LTESniffer: An open-source LTE downlink/uplink eavesdropper [pdf]
syssec.kaist.ac.kr
syssec.kaist.ac.kr
Except it’s not security of course; the difficulty in obtaining hardware is a large reason as to why industrial control systems had such abysmal security for as long as they did.
[edit to add] https://www.ettus.com/all-products/ub210-kit/
Bold of you to use past tense there
Either your customer would disagree with the premise of the standard implementation being "insufficiently secure" or your contribution to security should be reviewed as an evolution to the standard.
Result: Security is not being questioned in this realm of commercial discussion.
its a soft target. US telecom has habitually revealed their almost contemptuous disinterest in security and rely almost entirely on price barriers or law.
It would be trivial to pivot your narcotics racket to digital for only 9k or your online ransomware to LTE snooping.
I would have guessed LTE traffic was "HTTPS" levels of encrypted?
LTE stands for 4G and they use 128-EEA2 (AES-CTR) or 128-EIA2 (AES-CMAC) which are kinda same as TLS 1.2 and TLS 1.3. Where the latter suppors chacha additionally.
GCM on TLS gives greater performance and the integrity can be confirmed earlier, but there are no serious security problems on algorithm side.
Elsewhere, the article notes that one of the difficult things about sniffing LTE is that even the parameters used for the radio connection are encrypted, so some of them have to be inferred and guessed. That encryption isn't really intended as a security feature, we're talking about the modulation mode, but comes out of the fact that LTE revisions have erred on the side of caution with encrypting as much of the management traffic as practical. Much of this is a result of lessons learned with previous cellular protocols and protocols like WiFi, where unencrypted/unauthenticated management traffic has often become an attack vector.
> There are more reliable hardware options available for detecting IMSI catchers, which make sense when protecting multiple smartphone users in a single site, like a corporate headquarters or military base. Typically, such a setup involves a fixed, embedded system containing sensor hardware and a cellular modem for continuously monitoring the broadcast signals of the surrounding base stations, along with a database to which data is uploaded for analysis. When an IMSI catcher is detected, alerts can then be sent to all of an organization’s smartphone users.
Phones should allow users to define a whitelist of known-good cell tower IDs, which could be loaded for a known geo-location.
Why don't cell towers have the equivalent of an SSH host key, so that unknown cell towers trigger a warning before connection?
The risk of insecure-by-design telco standards, radio networks and untrustworthy phones is that zero-day and unfixable vulnerabilities could be abused for targeted and mass surveillance by networks of criminal, corrupt or non-state actors.
If Clearview AI can scrape billions of human images from public social networks, for commercial facial recognition services, imagine the per-geo economic value of passive radio signal collection and retroactive footprint analysis by AI.
There's no point in designing telco standards for cases where the telco is a malicious party.
My comment was about non-gov, non-telco malicious actors harvesting metadata via passive sniffing.
> If your cell provider is going to help stingrays connect to your phone...
Since most phones no longer have power-off, a faraday bag is needed to block all RF (cellular, wifi, bluetooth) radios on the phone from communicating with nearby radios.
> The concern with the attack is that someone is snooping on my connection while I use it. If I can't use my phone confidently knowing no one is watching, then my only other option would be not to trust the phone at all.
This is sadly the case today. It will only change with greater participation of civil society in technology standard-setting, open-source "cyber" defense and security research.
In addition to reducing usage of untrustworthy phones and radio bands, reduce funding of untrustworthy telcos by subscribing via lower-cost prepaid MVNOs.
What does this mean? I can power off my phone same as I always have.
> IMSI Catcher attacks are really practical for the state-of-the-art 4G/LTE mobile systems too. Our IMSI Catcher device acquires subscription identities (IMSIs) within an area or location within a few seconds of operation and then denies access of subscribers to the commercial network. Moreover, we demonstrate that these attack devices can be easily built and operated using readily available tools and equipment, and without any programming. We describe our experiments and procedures that are based on commercially available hardware and unmodified open source software.
The use case for "Stingray" like devices is to determine the proximity and or ID of a device|user based on the IMSI | IMEI.
> This feature is not intended to improve the confidentiality of traditional calls and texts, but it might somewhat raise the bar for some forms of interception. It's not a substitute for end-to-end encrypted calls / texts or even transport layer encryption. LTE does provide basic network authentication / encryption, but it's for the network itself. The intention of the LTE-only feature is only hardening against remote exploitation by disabling an enormous amount of both legacy code (2G, 3G) and bleeding edge code (5G).
Oddly enough, since the 3G shutdown, I have to set it to LTE-only to get service. Auto 3G/LTE results in no service.
So I can safely disable 2G knowing that I will not need it, since the networks don't exist and while I'm in the country the only possible use would be a downgrade attack. Similarly, I'm happy to turn off 3G given I'm very rarely out of LTE coverage and it's not long until it will be gone anyway.
If it's really a problem, they could have an "re-enable bands if needed while attempting an emergency call" option (or have it do it automatically with no option).
Also I think the paper mentions that many types of packets are in fact encrypted, and only certain control packets are sent in the clear. This seems to be not any more concerning than other Internet related protocols which also send a lot of coordination information in cleartext.
Try searching radioreference forums for “pager decoding” as a counter example.
I didn’t spend a lot of time searching FCCs site but they do mention this parenthetically in this article: https://www.fcc.gov/consumers/guides/interception-and-divulg...
Of course, you should be able to follow wiretap law by listening to your own devices. They same way people use wireshark legally: run it on your own network.
For example here in Michigan the law explicitly allows ham radio licensees more privileges: http://legislature.mi.gov/doc.aspx?mcl-750-508
It seems pretty important that MI would have that exception the way that statute is written, otherwise it would prohibit the ownership of ham radios.
Because ...
> a radio receiving set that will receive signals sent on a frequency assigned by the federal communications commission of the United States for police or other law enforcement, fire fighting, emergency medical, federal, state, or local corrections, or homeland security purposes.
... doesn't just describe police scanners. It describes basically all VHF/UHF ham radios.