3 ms·
A few years ago I worked for a small Telco company who provided software for virtual MNOs, and security there was not that, let's say, inspiring confidence. It
by metafex 12y ago
A few years ago I worked for a small Telco company who provided software for virtual MNOs, and security there was not that, let's say, inspiring confidence.
It is generally a problem with small companies in the Internet and Mobile-services areas that security is only an afterthought. Partially also due to the fact that the protocols which are used are pretty old and do not implement much, if any, security measures.
edit: customers of the company were mostly in eastern europe, middle east and oceania, so maybe that was another reason ;-)
- maxerickson 12y agoUp until 2 years ago, Virgin Mobile USA rate limited PIN attempts using cookies: https://kev.inburke.com/kevin/open-season-on-virgin-mobile-customer-data/ https://kev.inburke.com/kevin/open-season-on-virgin-mobile-c... (VM USA was a VMNO, but now it's more of a Sprint brand, since 2009 Sprint owns them outright)
- schoen 12y agoThere's also the problem that when communications companies think of security, they may be thinking of "revenue protection" more than customer privacy (that is, making sure that customers have to pay to communicate, and that they get billed accurately). Ross Anderson liked to point out that the crypto that some cell phones used to discourage you from using aftermarket batteries was stronger than the crypto they used to protect your voice calls over the air. He's also suggested that the crypto in GSM ended up more focused on subscriber authentication than on voice privacy. There is also now a source for the notion that governments pressured the designers of GSM to make it not provide strong cryptographic privacy: http://www.aftenposten.no/nyheter/uriks/Sources-We-were-pressured-to-weaken-the-mobile-security-in-the-80s-7413285.html http://www.aftenposten.no/nyheter/uriks/Sources-We-were-pres... Here is a sad thing: Governments are STILL pressuring the designers of GSM to make it not provide strong cryptographic privacy. Like, today. We got some documents from ETSI only a couple of years ago showing that they are designing a cryptographic backdoor mode for the official GSM end-to-end voice encryption, which isn't even deployed yet. The use of the backdoor mode will be optional according to carriers' view of their jurisdictional obligations. Sorry, that last part is less on-topic for this thread. But in the big picture, I'm sure the people who are involved in those efforts are not making corresponding compromises in the billing and revenue-protection areas.