Finger print scanners and facial recognition are prevalent on phones these days, would that be a solution to circumvent this vulnerability?
Finger print scanners and facial recognition are prevalent on phones these days, would that be a solution to circumvent this vulnerability?
* 3G has no integrity protection. Downgrade attacks from 3G->2G work. Also, it's the base station who decides if authentication and encryption is done. Fake base stations can still be used to track location, intercept calls and data.
* LTE/4G has mutual authentication and mandatory integrity protection. In theory you can't get IMEI if the message has no integrity but the protocols are not perfect.
LTE/4G can still be intercepted by using jammers, DoS attacks or exploiting weaknesses in the protocols and implementations to force a downgrade. Some messages in the protocols still go unencrypted and without authentication. It's for example possible to edit voice domain preference or send "LTE services not allowed" messages or edit the list of supported protocols to force downgrade.
Practical attacks against privacy and availability in 4G/LTE mobile communication systems https://arxiv.org/pdf/1510.07563v1.pdf
This is the nature of the zero-trust peer-to-peer nature of the global telephony system.
I wonder if there’s an application for some kind of a blockchain here ..
EDIT just to note, your example of laptops and wireless APs, you must reveal at the very least your MAC address which is if anything less secure because it doesn’t change - at least not trivially.