Detecting Fake 4G Base Stations in Real Time (2020) [pdf]
i.blackhat.com
i.blackhat.com
I know fake base stations might not be the reason for scammers targeting my phone but would be curious if others have seen this and have their own hypothesis?
I guess my paranoia here stems from this link in the OPs pdf[0].
0. https://venturebeat.com/2014/09/18/the-cell-tower-mystery-gr...
I only ever get spoofed number calls from the area code of my cell phone number. Works out pretty well because I only lived there in passing 12 years ago, so never wonder if I'm missing a real call by ignoring them.
Could it be apps sharing location info?
> Even though the UE authenticates the tower there are still several messages that it sends, receives, and trusts before authentication happens or w/o authentication. This is the weak spot in which the vast majority of 4G attacks happen
I'm a layman but here's my understanding. Imagine you're a police force and you know a criminal has a phone with IMEI of ABC123. You think the criminal might have a headquarters inside a warehouse but you want to be sure they're there before conducting a raid. Set up one of these, on arrival the target phone tells the fake tower what its IMEI is when within range, and you've got them.
There is no way to avoid this.
Can't wait to go to Defcon this year as well for work exactly like this!