Live data from Hacker News

Hacker Spoofs Cell Phone Tower to Intercept Calls

wired.com

11–20 of 26 posts

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#11
Having recently returned an AT&T 3G MicroCell after a 30 day exercise in futility and "support" horror attempting to activate it in a rural location… I want one of these![1]

If AT&T won't utilize the spectrum through my land for which they have been given stewardship, then perhaps I ought to be allowed to exercise it.

[1] Except I wouldn't get incoming calls, which is more important to me than outgoing.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#12
This reminds me of OpenBTS, the project to create an open-source GSM interface. A full dev kit costs about $2000.

http://openbts.sourceforge.net/

They've been using this system at Burning Man to operate a free experimental cell network:

http://pagalegba2010.wikispaces.com/PublicInformation

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#13
post #12

This reminds me of OpenBTS, the project to create an open-source GSM interface. A full dev kit costs about $2000. http://openbts.sourceforge.net/ They've been using this system at Burning Man to operate a free experimental cell network: http://pagalegba2010.wikispaces.com/PublicInformation

The guy who gave this talk, Chris Paget, actually used OpenBTS in his demo.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#14
post #11

Having recently returned an AT&T 3G MicroCell after a 30 day exercise in futility and "support" horror attempting to activate it in a rural location… I want one of these! [1] If AT&T won't utilize the spectrum through my land for which they have been given stewardship, then perhaps I ought to be allowed to exercise it. [1] Except I wouldn't get incoming calls, which is more important to me than outgoing.

You could probably setup a system to get incoming calls using something like Google Voice. Get a phone number for a VoIP account, forward GV to it and your real cell phone number, and set up your tower to route VoIP to your handset when it's connected.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#15
post #3

I have it on good authority that the U.S. military uses similar technology overseas for monitoring terrorists.

According to the italian anti mafia police force, mafiosi use skype to communicate to each other via voice. ( http://www.google.com/cse?q=Mafia+skype ) I would be surprise if terrorists weren't.

I'd be very surprised if most terrorists were 1/10 as clued in as the Mafia when it come to avoiding attention from law enforcement. Most Mafia bombs work and they don't run around setting their underwear on fire.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#18
post #5
post #3

I have it on good authority that the U.S. military uses similar technology overseas for monitoring terrorists.

Systems like these (tactical SIGINT, vs. the kind of strategic collection of everything. like NSA does) have been part of war pretty much ever since radio was invented. Most of Rommel's awesomeness in North Africa was due to his superior radio directing finding units. No need to necessarily translate enemy communications if you know where they are and when they're sending. The premier tier-1/special mission unit in t…

> I'm just waiting for the first fully autonomous weapon which combines signals intelligence and killing -- flies around listening for a specific IMSI, then drops down on the target and blows up.

The road to Skynet is paved with these kind of desires.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#20
post #19

Can a similar, simpler method be used to steal WEP/WPA passwords? Set up a wireless AP broadcasting an existing SSID. Some existing clients connect to it passing the keyphrase. Verify against the actual AP. Would this work?

in WEP's case, your AP would receive an auth response encrypted with the keyphrase... you'd have to get quite a few of these to deduce the password, in general. people find it easier to just sniff traffic and deduce the key from all the traffic generated from someone downloading crap.

i don't think this is at all realistic with wpa.

you could just set up an open network with an equivalent essid, but that's nothing new is it? :)

Post reply on HN