I work in the field of cell network security research and want to help clear up some misinformation I'm seeing in these comments. First, I just want to highlight that reason cell site simulators (the more general term for StingRays/IMSI-catchers) exist is because cell phones cannot authenticate all messages coming from cell towers. I'm seeing some vague comments about "a lack of encryption", but it's primarily more o…
We have SIM cards for 30 years to authenticate unique users to the network, but those same cards can't authenticate the network? No, this is entirely by choice and could have been trivially solved. They just forgot the "server certificate" part.
Also, why couldn't law enforcement simply coerce the cellular carriers to sign their stingray cert? It's been known to happen for SSL: https://arstechnica.com/information-technology/2010/03/govts...