Live data from Hacker News

Hacker Spoofs Cell Phone Tower to Intercept Calls

wired.com

21–26 of 26 posts

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#21
post #19

Can a similar, simpler method be used to steal WEP/WPA passwords? Set up a wireless AP broadcasting an existing SSID. Some existing clients connect to it passing the keyphrase. Verify against the actual AP. Would this work?

http://webcache.googleusercontent.com/search?q=cache:VArK7Jz...

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#22
post #8

I believe one of the more important differences between a GSM SIM and 3G USIM is that the network is required to prove its identity to the user. You can use a standard GSM 2G SIM with a 3G WCDMA network and in that case only the network requires the phone to prove its identity. With a USIM, the network also has to prove its identity. So you're not automatically protected when using 3G WCDMA network. You need to upgra…

I know there are several conversion functions for a USIM to be able to authenticate on a 2G network, but I didn't think it was possible for a 2G SIM to register on a 3G network. Can you explain this more thoroughly?

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#23
As I had not seen this mentioned here or in article; You can read more about Chris's work here, http://www.tombom.co.uk/blog/ and I would have posted the 'OpenBTS on Droid' a while back if I'd known it was a 'scoop' :) My thoughts were of some kind of shared cellular access point that could be used in the developing world to give access to a sub-let access point with a 'real' connection.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#24
post #6

This reminds me of one of the points in the End-to-End Argument by Saltzer. The network protocol offering to encrypt the payload is broken, because the two end clients should undertake to secure their communication if it's necessary. In this case I have some sympathy though, because it's not easy for two humans speaking with their voices to come up with a way to encrypt it. Maybe the responsibility should fall on the…

Most phones do issue a warning if ciphering isn't enabled. On some you may be able to force it to require it. But keep in mind that this is only applied on the radio interface anyways (and GSM encryption is so broken you shouldn't be relying on it anyways). If you want end to end encryption of your calls you will need to use encrypted VOIP over your data connection.

Re: Hacker Spoofs Cell Phone Tower to Intercept Calls

#26
post #22
post #8

I believe one of the more important differences between a GSM SIM and 3G USIM is that the network is required to prove its identity to the user. You can use a standard GSM 2G SIM with a 3G WCDMA network and in that case only the network requires the phone to prove its identity. With a USIM, the network also has to prove its identity. So you're not automatically protected when using 3G WCDMA network. You need to upgra…

I know there are several conversion functions for a USIM to be able to authenticate on a 2G network, but I didn't think it was possible for a 2G SIM to register on a 3G network. Can you explain this more thoroughly?

It all depends on the operator. A UMTS (3G) network can accept users using a GSM SIM if the operator allows it.

Authentication is performed by the network HLR (Home location register) which is independent of the radio technology used. The procedure/algorithms are different for 3G-capable UEs with USIM, but the HLR can accept 2G users as well.

Bottom line is that if your 'home carrier' (the one that produced the SIM) allows it, you can use your SIM in any 3G network that is part of the roaming agreement of that carrier.

Post reply on HN