"It should be noted that, while cell phones do use encryption for content, the encryption can be turned off easily by a cell-site simulator itself, and there’s no notification that encryption is no longer operating."
The incompetence of telecom companies / chipmakers knows no bounds. Of course, it could be by design.
It is absolutely by design. The GSM standard recommends that, if encryption is disabled, the user be notified. This feature is called the "chiphering indicator". However, practically none of the available handsets do so.
oops, "ciphering" ... also, even if the handset supports ciphering indication the SIM can disable it. Oh, and you're not permitted to reconfigure that part of the SIM either.
I don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.
No production basestation ever used the "no encryption" mode. No handset should ever accept using it, just as no browser will accept to using the NULL cipher. So what is the justification 25 years on?
I remember seeing "lawful intercept" being mentioned somewhere in the GSM standards, and it seemed they were certainly not opposed to it...
they don't have the option to oppose (in the US, at least):
And the same has been true in practically all countries, democratic or not, developed or not, ever.
Perhaps many phones don't, hence the many complaints that "phones stopped working" when the surveillance vehicle was nearby.
They stop working maybe because the stingray is only collecting identifiers instead if conducting a true MITM attack and forwarding any calls por SMS's. In any case, I suspect they could only do a MITM to outgoing traffic, so any incoming traffic/data would not be delivered, like the phone is out of service/no network.
GSM crypto was designed to not be strong (in the late 80s).
Does it affect the data connection, like a SSL connection to my bank? Can it see that data stream as well?