Who catches the IMSI catchers? Researchers demonstrate Stingray detection kit
techcrunch.com
techcrunch.com
And the web site with all of the software: https://seaglass.cs.washington.edu/ (most interesting section: algorithms)
T-Mobile's HQ is in Bellevue, and I'm sure they have some test towers probably set up in their building. These signals can easily "get away from you."
I worked on Windows Phone, and we had a faraday cage setup with various different cellular networks coming in over the wire, which we would set up with different attenuation to test cellular radio handoff. One time someone left the door open, and the whole floor of the building roamed over to the UK. It was not a good day for international roaming charges.
Don't know if that will actually help, because the telcos are already quite compliant about giving every bit of data that passes through their systems to the NSA.
3G already does this. But apparently IMSI catchers have often been able to get around this by various means, including downgrading to an earlier GSM protocol (that lacks authentication), or spoofing a carrier from a different region (whose keys they have obtained somehow) in order to induce roaming, or somehow obtaining keys of a local carrier. I have heard there are a couple of other tricks too but I don't know what those are.
> Don't know if that will actually help, because the telcos are already quite compliant about giving every bit of data that passes through their systems to the NSA.
It's true that IMSI catchers can also be used to wiretap mobile telephony and SMS, which trust the carrier to provide confidentiality, but that doesn't cover everyone's use of mobile data services. But IMSI catchers often represent a very different kind of threat, which is not just wiretapping but real-time location tracking and/or enumerating devices that are present in an area.
The major drawback of the SnoopSnitch solution is that they are phone apps and are tightly coupled with the hardware and drivers. We were attempting to demonstrate that it could be done in a way portable across desktop operating systems and phones and we succeeded in creating a proof of concept at a cost of $200 [2].
This solution is also better suited to use as a centralized device for organizations to use that can be audited by security personnel to protect against corporate espionage. This is a real threat demonstrated by the fact that by simply changing a few lines of code in the IMSI Catcher detector a few undergrads built we could have an IMSI Catcher. This need is often left out of the arguments for IMSI Catcher detectors and I think that is very harmful because the first thing said about the project has always been "They will just make it illegal." This is much more unlikely when you consider that anyone can build one.
I would like to continue development beyond the proof of concept but have lost most of my team now that school is out if anyone would be interested you can contact me. Some commercial IMSI Catcher detectors sell for as much as $40,000.
[1] https://opensource.srlabs.de/projects/snoopsnitch/wiki/IMSI_...
> This need is often left out of the arguments for IMSI Catcher detectors and I think that is very harmful because the first thing said about the project has always been "They will just make it illegal." > This is much more unlikely when you consider that anyone can build one.
But that isn't true. Anybody can make fire-arms, explosives and all kinds of bad stuff and plenty of that is illegal depending on where you live.
The fact that something is easy does not have much to do with legality, if it did then pot would have been legal long ago.
I think I read that SnoopSnitch was gathering data but only for detection of known attacks not anomalies.
Wouldn't it be a desirable phone feature to be able to list and select a cell tower connection the same way you can select wifi?
Overnight Stingray producer - bankrupt.