5 ms·
Why aren't cell phone tower communications secured? Why aren't cell towers secured with certificates verified by the network? Why aren't stingray devices cons
by bvinc 6y ago
Why aren't cell phone tower communications secured? Why aren't cell towers secured with certificates verified by the network? Why aren't stingray devices considered an attack on the cell network?
If stingray devices work by tricking your phone to connect with older protocols like 3G, why aren't those protocols deprecated just like we deprecate older encryption methods that are no longer secure?
- alasdair_ 6y agoOversimplified answer: because people want their cellphone to work outside of major US cities. For example, the laws on what is allowed to use encryption and what is not differ significantly from country to country. There are also often older installations that only provide 3G support. Basically, it's complicated and there are a lot of different reasons but it mostly comes down to the world being a big place with lots of different laws and requirements, yet people want a phone that works everywhere.
- numpad0 6y agoI think it has to be 2G GSM specifically, 3G UMTS do cipher that kind of holds, also a lot of phones aren’t dynamically updatable or updated smartphones GSM downgrade attacks as well as USB SDR gears came out late 3G era, I kind of trust 3GPP guys for protection for LTE onwards but if GSM downgrade attacks are your primary concern in your life you can move to Japan and get contract on au by KDDI as KDDI flat out ignored CSFB to CDMA2000 and went all VoLTE
- gruez 6y ago>if GSM downgrade attacks are your primary concern in your life you can move to Japan and get contract on au by KDDI as KDDI flat out ignored CSFB to CDMA2000 and went all VoLTE Wouldn't it be easier (at least on android) to go to mobile network settings and change it to "lte only" or "3g only"? As for using au by KDDI, I'm not even sure whether using their SIM cards will prevent a downgrade attack. It's possible that they still support 2g for roaming use, for instance.
- numpad0 6y agookay, I’ve mistaken, KDDI do have eCSFB to CDMA since the get go...my brain was stuck in pre-LTE launch era. Sorry. I’m not sure how “LTE Only” options work on every phones, moving across countries to just make a phone behave certain way is beyond absurd but verifying how it’s working might be a bit of challenge? regarding roaming, you mean a fake GSM tower with backend going over a VPN to a GSM tower somewhere the phone could roam to? That I didn’t realize. That could happen indeed.
- boring_twenties 6y agoLTE Only is an option (albeit hidden) on every Android phone I've ever used, at least. Just enter ##4636## in the dialer. I usually have it set, and in areas that only have 3G coverage, I get no signal unless I change the setting.
- boring_twenties 6y agoHrm, just noticed that hn ate my asterisks. Backslashes don't work, either. Unicode to the rescue: ⁕#⁕#4636#⁕#⁕
- SamuelAdams 6y ago> Why aren't cell phone tower communications secured? Why aren't cell towers secured with certificates verified by the network? They can be, but that adds cost to running a cell phone network. Since very few people ask for their cell phone communications to be secured, companies just don't do it. it's like how GPS is completely unsecured - anyone with a couple hundred bucks can interfere with GPS signals. Maybe route a cruise ship into an island, or a random driver to a sketchy area of town. > Why aren't stingray devices considered an attack on the cell network? LEO's use them very frequently to conduct investigations and gather evidence. Just look at the current debate around full-device encryption. USA Law Enforcement really likes access to information. Telecommunications (and a lot of the inernet: TCP/IP, DNS, etc) were initially set up to be open - security was an afterthought. And they just never bothered to add security later on. Also deprecating old things is hard. People still expect to be able to pick up a charged Nokia phone from 2001 and call 911 on it.