3 ms·
I'm not super familiar with how cellular networks operate, but isn't there a way to authenticate the session with the tower so that the IMSI doesn't get transmi
by zebrafish 8y ago
I'm not super familiar with how cellular networks operate, but isn't there a way to authenticate the session with the tower so that the IMSI doesn't get transmitted to a snooping party? If we do it with laptops and wifi APs, can't we also do it with phones?
Finger print scanners and facial recognition are prevalent on phones these days, would that be a solution to circumvent this vulnerability?
- deleted 8y ago[deleted]
- rusk 8y agoYou could encrypt the (T)IMSI somehow, but using what? You could use a pre-shared key but then to support roaming this would have to be shared among operators but that’s trivial to defeat for state actors. You could go for an asymmetric scheme like HTTPS but there has to be some way for the network to “get back to you” much as you have to reveal your IP Address to kick off a TLS handshake. You can’t rely on alternative addressing schemes because then how do you allocate these? You have to stick your head over the parapet at some stage. This is the nature of the zero-trust peer-to-peer nature of the global telephony system. I wonder if there’s an application for some kind of a blockchain here .. EDIT just to note, your example of laptops and wireless APs, you must reveal at the very least your MAC address which is if anything less secure because it doesn’t change - at least not trivially.
- Nokinside 8y ago* GSM (2g) does not have authentication at all. * 3G has no integrity protection. Downgrade attacks from 3G->2G work. Also, it's the base station who decides if authentication and encryption is done. Fake base stations can still be used to track location, intercept calls and data. * LTE/4G has mutual authentication and mandatory integrity protection. In theory you can't get IMEI if the message has no integrity but the protocols are not perfect. LTE/4G can still be intercepted by using jammers, DoS attacks or exploiting weaknesses in the protocols and implementations to force a downgrade. Some messages in the protocols still go unencrypted and without authentication. It's for example possible to edit voice domain preference or send "LTE services not allowed" messages or edit the list of supported protocols to force downgrade. Practical attacks against privacy and availability in 4G/LTE mobile communication systems https://arxiv.org/pdf/1510.07563v1.pdf https://arxiv.org/pdf/1510.07563v1.pdf
- droopybuns 8y agoGSM does not have meaningful tower auth. It does have UE authentication.
- dfox 8y agoTo clarify: GSM is essentially first cellular protocol that does meaningful user authentication, on the other hand there is no way for user to explicitly authenticate the network. In usual operating mode the session is implicitly bidirectionally authenticated by the fact that both UE and network has to be able to derive same Kc, but nothing prevents the network from just ignoring the authentication response from UE and continuing in plaintext mode.