6 ms·
Simjacker vulnerability exploited by surveillance companies
- client4 6y agoI'm for cool research, but I am also tired of the trend where security companies come up with a flashy name, logo, url, etc. for every exploit/vuln.
- lima 6y agoWhy?
- generalizations 6y agoIt reeks of marketing, which is antithetical to the hacker spirit?
- notretarded 6y agoGood.. Instantly recognisable name for e-peen augmentation, enters lexicon of general public easily, media outlets can spam it easier, vendors hand forced to fix promptly. This is hardly a bad thing.
- Talanes 6y agoIf it's antithetical, why do open source projects tend to have cute little mascots?
- cghendrix 6y agoYeah the little SIM card face cringed me out
- malwrar 6y agoI'm the opposite. Security researchers have struggled for decades to get people to fix their stuff after discovering something is broken. When a vuln has a human-readable name that sounds vaguely scary, even nontechnical decision makers can ask good questions like "are we vulnerable to this 'heartbleed' thing?". Anecdotal, but I've definitely noticed people talking about them; I've seen articles in mainstream press referencing some of these named vulns and have even had friends who are otherwise uninterested in computers ask me about them! Certainly there's a self-serving glamorous aspect to it on the part of security researchers, but fun names and logos brings attention to issues that otherwise result in eyes glazing over. As much as this stuff makes me cringe to read, I'm willing to bet the branding for this issue will result in more eyes on it and probably will result in a fix. That's ultimately what vuln disclosure is about, after all.
- justinclift 6y agoYeah, the in-your-face advert right before the main text is very spammy too: "Do you know if attacks like like Simjacker or other next generation attacks are happening in your network? Book a meeting [with us to find out]." The website feels like a con/ad rather than something legit.
- pluc 6y agoThis is from September 2019. They haven't really bothered with updating the topic since then: https://www.adaptivemobile.com/search/3a08888ea06c35015d1248114e619fac/ https://www.adaptivemobile.com/search/3a08888ea06c35015d1248...
- xfitm3 6y agoDead link?
- pluc 6y agoYeah it's just a search for "simjacker" on their site, which encodes it in a string instead of common sense.
- surgecoach 6y agoFound More info on the site here : https://www.adaptivemobile.com/blog/simjacker-frequently-asked-questions https://www.adaptivemobile.com/blog/simjacker-frequently-ask...
- willvarfar 6y agoSo which company, working for which government, and how to stop it? The article is just a talk-to-our-salesman piece?
- prophesi 6y agoYep, it's all fluff. They were supposed to reveal more information on the matter in a conference back in October. But we still only have a "technical" paper with nice looking graphs and an unnamed boogie-man.
- plufsim 6y agoThis product/company, for example: https://rayzone.com/geomatrix-geolocation-system/ https://rayzone.com/geomatrix-geolocation-system/
- sloshnmosh 6y agoMost likely: NSO Group
- plufsim 6y agoLess likely, NSO's expertise is in development of exploits for browsers and apps (ex: WhatsApp), not ss7 exploits
- surgecoach 6y agoCircles is affiliated with NSO, and they use ss7 exploits. Dont think they named directly who but they mentioned Circles, Rayzone in ChaosComputingClub a few days ago. THowever the link with the talk is dead for some reason - https://media.ccc.de/v/rc3-11511-watching_the_watchers_-_how_surveillance_companies_track_you_using_mobile_networks https://media.ccc.de/v/rc3-11511-watching_the_watchers_-_how...