Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Laya the open source version of Jev(convaiinnovations.com ↗)
    59comments
  2. What Zig felt like, coming from Rust(besok.github.io ↗)
    7comments
  3. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    338comments
  4. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    156comments
  5. Tin: full-text search for Postgres(planetscale.com ↗)
    3comments
  6. A graphical desktop for the ZX Spectrum(github.com/mindbox77 ↗)
    3comments
  7. “The Secret Life of Circuits” is here(coredump.cx ↗)
    33comments
  8. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    512comments
  9. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    2comments
  10. San Francisco Onion Futures Company(onionfutures.com ↗)
    91comments
  11. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    117comments
  12. Asking Authors About Their Own Papers(medium.com/tmlrorg ↗)
    discuss
  13. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    154comments
  14. Communication by means of modulated Johnson noise(pnas.org ↗)
    17comments
  15. From Stonemasons to Carpenters(thelastsoftwareengineer.substack.com ↗)
    4comments
  16. Cloudflare Quick Tunnels(cloudflare.com ↗)
    297comments
  17. How to Write with an LLM(sockpuppet.org ↗)
    356comments
  18. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    23comments
  19. SDCC – Small Device C Compiler(sourceforge.net ↗)
    21comments
  20. Saving another 100TB of RAM(cloudflare.com ↗)
    86comments
  21. Learning Another Language May Be One of the Best Ways to Keep Your Brain Healthy(theconversation.com ↗)
    1comments
  22. Science Is Open Software(jepedersen.dk ↗)
    46comments
  23. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    42comments
  24. NASA-IBM Lunar Foundation open-Source Geospatial AI Model(usra.edu ↗)
    5comments
  25. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    111comments
  26. Ctenophores: Wonders of Biology(quantamagazine.org ↗)
    6comments
  27. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    116comments
  28. OpenJev(openjev.com ↗)
    275comments
  29. Ray Ozzie and the Optimism of Being Early(reproof.app ↗)
    4comments
  30. Goroutine Leak Profiles(go.dev ↗)
    6comments

German researchers discover flaw that could let anyone listen to cell calls

311 pointsby 11y agowashingtonpost.com
137 comments
11y agoHN ↗

There is a maintenance mode in every cell phone that allows it to be remotely turned on, that is, used as a listening device, without your knowledge.

I don't know what authentication is required. I expect that it was designed so that only your cell carrier could enable it, however whatever may have been secret about it, quite likely has leaked out by now.

If you don't want to be listened-to, don't have _any_ cell phones anywhere near you. Not just your own - say you want a private conversation in a public place; the phones of other people in your general vicinity could be switched on to listen to you.

I learned this from a well-known left-wing radical organization known as the United States Air Force, when I applied for the USAF Cyber Command. Their site had a recruiting video, that depicted a couple officers locking their phones into a grounded metal box - a faraday cage - before entering a secure area, that is, a room where secrets were openly discussed.

11y agoHN ↗

I've been asking everyone I know questions about this to make them realize how intense the total surveillance possibilities are.

"How many internet-connected microphones are in the same room as you?"

It's astonishing how big that number gets. For me right now, it's ~50. And so many of them are made by different companies, assembled in different countries, etc. The chance that someone, somewhere, can listen to you is nearly 100% if you're in a semi-public space. We're living in a dramatically more invasive surveillance society than 1984 ever predicted (that was just street cameras & one 'telescreen' in your home).

And then, add into this mix that we have new market acceptance for devices that intentionally open this behaviour: XBox One, Moto X, Amazon's...whatevertheycallit. There's not only technical capability, but also increasing consumer desire. It's crazy.

Further edits: There's a lot more at stake here, too, if you extrapolate from their[1] known capabilities and combine with actors who may also have motives at large scale. Take Facebook's mood-altering study, for example. We know that someone/Facebook has the ability to alter the moods and opinions of large groups of populations. The same actors can also listen/watch those people in real time. Dystopian scenarios of totalitarian governments exercising total population thought-control is more and more plausible as we all trade our privacy and security to giant corporations in exchange for mere convenience in our daily lives.

[1]: Who is 'they'? I don't know, but there are many possible 'they's and it might be many of them.

11y agoHN ↗

Most notebook computers have video cameras built into the display's frame, at the top. These cameras typically have a light that powers on when the camera is in use.

However there is nothing at all to indicate that the computer has its audio microphone in use.

11y agoHN ↗

A quick google search shows that some cameras can be activated without that little LED coming online.

11y agoHN ↗

I was once paid specifically to figure out a way to activate a camera without turning on the light.

However in that case it was for a legitimate purpose.

11y agoHN ↗

Out of curiosity - what was that legitimation? Can you tell?

11y agoHN ↗

One idea: I can easily imagine research studies getting IRB approval for this. The red light could alter the subject's behavior, and video analysis could be part of the metrics (for measuring attention/distraction or gross estimates of gaze, etc).

11y agoHN ↗

I wish I could.

It's not just that I am still bound by my NDA, but telling anyone what the application actually did, would result in bad things happening to completely innocent people.

11y agoHN ↗

The point of the GP was to say that while cameras on computers at least pretend to let you know when they are on, microphones do no such thing.

11y agoHN ↗

Has Apple done anything to fix this yet?

11y agoHN ↗

That was Badusb before Badusb. iSight is USB, and its firmware was (and probably still is) not authenticating in any way before firmware update.

11y agoHN ↗

I'm pretty sure that (on my MacBook Air, anyway) you only need to get a kext installed for the camera to not light up.

11y agoHN ↗

I could tell you but then I'd have to kill you.

Well OK...

More or less like writing any kind of virus.

Apple likes to claim that OS X is more secure. In reality, most of those who write malware own Windows boxen.

11y agoHN ↗

I don’t think you fully understood what 0942v8653 said; why would you write malware to perform the default behaviour (the LED turning on when the camera is on)?

11y agoHN ↗

You make it sound as if that is some kind of security revelation. In reality, what you are saying is 'the light is controlled in software'. Which is just another way of saying "that light is just a light, and it has only a tenuous connection to the camera being enabled".

Which is of course an utter joke.

11y agoHN ↗

The light was not meant to be controlled in software, it was intended to have a “hardware interlock” to the camera.

But they forgot firmware is software too, and is hackable too. (Now that's a 'leaky abstraction' for ya).

http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/18...

Turns out security is hard. Even compared to just 5 years ago, I think a lot more engineers are realizing how hard security actually is.

11y agoHN ↗

Turns out this is a really, really trivial problem to solve in hardware. Delegating it to their peripheral microcontroller is not a hardware solution, it's just the same software nonsense.

Security is hard in software because from the undecidable halting problem it immediately follows that any non-trivial property of software (such as "does the micro firmware turn the LED on when the camera is on") can also not be decided.

There is no halting problem in hardware. But I hear they have very, very cheap switches nowadays that could easily control the power to the camera and a parallel LED.

11y agoHN ↗

First:

immediately follows that any non-trivial property of software (such as "does the micro firmware turn the LED on when the camera is on") can also not be decided.

Any non-trivial property of arbitrary software, you mean.

It is entirely possible to prove that some software is or isn't "secure", for however you define secure. It's just not possible to do that for arbitrary software.

It is entirely possible to (for example) write your micro firmware with an integrated proof that non-trivial properties (like the LED/camera thing you mention) are satisfied.

Second:

There is no halting problem in hardware.

Actually, there is, kind of. Have you heard of the arbitrator problem? Long story short, analog behavior may propagate arbitrarily far into any digital system. You can make it less common, but you cannot get rid of it. Also: any non-trivial property of arbitrary hardware is also isn't provable. (Otherwise you could solve the halting problem, again)

11y agoHN ↗

Many eBook readers will phone home about what you're reading.

It's bad enough that Amazon would know what ebooks I've purchased. The Kindle will tell Amazon what pages I've read and when I read them.

There is a damn good reason I don't even own an ebook reader.

11y agoHN ↗

Hey thanks for that.

I might buy the reader that Portland's Powells City of Books sells, but have not yet looked into whether it phones home.

11y agoHN ↗

eh, it's 50-50. Some people like that ebook reader picks up from where you left off from another device.

11y agoHN ↗

I'd be completely cool with that, were the implementation of that feature to only communicate between devices that I myself own.

11y agoHN ↗

There is a damn good reason I don't even own an ebook reader.

On my Kobo Aura HD I was able to disable the snitching and with the sideloading working so great I had no reason to turn on the wi-fi since I bought it.

11y agoHN ↗

There's not only technical capability, but also increasing consumer desire.

After "baby boomers", "Gen X", etc., I think the most appropriate name for today's kids is "the selfie generation". They're flattered if you stalk them. I wish I was kidding.

11y agoHN ↗

And many people don't know why their battery is getting sucked dried too quickly

11y agoHN ↗

For quite a long time, I only used my Win2k box through a Linux IP Masquerading gateway. But during a long stay at a hotel, while looking for a new place to live, I noticed that my dialup modem activity lights flickered even when I myself wasn't doing anything online.

I asked a friend who recommended a firewall product whose name escapes me just now. Most coders think of a "firewall" as a way to keep bad packets out. This firewall would also keep bad packets _in_.

It identified the miscreant as the Welchia worm. What Welchia does is to install some completely legitimate Win2k security updates, as well as installing itself on some other Win2k box.

The only really _bad_ thing it did was to slow down my network.

11y agoHN ↗

Poor city-dwellers, always in a crowd. I spend the larger part of every day in a house in the country, with maybe 1 cell phone in the house but probably not in earshot. Didn't know I was so unusual!

11y agoHN ↗

I remember back in the day /dev/audio had bad default permissions on, I think, SunOS, and you could just cat it to a file to record.

11y agoHN ↗

There are other reasons that cell phones would not be allowed in such a location. For instance, it makes it more difficult for an insider to remove sensitive information.

11y agoHN ↗

While I expect you are correct, the USAF recruiting film specifically pointed out that cell phones aren't permitted in secure areas because of that maintenance mode.

11y agoHN ↗

You're not allowed to bring any electronic devices into a secure area. Period.

That means, watches, phones, laptops, pedometer and just about anything that has circuits.

11y agoHN ↗

Lots of good reasons for that.

How do you know that a pedometer is really just a pedometer?

That's how Bradley Manning made off with 800,00 diplomatic cables. He used a CD label printer to print CD-R blanks so that they looked like the albums from all his favorite bands, put the CD-R media into a portable player, then burned the CDs at his PC after downloading the cables over the Internet.

Oddly, he was always searched on the way in, never on the way out.

11y agoHN ↗

If they did use a user account system with capabilities (CD burning would be one of them) this couldn't have happened. That probably a million other possibilities.

11y agoHN ↗

Alternatively, they could crack open an Internet RFC or two.

Internet Protocol packets have a field for the security classification - unclassified, confidential, secret, top secret, there are other classifications that are themselves classified, as top secret ultra once was - as well as the compartment.

I expect Bradley Manning had a top secret clearance, but I doubt he had the same compartment as was required to read diplomatic cables.

Quite likely everyone was using commodity routers, such as one can purchase at Fry's. It must be expensive to purchase routers that enforce what has been in the Internet Protocol since the 1970s.

11y agoHN ↗

Do you know in which part of the phones this is supposed to be in?

In every cell phone? Without more details I call BS on this. It might be possible, but stating that every cell phone has it, sounds unlikely to me. I don't think it is part of the GSM specification, so what would be the reason that EVERY cell phone (Also non-GSM phones) has it?

11y agoHN ↗

I don't know.

I don't think the Air Force would just make something like that up. It's not just a USAF policy, not to permit cell phones in secure areas. I know lots of people with clearances, none of them are permitted to bring cell phones into their offices.

I applied to the Cyber Command in the Summer of 2008. What kinds of phones were in use at the time, in the United States?

And the video did specifically say "every cell phone".

11y agoHN ↗

That seems like a good policy even if most cell phones were immune to hacking.

11y agoHN ↗

Everything that has the capability to record must be assumed to be recording, I would argue.

11y agoHN ↗

How do you know that those policies aren't in place to prevent a person from knowingly recording sensitive data with their phone? Was there anything indicating that it was specifically for the reasons that you gave?

11y agoHN ↗

This policy is so widespread, and it has been the policy for so long, that I would be quite surprised were such a reason not to have leaked out by now.

People with clearances all know about this maintenance mode. None of them ever explain the error of my ways, when I discuss it with them.

11y agoHN ↗

Sorry for the late reply. I would be very surprised if iPhones and most Android phones had this "maintenance mode". There are many people that are very familiar with every aspect of the hardware and software. When you have access to the bootloader, kernel, OS and even the init process before the bootloader, there isn't really anywhere to hide such a thing.

This just seems like outdated and paranoid policy to me.

11y agoHN ↗

The "real" reason for a policy is always more exciting. Watch:

The real reason you have to turn your phone off on a plane is so that you can't record the takeoff and landing. That way, if there's a crash, there's no evidence to dispute the airline's black box version of the story.

Pretty sick, no?

11y agoHN ↗

You just gave me a kickstarter project.

Send me your bill in the mail.

11y agoHN ↗

Nonsense. I've never heard that claim. And that policy was in place long before smartphones came along.

11y agoHN ↗

Tyler Durden is real, and he reads Hacker News!

What's the REAL reason credit card companies don't keep backups?

11y agoHN ↗

That's completely bogus. You only need to turn off the broadcasting it does, and even that was declared unnecessary by the FAA recently(iirc). You can record the takeoff and landing all you want, as long as you aren't affecting other passengers.

11y agoHN ↗

Funny story: two years ago, back when anything electronic was banned during takeoff/landing, I was flying to Svalbard. If you don't know it, it's a very beautiful, very cold island north of Norway. During final approach, the sunset was so beautiful that the flight attendants went "ah, screw it" and turned on their phones to take pictures. Naturally everyone else did as well.

11y agoHN ↗

The people missing the point/satire of this comment are actually airline shills terrified that their secret has just been discovered.

11y agoHN ↗

The shills are everywhere, man. Who knows? You could even be a double-shill.

11y agoHN ↗

In airline accidents, the NTSB and first responders handle the black box recovery. The airline doesn't touch the unit itself. The NTSB techs read the data and CVR audio.

Airlines are not allowed to comment on the investigation (including interpreting black box data) so the only official version is that of the NTSB.

I've never heard of an airline accident in the US where public or passenger video (cellphone or otherwise) contradicted the black box data.

11y agoHN ↗

There have been some reports of government-sanctioned malware being installed on smartphones to override the behavior of the power-off switch, making it appear that the phone has been turned off when it's actually not. This could presumably be used for surveillance purposes, and probably has been, given what we've seen in the Snowden disclosures and elsewhere.

However, the idea that an unmodified or unhacked phone can be made to behave this way is sheer tinfoil hattery. You're not allowed to bring anything even vaguely electronic into a SCIF, but that's because the whole idea behind a SCIF is to have a room in an otherwise-unsecure facility where even the vaguest potential security risks are aggressively countered.

11y agoHN ↗

Baseband alone is not enough to act as an eavesdropping device. There's no direct connection between the baseband chipset and the microphone and camera. And if they left the baseband subsystem powered up when the phone was physically turned off (as opposed to in standby), the battery drain would be obvious.

Some of the confusion probably arises from the distinction between power-down and standby modes. If anything but the supervisory processor that monitors the power button were active with the phone turned all the way off, it would be noticed, and give rise to a substantial (and well justified) outcry. Under normal conditions, that can happen only if the phone has been hacked.

11y agoHN ↗

What I personally am talking about, would apply when the phone is powered on, for example while it is in my pocket, available to receive calls or texts.

11y agoHN ↗

power-off switch

there is NO power switch in phones. My first GSM phone was something like Nokia 2110, and even that had no power switch.

Cellphones have a SLEEP mode, they NEVER turn off. Just like laptops (there is always at least one processor running, EC) and PCs (since ATX).

You can compare it to a turned off PC. In principle its off, but network card is still linked with ethernet switch and listening for WoL packets.

11y agoHN ↗

CALEA seems to be only about intercepting telecommunications, i.e., in this case, intercepting running phone calls. Nothing there about secretly turning on the microphone when no call is going on. (If the Wikipedia article is correct and mostly complete.)

11y agoHN ↗

Do you know in which part of the phones this is supposed to be in?

The baseband chip.. it runs its own RTOS (separate from Android/ios/etc): http://en.wikipedia.org/wiki/Baseband_processor

Rather than explaining, I think this link is a pretty good example: a chip from qualcomm that was sold at least through 2012:

http://www.osnews.com/story/27416/The_second_operating_syste...

It was demonstrated at BlackHat in 2011 on an iPhone 4 and HTC Dream (android):

https://www.blackhat.com/html/bh-dc-11/bh-dc-11-briefings.ht...

http://www.infoworld.com/article/2625180/smartphones/coming-...

Edit: Slides from a talk at DeepSec:

http://2010.hack.lu/archive/2010/Weinmann-All-Your-Baseband-...

Edit: video: https://www.youtube.com/watch?v=fQqv0v14KKY

edit: I think this is the paper: https://www.usenix.org/system/files/conference/woot12/woot12...

11y agoHN ↗

Thanks for posting that.

I quite commonly experience the phenomenon that when others don't agree with me, they make up reasons that I must be wrong, completely out of the blue.

For example, I'm working on a Conway's Game of Life implementation for iOS. It's taking a long time, so some joker published a web page that lists all the other members of our site, who have already shipped Conway's Life implementations.

So I pointed out that I shipped my own Life game for the Classic Mac OS in 1997, and that it was particularly fast because it set the bit-depth of the screen to 1 (black and white, no color, no greyscale), then drew directly into the video card memory. My old website where I published its source has been available in the wayback machine this whole time.

The response? Two other people pointed out that they knew how to draw directly to the screen decades ago.

No one is willing to acknowledge that I shipped my own Life implementation fourteen years ago, long before that site even existed.

11y agoHN ↗

Not sure why the downvotes, its common human behaviour. Its even discussed at length in Carnegie's htwfaip.

11y agoHN ↗

As I said I am mentally ill. If I tell my own mother something she disagrees with or does not understand, she regards it as a symptom of my mental illness.

For example I told her that I am a webmaster, and that it costs me money to register my domains and host my sites.

She regards such statements as evidence that I have not been taking my medicine, and will, from time to time, call the police to get me involuntarily held in a psychiatric hospital, whose staff will agree that I must be delusional, because I claim to be a webmaster.

11y agoHN ↗

wait, wait ... wasn't there some michael crawford personality on kuro5hin years and years ago ? I never really understood what was going on there, but ... is this related in some way ?

11y agoHN ↗

Yes, I've been an active kuro5hin member since 2002.

Oddly, I am considered not notable enough for wikipedia, because someone made the argument that I am only known at k5, despite being widely published, having led the development of some protocols, invented things, written a whole bunch of highly regarded software products.

11y agoHN ↗

It's built into the baseband.

Google around, there are plenty of public media stories indicating that the capability exists. In one case, the FBI arrested a mafia leader based on covert capture of all conversations that happened in a rental car equipped with OnStar.

11y agoHN ↗

My understanding is that it was this facility (in part) which was used to track & monitor ex-US Marine Toby Studabaker when he went "missing" around 12 years ago with 12 year old Shevaun Pennington. He was 'found' in a hotel room in Germany - despite his phone being turned off.

11y agoHN ↗

that depicted a couple officers locking their phones into a grounded metal box - a faraday cage

I once tried that using a metal lunchbox, with a tight fitting metal lid - the phone rang anyway.

Anyone else ever tried it?

And as a side note, be sure and turn off (or airplane mode) your phone if you do put it in an effective faraday cage, or you will rapidly drain the battery as the phone constantly tries - at full power - to find a base station.

11y agoHN ↗

One has to also consider the skin effect.

Electromagnetic waves penetrate a conductor to a depth comparable to their wavelength, with an intensity that decreases exponentially.

11y agoHN ↗

There is a maintenance mode in every cell phone that allows it to be remotely turned on, that is, used as a listening device, without your knowledge.

Sounds tin-foily, any references? This conspiracy theory has been making the rounds for a long time and there's no evidence for it so far. Some problems immediately come to mind:

- would eat phone battery quickly to keep radio listening for these things

- would be vulnerable to discovery, eg leaks from phone industry engineers, reverse engineering by tinkerers, etc - yet has stayed secret for a long time (assuming this isn't a new thing)

More realistic would be exploiting a bug in the phone baseband firmware to get remote code execution, and then reprogramming the phone to do what you want. And reason enough to treat phones like you observed.

11y agoHN ↗

would eat phone battery quickly to keep radio listening for these things

your phone already listens for incoming call signal, this would be just another type of signal.

11y agoHN ↗

He was talking about turning the phone on remotely.

11y agoHN ↗

Perhaps I should have been more clear:

I wasn't claiming that this maintenance mode turns on the power to a phone, rather that if the phone is already powered on, the maintenance mode silently and invisibly turns on the phone's microphone, then transmits audio back to the cell tower.

So if you leave your cell powered on, anyone who knows how to activate that maintenance mode can listen to what you are saying, without your knowledge.

11y agoHN ↗

More realistic would be exploiting a bug in the phone baseband firmware to get remote code execution, and then reprogramming the phone to do what you want.

Or using baseband as intended to get remote code execution, and then on the cell company side wrap it up in a nice GUI or set of scripts, and voilà - you have the "maintenance mode" mentioned.

11y agoHN ↗

That also to stop the oficers from recording the meeting - a mate of mine worked for qinetiq and they have strict rules on phones being found with a phone with a camera inside his work place woudl have been a gross misconduct offence.

I have been for DV clearnce job interviews (The FO at Milton keynes) and you can have NO electronics on your person past the reception area.

11y agoHN ↗

The presence of such a mode has never been proven in any commercially available cell phone.

Your anecdotal USAF story does not prove anything either.

The story in the link has nothing to do with surveillance at the cell phone level. Its about interception/rerouting in the global phone network.

11y agoHN ↗

OTA updates are a pretty simple way to load whatever you want on the phone, and that just requires digitally signed SMSes, but signed with DES.

11y agoHN ↗

Of course we can be sure, that those fellows were not the first to learn about that.

The hack of belgium telco Belgacom sees more light day by day.

This system is broken beyond repair. We need to build it up from the ground, safe.

11y agoHN ↗

Someone is making encrypted Android phones in Switzerland, they said they would cost about $600.00, and should be shipping by now.

They can interoperate with regular Android phones if those phones have their app installed. I don't know what happens, if one calls a phone that does not support encryption.

Boeing is, or will soon be making such a phone, specifically intended for classified communication. I don't know whether they will be sold to the public.

11y agoHN ↗

One more reason to encrypt every bit we send and to use voip instead of the PSTN/Cellular voice.

11y agoHN ↗

Signaling System 7 (SS7) is a big security problem. It's the packet-switched control network for the phone system, and it has very little security. It was designed in 1980 to be run only internally between phone switches.

The main function of SS7 is call setup. All the switches along the route get their switching commands over SS7, not over the circuit-switched channel. (That went out with SS5, the old audio-tone based system). Call setup is preceded by "translation", turning a destination phone number into a route. That's done with query messages over SS7.

This allows outsourced wiretapping. Verisign offers this as a service for telcos, so they don't have to deal with law enforcement themselves.

http://www.verisign.com/static/001927.pdf

Verisign, which also runs much of the US SS7 network (http://www.verisign.com/stellent/groups/public/documents/dat...) is well placed to do this. All they have to do for a wiretap is to have the translations for a source or destination number reroute to a wiretap point, which then records while forwarding to the desired destination. As an SS7 provider, they already have all the call metadata.

Vulnerabilities come in because more parties now have SS7 access. Cellular roaming and VoIP to landline routing are managed over SS7. So a large number of computers other than dedicated telco switches now have SS7 connections. A break-in at any of those points has wiretapping potential.

11y agoHN ↗

It's funny because some developing countries still use the now ancient R2 signalling and wouldn't be directly affected by this (just in connecting networks I'd assume). IIRC Brazil is still a big user of R2, unfortunately for those working with VoIP. Also China.

11y agoHN ↗

A bit of a plug. If anyone is interested in playing with (doing research on) SS7 vulnerabilities, a few years back (five) I've participated in building a pretty cute test toolkit that allows one to sent/receive/parse/play scenarios using SS7/C7/3G/CDMA/.../SCTP/SS7 over IP/... packets on any level of the network. The list of supported protocols is available here: http://www.linkbit.com/platforms It follows standards and usually implements 100% of the protocol (including conditional constraints, etc). But also allows one to 'break' stuff and send custom/unsupported/broken fields.

It is pretty cute, you can do most of the stuff just in the visual packet editors / flow editors and where necessary revert to python snippets.

To get the feel of it, and see some pics: http://docs.linkbit.com/

edit: and basically yes. as a protocol engineer and somebody very familiar with SS7/C7/GSM/.., once you have the access to the network (which can be done over IP!) I wouldn't be at all surprised, you could misuse it.

11y agoHN ↗

As someone that used to be more interested in this stuff, it seems I missed the part where SS7 access became generally available. The first I saw mention of it, I think, was on an SMS provider's web site under a "Contact Us" type banner. Which makes me wonder, what changed to allow more businesses access and more importantly where do I sign up? :)

SS7 is one of those revered buzzphrases from my teen years, even getting to play with it for a weekend would really sweeten my Christmas.

11y agoHN ↗

SS7 really isn't generally available, it'd be another carrier doing the insertion into the network.

11y agoHN ↗

If I understand correctly, all of the femtocell products that consumers can purchase and deploy are little SS7 gateways that you can have right in your home...

11y agoHN ↗

The only interesting thing here is the new attack at the radio level that allows call monitoring. It sounds like it might be easier than setting up a fake tower. It still sounds like it required an active attack though so in practice the difference might be all that important.

11y agoHN ↗

An interesting read on the current state of SS7, circa 2013:

http://blog.pt.com/vendors-eol-announcement

The 3G/4G segment of subscribers will have a distribution of 3.4 billion using 3G (SS7) services and .9 billion using 4G services. The total outcome of this research indicates that a total of 7.65 billion subscribers, out of a total of 8.5 billion subscribers, will remain on SS7-based networks in 2017.

Verizon went on to further explain that a final 2G/3G (SS7) sunset timeframe decision has not been made.

The good news is vendors are not happy considering the availability of hardware is will decrease significantly over the same time period, hopefully speeding the sunset for this technology.

Some service providers are planning on a strategy of consolidating their network, having no support and cannibalizing existing spare equipment for hardware support.

11y agoHN ↗

In Turkish Ministry of Foreign Affairs it is forbidden to bring cell phones in to meetings. However it is totally okay to bring tablets and laptops into the meetings. Source: my friend works there.

Edit: phones are forbidden due to the recent spying events.

11y agoHN ↗

Do they allow 3G tablets or anything that falls in the not-a-phone-but-has-a-SIM/baseband proc?

I'm assuming a GSM (or equivalent) baseband is the only thing separating smartphone from smartablet and smartlaptop nowadays, correct? If they allow 3G tablets, then this is a security-theater kind decision, aimed to appease "management", and we must make fun of them.

If they ban all baseband-carrying devices, then this is a consistent policy that is paranoid about a very specific thing that, quite frankly, invites a lot of healthy paranoia.

I wonder what it'll take to open up those baseband processors.

11y agoHN ↗

They have internet access there. Why would someone use their phone while they have microphones and internet acces in their tablets and laptops... These people are clueless about technology. Also they use Windows.

11y agoHN ↗

As far as I remember nobady checks wheter you carry a phone into a meeting. It is just forbidden. If they say that phone is forbidden it means literally that phone is forbidden, no matter smart phone or dump phone, tablet with 3G is okay because it is not a phone overall. You may show some slides ets you know... or you might want to connect to the internet...

11y agoHN ↗

"anyone" can not listen to your cell calls. Only people that have access to inject commands into the SS7 network that your call is routed through can do that.

11y agoHN ↗

Or those that can create a pico cell that your phone connects to and then MITM your call. I gather the equipment is pretty accessibly priced now.

11y agoHN ↗

The expertise to do these things is the domain of well outfitted organizations, who have other simpler methods of making you talk. Indeed, electronic surveillance of is often used to protect agents from dangerous work.

11y agoHN ↗

I'm not sure how to hack a mobile phone using this software? The expertise to find these kinds of exploits is hard to develop individually.

11y agoHN ↗

The expertise to find these kinds of exploits is hard to develop individually.

Yes, but numerous people participating in the Osmocom projects have that expertise. Fortunately, they're interested in building an open-source baseband processor (among other cool things), and not in hacking into anyone's private communications.

11y agoHN ↗

It is well know that GNURadio is used by the US navy. I could easily see Osmocom, being used for good or bad - the most important thing being human resources. Although in the case of Osmocom, I'm still not sure how it is related to this kind of hacking.

11y agoHN ↗

Did you even look at the OsmocomBB project? It's pretty well-known that the their software (with some alterations) can be used as a poor man's BTS, and so can passively sniff other phones. They're pretty cagey about it, and understandably so since they're pretty conscientious about complying with laws and regs and yet they apparently draw a lot of script kiddies looking to "hack peoples phones signals".

Besides, base stations are available openly on the market now at pretty reasonable prices. It's why I never talk about anything truly private on a mobile phone.

11y agoHN ↗

A couple of random thoughts on potential applications/uses:

1. Alexandria needs to communicate with Bilbo. Alexandria has the privilege of being trusted by whatever organization she belongs to (be that her country, company, etc) and as such is unmonitored AFAsheKs. Biblo on the other hand is some fugitive-type and is unable, or perhaps unwilling, to enter direct communication with Alexandria for fear of compromising himself or his beloved Alexandria. Bilbo could then monitor Alexandria's calls for an encoded message via a protocol they predetermine. This protocol could take the form of linguistic or audio steganography. One could image all sorts of information being leaked by Alexandria.

2. More realistically this could be tool for bribery. Monitor a set of vulnerable targets, wait until they reveal something, take a bribe to stay quite.

3. Or, for the Machiavellian-minded leak information that was supposedly confidential between two parties.

11y agoHN ↗

I didn't understand anything. Could you explain it with Alice and Bob instead ?

11y agoHN ↗

German state-controlled media and the Deutsche Telekom immediately reported that big carriers have already fixed the problem and are no longer allowing "unauthorized" requests for encryption parameters via SS7. ;-)

(source: http://heise.de/-2503376 - sorry, German)

11y agoHN ↗

Of course there are insecurities, but this sounds like an opening shot calling for a "new" system to allow better security, or rather, a system even more easily controlled.

11y agoHN ↗

Really, none of this is surprising or new. If you're bored/curious, here's some fun reading on exploring/exploiting telecom networks. Spoiler alert: it's really easy and it has been forever. Big ups to Philippe Langlois for all his great research over the years.

Interview: Telecom Security Expert Philippe Langlois on GCHQ Spying (http://www.spiegel.de/international/europe/interview-telecom...)

Vulnerabilities and Possible Attacks against the GPRS Backbone Network (http://critis06.lcc.uma.es/files/Vulnerabilities%20and%20Pos...)

Getting in the SS7 kingdom: hard technology and disturbingly easy hacks to get entry points in the walled garden (http://www.hackitoergosum.org/2010/HES2010-planglois-Attacki...)

Telecom Signaling Attacks on 3G and LTE networks (http://www.slideshare.net/p1sec/telecom-security-from-ss7-to...)

GSM and 3G Security (https://webcache.googleusercontent.com/search?q=cache:WlEd4H...)

Locating Mobile Phones using Signalling System #7 (http://events.ccc.de/congress/2008/Fahrplan/attachments/1262...)

SCTPscan - Finding entry points to SS7 Networks & Telecommunication Backbones (https://www.blackhat.com/presentations/bh-europe-07/Langlois...)

LTE Pwnage: Hacking HLR/HSS and MME Core Network Elements (http://www.slideshare.net/p1sec/p1security-lte-pwnage-v21)

Map of mobile network security (https://srlabs.de/gsmmap/)

Rooting The HLRs Mobile And Critical Infrastructure Insecurity (https://archive.org/details/D3T202201308021200RootingTheHlrs...)

AURORAGOLD Working Group - Shaping understanding of the global GSM/UMTS/LTE landscape - from the Snowden leaks (government employees should probably not click this) (https://s3.amazonaws.com/s3.documentcloud.org/documents/1374...) (https://firstlook.org/theintercept/2014/12/04/nsa-auroragold...)

11y agoHN ↗

I just tried searching this entire comments page for the string “batman”. Incredibly, there were 0 occurrences. So I'll just add: this sounds kinda like that batman movie where they turned every cellphone in the city into a remote listening device (and then declared that nobody should have that kind of power).