4 ms·
> since they're internet based, they aren't vulnerable to SS7 exploits. I think the problem with SS7 is that there's no authentication between providers. At le
by lmns 9y ago
> since they're internet based, they aren't vulnerable to SS7 exploits.
I think the problem with SS7 is that there's no authentication between providers. At least as far as I know.
- gruez 9y agoafaik the ss7 exploits essentially involve a rogue carrier saying "hey verizon, your client 212-555-1234 is roaming on my network, plz send all his calls/texts to me". i don't think this attack applies to non-mobile providers because there's no roaming. and unlike the internet, there's no bgp-like system[1] for "announcing" phone numbers. it's all centralized, which should reduce your attack surface from every telecom in the world, to the originating telecom, whoever's in charge of the numbering database, and your carrier. [1] https://en.wikipedia.org/wiki/Local_number_portability#Portability_schemes https://en.wikipedia.org/wiki/Local_number_portability#Porta...