5 ms·
Unauthorized alert sent to cell phones across Brazil
- jpablo 4mo agoThe power to send mass messages to a whole country is the worst thing google/apple have given to governments across the world.
- woodruffw 4mo agoThis implies that governments didn’t already have this ability, which appears to be largely untrue? To my understanding, many countries already had emergency messaging systems, and mobile integrations are just a way of modernizing them. (It seems exceedingly good that the government can warn every civilian about natural disasters, etc.)
- fc417fc802 4mo agoGovernments had poorly thought out poorly secured barely functional systems involving the network operators and those were then integrated with default system apps that have terrible UX without fixing any of the problems AFAICT. Agreed that it's clearly necessary functionality but it's worse than useless when it's so far proven to be (at absolute best) a constant stream of irrelevant alarms.
- murderfs 4mo agoThese aren't from Google or Apple, they're from the wireless providers: https://en.wikipedia.org/wiki/Cell_Broadcast https://en.wikipedia.org/wiki/Cell_Broadcast
- alpinisme 4mo agoIf you say so. In the meantime I’ll continue to appreciate the occasional tornado warning.
- fc417fc802 4mo agoI've yet to receive one of those that was useful. Meanwhile the 70+ year old storm sirens mounted on the nearby office buildings work perfectly in my experience, being audible even indoors from many miles away.
- drivers99 4mo agoEven then. During a recent storm, they went off erroneously in Denver. (Looks like the other two erroneous alerts were via phone though.) > Denver emergency officials say they are working to rebuild public trust after a mistaken tornado siren activation Monday became the third improper emergency alert issued in the city this year. https://www.cbsnews.com/colorado/news/denver-tornado-alarms-mistake-official-skipped-protocols/ https://www.cbsnews.com/colorado/news/denver-tornado-alarms-...
- vitorgrs 4mo agoThis is not related to Google or Apple. And this extreme alert, it's sent even to cable TV automatically. In a few countries, it's sent even on Fax lines.
- antonvs 4mo agoWhere do AI-based military target selection systems fit in your ranking?
- mseepgood 4mo agoOf all the messages they could have sent they chose the most boring.
- neko_ranger 4mo agolets play a game HN, what would be the best alert to send? mine would be something scifi, like "ALIENS HAVE LANDED" or "PLUTO DECLARES WAR"
- tedk-42 4mo agoARGENTINA IS BETTER THAN BRAZIL
- michaeljx 4mo agoMETEOR STRIKE IN 8 MINUTES
- mckirk 4mo ago"THERE IS ABSOLUTELY NO CAUSE FOR ALARM"
- peddling-brink 4mo ago“DO NOT LOOK AT THE MOON”
- themafia 4mo ago"ALL DEBTS HAVE BEEN ERASED. JUBILEE."
- Scoundreller 4mo agoNot “unauthorized”, but previous cellular alert false alarms: https://www.ctvnews.ca/toronto/article/mistaken-pickering-ont-nuclear-alert-sparked-panic-emails-show/ https://www.ctvnews.ca/toronto/article/mistaken-pickering-on... https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_alert https://en.wikipedia.org/wiki/2018_Hawaii_false_missile_aler... Ok, hackers got blamed for this one: https://www.theguardian.com/us-news/2017/apr/09/dallas-hackers-sirens-alarms-emergency-system https://www.theguardian.com/us-news/2017/apr/09/dallas-hacke...
- throwaway81523 4mo agoThere was a Larry Niven story where if you tried to call a certain guy, every phone in South America would ring instead. Anyone remember which story it was? The phone thing was just a throwaway line, not a significant plot point.
- shagie 4mo agoRingworld. https://sciencemeetsfiction.com/2021/06/20/ringworld-theory-did-teela-brown-have-bad-luck/ https://sciencemeetsfiction.com/2021/06/20/ringworld-theory-... “When we call, they are out. When we call back, the phone computer gives us a bad connection. When we ask for any member of the Brandt family, every phone in South America rings.”
- p0w3n3d 4mo agoIt might have been the Ringworld "Well?"Nessus began to pace the floor. "Many disqualify themselves by obvious bad luck. Of the rest, none seem to be available. When we call, they are out. When we call back, the phone computer gives us a bad connection. When we ask for any member of the Brandt family, every phone in South America rings. There have been complaints. It is very frustrating." https://www.naneahoffman.com/the-blog/shelf-care-alien-architecture https://www.naneahoffman.com/the-blog/shelf-care-alien-archi...
- jagged-chisel 4mo ago“ When we ask for any member of the Brandt family, every phone in South America rings.” That sounds like the computer had a bad solution to “find a Brandt.” The comment with the request to find this reference had me thinking it would be a single phone number misconfigured to call a large population.
- Loughla 4mo agoIt actually had nothing to do with a computer! It was the luck of either Teela Brown, or Mr. Brandt depending on how you read the genetic trait of luck. If you haven't read ringworld, you should. It's really quite good. But stop before you get to ringworld's children or whatever it's called. Niven's furry fetish is in full force later in the series.
- p0w3n3d 4mo agoTBH phones in Poland allow to call you "from" an arbitrary number (i.e. display it on your phone). Also send SMS with arbitrary source. This is being used by scammers who call you and tell they are from police bank etc
- lxgr 4mo agoThis works in many countries, since the signalling protocols historically assumed a trusted small set of participants, not unlike email – with similar consequences once those assumptions became less and less true.
- deleted 4mo ago[deleted]
- kakacik 4mo agoI've worked a bit on the app which calls major telco provider directly. It was a basic web service call, and sender could be entered as anything. This is basic property of cellular networks, no more safety than say standard email.
- baconhigh 4mo agoit’s common for cheap esim providers to route data etc through cheaper data exits, i imagine this is partly why. (I recently purchased an esim and was surprised to see it exiting poland instead of the country the mobile provider (Bell) resides in)
- allthetime 4mo agoI constantly get scam calls from numbers that are very similar to my own in Canada. I assume this is an attempt to look like a normal trustworthy number.
- alfanick 4mo agoA) How is it related? B) I cannot just in my phone select caller ID I want, "phones in Poland allow to call you 'from'" is not true. It's just spoofing as in anywhere else and requires non-trivial technical knowledge.
- knuppar 4mo agomisantropia é um perigo rapaziada
- initramfs 4mo ago"The message sent was of the ‘Extreme Alert’ type and contained the word ‘misanthropy’ – which means hatred towards humanity. It is probably a hacker attack,” the agency’s statement said." As this happens whenever there is an intrusion reported in the press, the word "hacker" is often misused: "There is another group of people who loudly call themselves hackers, but aren't. These are people (mainly adolescent males) who get a kick out of breaking into computers and phreaking the phone system. Real hackers call these people ‘crackers’ and want nothing to do with them. Real hackers mostly think crackers are lazy, irresponsible, and not very bright, and object that being able to break security doesn't make you a hacker any more than being able to hotwire cars makes you an automotive engineer. Unfortunately, many journalists and writers have been fooled into using the word ‘hacker’ to describe crackers; this irritates real hackers no end. The basic difference is this: hackers build things, crackers break them." http://catb.org/~esr/faqs/hacker-howto.html http://catb.org/~esr/faqs/hacker-howto.html
- WarOnPrivacy 4mo agoDisabling alerts is the second thing I do to a new handset (after rooting) - including Presidential alerts. The Amber alerts I got were often hundreds of miles away. But even if they were closer - say only 25 mi away, I'm still not going to be any help. Weather alerts weren't much better. Having my device sound the klaxons over Red Flag warnings conditioned me to ignore all alerts.
- fc417fc802 4mo agoWhile I understand how we arrived at this point I find these centralized systems with special privileges frustrating. That they have repeatedly exhibited severe vulnerabilities and mismanagement is just the cherry on top. There ought to be a specification of an open protocol that includes certificate based authentication. I should be able to have my pick of which app to use and then subscribe to whatever feeds I'm interested in from anywhere in the world. In addition the local network operator should advertise various local feeds. What I'm describing is about as technically complicated as RSS plus public keys but as usual even moderate technical competency is a bridge too far for the government.
- harrall 4mo agoIt’s not a technical problem. And the problem is that it’s not centralized. Everyone and their mom has their own system, managed by different people with different standards. It’s like USB cables — yes there are strict technical standards but when you have a million different manufacturers, they all do it differently and some cut corners and bend the rules how they want to. Look at how two different cities handle their water supply or their police — different management, different priorities.
- fc417fc802 4mo ago> It’s not a technical problem. I agree. It's a lack of technical proficiency on the part of the world's government's problem, which is another way of saying it's a political problem. > And the problem is that it’s not centralized. It is, though. The implementation might not be uniform but the architecture is inherently centralized. Subscribers do not get to pick and choose sources, that is decided by the network operator (AFAIK). Consider, if BigCo wanted the ability to push alerts to people on their campus (who consent to receive them ofc) how would they go about it? If you have family who live elsewhere in the world and wanted to be apprised of natural disasters how would you subscribe to receive those alerts?
- thecaio 4mo ago[dead]
- denysvitali 4mo agoThere's a video [1] from the "hacker" sending the message. The hacker allegedly [2] stole the VPN credentials (of an employee and two colleagues, because they were doing credentials sharing apparently) from a personal computer ("RGB gaming PC") running Windows 7 (EOL), w/o antivirus and reportedly having search for Windows activators for Windows 10 and Office 2019. Cherry on top: the malware seems to have dropped via a malicious game install. Lol Ironically he recorded the video with CapCut, showing his ID, which also revealed their profile picture and identity [2]... If all of this is true, we're lucky they "only" paged the whole country instead of doing something even more harmful. This is some crazy level of incompetence / lack of security. [1]: https://x.com/i/status/2068482069643071749 https://x.com/i/status/2068482069643071749 [2]: https://x.com/i/status/2068633434591830290 https://x.com/i/status/2068633434591830290 [3]: https://x.com/i/status/2068488298998231117 https://x.com/i/status/2068488298998231117
- denysvitali 4mo agoIt also looks like they've used leaked old credentials that weren't updated in years: https://x.com/i/status/2068635848786972863 https://x.com/i/status/2068635848786972863
- danillonunes 4mo agoThe funniest thing is that apparently "misantropia" is just the hacker's nickname. People were making wholes theories about the meaning of the message, but most likely it was just a signature.
- ck2 4mo agoUSA has that new "Presidential Alert" right? wonder how that will be abused by 2029, at least once https://www.aau.edu/research-scholarship/featured-research-topics/new-spoofing-scam-national-emergency-alerts https://www.aau.edu/research-scholarship/featured-research-t...
- antonymoose 4mo agoMy state introduced Blue Alerts for crimes against police. I’ve been woken up at 0200 for an officer shot 200 miles away, as if I’m going to gather up a posse and ride on the scallywags responsible.