duplicate system is imperfect. Sometimes it's just luck. It looks like this has been posted several times over the past few days. https://hn.algolia.com/?query=How%20to%20Build%20Your%20Own%20Rogue%20GSM%20BTS%20for%20Fun%20and%20Profit&sort=byDate&dateRange=all&type=story&storyText=false&prefix&page=0 https://hn.algolia.com/?query=How%20to%20Build%20Your%20Own%...
- striking 11y agoDuplicates are allowed if a post hasn't gotten much attention in a while. Sometimes HN will auto-repost your post. It's not a bug, it's a feature!
- mercora 11y agoPhones automatically connect to any unencrypted BTS? This is really insane. I thought service providers provision the sim card with white listed and authenticated providers or only tunnel their traffic securely through foreign networks. This is way to easy. Are there apps to detect such things? EDIT: found 2 apps claiming to be able to detect this. https://play.google.com/store/apps/details?id=com.skibapps.cellspycatcher https://play.google.com/store/apps/details?id=com.skibapps.c... https://play.google.com/store/apps/details?id=de.srlabs.snoopsnitch https://play.google.com/store/apps/details?id=de.srlabs.snoo...
- Vexs 11y agoIt's moderately interesting how these work, they basically check if you're connecting to a "new" tower. Another app is called aimsicd, I use it personally. Not paranoid, but there's no reason not to use it really. No noticeable drain on battery, and it would be interesting to know if it ever did throw anything.
- yuubi 11y agoNewer systems using 3GPP-type authentication (LTE, and I think UMTS) require mutual authentication between the SIM and the network (details in [1] section 6.3). If the network doesn't provide a satisfactory AUTN, the mobile can't proceed with connecting to the network because later steps in the connection procedure need some keys derived from the authentication procedure. I think in older GSM-derived systems, the SIM just computed an authenticator based on a nonce provided by the network. I know for sure that CDMA (IS-95 and 2000) and later AMPS systems supported one-way authentication or not, as selected by the network. I've heard rumors that attackers have to force a protocol downgrade to something without mutual authentication by jamming the legitimate signal. The other options for the attack would seem to include - obtaining the secret key value (or a set of authentication vectors) from the legitimate network. Either of these seems more difficult to obtain than the actual locations that the attackers claim to want. - obtaining K from SIM manufacturers, which has happened [2]. - exploiting implementation defects in SIMs or mobiles. [1] 3GPP/ETSI TS 133 102 "3G security: security architecture", http://www.etsi.org/deliver/etsi_ts/133100_133199/133102/13.00.00_60/ http://www.etsi.org/deliver/etsi_ts/133100_133199/133102/13.... [2] https://hn.algolia.com/?query=gemalto&sort=byPopularity&prefix&page=0&dateRange=all&type=story https://hn.algolia.com/?query=gemalto&sort=byPopularity&pref...
- kiwijamo 11y agoIs that an issue with more modern systems like UMTS and LTE? For some reason I remember reading somewhere that when UMTS was introduced, the SIM card standard was updated to include some data allowing devices to challenge UMTS (and I assume LTE too) BTSes to provide proof in the form of an answer to a challenge code presented by the device using data from the SIM card. Have I got this right?
- nuand 11y agoYes, you are correct. Some parts of LTE and WCDMA use a pre shared secret and rolling keys to allow UEs to identify themselves to the mobile network. There are however many non-data carrying parts of LTE that are not encrypted or authenticated, sort of how 802.11 has AES but management frames are still fully unecrypted.
- methou 11y agoThis is exactly the method how criminals in my home country send scam texts to victims[1], it's hard to trace since they are mobile. Before LTE towers were widely deployed, two major GSM operators can't prevent people from connecting to a malicious station, since 2G sim cards do not have capabilities to authenticate operator's network. It's a relief that major operators today are actively rolling out 4G SIM cards, and law enforcements are taking malicious stations seriously. So today if you set up rogue GSM BTS, you might be prosecuted. [1] http://www.theregister.co.uk/2014/03/26/spam_text_china_clampdown_police/ http://www.theregister.co.uk/2014/03/26/spam_text_china_clam...