Build a do-it-yourself IMSI Catcher for about $20
motherboard.vice.com
motherboard.vice.com
1.) It seems to listen to messages from the cell towers rather than listening directly to phones. This means you are likely to catch IMSIs from a very wide area (i.e., every phone that connects to the cell tower you're listening to), which means you don't get much information about "who was in the local vicinity". This probably also means you can't tell the phone's signal strength, as the received signal strength is that of the tower not the phone (unless the tower modulates its transmit power based on how poor the phone's signal is?).
2.) It can only listen to one frequency at a time. This means you need N RTL-SDRs if you want to listen to phones connecting to N cell towers. (But the RTL-SDR does have about 3MHz bandwidth, so in theory it should be possible to listen to multiple cell towers simultaneously).
3.) It can only see IMSIs when a phone first connects. I don't think the IMSI is sent when making a call or transferring data.
4.) It only works on GSM, i.e 2G. Hardly anyone uses that these days. (I don't know if a similar passive approach would work on 3G and 4G, it may be that only software is required in order to support more than 2G).
The benefits of this approach compared to other things I've seen are that it is totally passive, so even a savvy target is unlikely to be able to detect that his IMSI has been caught, and it is extremely cheap to carry out.
Do you have some data that supports this claim? I haven't gone sniffing recently- but I believe T-mobile is still wed to 2G for the foreseeable future, and internationally, 2G is still in a lot of countries. I believe one northern european telco is going to decommission their UMTS network and support both LTE & GPRS.
T-Mobile is keeping it running until at least 2020: https://www.t-mobile.com/news/att-2g-iot-lifeline
edit: Wikipedia has a pretty solid list: https://en.wikipedia.org/wiki/2G#Past_2G_networks
Only that I don't know anyone who is happy if their phone ever connects over 2G.
By "hardly anyone uses that", I meant end users, not phone companies. I am happy to agree that 2G infrastructure still exists, it's just that most phones aren't using it.
I believe this is correct, in fact (someone please correct me if I've got this wrong?) it looks as if this open source tool being cited is incorrectly labelling TMSIs as IMSIs.
EDIT yes http://www.gsm-security.net/faq/timsi-temporary-imsi-gsm.sht...
Like trying to stop MITM attacks on the internet by randomizing MAC addresses between sessions. IMSI are printed on a sticker stuck to the phone. How secret can it really be?
Even if TIMSI worked well, there are other techniques: https://arxiv.org/pdf/1607.05171.pdf
My phones have the IMEI number written on them, not the IMSI numbers. I'll have to take the SIM out to see if it has the IMSI written on it somewhere.
That said there is a trick to bypass TMSI for tracking as you can trigger an IMSI re-registration by interrupting mobile data or by forcing the mobile phone to downgrade through jamming.
Also TMSI only prevents tracking not eavesdropping, it makes targeted eavesdropping harder but not impossible if you can track the target through other means.
My quick skim through the code looks like it'll track that too though:
# Register IMSI as seen if a TMSI believed to
# belong to the IMSI is seen.Edit: Changed Debian-based to Debian-derived
[1] https://www.ubuntu.com/download/iot/raspberry-pi-2-3
[2] https://wiki.ubuntu.com/ARM/RaspberryPi#Ubuntu_.27classic.27
Yes, but this is a GSM only implementation, using gr-gsm, correct ? They aren't doing anything like Tracking Area Update Request for LTE[1], correct ?
https://sdr-x.github.io/Whole-20MHz-config-LTE-signal-is-dec...
https://greatscottgadgets.com/hackrf/
Way different price though still interesting.
[0] https://www.rtl-sdr.com/potentially-receiving-up-to-10-ghz-w...
Finger print scanners and facial recognition are prevalent on phones these days, would that be a solution to circumvent this vulnerability?
* 3G has no integrity protection. Downgrade attacks from 3G->2G work. Also, it's the base station who decides if authentication and encryption is done. Fake base stations can still be used to track location, intercept calls and data.
* LTE/4G has mutual authentication and mandatory integrity protection. In theory you can't get IMEI if the message has no integrity but the protocols are not perfect.
LTE/4G can still be intercepted by using jammers, DoS attacks or exploiting weaknesses in the protocols and implementations to force a downgrade. Some messages in the protocols still go unencrypted and without authentication. It's for example possible to edit voice domain preference or send "LTE services not allowed" messages or edit the list of supported protocols to force downgrade.
Practical attacks against privacy and availability in 4G/LTE mobile communication systems https://arxiv.org/pdf/1510.07563v1.pdf
This is the nature of the zero-trust peer-to-peer nature of the global telephony system.
I wonder if there’s an application for some kind of a blockchain here ..
EDIT just to note, your example of laptops and wireless APs, you must reveal at the very least your MAC address which is if anything less secure because it doesn’t change - at least not trivially.
An IMSI catcher is nothing but a 'fake' cell phone tower for a phone.
Likely with a semi-busted protocol, depending on whether we're talking GSM/CDMA/LTE/etc, but a pain to attack, regardless.
2) Your security needs only to be as strong as your likely adversary OTP over SMS is fine for most use cases in any case this isn’t an argument against it networks with piss poor controls over SS7 which could allow you to reroute calls and texts to another number or networks that allow you to access voicemail without password if you spoof the origin number are.
Yes SMS based 2FA isn’t going to be reselient against a state actor but that shouldn’t be the adversary you protect yourself against if it is you’ve already lost.
In nearly all other cases it’s fine, attacks against it aren’t scalable and extremely hard to pull off outside of purely academic exercises and the benefits from the added security are considerable when compared to the use of only passwords or pre-generated auth codes.
So go grab somebody's phone and enjoy access to anything that uses SMS-based 2FA, because those messages are going to be shown even if you are unable to unlock the phone. Far from "academic exercices" or "state-level actors", I'd say.
So yes what you are describing is nonsensical you need to know the target, be able to steal their device and use it within a time frame before it would be disabled.
And this is if they don’t use say an iPhone or an Android phone with biometric login which often hides the notifications.
Also the biggest hole in this premise is that you wouldn’t even care if the device displays texts when locked or not since if you have the device you can take out the SIM and put it into your own phone.
So based on this any TOTP or U2F token is useless since they can be stolen and used.
Seriously if this is your threat model I don’t think you should leave the house since you are clearly in a lot of danger.
Much easier to just social engineer the provider into giving you a replacement SIM.
This isn’t any different than stealing a ubikey of someone it’s game over.
Also at least in the U.K. it’s pretty hard to get a replacement SIM through social engineering you either need an ID in store or they send it to your billing address only with signed post.
In either case the previous SIM would be disabled on the spot which would likely mean that the owner would notice and block it before this can be leveraged for an attack and this is also less scalable than stealing phones since it’s actually more involved in most cases.
Huh? Apple's two-factor auth is weird, but I easily use TOTP everywhere I can using e.g. 1pw…
See https://www.youtube.com/watch?v=3dridHDUHJQ&list=PLRovDyowOn...
TMSI is not as "temp" as the name implies, but that doesn't make it an IMSI catcher.