5 ms·
I have no idea how this works. Can someone explain the site simulators? When the site simulators intercept the traffic, they can see all the data. If it's encry
by analogmemory 10y ago
I have no idea how this works. Can someone explain the site simulators? When the site simulators intercept the traffic, they can see all the data. If it's encrypted, can they still read it or decrypt it somehow?
- dsp1234 10y agohttps://www.eff.org/sls/tech/cell-site-simulators/faq#faq-How-does-it-work https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-Ho...?
- lend000 10y ago"It should be noted that, while cell phones do use encryption for content, the encryption can be turned off easily by a cell-site simulator itself, and there’s no notification that encryption is no longer operating." The incompetence of telecom companies / chipmakers knows no bounds. Of course, it could be by design.
- Kalium 10y agoI don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.
- revelation 10y agoNo production basestation ever used the "no encryption" mode. No handset should ever accept using it, just as no browser will accept to using the NULL cipher. So what is the justification 25 years on?
- userbinator 10y agoI remember seeing "lawful intercept" being mentioned somewhere in the GSM standards, and it seemed they were certainly not opposed to it...
- deleted 10y ago[deleted]
- tastythrowaway2 10y agothey don't have the option to oppose (in the US, at least): https://en.m.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://en.m.wikipedia.org/wiki/Communications_Assistance_fo...
- ptaipale 10y agoAnd the same has been true in practically all countries, democratic or not, developed or not, ever.
- ams6110 10y agoPerhaps many phones don't, hence the many complaints that "phones stopped working" when the surveillance vehicle was nearby.
- funnyfacts365 10y agoThey stop working maybe because the stingray is only collecting identifiers instead if conducting a true MITM attack and forwarding any calls por SMS's. In any case, I suspect they could only do a MITM to outgoing traffic, so any incoming traffic/data would not be delivered, like the phone is out of service/no network.
- throwawayish 10y agoGSM crypto was designed to not be strong (in the late 80s).
- deleted 10y ago[deleted]
- justinjlynn 10y agoIt is absolutely by design. The GSM standard recommends that, if encryption is disabled, the user be notified. This feature is called the "chiphering indicator". However, practically none of the available handsets do so.
- justinjlynn 10y agooops, "ciphering" ... also, even if the handset supports ciphering indication the SIM can disable it. Oh, and you're not permitted to reconfigure that part of the SIM either.
- analogmemory 10y agoDoes it affect the data connection, like a SSL connection to my bank? Can it see that data stream as well?
- revelation 10y agoSite simulators aren't very new technology. Police departments have had these devices for so long that they were even mentioned in The Wire (2002) with the exact brand name (StingRay). Handsets will always connect to the basestation with the strongest signal, there is no authentication involved. They then "exploit" (it's really by design) a feature of GSM where you can simply tell the handset not to use any encryption, and since the interface between baseband chip and application processor (the ARM that runs your Android or iOS) is more akin to a cold war curtain than actual information exchange, your device won't ever notify you. Even if they enable the old A55 encryption, that can be cracked in realtime nowadays. One popular use is to mount them on a drone, wait for it to detect a particular IMSI and then bomb the general area. That is the reality of the so called "precision strikes" in Afghanistan or Iraq.
- iak8god 10y ago> One popular use is to mount them on a drone, wait for it to detect a particular IMSI and then bomb the general area. That is the reality of the so called "precision strikes" in Afghanistan or Iraq. Holy crap. Do you have a good source for that? I've somehow never heard this before.
- zkms 10y agoAFAICT the codename for the SIM-card-finding operation on drones is "GILGAMESH", here's a few things about it: See https://theintercept.com/2014/02/10/the-nsas-secret-role/ https://theintercept.com/2014/02/10/the-nsas-secret-role/ and https://theintercept.com/surveillance-catalogue/gilgamesh/ https://theintercept.com/surveillance-catalogue/gilgamesh/