4 ms·
> “I think the telco industry is very much aware that this can be a big issue,” he says. “It’s critical for survival, so I don’t think it’s taken lightly at all
by lovelearning 4y ago
> “I think the telco industry is very much aware that this can be a big issue,” he says. “It’s critical for survival, so I don’t think it’s taken lightly at all.”
It's always been critical but telco's history of preventing security issues in the design stages doesn't inspire confidence. Wasn't SS7 notoriously insecure for decades? I should probably say "isn't" because I'm still finding articles written in 2022 on the topic. LTE too was called out some years ago IIRC.
- ng55QPSK 4y agoi'd recommend to watch the presentation https://media.ccc.de/v/mch2022-273-openran-5g-hacking-just-got-a-lot-more-interesting https://media.ccc.de/v/mch2022-273-openran-5g-hacking-just-g... in which it's made clearer, that the telco part wasn't the issue. 5G systems can be operated rather secure, but operators or subcontractors that build these cloud installation have strange ideas about trust and config. On the topic of 'telcos don't take security seriously', CoryD recently wrote some wise words in https://pluralistic.net/2022/08/12/regulatory-uncapture/#conscious-uncoupling https://pluralistic.net/2022/08/12/regulatory-uncapture/#con... "The public-private surveillance partnership is very old, and it's key to monopolists' strategy. It took 69 years to break up AT&T, because every time trustbusters came close, America's cops and spies and military would spring into action, insisting that the Bell System was America's "national champion," needed to defend it from foreign enemies. The Pentagon rescued Ma Bell from breakup in the 50s by claiming that the Korean War couldn't be won without AT&T's help" I know some people in designing 5G, that were rather frustrated by outside influence on "can we have another unsafe option also, just in case we need it?"
- LargoLasskhyfv 4y agoRelated: https://berthub.eu/articles/posts/5g-elephant-in-the-room/ https://berthub.eu/articles/posts/5g-elephant-in-the-room/
- fahrradflucht 4y agoI think the researcher is very much aware of these dynamics, so if he says they are doing something this time, I'm inclined he has reasons to believe that. Karsten Nohl was involved with and gave a number of talks on SS7 hacks over the years: https://media.ccc.de/v/camp2015-6785-advanced_interconnect_attacks https://media.ccc.de/v/camp2015-6785-advanced_interconnect_a... https://media.ccc.de/v/31c3_-_6122_-_en_-_saal_1_-_201412271830_-_mobile_self-defense_-_karsten_nohl https://media.ccc.de/v/31c3_-_6122_-_en_-_saal_1_-_201412271...
- pid-1 4y agoYou don't need to go as far as govt. conspiring for telcos to be insecure (note: I'm not challenging that). Your average telco: 1 - Is just a commodity dumb pipe with a shitty margin and no honest way of getting more money from customers. 2 - Outsources almost all engineering work to Nokia, Huawei, Cisco, etc...and smaller contractors. A consequence of (2) is that most have no strong engineering or long term thinking culture. I can guarantee you most telcos around the world don`t have basic security shit like having a password manager for router secrets solved correctly.
- lovelearning 4y agoYes, I personally agree with you. I worked a bit for one of those many years ago, and I'd say ignorance of security concepts were the biggest risks for security.
- px43 4y ago> Wasn't SS7 notoriously insecure for decades? Are you implying that someone has recently fixed SS7? Last I checked it was as vulnerable as ever, and is still basically at the core of all global telecom.
- lovelearning 4y agoWasn't implying that. I have only passing knowledge of the tech nowadays but knew it better many years ago. I wasn't certain whether SS7 is even used nowadays or it's obsolete, hence the subsequent sentence. I'm actually shocked it's still used and still as vulnerable!
- kkielhofner 4y agoLast I dealt with it SS7 is worse than ever. When SS7 was designed and first implemented the assumption was it would be a physically closed off network run by telecom clergy. It was usually implemented between licensed ILECs and CLECs on dedicated physical data links (from what I remember an ISDN data channel). In addition to the physical requirements there was a lot of regulatory (licensing) and legal (contracts) work required to begin to get access in the first place. Even getting your hands on the hardware and software that implemented SS7 wasn't an easy task and was gated a variety of ways (principally cost). Once you jumped through all of these hoops you were provided with an SS7 circuit that's essentially wide open to the entire telecom network with no security whatsoever. As deregulation pushed further and further it was realized that unscrupulous ILECs and CLECs would often look the other way on bad behavior as long as you kept paying your bills but at this point it was already too late. Interesting because the impetus for SS7 in the first place was to completely separate call control and signaling from the end user accessible data (voice) portions of the network. This came out of the issues with prior inband signaling systems and their vulnerability to tools used by the "phreaking" community such as the blue box[0]. SS7 over IP and various API driven cloud providers, etc have resulted in essentially opening up access to what was once a closed and sacred network to anyone with a few dollars and an internet connection. Meanwhile the SS7 network on the other side of these gateways has been left essentially defenseless. [0] - https://en.wikipedia.org/wiki/Blue_box https://en.wikipedia.org/wiki/Blue_box
- lovelearning 4y agoThanks for the insight! And that's just plain scary.