Live data from Hacker News

Hacker Spoofs Cell Phone Tower to Intercept Calls

wired.com

1–10 of 26 posts

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#4
post #3

I have it on good authority that the U.S. military uses similar technology overseas for monitoring terrorists.

For a month in the spring my route to work took me by bicycle past three of the embassy in Copenhagen. You could see some radio antennas on one of them (I think it was the Russian one, but I am not entirely sure) - it didn't take that many brain cells to figure out what that was being used for.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#5
post #3

I have it on good authority that the U.S. military uses similar technology overseas for monitoring terrorists.

Systems like these (tactical SIGINT, vs. the kind of strategic collection of everything. like NSA does) have been part of war pretty much ever since radio was invented.

Most of Rommel's awesomeness in North Africa was due to his superior radio directing finding units. No need to necessarily translate enemy communications if you know where they are and when they're sending.

The premier tier-1/special mission unit in the US military (Intelligence Support Activity (ISA), aka "the Activity", Gray Fox, Torn Victor, Cemetery Wind, Centra Spike, ... they have a lot of code names) was basically the key piece in killing Pablo Escobar (the book "Killing Pablo" is a pretty good account). They're obviously extensively involved in Iraq and Afghanistan.

One of the major reasons the military was more effective in 2005-now in Iraq, vs. 2003-2004, is that cellphones spread out to cover the whole country, and insurgents and their friends used cellphones (although this is more "strategic" vs. tactical/field gathering like this system).

I'm just waiting for the first fully autonomous weapon which combines signals intelligence and killing -- flies around listening for a specific IMSI, then drops down on the target and blows up.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#6
This reminds me of one of the points in the End-to-End Argument by Saltzer. The network protocol offering to encrypt the payload is broken, because the two end clients should undertake to secure their communication if it's necessary. In this case I have some sympathy though, because it's not easy for two humans speaking with their voices to come up with a way to encrypt it. Maybe the responsibility should fall on the local code running on each phone?

http://web.mit.edu/Saltzer/www/publications/endtoend/endtoen...

Of course, I know close to nothing about radio security, so maybe the world as it exists today is optimal but the phone makers blundered in ignoring the insecure warning?

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#7
post #3

I have it on good authority that the U.S. military uses similar technology overseas for monitoring terrorists.

According to the italian anti mafia police force, mafiosi use skype to communicate to each other via voice. (http://www.google.com/cse?q=Mafia+skype) I would be surprise if terrorists weren't.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#8
I believe one of the more important differences between a GSM SIM and 3G USIM is that the network is required to prove its identity to the user.

You can use a standard GSM 2G SIM with a 3G WCDMA network and in that case only the network requires the phone to prove its identity. With a USIM, the network also has to prove its identity.

So you're not automatically protected when using 3G WCDMA network. You need to upgrade to a USIM.

Note: The above refers to 3GPP GSM/WCDMA technology. Not sure about IS-95 (Qualcomm's CDMA) and its multiple variants.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#9
post #6

This reminds me of one of the points in the End-to-End Argument by Saltzer. The network protocol offering to encrypt the payload is broken, because the two end clients should undertake to secure their communication if it's necessary. In this case I have some sympathy though, because it's not easy for two humans speaking with their voices to come up with a way to encrypt it. Maybe the responsibility should fall on the…

As far as I understand the issue in this case is not the lack of end-to-end security, it is that it's possible to trick the phone to tranmsit without encryption for regular calls. Non-encrypted calls are needed because it is important to allow making emergency calls (e.g. 911) without a SIM being present or without a PIN number and it's the SIM card that has the encryption key, not the handset.
Post reply on HN