Live data from Hacker News

Did 5G kill the IMSI catcher?

zetier.com

21–30 of 122 posts

Re: Did 5G kill the IMSI catcher?

#22
The article mentions active catchers "requires RF transmission, which violates FCC laws (and international equivalents) and is detectable"... except...

... couldn't one build a 'modern' IMSI catcher with a CBRS LTE band 48 small cell and their own LTE infrastructure and be above-board legal anyways?

Re: Did 5G kill the IMSI catcher?

#23
post #21

I know very little about the protocol aspects of cellular communication, so can anyone explain how such a huge gaping security hole could come into existence?

No curious reason for it coming into existence. It's software, it will have bugs and oversights. What's curious is that it and so many other problems of the cellular grid have been left untended to for almost three decades.

Re: Did 5G kill the IMSI catcher?

#24
post #3

I've always been wondering: Is there a SIM card configuration flag that allows telling the phone to never even attempt an attach using a given technology? This would allow leaking identifiers (at the cost of greatly reducing roaming coverage, at the moment), attaching to spoofed networks (for 2G, which does not have mutual authentication) etc.

if you pay the google tax for a pixel, you get a convenient 2G toggle. if you don't have an extra $400-900 and buy a cheaper android, you get to dial # #4636# # (hn screws asterisks, look it up) them go into phone info, select each sim radio and change the drop down (and hopefully you know all the standards by all names to make the right choice. hint 5G is NR there)

There's a convenient toggle on my Moto G Stylus 5G 2023, if not a convenient name. In the carrier settings right next to allow 5G. Can't easily disable 3G or LTE though. IIRC, LTE is also mutually authenticates, but if we're talking about passive catching and the ismi is sent in the clear as the article says, then that doesn't eliminate passive catching. I'm not sure about 3G, I thought it wasn't mutual auth either.

Re: Did 5G kill the IMSI catcher?

#25
post #21

I know very little about the protocol aspects of cellular communication, so can anyone explain how such a huge gaping security hole could come into existence?

In the beginning of cell phones, security was too expensive. Telcos also like to do their own things, so GSM encryption wasn't built on best practices. And some countries forbid use of even GSM encryption.

Early mobile phone networks suffered from cloning, so work was done to improve verification of clients, but verifying the network wasn't seen as required. Telcos have been historically light on authentication and verification; so it's not surprising.

Re: Did 5G kill the IMSI catcher?

#26
post #6

Criminal IMSI catchers are pretty much dead, but with the aid of carriers law enforcement can still use similar technology even with full standalone 5G networks. I don't know how often unauthorized IMSI catchers are used in the wild, but I doubt it's a relevant percentage of the total amount of IMSI catchers out there. Thanks to mmWave and beam forming, 5G allows operators to practically track you down to the exact c…

5G beamforming is not that accurate a proxy signal, and mmWave is phone vaporware, instead only significantly used for point-to-point connections. Line-of-sight requirements make it dead in the water for anything else.

Re: Did 5G kill the IMSI catcher?

#27
post #4
post #2

iPhones, in general, will not connect to a 5G Standalone network that doesn’t have SUCI enabled.

So they'll just fall back to 4G then, which always sends the IMSI in the clear on initial attach?

5G Standalone networks don’t have 4G to fall back to. 5G Non-standalone networks are essentially 4G networks with a 5G RAN, so SUCI remains optional and most core vendors don’t support it.

Re: Did 5G kill the IMSI catcher?

#28
post #12
post #5

Earlier quoted context omitted.

Source?

> 5G Standalone security and privacy requirements > To help ensure compatibility of iPhone and cellular iPad devices on private 5G SA networks, infrastructure vendors must adhere to the following security and privacy requirements: > Privacy concealment: The Subscription Concealed Identifier (SUCI) must use a non-null protection scheme. This can be achieved through either an on-SIM SUCI calculation or an ME SUCI calcu…

In the US, the T-Mobile 5G SA eSIM and SIM cards all have SUCI at least. I don’t have any idea about other networks.

Re: Did 5G kill the IMSI catcher?

#29
post #6

Criminal IMSI catchers are pretty much dead, but with the aid of carriers law enforcement can still use similar technology even with full standalone 5G networks. I don't know how often unauthorized IMSI catchers are used in the wild, but I doubt it's a relevant percentage of the total amount of IMSI catchers out there. Thanks to mmWave and beam forming, 5G allows operators to practically track you down to the exact c…

Is this a US-centric view? Presumably crossing national borders, as noted in the article, it would be more effective to catch IMSIs. When there are lots of countries clustered together in a smaller geographical space, ie, not the USA, it might be relevant.

But I don't know.

Re: Did 5G kill the IMSI catcher?

#30
post #8

Earlier quoted context omitted.

> depending on how willing the firmware of your modem is, the signal used to transfer GPS coordinates to the carrier for emergency response situations can also be triggered remotely by carrier hardware Do you know if (at least some) basebands actually limit network-side location requests to emergency call/text situations only?

All I know is that some don't. I don't know brands or if there are even common modems that are filtering for this. If you don't have a Faraday cage and cell site equipment, you're going to have a hard time verifying any of this. The modem is closed source, the SIM card is closed source, and various firmware blobs to make phones work are all closed source. I believe Qualcomm has debug interfaces on some chipsets, whic…

Agreed – it's not really a personal concern I have (I have no illusions about the chances that none of the apps I grant location access to are selling it to the highest bidder), but I'm still curious. I can also imagine some legitimate use cases, such as pinging the location of somebody that had an accident and is possibly unable to call 911 themselves.

And same here – I've read a few of the 3GPP specs, but they make legalese sound like plain English, and of course never tell the full story including actual manufacturer decisions.

Post reply on HN