Live data from Hacker News

Feds: There are hostile stingrays in DC, but we don’t know how to find them

arstechnica.com

71–80 of 101 posts

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#71

I work in wireless telecom: Really doubtful "we don't know how to find them". The FCC's enforcement bureau has a set of vans equipped to find unauthorized transmitters. IMSI catchers must transmit and remain on the air. It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours. The only other explanation I…

While there is extensive infrastructure for detecting active transmitting devices like Stingrays, there's no discussion (or tooling) around passive IMSI grabbers. These devices are significantly more limited (no IMEI or MSISDN, GSM-only), they remain pretty effective in areas/networks where GSM is still in place.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#72

I work in wireless telecom: Really doubtful "we don't know how to find them". The FCC's enforcement bureau has a set of vans equipped to find unauthorized transmitters. IMSI catchers must transmit and remain on the air. It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours. The only other explanation I…

While there is extensive infrastructure for detecting active transmitting devices like Stingrays, there's no discussion (or tooling) around passive IMSI grabbers. These devices are significantly more limited (no IMEI or MSISDN, GSM-only), they remain pretty effective in areas/networks where GSM is still in place.

https://mg.co.za/article/2016-09-01-00-meet-the-grabber-how-...

Verint engage gi2

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#75
This is not limited to the US. In fact, you are late to the party. Both in Oslo and in London these where uncovered and published about, that was 2015.

https://www.aftenposten.no/norge/i/kamWB/New-report-Clear-si...

https://commsrisk.com/reporters-find-20-imsi-catchers-in-lon...

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#76
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

> Why don't towers have a sort of encryption certificate verifying they're legit?

Pushback from various parties/regimes to keep this out of the standards. (e.g. the brits pushed back against strong encryption in the 1. GSM standards, https://www.aftenposten.no/verden/i/Olkl/Sources-We-were-pre... , and this has gone round to other countries pushing back in all kinds of ways since then.)

> Why doesnt my cell provider just provide my phone a list of it's legit towers?

It does, but not securely, so it can be faked. And since the towers does not authenticate themselves to the phone, you can just pretend to be a tower anyway.

> I can think of so many ways to solve this problem. But it's super hard to find any information if how this all works.

Sure, there's numerous ways to solve this - but there is little incentives to do so. it does get somewhat better - LTE can authenticate the network to the phone. But then there are countries where it's illegal to encrypt the public phone networks, so the protocol specs include an option to just disable this mechanism alltogether.

- Phone manufactures want to make their phones work everywhere, and the standards make them have all kinds of fall back mechanisms. So new LTE phones supports everything from LTE to the oldest GSM standards - they don't want a reputation of their phone not working when traveling to XXX.

- Telco companies gets pushback from governments, or in most cases around the world are owned and operated by governments - and they want backdoors into networks for surveillance.

- Telco equipment manufactures just make equipment that the telco companies wants. While all the standards for all the protocols and mechanisms work, they are product of a design-by-commitee, mostly made up by telco companies and telco manufacturers.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#77
post #45

Earlier quoted context omitted.

Doesn't that make them really detectable? A deadspot with full signal bars would be really suspicious.

A phone doesn't stay connected to a stingray, it will get the imsi and then move on to a real site of the phone's carrier.

How/why? Could you elaborate? Will the rouge tower drop the phone? Won't the phone try to connect again and again to the tower with the strongest signal?

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#79
post #26

Earlier quoted context omitted.

>It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours. how about quick switching between several [semi-stationary or briefcase carried] catchers (by analogy with an old Russia/USSR anti-aircraft tactic of quickly switching between several radars to avoid being detected and locked-in by an anti-radar m…

Theoretically possible. Using current off the shelf tech, several imsi catchers could be networked together by normal LTE data networks with battle tested VPN crypto. Doable with any mifi type hotspot device or even just a modern phone and tethering. People with high end spectrum analyzers and directional antennas would struggle to locate a thing that only powers on for 1-2 minutes, and the relocated to a random loca…

> networked together

The manufacturer bears responsibility for misuse given the current state of the market; this is why markets exist, to trade information. If there is a genuine inability to communicate, then the market ceases to exist.

Open societies favor markets for a reason: communication, open lines of communication, and stable ones at that. There are all kinds of ways a computer virus can infect a system that is automatic; consider the possibility that a virus has infected an "autonomous" control system for a moving vehicle. A mechanical coupling usually makes this impossible, a steering wheel.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#80
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

I think there is a perfect storm of savant security nerds with piss-pour communications skills and telcos over-indexing on mba/finance leadership. The security nerds make blustery comments that “anyone with motivation and a couple g’s worth of gear can target ANYONE.” There are a bunch or problems with this argument. Gnuradio is not easy. You need to be in radio proximity to your target. Targeting someone requires so…

> piss pour

Eww. That’s nasty. ‘Piss poor’ is likely the phrase you’re looking for.

Post reply on HN