4 ms·
Not much can be done, other than turning off the phone, https://www.securitymagazine.com/articles/91767-protecting-high-level-personnel-from-imsi-catchers https
by stacktrust 3y ago
Not much can be done, other than turning off the phone, https://www.securitymagazine.com/articles/91767-protecting-high-level-personnel-from-imsi-catchers https://www.securitymagazine.com/articles/91767-protecting-h... & https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=imsi&sort=byPopularity&type=story https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
> There are more reliable hardware options available for detecting IMSI catchers, which make sense when protecting multiple smartphone users in a single site, like a corporate headquarters or military base. Typically, such a setup involves a fixed, embedded system containing sensor hardware and a cellular modem for continuously monitoring the broadcast signals of the surrounding base stations, along with a database to which data is uploaded for analysis. When an IMSI catcher is detected, alerts can then be sent to all of an organization’s smartphone users.
Phones should allow users to define a whitelist of known-good cell tower IDs, which could be loaded for a known geo-location.
Why don't cell towers have the equivalent of an SSH host key, so that unknown cell towers trigger a warning before connection?
- elguyosupremo 3y agoSupposing cell towers don't currently have a key; if they did your cell provider would certainly have a way to push new ones to your phone, and under government warrant they'd simply push the key of the stingray to your phone as well, or give the stingray the key of an existing tower.
- deleted 3y ago[deleted]
- yosito 3y agoIf your cell provider is going to help stingrays connect to your phone, the government might as well just install the wiretap at the provider and none of this matters.
- stacktrust 3y agoGovernments and law enforcement would be the best-case scenario for telco monitoring and phone/endpoint hacking via NSO et al, because there would at least be some legal framework for narrowly targeted lawful intercept. The risk of insecure-by-design telco standards, radio networks and untrustworthy phones is that zero-day and unfixable vulnerabilities could be abused for targeted and mass surveillance by networks of criminal, corrupt or non-state actors. If Clearview AI can scrape billions of human images from public social networks, for commercial facial recognition services, imagine the per-geo economic value of passive radio signal collection and retroactive footprint analysis by AI. https://hn.algolia.com/?query=imsi https://hn.algolia.com/?query=imsi
- cmeacham98 3y agoSure, but the point is that if we assume that the telco is malicious none of LTE's security matter or could ever matter. They are the party you are encrypting the data for, so they always by definition can log/sniff/whatever it. There's no point in designing telco standards for cases where the telco is a malicious party.
- stacktrust 3y agoDid someone suggest the telco as a malicious party? My comment was about non-gov, non-telco malicious actors harvesting metadata via passive sniffing.
- cmeacham98 3y agoYes, that's literally what the parent comment to your comment is talking about when they said this: > If your cell provider is going to help stingrays connect to your phone...
- yosito 3y agoTurning off the phone isn't a solution though. The concern with the attack is that someone is snooping on my connection while I use it. If I can't use my phone confidently knowing no one is watching, then my only other option would be not to trust the phone at all.
- stacktrust 3y ago> Turning off the phone isn't a solution though. Since most phones no longer have power-off, a faraday bag is needed to block all RF (cellular, wifi, bluetooth) radios on the phone from communicating with nearby radios. > The concern with the attack is that someone is snooping on my connection while I use it. If I can't use my phone confidently knowing no one is watching, then my only other option would be not to trust the phone at all. This is sadly the case today. It will only change with greater participation of civil society in technology standard-setting, open-source "cyber" defense and security research. In addition to reducing usage of untrustworthy phones and radio bands, reduce funding of untrustworthy telcos by subscribing via lower-cost prepaid MVNOs.
- TheHappyOddish 3y ago> Since most phones no longer have power-off What does this mean? I can power off my phone same as I always have.
- stacktrust 3y agoiOS15+ "powered-off" iPhones can act as Airtags, https://9to5mac.com/2021/06/07/ios-15-find-my-network-can-find-your-iphone-when-it-is-powered-off/ https://9to5mac.com/2021/06/07/ios-15-find-my-network-can-fi...
- jcrawfordor 3y agoLTE does perform authentication of the tower, it's one of the reasons cell site simulators are becoming less useful---phones that refuse a downgrade to 3G will refuse to fully associate with a simulated site, so only limited information about the phone (some identifiers) can be obtained.
- stacktrust 3y ago2017, https://arxiv.org/abs/1702.04434 https://arxiv.org/abs/1702.04434 > IMSI Catcher attacks are really practical for the state-of-the-art 4G/LTE mobile systems too. Our IMSI Catcher device acquires subscription identities (IMSIs) within an area or location within a few seconds of operation and then denies access of subscribers to the commercial network. Moreover, we demonstrate that these attack devices can be easily built and operated using readily available tools and equipment, and without any programming. We describe our experiments and procedures that are based on commercially available hardware and unmodified open source software.