16 ms·
Stealth Cell Tower Disguised as Printer
- AdmiralAsshat 10y agoAnd it's still only the second worst modification made to HP Printers.[0] [0]:http://arstechnica.com/information-technology/2016/09/hps-drm-sabotages-off-brand-printer-ink-cartridges-with-self-destruct-date/ http://arstechnica.com/information-technology/2016/09/hps-dr...
- detaro 10y agoThere is also the Shrinter https://www.thinkgeek.com/stuff/looflirpa/shrinter.shtml https://www.thinkgeek.com/stuff/looflirpa/shrinter.shtml
- nickbauman 10y agoThere's always the old News Radio reference you can use with any office copier / mopier or printer. http://www.freakzilla.com/ocas/ http://www.freakzilla.com/ocas/
- gm-conspiracy 10y agoThat was morbid.
- Houshalter 10y agoI don't know if it was HP, but my favorite malicious printer was one that scanned documents and then randomly changed numbers in them. This was the byproduct of an overly clever compression algorithm saving bytes by replacing parts of the image with other similar parts. God only knows how much important information was corrupted by that 'feature'.
- gpvos 10y agoIt was Xerox. http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_...
- deleted 10y ago[deleted]
- ethbro 10y agoYou know, you could probably cripple a society over a few years with that bug (if the probability were tweaked right).
- harry8 10y agoExcel is pervasive. If you consider every single spreadsheet used for financial analysis and then used to allocate resources has material bugs in it, you'll be so close to the truth as makes no difference. Has it crippled society?
- dr_zoidberg 10y agoHmmmm... I remember about an Excel macro-virus that would multiply numbers (and adjust the format to hide it) in data cells by small random number, between 0.99 and 1.01 slowly over time. By the time you realized what was going on, your data was completely gone. Can't remember the name though.
- ethbro 10y agoI think material but well known bugs are probably less dangerous because they're deterministic. The true insidiousness of a random mutagen exploit is the fact that you can't pin in down. Hell, you could even specifically code it to be resistant to reproduction attempts. ;)
- harry8 10y agono no no. Not the many formula implementation bugs. I mean every survey of financial models done in excel has material error in their conclusions. Regardless of known bugs in excel that microsoft won't fix. I mean that merger you just read about where the financial model was done with excel - it has material bugs in it. Material by the GAAP accounting & attest definition. > +/-5% of profit. +/- 10% of total assets. It's quite something...
- jlgaddis 10y agoI'm not sure if it's still possible or not but at one time you could "bounce" port scans and such off of networked HP printers (due to an "IP ID" bug in their IP stack, IIRC). I did this to a very security-conscious co-worker who freaked out when he noticed his workstation being "attacked" by a printer in a computer lab.
- brotherjerky 10y ago> Masquerading as a regular cellular service provider, Stealth Cell Tower surreptitiously catches phones and sends them SMSs written to appear they are from someone that knows the recipient. It does this without needing to know any phone numbers. Pretty witty, but how does this work? Does it wait for the user to send a message and snoop?
- deleted 10y ago[deleted]
- schwarrrtz 10y agoNo. The devices automatically connect to the base station with the strongest available signal.
- vosper 10y agoThat doesn't explain how the SMS message comes from someone the user knows. I would assume (and I think this is what GP was getting at) that the fake tower snoops on outgoing messages in order to collect numbers that the user has in their address book, and then spoofs a message from that number?
- vbit 10y ago> SMSs written to appear they are from someone that knows the recipient I don't think this means they are sent from numbers known to the recipient. Only that the content is written such that it appears to be from someone who knows the recipient. I don't know if actual spoofing is possible.
- schwarrrtz 10y agoYeah, if you look at the codebase it just selects a random string from an array of prewritten messages and sends that.
- deleted 10y ago[deleted]
- Raphmedia 10y agoMonthly (daily?) reminder that you should use an app that encrypt your messages.
- Desustorm 10y agoWould you count WhatsApp amongst that list of apps?
- sschueller 10y agoThere are also apps that can tell you when you are connected to a new unknown tower.
- initram 10y agoCan you post some names and links? I'd like to check them out.
- sschueller 10y agoSnoopSnitch is such an app: https://play.google.com/store/apps/details?id=de.srlabs.snoopsnitch&hl=en https://play.google.com/store/apps/details?id=de.srlabs.snoo...
- loeg 10y agoAny for iOS?
- brianpgordon 10y agoDo phones not do any kind of cryptographic verification that the cell tower is real and that mobile data is sent securely between the phone and the tower? In 2016?
- revelation 10y agoThe cell tower is trusted, and the preferred cell tower is the one with the strongest signals. That's literally the entire selection strategy. Cell towers also choose the encryption that the cell phone should use. I don't think any currently available phone notifies you when no (A5/0) or weak (A5/1) encryption is used.
- digi_owl 10y agoAnd then there is the whole "notification fatigue" issue, where people will dismiss or ok notifications because they get so many in a day.
- stanleydrew 10y agoIt's a collective action problem. How do you incentivize an upgrade while allowing for seamless fallback? For billions of devices made by thousands of manufacturers? Which access hundreds of different carrier networks around the world? I think you need some industry leader to push for this. Apple could do it, or possibly Google although they have a hard time exerting influence over Android device manufacturers.
- Malk0lm 10y agoApple and Google aren't going to do anything. If you want someone to change it talk to Ericsson, Nokia and Qualcomm.
- joecool1029 10y agoWell, here's the deal. They can't do anything as it would be a potential quality of service issue to the end user if GSM were disabled currently. Can't blame the vendors either, they built the hardware years ago that operators continue to operate. It's like wanting to blame Ford and Chevy because you bought a car from the 1950's and it doesn't have airbags. T-Mobile and AT&T are the national carriers supporting GSM through most of their footprint, AT&T is phasing out their network at the end of the year. T-Mobile moved to A5/3 to try to slow down eavesdropping a bit. There are more rural carriers who aren't in a rush to upgrade and probably still use the older ciphers. Currently, I am on T-Mobile. There are a few areas that never saw HSPA deployed, and voLTE is not supported on all devices and also suffers separate outages. GSM is needed in those situations as fallback. Operators would prefer to not have customers complain about outages due to accidentally having GSM turned off. So many phones don't have the option to disable.... though I'd argue now with low band LTE, the footprint is becoming larger than GSM. I would expect Apple to whitelist 'disable 2G' option sometime in the future for AT&T sims. If not just disabling it outright (unless gov pressure gets in the way) EDIT: as noted below, some manufacturers/OS you can set 3G only. Android is pokey about it on some devices. With Blackberry 10, I have the option to change network generations on T-Mobile, but not if I put an AT&T sim in.
- aaroninsf 10y agoGreat project IMO. But the conceit that cell towers are 'badly disguised' is incorrect; the goal is not to successfully hide, but simply to meet the much lower bar of obscuring a non-conforming shape in the environment, so that it doesn't trigger human perceptual interest. You don't put duplicitously palm fronds on a tower to hide it; you put them so that someone scanning the cityscape from a mile away is not distracted by the utilitarian tower.
- johansch 10y agoWell, that was entirely pointless. The meat of the post (the photos of disguised cell towers) would have been exactly as relevant and impactful without that pre-pubescent "hacking". (ooh! we can run six year old software (an openbts fork) on a raspberry pi! we are so cool!)
- foolrush 10y agoIt is an art installation. About the only thing prepubescent is your commentary.
- johansch 10y agoOh! It is art? Well, in that case it must be good.
- striking 10y agoThat's not why it's good, that's why it exists in that state. A lot of people don't know about stuff like this and won't want to trudge through a heavy technical post. But send them a fake SMS and maybe they'll start listening.
- telesilla 10y agoArt is one of the tools we use in society to alert each other about issues, i.e. social commentary. The point is, that it's rhetorical so you may be having a reaction that "Yes, I already know this", because you are working from a privileged position of knowledge inside the system being commented on. Some fairly well-known examples of art as commentary: Guernica - https://en.wikipedia.org/wiki/Guernica_(Picasso) https://en.wikipedia.org/wiki/Guernica_(Picasso) Banksy - http://www.relevantmagazine.com/culture/banksy%E2%80%99s-10-most-powerful-works-social-commentary http://www.relevantmagazine.com/culture/banksy%E2%80%99s-10-... George Orwell - https://en.wikipedia.org/wiki/Animal_Farm https://en.wikipedia.org/wiki/Animal_Farm Given that today we live surrounded by technology, it's not surprising that artists will use that technology to comment about and around our lives, particularly to announce to those outside the sphere of technology how networks, appliances and technological actions actually are affecting their lives.
- dev_throw 10y agoPerhaps a temporary fix might be to have a on-board verifiable hash map of cell tower addresses by location. Either that, or a way to block 2G on the device.
- pmoriarty 10y agoI was walking around San Francisco the other day and suddenly noticed that my phone had switched from its usual AT&T provider to "China something" (maybe "ChinaNet"? I don't remember exactly what it was, and it was only there briefly). And then I got a text saying: Welcome to the test network. Your IMSI is IMSI: 346234543252301 Not very stealth in this case. And I'm still not sure what it was. It went back to AT&T after I walked around some more.
- revelation 10y agoAlso illegal. Call FCC.
- cookiecaper 10y agoI filed a complaint with the FCC regarding a suspected jamming device. I'm pretty sure they didn't even read it. They forwarded the complaint to my wireless carrier, who sent a reply saying that the complaint had nothing to do with them and that my original complaint had reported a jammer. The FCC closed the complaint and considers it satisfied.
- Spooky23 10y agoIn this case, the complaint is unauthorized radio operation.
- droopybuns 10y agoThis is the gold standard example of the FCC's behavior towards cellular spectrum. They have a very different mission when it comes to HAM spectrum. Cellular spectrum: Grandstand and extract cash from the carriers. Ham spectrum: Antenna-laden vans canvasing neighborhoods for radio pirates. It is despicable.
- themodelplumber 10y ago> Antenna-laden vans canvasing neighborhoods for radio pirates. Got any photos, or links to accounts of these? I did a quick google image search because you think someone would have caught one in the wild by now, but no.
- mkhalil 10y agoSo do cell phones automatically connect to the strongest 2G cell tower? Aren't they filtering for cell towers that only belong to their respective carrier?
- JTon 10y agoThe unlocked phones I've used can be put into auto mode (strongest signal, I guess?) or preference mode. Carrier locked phones do not switch to other providers unless there's no service. Then it'll switch over to another carrier but only allow emergency calls (911 in NA). I'm not sure what type of handshakes/communications happen in the background
- mkhalil 10y agoBut even carrier unlocked phones connect to other carries, hence what they call "roaming charges".
- toast0 10y agoThe SIM includes a list of preferred and forbidden networks, but I'd guess if a non-preferred, non-forbidden network is significantly stronger than a preferred network, the phone would ask if it could connect. Also, the fake tower could just claim to be networks that are commonly preferred.
- tbihl 10y ago2G is an open standard, and I'd imagine it's not hard to find a lecture deck about how 2G handshake and session establishment. But to briefly guide your inquiry, I recommend looking up CRO and C1/C2 criteria.
- deleted 10y ago[deleted]
- 3chelon 10y agoI always wondered why these things weren't used in prisons. Maybe they are? Here in the UK there is a massive problem with smuggled phones in prisons, and since by definition their use is illegal in that environment then surely it's OK for law enforcement to jam or even intercept everything? Add to the mix the thick walls and total control of infrastructure and I see no good reason why every illegal phone can't be forced onto a fake network. Legal phones used by staff could be whitelisted.
- aembleton 10y agoGood idea, a pico cell could forward on the calls and SMS from devices with a whitelisted IMSI. Everyone else could just get there's logged and rejected.
- hvidgaard 10y agoJust log everything from non whitelisted devices, but let it through and use the intelligence for law enforcement.
- mschuster91 10y ago> I always wondered why these things weren't used in prisons. > Add to the mix the thick walls Because thick walls do not intercept enough of the radio signal. This only works in really remote locations - but e.g. here in Munich there are a number of jails in the city area. If someone would employ a jammer there, the neighbours would protest and/or sue.
- 3chelon 10y agoYou're probably right about urban prisons. I always think of them as remote but there are plenty in places with very high signal strengths, which would create problems. Low-power pico-cells inside the prison walls could presumably be configured to not cause problems outside. But yes, RF planning is a nightmare and there would doubtless be problems.
- MertsA 10y ago
- DeAndre222 10y agoI know some really good hackers who has worked for me 2x 1dataexit@gmail.com They are very good at hacking anything concerning database, phone,social media.You wll be grateful
- DeAndre222 10y agoHello Guys, I want to fully recommend the efforts of shadow duty he is a guru he increased my credit score from poor credit and helped my nephew upgrade her school grade and GPA without any traces, he is geniun and safe Shadowdataduty@gmail.com you will be grateful
- iRobbery 10y agoFirst question/thing i wonder about is if this printers toner does last as long as expected instead of those you get with printers generally.
- cyanbane 10y agoIn the same vein as Reddit's ELI5 (Explain Like I'm 5) For Us Laymen (FUL) on this topic, why can't Apple/Google currently default to a Full dropdown to 2G and give the option for by choice users to never allow dropdown to 2G (or 3G/4G) at the OS Level? Is there a legal mandate (911 Surface Area increase), a hardware impasse (phones physically can't) or is it a company decision to not allow (for whatever reason)?
- kalleboo 10y agoI've had Sony Ericsson Android phones where you can completely disable 2G/GSM, so it seems to purely be a UI decision.