How to Block Stingray Devices
21–30 of 58 posts
Re: How to Block Stingray Devices
#22So unless you can verify that only Stingray I is deployed in the vicinity, I think it’s a stretch to say that the Stingray product “doesn’t care” about anything other than 2G.
[1] https://www.blackhat.com/docs/us-17/wednesday/us-17-Borgaonk...
Re: How to Block Stingray Devices
#23Is that relevant, if your apps only communicate with encrypted messages (https only and so on)?
Re: How to Block Stingray Devices
#24Earlier quoted context omitted.
Do you have information on professional detection equipment? Detection apps are known to be ineffective. It's mostly because IMSI catchers comply with the standard. Your baseband will fall for that - there's not much useful information to be passed to the operating system - or even an app.
Most firms who sell lawfull interception appliances also sell the appliances required to protect, detect or mitigate against it. Usually they only sell their appliances to law enforcement, the militairy and intelligence agencies after signing a NDA. The legality is often dubious, and atleast some are nothing but a expensive user friendly box around GNU radio, osmocom and very little code of their own. ( But my knowle…
Re: How to Block Stingray Devices
#25Earlier quoted context omitted.
Stingrays already work with 4g. And 5g has many of the same flaws, likely on purpose. We can only hope common criminals will start massively exploiting them if we want real change to happen.
What flaws are there, exactly? Missing mutual authentication are the main cause for 2G's security issues. There are no trivial MitM attacks on 3G and 4G - besides denial of service that may result in downgrades. There are location and identity leaks, but that's user tracking at best. Not to compare with 2G. What am I missing here?
Re: How to Block Stingray Devices
#26Earlier quoted context omitted.
What flaws are there, exactly? Missing mutual authentication are the main cause for 2G's security issues. There are no trivial MitM attacks on 3G and 4G - besides denial of service that may result in downgrades. There are location and identity leaks, but that's user tracking at best. Not to compare with 2G. What am I missing here?
There is no problem for a stasi wannabe to use legal process to extort the base station credentials from the phone company. There should be defences against carrier assisted MITM, like signed NONCEs and per-carrier station public key registers with accountable station data (location, station photos, etc)
There are good reasons to have security endpoints in the core network instead of the base stations. But it doesn't affect lawful interception at all.
Re: How to Block Stingray Devices
#27Re: How to Block Stingray Devices
#28Re: How to Block Stingray Devices
#29> So they stand between you and the tower and sift through the transmission first. This means they can now intercept data on that transmission. I don’t know what they can do with it, and there is no real clear information on what data they can get. They do say metadata and access the cellphones internal storage, so that is enough to want to block the Stingray. Cellphones internal storage? Seriously?
"Service update" SMS messages can write certain things to the SIM card and other aspects of the phone without user interaction. (this machinery is rather hard to google for and I'm not sure if it has a better name in the official GSM documents)
Re: How to Block Stingray Devices
#30Earlier quoted context omitted.
You can force a phone into 2G handshaking, that's how stingrays work.
Okay, thanks for the explanation. Meanwhile, setting my Samsung Galaxy S9 to no-2G gives me a warning message that cannot be dismissed: "This setting turns off 2G service. If 2G service is off, some app..." (the remainder can't be viewed).
Sounds like terrific UI design