7 ms·
LTESniffer – An Open-Source LTE Downlink/Uplink Eavesdropper
- raini 3y agoPrevious discussion: https://news.ycombinator.com/item?id=35705683 https://news.ycombinator.com/item?id=35705683 (256 points, 55 comments)
- nntwozz 3y agoIt is what it is, no need for posts like this.
- cloudripper 3y agoI find references like this to other posts with good commentary to be useful in understanding the discourse surrounding the topic.
- deleted 3y ago[deleted]
- iaw 3y agoDoes anyone know the encryption schema of LTE? Does the key change with each message or is it for a longer period of time? I'm wondering how feasible it is for an attacker to capture and then break the encryption (obviously if we're talking 2048-bit that wont be happening anytime soon)
- zitterbewegung 3y agoThis looks like a good overview of the subject. https://www.eecis.udel.edu/~salehi/files/asee13_lte.pdf https://www.eecis.udel.edu/~salehi/files/asee13_lte.pdf
- sidewndr46 3y agowhy bother? Just force the handset down to 2G and intercept that.
- slicktux 3y ago2G is deprecated so a lot of the newer phones won’t even support that..?
- sidewndr46 3y agoI can't even turn off 2G on my relatively new Samsung handset, so I find it hard to believe it is "deprecated". There are likely zero 2G towers in my area, but that doesn't mean handset suppliers don't ship it still.
- ronsor 3y agoAs long as there are countries with GSM service, it's not going to stop being shipped.
- slicktux 3y agoYea relatively speaking…
- Fnoord 3y agoOn an Android smartphone you can disable it usually, via *#*#4636#*#* There's a frontend for this on F-Droid if you prefer that [1] [1] https://f-droid.org/en/packages/pl.lebihan.network/ https://f-droid.org/en/packages/pl.lebihan.network/
- sidewndr46 3y agoThis doesn't work on Samsung phones
- noselasd 3y agoNot really no. Newer phones absolutely support 2G.
- betaby 3y agoThere is nothing to intercept on 2G in Canada and USA, 2G was decommissioned.
- dilyevsky 3y agoIt’s a key set per session. See https://arxiv.org/pdf/1510.07563.pdf https://arxiv.org/pdf/1510.07563.pdf to answer your other question
- dfox 3y agoThe authentication model is based on Radius with EAP, the main point is that anything after and including 3G does mutual authentication and in 4G/5G this is based on IETF protocols, in theory, you can associate with 4G network with whatever authentication supplier that works with WPA-Enterprise (and in theory that even works the other way around). The idea there is that 4G/5G is simply an physical layer for Ethernet2 frames with some kind of access control and QoS layer. And quite obviously the frames are encrypted and authenticated on L2. And as the whole thing is IP, some carriers just tunnel the whole thing in additional layer of IPSec tunnels.
- efitz 3y agoUm, yeah, I don’t have $20k to drop on an Ettus USRP X310 and two daughterboards. I would have liked to have played with it but that is too rich for me.
- bryancoxwell 3y agoA B210 with GPSDO is expensive, but considerably cheaper than $20k. Granted the functionality would be limited but it is possible for hobbyists to play with this.
- dylan604 3y agoThis is usually the very inspiration for a hacker to pull out the soldering iron to make one themselves because the off-the-shelf item is too damn expensive
- emrah 3y agoI don't know for this particular case but usually expensive stuff has expensive components too, especially in low quantity
- efitz 3y agoI have a B210 but the project indicated that it was only compatible with the X310 with two daughterboards.
- cloudripper 3y agoFrom Hardware Requirements > SDR: "To sniff only downlink traffic from the base station, one can operate LTESniffer with USRP B210 which is connected to PC via a USB 3.0 port. Similarly, USRB B210 should be equipped with GPSDO and two RX antennas to decode downlink messages in transmission modes 3 and 4."
- dylan604 3y agoThat’s one of the lessons learned when hacking your own thing. After enough projects and buying the parts & pieces (you never buy just one component), you end up with a stash that eventually means you don’t have to buy anything for a future project. It’s part of the cost of being a hacker.
- yieldcrv 3y agoEavesdropping tool with eavesdropping name with a little disclaimer about not being responsible for illegal use Yeah this is the kind of repository that you clone immediately Clone, dont just Fork
- JohnMakin 3y agoThe FBI got caught doing something kind of similar in a pretty hilarious way (the full story is nuts) using a device called a "stingray" - https://www.aclu.org/news/privacy-technology/surreal-stingray-secrecy-uncovering-the-fbis-surveillance-tech-secrecy-agreements https://www.aclu.org/news/privacy-technology/surreal-stingra... Although in this case, they were disguising themselves as a cell tower and intercepting traffic that way.
- acaloiar 3y agoIf I recall correctly, what this software is capable of doing is not what the Stringray debacle was about. While the Stringray could also be used as a passive sniffer, the FBI Stringray debacle was about it being used as an active fake cell site, in proximity to a target, to intercept communications.
- bippihippi1 3y agoif you control the access point, you can block or modify traffic. listen to the traffic and get inside.
- noselasd 3y ago"Fake" cell towers, imsi catchers and similar tech is a rather common way for to spy on people, it's certainly not just FBI.
- JohnMakin 3y agothe stingray was a long time ago and it was not known at the time. go ahead and read the story, it’s interesting