Live data from Hacker News

Did 5G kill the IMSI catcher?

zetier.com

31–40 of 122 posts

Re: Did 5G kill the IMSI catcher?

#31
post #27
post #4

Earlier quoted context omitted.

So they'll just fall back to 4G then, which always sends the IMSI in the clear on initial attach?

5G Standalone networks don’t have 4G to fall back to. 5G Non-standalone networks are essentially 4G networks with a 5G RAN, so SUCI remains optional and most core vendors don’t support it.

That's not what 5G standalone means, as far as I understand.

The network I'm using supports 5G SA in some cells, but my phone definitely still falls back to both 4G and 5G non-SA in some areas where it's not yet available.

And even if 5G SA were available everywhere, there's the concern of roaming.

Re: Did 5G kill the IMSI catcher?

#33
post #8

Earlier quoted context omitted.

> depending on how willing the firmware of your modem is, the signal used to transfer GPS coordinates to the carrier for emergency response situations can also be triggered remotely by carrier hardware Do you know if (at least some) basebands actually limit network-side location requests to emergency call/text situations only?

All I know is that some don't. I don't know brands or if there are even common modems that are filtering for this. If you don't have a Faraday cage and cell site equipment, you're going to have a hard time verifying any of this. The modem is closed source, the SIM card is closed source, and various firmware blobs to make phones work are all closed source. I believe Qualcomm has debug interfaces on some chipsets, whic…

Also worth noting that if the carrier is cooperating then you can do better than static snapshots. Tracking signal strength of a target moving between towers will give you quite a precise historic path (within a few seconds or minutes depending on velocity).

Re: Did 5G kill the IMSI catcher?

#34
post #21

I know very little about the protocol aspects of cellular communication, so can anyone explain how such a huge gaping security hole could come into existence?

No curious reason for it coming into existence. It's software, it will have bugs and oversights. What's curious is that it and so many other problems of the cellular grid have been left untended to for almost three decades.

The issues with cell network security go way beyond "bugs and oversight". Whether malicious or incompetent I have no idea.

Re: Did 5G kill the IMSI catcher?

#35
post #25
post #21

I know very little about the protocol aspects of cellular communication, so can anyone explain how such a huge gaping security hole could come into existence?

In the beginning of cell phones, security was too expensive. Telcos also like to do their own things, so GSM encryption wasn't built on best practices. And some countries forbid use of even GSM encryption. Early mobile phone networks suffered from cloning, so work was done to improve verification of clients, but verifying the network wasn't seen as required. Telcos have been historically light on authentication and v…

Adding to this the GSM A3/A8 algo were broken shortly after they arrived in the US. The only mitigating control was my boss in a wireless provider and the FBI meeting up with someone that was going to demo breaking it. They were advised what prison they would be relocating to and the demo was called off. Rinse and repeat. This was before the internet was popular or even widely used. The word eventually got out.

Re: Did 5G kill the IMSI catcher?

#36
post #25
post #21

I know very little about the protocol aspects of cellular communication, so can anyone explain how such a huge gaping security hole could come into existence?

In the beginning of cell phones, security was too expensive. Telcos also like to do their own things, so GSM encryption wasn't built on best practices. And some countries forbid use of even GSM encryption. Early mobile phone networks suffered from cloning, so work was done to improve verification of clients, but verifying the network wasn't seen as required. Telcos have been historically light on authentication and v…

[deleted]

Re: Did 5G kill the IMSI catcher?

#37
post #3

I've always been wondering: Is there a SIM card configuration flag that allows telling the phone to never even attempt an attach using a given technology? This would allow leaking identifiers (at the cost of greatly reducing roaming coverage, at the moment), attaching to spoofed networks (for 2G, which does not have mutual authentication) etc.

if you pay the google tax for a pixel, you get a convenient 2G toggle. if you don't have an extra $400-900 and buy a cheaper android, you get to dial # #4636# # (hn screws asterisks, look it up) them go into phone info, select each sim radio and change the drop down (and hopefully you know all the standards by all names to make the right choice. hint 5G is NR there)

One can backslash escape the asterisks. **

    \*\*

Re: Did 5G kill the IMSI catcher?

#38
This is sort of meta to the article...

Wow a web site generated using AI[1]. (or perhaps a human using AI)

Anecdotally, when I was attending college there was a 12 year old girl also attending and in some of my classes, particularly my freshman physics class. She was knocking the curve off with high scores on all of the exams. I got a chance to talk to her at lunch one day and it turned out she had an eidetic memory. It was amazing, she could tell you what was on any page of the text book perfectly. That allowed her to recall worked problems in the text that were identical in form to the question on the test, and she could then use the same steps to solve the test problem. But, and this was an important part, she didn't really understand physics. Whenever our conversation went into areas where she could have used physics principles to derive an understanding or at least a good guess at some of the depth of a new topic, she did not. That didn't hinder her progress through school but I had to believe that at some point it would.

After that experience I started paying more attention to people who "knew" facts, and people who "used" facts, which is to say that people who had learned something and understood it, would use that learning to extrapolate into new areas, open up places they didn't understand, and pursue new knowledge about those gaps. And there were people who would rebut arguments with "facts" but seemed not to grasp the fundamental principles at issue.

AI generated "answers" to prompts have exactly the same properties as answers from people who know facts but don't understand them.

I would guess that the article in question was generated with some prompts of the form, "Describe how an IMSI catcher works for each type of network." If you're a human and you read the answer and noticed that 5G was different you can add the click-bait headline and voila, article!

And yet for someone who understands how IMSI catchers work and understands the general compatibility environment of the cell phone networks, they would point out that most phones are designed to work "around the world" which means with all types of networks 2G/3G/LTE, and so even if the world around you is LTE/5G if you pop up a GSM cell tower signal a modern phone will see it and say hi. And then they would go on to describe that WiFi and Bluetooth device hardware (MAC) addresses are unique too, and those are also sent around if you bleat out your an open wifi network or a lonely bluetooth device. Finally it would point out that even with the 5G "SUCI", that value is unique to your phone and even if you don't give someone enough information to reverse map your phone to you, it is absolutely enough information to keep track of where this particular phone has been over time.

But all of that context is related to understanding why you would even want to capture and IMSI number and how the entire system was designed to make that easy even though now that is seen as a vulnerability.

So if you've spent some time recognizing the difference between people who are talking about something they understand and people who are talking about something they read about but don't understand, stuff written by AI just sort of pops out at you like that.

[1] All the generated images at the bottom was a dead giveaway but the structure of the article was also indicative of an LLM construction.

Re: Did 5G kill the IMSI catcher?

#39
post #8

Earlier quoted context omitted.

> depending on how willing the firmware of your modem is, the signal used to transfer GPS coordinates to the carrier for emergency response situations can also be triggered remotely by carrier hardware Do you know if (at least some) basebands actually limit network-side location requests to emergency call/text situations only?

All I know is that some don't. I don't know brands or if there are even common modems that are filtering for this. If you don't have a Faraday cage and cell site equipment, you're going to have a hard time verifying any of this. The modem is closed source, the SIM card is closed source, and various firmware blobs to make phones work are all closed source. I believe Qualcomm has debug interfaces on some chipsets, whic…

> If you're not a criminal or a human rights activist, the government is probably not pointing its secret spying equipment at you

If there's one thing we know for certain about the US and domestic spying it's that they're targeting literally everyone. They were caught copying all internet traffic going over the AT&T backbone in the early 2000s and decades later Snowden showed us they never stopped pointing their secret spying equipment at us. The best you can hope for is that if you don't become an activist or commit enough crimes they won't pay much attention to the massive and ever-growing troves of data they have on you personally.

Re: Did 5G kill the IMSI catcher?

#40
post #26
post #6

Criminal IMSI catchers are pretty much dead, but with the aid of carriers law enforcement can still use similar technology even with full standalone 5G networks. I don't know how often unauthorized IMSI catchers are used in the wild, but I doubt it's a relevant percentage of the total amount of IMSI catchers out there. Thanks to mmWave and beam forming, 5G allows operators to practically track you down to the exact c…

5G beamforming is not that accurate a proxy signal, and mmWave is phone vaporware, instead only significantly used for point-to-point connections. Line-of-sight requirements make it dead in the water for anything else.

Verizon has actually deployed mmWave 5G fairly widely.
Post reply on HN