3 ms·
It's as if SS7 was deliberately SIGINT-Enabled to allow for snooping. I'm not saying it is deliberately weak, but they could have done a better job baking in pr
by blindm 6y ago
It's as if SS7 was deliberately SIGINT-Enabled to allow for snooping. I'm not saying it is deliberately weak, but they could have done a better job baking in privacy. SS7 telephony is horribly outdated and needs something else in its place, and preferably something not weak and something that can stand the test of time, going forward (possibly even quantum resistant secure comms would be nice to have).
- jlgaddis 6y agoI don't imagine they deliberately intended to facilitate all the snooping and tracking that's happening nowadays -- think about how old SS7 is, how "closed" telco networks were at the time, and how the Internet and VoIP were still just figments of our imaginations. I'll give 'em the benefit of the doubt in that regard. However... The vulnerabilities in SS7 have been known publicly for at least 12 years (per Wikipedia). While I realize that it's going to take an absolutely enormous amount of time and effort to roll out protocol "enhancements" and "upgrades" across the biggest network in the world without completely breaking everything but the (apparent) lack of any progress whatsoever is what makes me start to question whether it's just negligence or if it is, in fact, intentional. The cellular / mobile phone networks, though? Personally, I'm 100% convinced the issues there (CMEA, A5/1, etc.) were intentional and "by design"... For those who don't know what I'm talking about, just look into NSA's "alleged" involvement with CMEA -- knowing what we do now, post-Snowden, about the NSA -- and let me know if you don't feel the same way!
- reaperducer 6y agoIt's fun to see people today rail against ESS7 for being insecure. Back when SxS and Crossbar were still around, SS7 was seen as the technology that was so secure it would stop all hacking of telcos forever. Same level of hyperbole. Different eras.