3 ms·
Crypto attempts have been made, but now we're starting to see both industry associations (GSMA) and open source (P1 Security SigFW [1]) working on filtering and
by philprx 8y ago
Crypto attempts have been made, but now we're starting to see both industry associations (GSMA) and open source (P1 Security SigFW [1]) working on filtering and encrypting SS7.
If placed in front of the legacy equipment, that could enable operators to gradually move toward signed+encrypted signaling traffic.
Problem is that this industry can be slow to react and would probably need government/regulatory pressure to move faster.
[1] https://github.com/P1sec/SigFW/ https://github.com/P1sec/SigFW/
- DanielDent 8y agoGSMA standards have always included purposeful insecurity, e.g. look at the history of A5/1 & A5/2. It's a group that buys into the idea of secure backdoors, I'm not sure it's possible for them to build a secure system. I actually think the current Huawei mess is direct fallout from our history of creating purposefully insecure systems: if the overall system was designed to be secure, the network infrastructure potentially being compromised wouldn't be such a significant issue.
- spc476 8y agoI work at a company whose customer is the Phone Company. As I complained to my manager, "We may have a two-week sprint, but the Phone Company has a two-year sprint."
- C1sc0cat 8y ago:-) Well back when I worked for BT they had quarterly sprints but this was for things like major changes to the entire system.