4 ms·
Technically speaking, how does this even work? And non-technically speaking, how does a major flaw like this not get spotted and patched when the architecture
by Varriount 6y ago
Technically speaking, how does this even work?
And non-technically speaking, how does a major flaw like this not get spotted and patched when the architecture for SMS was being initially designed? Or is this just one of those cases where no-one was willing/able to consider security (it where it wasn't even a usual consideration)?
Out of all the technologies I use on a day-to-day basis, I feel like telephony networks and transmission is the area I know the least about.
- techsupporter 6y agoIn order to allow the exchange of SMS between networks, a system of SMS interconnect was created in the late 90s. Essentially, each company that wants to exchange SMS will query a database to find out what carrier is responsible for delivering SMS to a given number. (There are a lot of moving parts and several databases, varying by country code, but you get the idea.) What services like this do is enable someone who owns a number that is not ordinarily enabled for SMS (POTS, VoIP, toll free/WATS) to enter their number into the SMS routing system and tell other carriers to deliver SMS to a service provider (one that can handle the inbound SMS traffic and display it on a web portal, for instance) of their choosing. The flaw is when a SMS-enabled number can have its instructions overwritten by a service like this so that messages are routed where they shouldn’t go. As all mobile numbers are considered SMS-enabled by default and only the owning carrier should be the destination, this is a flaw. (Yes, I can think of some scenarios where you might want your mobile number SMS messages going elsewhere, but that’s dead for now.) More specifically, the flaw is to do it on the back of an easily-faked, CYA letter of authority.
- redis_mlc 6y agoIt's worse than what the parent said. SIP, the protocol behind digital telephony, "has all the security of UDP." And CALEA is as bad as you would think. "Communications Assistance" is about as Orwellian a phrase as you can get for government spying on private citizens. https://en.wikipedia.org/wiki/Session_Initiation_Protocol https://en.wikipedia.org/wiki/Session_Initiation_Protocol https://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://en.wikipedia.org/wiki/Communications_Assistance_for_... Source: worked for a telco. We laughed about SIP in every meeting.
- fatnoah 6y ago>More specifically, the flaw is to do it on the back of an easily-faked, CYA letter of authority. The company the OP used bears a large part of the responsibility for the issue due to the intentional or negligent lack of validation. Several years ago, I built an application that offered similar ability to the one that caused the recent ruckus. In our case, we worked with industry groups to define an acceptable flow, which led to a one where we initiated a voice call to the customer that read a numeric code to them, which they had to enter as part of the registration process. We also checked each number to make sure that we were ONLY registering landlines and not mobile, toll-free, or other MVNO-associated numbers like Google Voice, etc. (We did support toll-free, but that required written LOA and manual verification with toll-free # registrar). The surprising part to me in the carrier's response was that they weren't already periodically reclaiming SMS routing for their numbers. Over the course of testing, I'd accidentally claimed my own cell # (Verizon) or the cell # (T-Mobile) of one of our test phones, and proper routing was always restored within a week for Verizon, and within a day or two for T-Mobile.