Live data from Hacker News

How to Block Stingray Devices

oaklandmofo.com

21–30 of 58 posts

Re: How to Block Stingray Devices

#22
It’s worth pointing out that even the author admits that the newer Stingray II has 3G/4G support. I think this is probably related to known insecurities in the AKA protocol, as researchers have recently found [1]. It looks like call interception isn’t so straight forward anymore, but IMSI capture and approximate location capture are alive and well.

So unless you can verify that only Stingray I is deployed in the vicinity, I think it’s a stretch to say that the Stingray product “doesn’t care” about anything other than 2G.

[1] https://www.blackhat.com/docs/us-17/wednesday/us-17-Borgaonk...

Re: How to Block Stingray Devices

#24
post #19

Earlier quoted context omitted.

Do you have information on professional detection equipment? Detection apps are known to be ineffective. It's mostly because IMSI catchers comply with the standard. Your baseband will fall for that - there's not much useful information to be passed to the operating system - or even an app.

Most firms who sell lawfull interception appliances also sell the appliances required to protect, detect or mitigate against it. Usually they only sell their appliances to law enforcement, the militairy and intelligence agencies after signing a NDA. The legality is often dubious, and atleast some are nothing but a expensive user friendly box around GNU radio, osmocom and very little code of their own. ( But my knowle…

I won't contact you in that matter. I get an idea from what you've said, thank you.

Re: How to Block Stingray Devices

#25
post #9

Earlier quoted context omitted.

Stingrays already work with 4g. And 5g has many of the same flaws, likely on purpose. We can only hope common criminals will start massively exploiting them if we want real change to happen.

What flaws are there, exactly? Missing mutual authentication are the main cause for 2G's security issues. There are no trivial MitM attacks on 3G and 4G - besides denial of service that may result in downgrades. There are location and identity leaks, but that's user tracking at best. Not to compare with 2G. What am I missing here?

There is no problem for a stasi wannabe to use legal process to extort the base station credentials from the phone company. There should be defences against carrier assisted MITM, like signed NONCEs and per-carrier station public key registers with accountable station data (location, station photos, etc)

Re: How to Block Stingray Devices

#26
post #25

Earlier quoted context omitted.

What flaws are there, exactly? Missing mutual authentication are the main cause for 2G's security issues. There are no trivial MitM attacks on 3G and 4G - besides denial of service that may result in downgrades. There are location and identity leaks, but that's user tracking at best. Not to compare with 2G. What am I missing here?

There is no problem for a stasi wannabe to use legal process to extort the base station credentials from the phone company. There should be defences against carrier assisted MITM, like signed NONCEs and per-carrier station public key registers with accountable station data (location, station photos, etc)

If you question lawful interception, then your problem is not the technical standard that allows it, but your have a problem with society and the laws it implements.

There are good reasons to have security endpoints in the core network instead of the base stations. But it doesn't affect lawful interception at all.

Re: How to Block Stingray Devices

#28
On modern phones Stingray devices are just one of the many tools that can be used to gain access to private communications and data. Any app requiring access permissions to everything is a potential vulnerability that can be exploited by 3rd parties (not to mention closed blobs etc); in this context smartphones are all things considered much more vulnerable than old 2G ones. Not being a target of interest for the police myself, I will rather trust my old obsolete 2G only dumb phone because the chances of it being spied upon by Google, Microsoft, Apple, Facebook etc. and associated parties are zero, zero, zero and zero.

Re: How to Block Stingray Devices

#29
post #20

> So they stand between you and the tower and sift through the transmission first. This means they can now intercept data on that transmission. I don’t know what they can do with it, and there is no real clear information on what data they can get. They do say metadata and access the cellphones internal storage, so that is enough to want to block the Stingray. Cellphones internal storage? Seriously?

"Service update" SMS messages can write certain things to the SIM card and other aspects of the phone without user interaction. (this machinery is rather hard to google for and I'm not sure if it has a better name in the official GSM documents)

That's interesting, it sounds like something that was being repeatedly sent to my Motorola flip phone in China in 2007. I had the ability to reject this SMS/MMS thankfully.

Re: How to Block Stingray Devices

#30
post #6

Earlier quoted context omitted.

You can force a phone into 2G handshaking, that's how stingrays work.

Okay, thanks for the explanation. Meanwhile, setting my Samsung Galaxy S9 to no-2G gives me a warning message that cannot be dismissed: "This setting turns off 2G service. If 2G service is off, some app..." (the remainder can't be viewed).

> (the remainder can't be viewed).

Sounds like terrific UI design

Post reply on HN