4 ms·
It's a pretty good troll, but the chances of it being true are very low. I think someone attended the excellent talk: "Femtocells: a Poisonous Needle in the Op
by trotsky 15y ago
It's a pretty good troll, but the chances of it being true are very low. I think someone attended the excellent talk: "Femtocells: a Poisonous Needle in the Operator's Hay Stack" [1] about 3G MITM and got inspired to have a bit of a laugh.
This is so far into the "state sponsored only" realm that if you'd actually pulled it off and were bragging about it you'd provide some kind of proof instead of generic symptoms designed to make people paranoid.
I'm pretty surprised at all the media outlets that are carrying this and people taking it at face value. Anyone can write up something and send it to a mailing list - remember that full disclosure is pretty much ground zero for security trolling.
[1] http://www.slideshare.net/zahidtg/femtocells-a-poisonous-needle-in-the-operators-hay-stack http://www.slideshare.net/zahidtg/femtocells-a-poisonous-nee...
- windsurfer 15y agoSo the people who make the 3G and 4G standards made them pretty secure. Those are not broken. What's broken is the implementation. The carriers are not the ones developing the technology, so they do boneheaded things like making the client identifiers sequential or using the wrong verification schemes. I would be willing to bet that if there is some kind of exploit here, it's due to the specific implementation.
- interurban 15y agoExactly, it sounds as if the mitm attack wasn't based on hijacking a broadcast, but on redirecting data/voice/sms/etc. from a cracked device to a network of the attacker's choosing. The redirection wasn't based on fooling the phone into connecting , it was based on explicitly changing the network the phone connected to. A very interesting attack, but not interesting in the sense that cdma/wimax (perhaps LTE too?) is unsafe but in the sense that there are serious vulnerabilities in the network stack for android.