3 ms·
There is an interesting 2019 academic paper out of CU Boulder, on the topic of spoofing 4G WEA alerts. I wouldn't recommend doing this, but it's very interestin
by cypherpunks01 3y ago
There is an interesting 2019 academic paper out of CU Boulder, on the topic of spoofing 4G WEA alerts. I wouldn't recommend doing this, but it's very interesting to understand the technical aspects of WEA, CMAS, and other non-standard mobile comms channels that are involved.
"This is Your President Speaking: Spoofing Alerts in 4G LTE Networks"
[PDF] https://dl.acm.org/doi/pdf/10.1145/3307334.3326082 https://dl.acm.org/doi/pdf/10.1145/3307334.3326082
- 0xbeefcab 3y agoCrazy that theres no cryptographic authentication. I get the whole point is rapidly informing, but there should still be some trivial barrier to sending out an alert
- onthecanposting 3y agoA surprising amount of important systems work because nobody can he bothered to mess with them. I think the takeaway is that most people are good, but perhaps also a bit lazy.
- lxgr 3y agoExactly. Another recent example: https://www.wired.com/story/poland-train-radio-stop-attack/ https://www.wired.com/story/poland-train-radio-stop-attack/
- lxgr 3y agoCryptographic authentication means somebody needs to require a set of trusted keys (or a PKI or similar), and I could imagine that during an actual emergency, availability might be a higher priority than non-spoofability.