Live data from Hacker News

Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

nbcwashington.com

101–110 of 112 posts

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#101

Earlier quoted context omitted.

Honestly, I don't want to be on the radar of any entity that is deploying this type of gear in the DC metro area. I am under no illusion that I can protect myself if targeted by a state based actor. Better to be lost in the crowd. Best case scenario is it's a legitimate LEO operation. Worse, it's a federal national security operation. Worse still, it's a criminal, or foreign national security operation. Only in the f…

I’m interested in attempting something similar in Europe. Do you have some links/pointers? Thanks!

There was a defcon talk a couple of years ago that covers some of the basics: https://www.youtube.com/watch?v=bbDAa0syz5A

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#102
post #72
post #35

Earlier quoted context omitted.

The protocol should have required enough authentication to make it impossible to manufacture these devices without also having a blessed, revocable key from the carrier you're snooping on. The FCC could have easily had their police exemption without also providing access to your average HAM, any reasonably competent hobbyist, and the security services of every other nation on the planet. Security on cellular networks…

Aren’t Stingrays basically fixed with LTE?

If your phone connects to a Stringray device, it will force it back to older protocols afaik.

Also:

https://www.zdnet.com/article/stingray-security-flaw-cell-ne...

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#103

Fix the busted protocol, why is anyone expecting this not to be a problem? Use legitimate warrants to monitor communications on premise at the telco.

Encryption protocols are hard. Two stories, one public and one from my current job: HTTPS is secured using SSL/ TLS. SSLv1 is so bad it didn't survive the laugh test when it was explained to actual cryptographers, I can't find any records of what it did. SSLv2 is also pretty bad. SSLv3 is at last good enough that actual cryptographers spent time finding holes in it and today it's considered so broken as to be useless…

I agree encryption is hard, but phone encryption protocols are intentionally weak for the wrong reasons. In the past the parameters have been picked low enough that domestic intelligence agencies can purposely hack them, while exporting even worse versions so that foreign adversaries are dead simple to hack. The protocols have changed over time, but this hasn't.

Also the examples you cite it's not clear of those standards bodies were infiltrated by the same agencies implicated above. They very much do run private cover operations and "plant" people or acquire companies that allow them to weaken these protocols or standards.

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#104
post #74

Earlier quoted context omitted.

They can't listen to your calls without cracking the keys shared between the phone company and your phone...though I do remember reading a while back that "someone" managed to steal the list from sim card manufacturers on more than one occasion.

That is not true. Stingray's are cell towers and phones trust them. The device just downgrades to A5/2 (export grade) encryption, or broadcasts that it does not support encryption at all.

Seems like a huge oversight to not let SIM cards disable certain types of encryption (that it knows the home network will never use). IIRC this is how downgrade attacks are prevented in EMV - the chip card will reject known-broken auth methods.

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#105
post #24

Earlier quoted context omitted.

Honest question: If an embassy started blaring very loud music (or a siren), can the US do anything about it? Likewise, if they started emitting strong microwaves at people, can the US do anything about it? It seems like there must be some limitation to what you can do from the embassy to people outside of it.

The loud music would draw a political rebuke / protest response, and then after if it didn't cease, it would plausibly draw some kind of tit for tat response in the other nation. The US can expel diplomats and isolate an embassy (eg cut power, water, etc), essentially making it non-maintainable (inhospitable) as a position. It could also surround it literally, effectively sealing it off to access, preventing the abil…

Given that embassies are not actually foreign soil, if the offense was bad enough, US authorities will simply storm the place and make it stop.

But that's a drastic action that won't happen before many other options have been tried.

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#106
When an encryption algorithm is no longer secure, it gets phased out and any protocol that uses that algorithm eventually gets denied.

Can someone explain why older protocols like 2g with inadequate encryption can't be phased out? Or why there isn't even an effort or attempt or option to disable it?

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#107
post #17
post #10

Earlier quoted context omitted.

Would this be defeated by having those people use some encrypted voip?

You wouldn't get the contents, but you could tell who was talking to whom, when, and for how long.

Unless the encrypted Voip went through a central server.

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#108
post #106

When an encryption algorithm is no longer secure, it gets phased out and any protocol that uses that algorithm eventually gets denied. Can someone explain why older protocols like 2g with inadequate encryption can't be phased out? Or why there isn't even an effort or attempt or option to disable it?

It’s not just the ciphers that were weak to begin with. It’s also the lack of mutual authentication: the network checks if the phone is entitled to service but the phone never checks if it’s a legitimate base station.

Telcos do not care about technical means of security. As long as the average person can’t eavesdrop it’s good enough. When it comes to protecting their economic interest (preventing free calls) they use smart cards and strong encryption. 800MHz scanners have been illegal for decades.

Legacy support and reliability are very important (in the context of cellular service which still is inferior to fixed telecommunications). Customers will get angry if you tell them their phone is obsolete. Or encryption incompatibility causes failed calls. The FCC takes a dim view on 911 failures, so phones must have a fallback no enciphering mode to maximize 911 call success. Compatibility with roaming host networks must be maintained.

AT&T shut down their GSM network Jan 1 2017 but UMTS has plenty of vulnerabilities too. The SS7 protocol underpinning the PSTN lacks authentication.

Re: Devices Which Track Cellphones, Intercept Calls Found All Over DC, MD, VA

#109
post #74

Earlier quoted context omitted.

That is not true. Stingray's are cell towers and phones trust them. The device just downgrades to A5/2 (export grade) encryption, or broadcasts that it does not support encryption at all.

Seems like a huge oversight to not let SIM cards disable certain types of encryption (that it knows the home network will never use). IIRC this is how downgrade attacks are prevented in EMV - the chip card will reject known-broken auth methods.

The FCC takes a dim view on 911 call failures. All phones must support disabling GSM encryption as a fail safe. Never disabling encryption would be “fail secure” (like door locks that remain locked during a power outage).
Post reply on HN