25 ms·
British duo arrested for SMS phishing via homemade cell tower
- usr1106 2y agoCloudflare turnstyle making government resources inaccessible (it's always an endless loop of clicking that I am human on my mobile)
- randunel 2y agoSame here, I cannot access that website, it's an infinite turnstile loop. Same issue with hibp, as far as I can see.
- moomin 2y agoPretty ironic considering it’s the City of London Police website. If malicious clients want to try their luck, I’d say let them.
- pheggs 2y agohow certain are you actually that you are not an android? :)
- szundi 2y agoWe are bio androids anyway
- happymellon 2y agoThis comment instantly made me think of this. https://en.m.wikipedia.org/wiki/The_6th_Day https://en.m.wikipedia.org/wiki/The_6th_Day Apparently it was also Terry Crews acting debut.
- Traubenfuchs 2y agoYou are probably using the suspicious setup Cloudflare wants to lock out. Please try again with Google (R) Chrome (TM), no experience manipulating addons (e.g. adblockers), no VPN and from a non-non-friendly country.
- mdp2021 2y agoIt is not that, it works on some odd setups.
- deleted 2y ago[deleted]
- jeroenhd 2y agoWorks fine on Firefox from a custom Android ROM through a VPN here. Last time I checked a post where people complained about Cloudflare, even Ladybird for Android made it through. You need cookies and Javascript, but that's all you need to pass the technical checks it seems. Cloudflare likes to block things like Tor and CGNAT because of the abuse and unidentifiability those networks provide, and maybe there's a filter on some enemy states set up by the British government, but they really don't seem to care all that much about what you're running on your phone. Blocks seem to be largely network-based in my experience.
- tgv 2y agoI can access with Firefox, macOS, UBlock Origin.
- cqqxo4zV46cp 2y agoThis is absurdly dishonest. I don’t use Chrome. I use a VPN sometimes, when I’m travelling, in a DigitalOcean IP range (which has a dubious reputation). I don’t live in the US or Europe, which is often Californian for ‘a list of trusted countries’. I’ve never, once, ever, had an issue with CloudFlare. The regular vocal super-minority of people that have this issue need only expose the fact that they’re running Lynx on their Gentoo-powered toaster, upside down, on the international space station.
- Jerrrrry 2y ago[dead]
- Perz1val 2y agoLets me in on my microg lineageos with brave browser
- deleted 2y ago[deleted]
- jgrahamc 2y agoIf you hit a problem like this I'd like to hear about it. If you're willing I an take a HAR file and pass it on to the Turnstile team and they can see why.
- usr1106 2y agoSorry, I missed your reply. Thanks for the offer. I'll try to figure out whether this phone browser (a rather old Firefox fork) can take HAR traces and send it to you by email if I succeed. Edit: No VPN, no Tor, no add-blocking, Javascript & cookies enabled. The only suspect is old hardware and slowly maintained software (although updated only recently by the vendor)
- mastermedo 2y agoWhy does this work? How simple is it to follow the sms protocol, I thought there were spam filters in place on the phones to prevent receiving any traffic from towers which are not registered to a well known network provider (or what have you).
- jeroenhd 2y agoSMS is sent in some leftover space in the mobile data channel, there's very little verification to that up until relatively recent standards. If you can pretend to be a 2G/3G tower and jam the real tower, you can force phones to connect to you and you can send whatever calls and texts you want. This is mostly a 2G issue. Modern Android devices, and perhaps iOS devices, have a toggle to disable 2G for this reason. With fully compliant 5G, even police IMSI catchers become pretty difficult to use.
- andyjohnson0 2y ago> This is mostly a 2G issue. Modern Android devices, and perhaps iOS devices, have a toggle to disable 2G for this reason. My Android phone, Motorola Edge 20, has a setting for preferred network type. Options are 5G/4G/3G/2G, 4G/3G/2G, 3G/2G, or 2G only. Doesn't seem to be a way to disable 2G or 3G, even though most networks here (UK) no longer support them.
- jeroenhd 2y agoFor phones that support it, there's a separate toggle for disabling 2G. I don't think the preference setting you're referring to has the same effect. If I recall correctly, The separate 2G toggle goes down to the modem especially rather than just being configuration. I do have my phone set to 4G+5G only through that same screen, though, as my modem lacks the 2G toggle as well. If there are missing options in the dropdown, try dialing *#*#4636#*#* and see if you can configure it through there. I don't know exactly what determines what configuration is exposed to the UI, it's possible your modem simply lacks support for disabling entire generations of cellular technology.
- gravescale 2y agoThat's a pretty clever way to be very stupid! Anyone who reports the message (forward it to 7726, spells SPAM) to a network tips the network off that messages are landing on subscribers devices that didn't come through their system. And I guarantee there are devices listening into, characterising and locating radio emitters in major cities at the very least.
- vasco 2y agoYeah if you run a private antenna either the police or some men from your country's equivalent to FCC will come to your door and politely ask you to stop, if they are having a good day, most likely confiscate some of the equipment as well. And that's just for emitting anything on reserved spectrum or with too much power, not even for crime.
- GordonS 2y agoI guess you could hoover up traffic at a location for a few hours, then move to another location and keep going like that without getting caught.
- vasco 2y agoListening isn't illegal so you can do that without moving. People move just to listen to different things with limited range, one form of it is called wardriving if you're doing it to wifi for example.
- GordonS 2y agoI'm fairly sure in the UK it's illegal, tho I don't know for certain. But even if not, you could be arrested for conspiracy to commit fraud (or similar).
- seabass-labrax 2y agoThat's not true - it is indeed illegal to listen in to radio transmissions which are not intended for you. Doing so is a criminal offence punishable by an unlimited summary fine (the precise amount is determined based on the offender's personal income and other circumstances). https://www.legislation.gov.uk/ukpga/2006/36/section/48 https://www.legislation.gov.uk/ukpga/2006/36/section/48
- cjrp 2y agoSlightly more detail on The Register: https://www.theregister.com/2024/06/10/two_arrested_in_uk_over/ https://www.theregister.com/2024/06/10/two_arrested_in_uk_ov... Sounds like they were using a Stingray-esque device, as the police do.
- skilled 2y agoI have emailed mods to ask for a link update so your comment can be demoted, and more room given for discussion. Thanks for pointing it out, did not see/check when submitting.
- dang 2y agoThanks! We've changed to that from https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/ https://www.cityoflondon.police.uk/news/city-of-london/news/... now.
- jack_riminton 2y agoFor those unaware the "City of London" is in fact a small part of London, what you might call downtown, and they have their own police force. fwiw they're regarded as a very competent police force
- cjk2 2y agoapart from the financial crimes unit...
- fragmede 2y agoGCP Grey on the city of London: https://youtu.be/LrObZ_HZZUc https://youtu.be/LrObZ_HZZUc
- mintplant 2y agoMap Men on London's 32 boroughs: https://www.youtube.com/watch?v=daeB46Z4fjs https://www.youtube.com/watch?v=daeB46Z4fjs
- jack_riminton 2y agoAs a londoner, even I learned several things from that video. And it's done by an American!
- oakesm9 2y agoHe's american, but moved to the UK to study and then become a Physics teacher in London. I think he's been London based for all of his YouTube career.
- LAC-Tech 2y agofwiw they're regarded as a very competent police force What makes them different?
- jack_riminton 2y agoWell it’s a reputation, so it’s hard to quantify. But anecdotally I’ve heard from numerous people who had dealings with that they were very competent (compared to most British forces presumably). I’ve also heard that their average level of policeman is more educated , ie many holding degrees, masters etc. I presume this must be due to the nature of the work they’re most known for ie combatting complex fraud, organised crime etc
- tiku 2y agoWhy is sms such a crappy protocol that this is even possible?
- sunbum 2y agoSMS isn't a protocol. Attacks like these are done via 2G. Which is really why most people should disable it if they can.
- dotancohen 2y agoBecause it dates to a time when such attacks were infeasible. GPS is very similar in that regard. Even HTTPS was uncommon back when I was in university. NASA spacecraft still communicate over unencrypted channels. Mindsets were different then.
- fragmede 2y agonot just mindsets, but the computing power available. These days, my smartphone is millions of times more powerful and the computation to do TLS encryption on every website I visit is trivial for a computer that fits in the palm of my hand. Way back when, the 1 or 2 kilobytes or so a modern RSA private key (PEM format) would take up on disk was meaningful when you only had 4 megabytes of RAM and CPUs ran in the megahertz range.
- oldgradstudent 2y ago> GPS is very similar in that regard. GPS originated as a military protocol and has some level of encryption and authentication, but this is not available to the general public.
- GJim 2y agoGPS *had* no encryption or authentication; indeed, such security is only a recent addition to the L2 frequency. USK: Galileo also has authentication available on its civilian frequencies.
- 2y ago
- Infinity315 2y agoSlightly off topic, but this is demonstrated in a show called Mr. Robot. I find it insanely cool that the hacking in Mr. Robot closely resembles real life.
- NilMostChill 2y agoIIRC they hired a bunch of real life professional white hats to consult. https://en.wikipedia.org/wiki/Mr._Robot#Technical_accuracy https://en.wikipedia.org/wiki/Mr._Robot#Technical_accuracy
- mdp2021 2y ago> Most phone providers are part of a scheme that allows customers to report suspicious text messages for free by forwarding it to 7726. If you forward a text to 7726, your provider can investigate the origin of the text and arrange to block or ban the sender, if it’s found to be malicious It would be useful to have a list of Countries/operators adopting the 7726 ("SPAM") number. It seems also some European Countries do.
- slowmotiony 2y agoHow do you forward a text?
- orra 2y agoOften there's a long click menu in your SMS app to do it. But all that really does is copy the body into a new SMS. There's no metadata to indicate it's forwarded, as you suspect. This means texting 7726 is a two step process. First you send the body. You immediately get a response asking for the phone number of the spam sender, so then you sent that.
- lxgr 2y agoDoes the phone number even matter for tracing? As far as I understand SMS delivery, it’s not authenticated at all. I suppose it can be used to help the operator identify the actual incoming message in their logs?
- toast0 2y agoSource number authorization depends on how the messages get to the carrier and how the carrier has things setup. At the end of the day, there's a lot of trust though; and a lot of connections would be difficult/expensive to confirm that the connection is authorized to send messages from the sources they're using. Think of BCP38 for IP spoofing, but for number spoofing. If you get an appropriate country mobile number from a carrier in that country, are you going to pay for a portability lookup to confirm that carrier is the authorized carrier for that number? Does that carrier check source numbers for all of the connections they have? Some of the aggregators are good at checking sources, and some aren't, but aggregators are often authorized to send messages from many different countries, so they're likely to have their connections unchecked, because keeping the list updated is hard. It's like IP transit, but a lot worse.
- shiroiushi 2y agoPeople in the UK still use SMS?
- mdp2021 2y ago> still use SMS? Instead of? If you have to send text to an occasional user, what do you think should be used? The article is about /receiving/ messages supposedly from firms. How should they have sent it?
- porker 2y agoThe National Health Service communicates with people via SMS. The NHS has an app, but doesn't send notifications through it. My guess is because our population can all cope with SMS by now, but anything more...
- denton-scratch 2y agoHMRC also seems to require an SMS-capable device for 2FA. Using the HMRC website is a soul-destroying adventure through severe speed-bumps, short session timeouts, and 72-hour delays. It's the epitome of awful, large-scale British public computer-system acquisition.
- Havoc 2y agoPeople not so much but services yes
- johneth 2y ago
- bloqs 2y agoThis is the police force for the ancient financial district in London called the City of London. Best explanation: https://youtu.be/LrObZ_HZZUc https://youtu.be/LrObZ_HZZUc
- ReptileMan 2y agoTrivial to make one - you just need a SDR and encryption key (harder to obtain, but probably could be found on the black market).
- bestbuyer__ 2y agoThis is giving off HackerNews DropBox vibes :)
- lxgr 2y agoYou don’t need any key for GSM, since the network/base station only started authenticating itself to the phone/SIM with 3G. That’s why it would be good to shut down GSM at some point: It would raise the difficulty of such attacks significantly. What I don’t understand is how they managed to actually intercept any SMS with an IMSI catcher. They’d need to get the network to send these through their infrastructure, so I wonder how that worked? Update: Ah, they were just sending out texts themselves, not intercepting anything.
- swiftcoder 2y agoI enjoyed the "Sorry, there was a technical problem. Please try again." when I tried to reject cookies
- exabrial 2y agoOh good, we better make sure we tie our bank accounts to SMS
- dang 2y agoCould you please stop posting unsubstantive comments and flamebait? You've unfortunately been doing it repeatedly. It's not what this site is for, and destroys what it is for. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
- robbyiq999 2y agoWhat interests me is the intelligence and innovation of this. You would think these bad actors would fair well doing societal good using their skills and not resort to crime.
- deleted 2y ago[deleted]
- dubcanada 2y agoWhy does that interest you? This is fairly common.
- ChrisMarshallNY 2y agoThat's always been the case. Dumb crooks don't last long. As to why they choose this way, over a "legitimate" (like dark pattern writing, or PID mining) vocation, there are many reasons. I suspect that a big one, is the "blackball" effect, that having a conviction on your record will create. Once we are convicted, then we become unhireable, in many industries, so it's not like we have a choice. Also, the pay for nefarious work can be quite good.
- rthnbgrredf 2y agoCan confirm. Have read many articles about known gang members and drug lords. It usually starts with doing some dumb things at younger age and then struggle to find and keep a legal job.
- RIMR 2y agoThink about the "innovation" here. Learning to set up your own cell tower is quite a feat, but how are you going to monetize it? Are you going to start your own cell provider and try to compete with the existing major players? Or are you going to use the tech for some fast capital right now? If the goal was to learn just enough about cell tech to exploit it for profit, then a legal approach is off-the-table because of the extraordinary effort needed to ever get anything off the ground.
- skrbjc 2y ago
- Scoundreller 2y ago> For example, EE has stopped tens of millions of scam SMS messages since stepping up its anti-spam filter in 2021. So, they blocked like 2% ?
- vdfs 2y agohttps://xkcd.com/1161/ https://xkcd.com/1161/
- tamimio 2y agoBuilding a homemade BTS (Base Transceiver Station) is easy. I remember making one back in 2011 with a USRP SDR. Nowadays, you can even create a 5G network, not just LTE. There’s plenty of good open-source software available. Paired with an SDR, you are good to go. The rest is just some scripting to automate some tasks, probably how they flooded the SMS.
- stainablesteel 2y agoso why do i pay for cell phone service? you're saying most people can just point some metal out of their window and the neighborhood would be happy?
- nexuist 2y agoWait till you find out about diesel generators!
- Elv13 2y agoThe phone part is no different. It's easy to run your own FreeSWITCH or Asterisk server at home and connect a cellphone using Wireguard. It costs ~0.5$ US per month to get nearly unlimited everything. Calls and SMS work just fine. The problem is always mobility. You need either Wifi or some of those odd reseller brand ultra cheap pre-paid plans (like "1$ for the first 200mb" plans). Then you need to make sure only the voice/sms is allowed to use the data and you get a 2$ nationwide working cellphone. You can also share someone else plan by having them leaving their Phone wifi hotspot on. As for reliability, well, that's your problem now, good luck! > point some metal out of their window and the neighborhood would be happy? You might, but the FCC won't
- tamimio 2y agoYou pay for the coverage and the infrastructure they built. > you're saying most people can just point some metal out of their window and the neighborhood would be happy Technically? Yes, you can do it in a few hours, or as a weekend project if you’ve never done it before. Just grab a full-duplex SDR; you don’t need to go for expensive ones like the USRP. Get a BladeRF or LimeSDR, download the software, and set up the station. The problem lies with the regulations. Depending on where you live, you might face hefty charges for violating spectrum rules, and they are actively looking for such violations by the way. One of the proofs of concept we did with the regulators here in Canada involves using a drone to detect these violations. It’s just a matter of time before they find you.
- Havoc 2y agoI do wonder whether this is the right move. Sure law breaking must be punished, but seems like precisely the skillset & mindset you'd want on your side if you were potentially heading towards confrontation in a world of cyber, drones and asymetric warfare...
- wongarsu 2y agoDepends on the sentence he gets. They did just write about his name and skillset in a national newspaper. If he only serves a year or two that can end up as a positive for his career.
- andylynch 2y agoI’m sure the folks from Cheltenham can find them if they want a chat. But given these guys appear to have been running this as part of a bigger spam/fraud game rather than for curiosity/ general mischief they might be too far in the poacher category for the gamekeepers.
- ptero 2y agoTo me, this is the right move. The skillset needed to build such RF endpoints is not that rare. Any decent EE college graduate should be able to rig one up with an off the shelf software-defined radio and some literature review. If all they did were to build it for laughs and boasts I would hope they would just be yelled at and threatened with a sizeable fine next time they try such spectrum violations. But they apparently phished a lot of information with the intent to defraud folks, which in my book completely changes the proper response. My 2c.
- coretx 2y agoThe A/51 rainbow tables can be found here: https://opensource.srlabs.de/projects/a51-decrypt/files https://opensource.srlabs.de/projects/a51-decrypt/files It can be made to work using a 10 bucks RTLSDR for RX. Had they used a legal provider for the TX, they would not have been caught. This smells like yet another case of children at work and police officers trying to sell themselves as super heroes. This is getting old.