Can either of you recommend resources or tools for learning how to design good protocols?
A simple software fix could limit location data sharing
11–18 of 18 posts
Re: A simple software fix could limit location data sharing
#12I'm co-author of this research (with my colleague Paul) -- happy to answer any questions.
First of all, congratulations, when you get Bruce Schneier to endorse your work, you have probably done something interesting. But still the article is not very clear on technical details. Of course on initial contacts your phone has to provide information about your service provider (they will somehow have to pay for your communications) and it has also has to have some form of identification about your phone (so th…
Re: A simple software fix could limit location data sharing
#13Can you elaborate a bit on that? Is every USIM using the same shared key?
Thanks!
Re: A simple software fix could limit location data sharing
#14I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by the AUF when it doesn’t know the shared key K between the USIM and the network? Can you elaborate a bit on that? Is every USIM using the same shared key? Thanks!
Re: A simple software fix could limit location data sharing
#15I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by the AUF when it doesn’t know the shared key K between the USIM and the network? Can you elaborate a bit on that? Is every USIM using the same shared key? Thanks!
Additional question for my understanding - this needs an app running in the background to send the signed token at every other time interval, correct?
Re: A simple software fix could limit location data sharing
#16I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by the AUF when it doesn’t know the shared key K between the USIM and the network? Can you elaborate a bit on that? Is every USIM using the same shared key? Thanks!
However, their use is to only gain IP connectivity - the equivalent of an allow list on the backend db (AUSF) which gives you IP connectivity. At that point you do billing and auth at the PGPP-GW using oblivious auth tokens.
Re: A simple software fix could limit location data sharing
#17BTW, why does truecaller on android 10 show an overlay after a call when settings page specifically disables it ?
Re: A simple software fix could limit location data sharing
#18I skimmed through the paper, what isn’t clear to me is how the original Registration Procedure is modified exactly. How is the Authentication Procedure done by the AUF when it doesn’t know the shared key K between the USIM and the network? Can you elaborate a bit on that? Is every USIM using the same shared key? Thanks!
The regular attach procedure is unchanged. In the simplest version we give every SIM the identical IMSI and key. However, their use is to only gain IP connectivity - the equivalent of an allow list on the backend db (AUSF) which gives you IP connectivity. At that point you do billing and auth at the PGPP-GW using oblivious auth tokens.
Also, regarding the IMEI - let‘s assume the UE nullified it, how would you distinguish between a legitimately nullified UE and a stolen UE that had its IMEI nullified?