5 ms·
Even engineers like doing it sometimes. The old telephone system was so hackable because of in band signaling.
by NegativeLatency 2mo ago
Even engineers like doing it sometimes. The old telephone system was so hackable because of in band signaling.
- dylan604 2mo agoSome physical constraints do not allow for the best security, and those physical constraints will always win out in the real world. When presented with the pick two of three options of fast, cheap, secure/done right, fast and cheap will always win out.
- kayodelycaon 2mo agoAnd sometimes security can’t be a high priority. When it comes to building things: fire, building codes, inspectors, public, utilities, lenders, and insurance all go before security. All those dictate whether or not you can build in the first place. Real world constraints are everywhere. :)
- TeMPOraL 2mo agoAlso more commonly, security is at direct odds with utility. Not in the least here.
- dylan604 2mo agoNothing more secure than a system the users cannot use
- DANmode 2mo agoThe “new” phone system (SS7) still relies on implicit trust and a lack of security.
- inigyou 2mo agothat is not new. It is newer than the phreakable one but it is many decades old from before there were things like encryption, and Linux.
- DANmode 2mo agoCurrent system, unfortunately.
- inigyou 2mo agoNo, that's not true, there is no single current system. There is no telephony equivalent to BGP. Each separate interconnection uses whichever protocol it wants to.
- DANmode 2mo agoNobody drew a comparison to BGP. The commonality of the spider of systems you’re referring to is still implicit trust.
- kayodelycaon 2mo agoGenuinely curious, does the telephone system have enough scope to make it dangerous? Elevators are extremely hackable all over the world. It’s generally not considered a problem because it requires physical access, specific knowledge, and defeating cameras to exploit successfully. What can you do with the telephone system?
- tredre3 2mo agoIt depends how you define dangerous, I suppose. - Before everything was IP-based you could occupy a large number of lines and making it impossible for more calls to go through (i.e. 911). It's called TDoS and could be achieved through phreaking. - You can spoof your caller ID to make your scam more convincing. - You know how when you call your voicemail from your phone you're not asked for your PIN? The voicemail system only checks your caller ID to know it's you and skip the PIN. So, again by spoofing your caller ID and calling the voicemail number you can access listen to anyone's voicemail. This doesn't work on all providers, many have now reluctantly fixed the problem.
- TeMPOraL 2mo ago> You can spoof your caller ID to make your scam more convincing. I recently came closer than I'd like to falling for a scam (read: I picked up a call and conversed with the caller for 30 seconds before realizing it's a bot), simply because the notification for automatic call screening[0] displayed a summary of ongoing conversation, which happened to look very much like caller ID - it said "Name Surname, Department of Security, ${my wife's bank}". But it wasn't caller ID, just a bad interaction between the way the scam bot introduced itself, the summary feature of the call screening feature, and the UI design of the notification... -- [0] - A thing Samsung has on recent phones, where LLM picks up a "potential spam/scam" call in the background and engages with it, while producing a transcript and recording you can review as it happens.
- ArnoVW 2mo agoI can pretend to be someone with authority? (bank, policy, whatever) If the system becomes unavailable, then that's a huge issue? Any system that is that widely anchored in society is a valuable target.