5 ms·
Breaking LTE on Layer Two
- lerie82 8y agoI am confused though, this seems unlikely since the attacker has so many hurdles to accomplish.
- exabrial 8y agoI really like the trend of offering a human-readable explanation of attacks, complete with illustrations. It's so much easier to present the danger to upper management if they can do some self-research.
- jacquesm 8y agoNice technical work but given the pre-requisites nothing to lose sleep over (yet). As a rule: if you are on a mobile network consider your activities to be public.
- ge0rg 8y agoThe attack is a combination of multiple "vulnerabilities": 1. the data link layer is not protected, so an attacker can perform a relay attack (forward the encrypted radio packets between the phone and the actual cell tower). 2. from watching the encrypted traffic patterns, it is possible to guess which websites the user is surfing by comparing the traffic fingerprints. 3. the packets are not integrity-protected, so it's possible to change bits of data, if you can guess which packet you have and how it's constructed. This is used to manipulate DNS requests to redirect traffic. I'm not sure about the significance of #1 and #2. A passive attacker might be able to obtain the same information simply by monitoring the physical layer traffic patterns emitted by the phone. Additionally, mobile operators are typically monitoring their frequencies for abuse, so an active attack might not stay under the radar for long. Regarding #3, this is a complicated way to achieve what you can do with a fake WiFi hotspot, and gives you control over unencrypted communications, which hopefully is only a very small subset of todays traffic thanks to omnipresent HTTPS.
- a012 8y agoIMO, to use always-on VPN is the best solution to countermeasure these kinds of attacks.
- ge0rg 8y agoA VPN will not protect you from fingerprinting of your traffic patterns. VPNs just add a fixed overhead to all packets and maybe a bit of fragmentation. A well-positioned attacker with a large database of traffic fingerprints is probably easily able to re-calculate the traffic fingerprints for the common VPN protocols.
- kardos 8y agoFor a clean setup where you're interacting with one website that makes sense. Perhaps less so with many streams. Could VPN protocols be modified to obfuscate traffic patterns (without adding intolerable latency or extra bandwidth costs)? Eg, rapidly change the MSS or add some padding?
- namibj 8y agoIf there is significant data that just has to be transferred within a given, larger timespan, e.g., if you need that update within the day or upload the picture(s) you took over the course of your lunchbreak, or similar situations, you could transfer that data when you want to send masking traffic. This way you don't have to generate dummy data to serve as masking traffic.
- kardos 8y agoAh, that's clever. It's hard to come up with a bunch of bulk data that needs to be transferred 'sometime in the next day or two'. Phone updates might be one but they are sporadic, and backups could be another. Also you'd need a supply of near-term bulk transfers in both directions. Interesting idea for sure.
- Rjevski 8y agoThis is nothing compared to the disasters that are mobile “core” networks. Those are where the real problem is (allows real time location tracking, call/text/data spoofing & interception, denial of service, etc) and the telcos don’t give a shit.
- gsich 8y agoTrue, but gaining acccess to those is not that easy.
- Rjevski 8y agoUnless you know the right people. Or that Tor Hidden Service that offered full HLR access to a (presumably compromised) carrier for like $5k/month. The problem with this kind of security by obscurity is that it gives people a false sense of security and nobody wants to change things. I’d prefer if telco attacks were cheap and accessible to any script kiddies because at the very least the resulting nightmare will draw attention to the problem and proper solutions will be implemented.
- cryptonector 8y agoIntegrity protection is critical. We've known this for many many years now. There is no excuse.
- monocasa 8y agoOne more reason to push DNSSEC?
- viraptor 8y agoWould it actually help here? If all requests are redirected to a given DNS server, how would you even know the zone is supposed to be signed?
- DrPhish 8y agoIt needs to be combined with something like dnscrypt with cached ssl credentials (and the occasional request to known dnssec domains for the slightly more paranoid)
- tptacek 8y agoNo; it wouldn't work at all in this setting, since phones don't run recursive DNSSEC resolvers and attackers can flip the authenticated-data bit just as easily as the bits in the address. It's actually a pretty good illustration of the last-mile problem that plagues DNSSEC.