Live data from Hacker News

New 5G flaws can track phone locations and spoof emergency alerts

techcrunch.com

11–20 of 27 posts

Re: New 5G flaws can track phone locations and spoof emergency alerts

#13
Anyone doing this would of course risk jail time but I wonder if not the only thing which would force them to fix the security issues in the cell phone protocols would be some large scale attacks from ordinary citizens. The cell phone protocols just seem like a total mess with security issues left in them for legacy reasons and various vulnerabilities used by police forces.

Re: New 5G flaws can track phone locations and spoof emergency alerts

#16

As did 4G. Nothing new.

The authors mention the headline attacks in a side note only. Their paper is about formal verification of the standard. That is indeed something new. Their framework finds a couple of new issues -- and also old ones, which made it to the headline.

Re: New 5G flaws can track phone locations and spoof emergency alerts

#17
post #13

Anyone doing this would of course risk jail time but I wonder if not the only thing which would force them to fix the security issues in the cell phone protocols would be some large scale attacks from ordinary citizens. The cell phone protocols just seem like a total mess with security issues left in them for legacy reasons and various vulnerabilities used by police forces.

> Anyone doing this would of course risk jail time

I think the folks who would be most likely to be be using these exploits are the last people who would ever face fail time for it: folks working for some three letter agency. They're not going to go to jail for their government-sanctioned abuse of these flaws.

Re: New 5G flaws can track phone locations and spoof emergency alerts

#18
post #17
post #13

Anyone doing this would of course risk jail time but I wonder if not the only thing which would force them to fix the security issues in the cell phone protocols would be some large scale attacks from ordinary citizens. The cell phone protocols just seem like a total mess with security issues left in them for legacy reasons and various vulnerabilities used by police forces.

> Anyone doing this would of course risk jail time I think the folks who would be most likely to be be using these exploits are the last people who would ever face fail time for it: folks working for some three letter agency. They're not going to go to jail for their government-sanctioned abuse of these flaws.

Maybe I expressed myself poorly but I think you missed my point. My point was that the only way to force people to fix the issues is if ordinary hackers who are not working for any three latter agency start attacking the infrastructure too. And if you do that you risk prison time, even if you only do harmless exploits to highlight weaknesses.

Re: New 5G flaws can track phone locations and spoof emergency alerts

#20
post #8

Oh boy here we go. What are the odds Chinese vendors have designed these as bugdoors? That'd give them a good motive to push so hard for this adoption.

Considering these are vulnerabilities in the underlying protocol/spec created by 3GPP (US, South Korea, majority Japan, with a single Chinese partner) and ratified by the UN's ITU, and exist on handsets that implement 5G as spec-ed from all over the world, nearly 0% chance.

What's your basis for the claim "Chinese vendors" did it?

Post reply on HN