Instead, SS7 access is usually gained by either locating a crooked telco, or compromising a device within a telco.
While SS7 has essentially no security features, the primary security measure is the difficulty of accessing the SS7 network since it is entirely based on address management and routing by central authorities. This has been sufficient to slow the pace of SS7 vulnerabilities but not at all to stop them, as both crooked telcos and telcos with poor security practices can be found throughout the world.
A nice readup upon SS7 here: https://www.infopulse.com/blog/telecom-security-ss7-network-... which also links to https://www.gsma.com/security/wp-content/uploads/2019/03/GSM... which fleshes out the picture even further.
Remember that SS7 was invented in 1975, so if they designed cyber warfare into it, I'd be impressed with that level of planning.
Might be why I've grown to love and appreciate analogue systems that just work.
It was not 56-bit, but 54-bit, not cutting edge even in the 80s. Remember that GSM's encryption was designed under the restriction of crypto regulations, weak security was deliberately used, just like how SSL had weak export ciphers thanks to the NSA. A few cryptographers behind GSM [0] have accused the GCHQ and the NSA for sabotaging GSM's security, or at least acknowledged the security was weakened due to political pressure.
> Jan Arild Audestad has been an employee of Telenor in many years and has also been a professor at Gjøvik Universty College and the Norwegian University of Science and Technology.
> — Originally we proposed that the encryption key length should be 128 bit, because we knew little about cryptographic systems, and how secure they were. The request was that the keys and algorithms should be secure at least for 15 years after the installation, Audestad tells.
> Audestad says that the British were not very interested in having a strong encryption. And after a few years, they protested against the high security level that was proposed.— They wanted a key length of 48 bit. We were very surprised. The West Germans protested because they wanted a stronger encryption to prevent spying from East Germany. The compromise was a key length of 64 bit – where the ten last bits were set to zero. The result was an effective key length of 54 bit.
> Aftenposten has spoken to several people who together with Audestad co-operated on building the GSM network.
> One of them is Peter van der Arend from Netherlands. He tells Aftenposten how he «fought» with the British about this case – especially in a meeting in Portugal.
> - The British argued that the key length had to be reduced. Among other things they wanted to make sure that a specified Asian country should not have the opportunity to escape surveillance.
> Van der Arend was very opposed to the British proposal.
> — The length was increased by the British – two bits at the time. They did not want to go further than 54 bits. And even though I argued against it, I eventually lost support from the others. And from that moment we had weaker security, and I am still angry about this.
> Thomas Haug, who was one of the most central persons in the making of GSM, also says that he was put pressure on by the British.
> — I was told by a British delegate that the British secret services wanted to weaken the security so they could eavesdrop more easily.
> Michel Mouly from France was one of the other central people in the making of GSM. He cannot confirm that the British were pushing for weaker encryption. But he confirms that the encryption was not as strong as planned, due to political pressure. Mouly also confirms that it would have been technological possible to have a much stronger encryption than what the result became.
[0] https://www.aftenposten.no/verden/i/Olkl/sources-we-were-pre...
Can you please cite your source?
I frequently hear that SS7 is "trivially easy" to exploit, yet do not hear of how people get access to SS7 in the first place.
- https://www.blackhat.com/presentations/bh-europe-07/Langlois/Presentation/bh-eu-07-langlois-ppt-apr19.pdf
- https://0x00sec.org/t/into-the-wild-gaining-access-to-ss7-part-1-finding-an-access-point/12418Thanks for the link.
Nothing except a connection to the SS7 network, which is not easy to get. You need to be a cellular operator, virtual (MVNO) or real.