4 ms·
For those who want to mess around with BTS -- 900mhz (Eurospec GSM freq; US' complement is 850) is unlicensed ISM band even without a Ham license, and legally c
by iheartmemcache 11y ago
For those who want to mess around with BTS -- 900mhz (Eurospec GSM freq; US' complement is 850) is unlicensed ISM band even without a Ham license, and legally compatible with all the Siemens production gear you can get fairly cheap (everyones phasing out the BS20s and what not).
There's a 1 watt/4 watt limit, but I'm really curious how easy it'd be to get full voice 2G (Euro spec standard) coverage for Manhattan. This is all on consumer-compatible Euro/Asia and/or quad-band units out of the box too. Capacity for each BTS was around 12 concurrent voice channels (IIRC) and when I ran numbers you'd get ~1.2 radial KM coverage[edit: indoors, not LOS (which is drastically further)] at the setup I spec'd out (it was a while ago, apologies, but I think it was Yagi style capable of +70dbm).
[0]http://www.afar.net/tutorials/fcc-rules/ http://www.afar.net/tutorials/fcc-rules/
- mindslight 11y agoBelow 928MHz doesn't exactly jive with https://en.wikipedia.org/wiki/GSM_frequency_bands https://en.wikipedia.org/wiki/GSM_frequency_bands. It looks like you'd be restricted to "Trunking GSM" and only part of the rest? Can the protocol/gear actually be restricted to only part of the band? Also, similar topic - why is there such a dearth of information on hacking / forcibly opening up mobile basebands? Is it that there isn't much tinkering to be done once inside (just a lot of opaque DSP code), or are they really locked down that well, or is it simply that the people who develop such knowhow earn a living through phone unlocking etc and thus don't publicize? I'd really like to see some device hacked open enough such that all the surveillance identifiers (IMEI etc) could be freely scrubbed. After that, psuedonymously obtain network access via a remote SIM card proxied over IP - bootstrap with an existing wifi, and then I'd hope any renegotiation could take place over the device's own connection.
- deleted 11y ago[deleted]
- iheartmemcache 11y agoSo, when you refer to 'restricted to nothing >928', I presume you mean side-band harmonic tone spill. To answer your question: I have no idea, but here's my educated guess based on the '08 auction[1] -- absolutely. I'm presuming that Verizon wouldn't pay billions of dollars for 2 6 mhz bands if they couldn't use it without violating FCC's "don't jump into my band, bro" stuff. Block A has 698–704 and 728–734 MHz. So, they're presumably using 6mhz here, another 6 mhz there (channel trunking) but they're definitely keeping within a 6mhz range. Granted you get a bit more of spectral content within a 700mhz band compared to the 900 to 928 range[edit: uh, per hertz obviously haha], that's still a massive band [edit: again, referring to the content you can fit per hertz; without actually running numbers, I'd gut-feeling-estimate that you're losing maybe ehh 30% capacity, so 900 to 928 is more than enough to operate a full 2G antenna]. RE: The dearth of information: Forcibly opening up? As in like, violating FCC rules? I mean, the knowledge is out there and readily available on the public internet if you know where to look. You can still find o-chem forums with PhD students talking about the manufacturing of research chemicals, but its masked in their own lexicon (an idiot can't just Google "how do i make {insert designer drug of choice}", but you'll find a lot re: "wacker oxidation of foo in bar" or "reductive amination in a Vigreux column"). Just like we've got specs and RFCs for all of our protocols, the mobile industry meets up and agrees on everything from MIPI standards (ever wondered how there are so many Chinese Android devices with so many different seemingly interchangable components like video cameras, GPS modules, etc? There's a spec everything). You could easily take over some of the 850mhz spectra for a day or two but a) what would you have to gain? I guess you could sell baseband equipment to private investigators for a huge premium, thats about it, b) even if you could monetize it, the FCC would storm in on you within a couple days, a week at most. RE: devices hacked open - Shenzhen has everything. [1] https://en.wikipedia.org/wiki/United_States_2008_wireless_spectrum_auction#Prior_auctions https://en.wikipedia.org/wiki/United_States_2008_wireless_sp...
- mindslight 11y agoI had forgotten how much the bands would be sliced up commercially, so yeah it makes sense that equipment can narrowly segregate. The two separate Verizon ranges are probably UL/DL, no? If you're messing with your own base station, then it seems like the phone would be the violator on the uplink frequencies, heh heh. For opening up, fundamentally any device should be open to inspection and modification by its owner. But my specific desire would be to eliminate the fixed identifiers from the protocol, to restore some privacy of these tracking devices we expect to carry everywhere. Homebrew hardware and a Free stack would be a massive undertaking and capital-intensive to distribute. So a better starting point would be some already-distributed piece of consumer hardware. I'd think there would be at least one device that got reverse engineered enough to create some community flash-it-yourself distribution. Perhaps I'm just not doing the right searches, but I just run across vague allusions from either people who are in the know and NDA, independents who dug in a bit but only published summaries of results, or commercial-oriented unlockers only interested in achieving their narrow result. I guess I'm left wondering whether Qualcomm's hardware security really is that good to destroy the enthusiasm for such tinkering, or whether it's just their legal goons have so far successfully contained the knowledge to the secretive unlocking market.
- seba_dos1 11y agoCheck out OsmocomBB - https://bb.osmocom.org/ https://bb.osmocom.org/ While it doesn't even intend to be "consumer friendly" firmware replacement, the project provides a lot of interesting info on hacking TI Calypso basebands used for instance in some old Motorola devices and Openmoko phones. Proxied SIM probably won't work due to timing constraints and I don't think it could be possible on device's own connection, but I'm not really an expert in this area, so don't believe me and my educated guesses too much. However, counter-intuitively, playing with stuff like IMEI number will probably make you even easier target. Some hardware characteristics of your device could be used to "fingerprint" it, and having a lot of IMEIs being advertised by some old Calypso device in similar area could easily bring some attention to it.
- mindslight 11y agoAh crap the timing could indeed be a fundamental problem. Proxying a SIM card is just a recent idea I've been kicking around. Alternatively a privacy-friendly VMVNO could just send a new SIM every (week,month,etc). Once the concept was proven (with non-fixed IMEI etc), I'm imagining a commercial demand would spring up in short order. There's no reason a SIM card must be treacherous hardware. Obviously a small or singular mix group can be worse than no psuedonymity at all, but the idea would be to go for wider adoption. If I actually wanted to privately engage in illegal activity, I'd just buy burner phones and use the appropriate opsec. Really I just want to enable privacy for all of us who don't have something to hide.
- acgh213 11y agoI remember being in Ireland last summer and seeing right off the plane a vending machine of burnable sim cards. The market doesn't exist in the US yet, but Europe seems to be somewhat accustomed to it.
- bogomipz 11y agoEven though it sounds like its not feasible could you explain the concept of "sim proxying"? I am curious. Thanks!
- bogomipz 11y agoCan you explain to my why baseband hacking would be important in this regard? Does all the protocol/handshake negotiation happen at the baseband layer before its modulated up? Is that correct?
- mindslight 11y agoIn the context of mobile, "baseband" colloquially refers to everything "below" the application processor (I guess technically stopping at the RF mixer). The physical layer protocol is carried out in the digital domain by the "baseband processor", which is also running code that takes care of the higher level session protocols. So yes, this generally includes all bits of protocol below the simplistic IP and AT-command based session interface that's exported. (My idea for "SIM proxying": The link between a SIM and the baseband processor is a simple serial link. So as long as latency requirements could be met, this serial link could be tunneled over IP, allowing one to rent a SIM card that wasn't actually in their possession).