Live data from Hacker News

Feds: There are hostile stingrays in DC, but we don’t know how to find them

arstechnica.com

51–60 of 101 posts

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#51

Earlier quoted context omitted.

totally not true, i was confused at first as well

Am stingray, can confirm. Edit: Hate that Steve Irwin guy

But your username says you're a swagasaurus. Do people really go on the internet and tell lies?

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#52

I wasn't familiar with the term 'stingray', so this headline was both confusing an amusing to me. I was confused about why they would even be looking for 'hostile' cartilaginous fish. I can't be the only one.

I too thought that for a brief moment when reading the title before remembering what stingrays were.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#53
Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it.

Why don't towers have a sort of encryption certificate verifying they're legit?

Why doesnt my cell provider just provide my phone a list of it's legit towers?

I can think of so many ways to solve this problem. But it's super hard to find any information if how this all works.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#54
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

I’ll take a wild guess:

* a lot of legacy kit that’s expensive and hard to upgrade

* lots of things rely on backward compatibility

* attacks are still too difficult/expensive to the point that only hushed adversaries are performing attacks

* lack of motivation from cell providers

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#55
post #38

Earlier quoted context omitted.

Something strong enough to get a whole building full of phones to ping it most certainly can be found by a $70,000 spectrum analyzers and trained RF engineer.

Hell - I bet you could find that with a $12 RTL-SDR and a home built antenna plugged into your laptop - if you were curious and suspected there was one nearby...

Never underestimate the amateur radio community. They hunt down radio pirates, emitters of interference, and hidden beacons for FUN! With the right antenna and a halfway decent receiver, it is not too difficult to hunt down the source of a transmission.

https://en.m.wikipedia.org/wiki/Transmitter_hunting

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#56
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

It's not the algo. The keys are the problem

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#57
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

> But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it.

Good news I guess: AT&T turned off their 2G in December of 2016: https://www.att.com/esupport/article.html#!/wireless/KM10848...

It caused a bit of a stir in the alarm system market, because so many of the alarm panels connected to the home office via embedded 2G modems.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#58
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

I think there is a perfect storm of savant security nerds with piss-pour communications skills and telcos over-indexing on mba/finance leadership.

The security nerds make blustery comments that “anyone with motivation and a couple g’s worth of gear can target ANYONE.”

There are a bunch or problems with this argument. Gnuradio is not easy. You need to be in radio proximity to your target. Targeting someone requires some homework and luck (converting msisdn to timsi isn’t trivial. It’s doable, but the nerds double down on trivial, burning credibility by claiming triviality that can easily be argued against by half-wits.). The mbas (whose job it is to move the needle on billion dollar businesses) are getting asked to add expenses that require new software at the base stations, replacement of mobile endpoints, Break roaming and generate NO ADDITIONAL REVENUE BECAUSE CONSUMERS DONT REALLY CARE ABOUT SECURITY.

What would you do? These are not the best and brightest. They have built careers in avoiding risk.

The MNOs have a serious culture problem. The single best solution would be to incentivize competition, but the only thing the SV people want is net neutrality, which only entrenches the established players.

We only have ourselves to blame for this mess. The moves that would resolve this problem: taking on risk that most wont recognize will not move the needle in the right direction. Consumers think mobile internet is too pricey- they won’t pay more for security. The solution creates costs. We are doomed.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#60
post #42

Earlier quoted context omitted.

I'm not a wireless expert, but then wouldn't it also be theoretically possible to have a network of direction finders? Isn't direction finding also a repeatable set of steps that can benefit from automation?

Yes, though DF can be much more efficient with directional (yagi, parabolic, horn) antennas. If fully automated by network the antennas connected to the spectrum analyzers need to be on two axis motorized platforms.

It would be easier to, you know, secure wireless communications to begin with. It's not like the Feds couldn't arrange to have stingrays that are properly keyed. (And there's always CALEA.) Yes, I know, it would only be easier for new kit, but it will take a long time to get it deployed. But every year we delay this makes the pain worse.
Post reply on HN