Freaky Leaky SMS: Extracting user locations by analyzing SMS timings
arxiv.org
arxiv.org
I didn't have time to read the whole doc. Did it say how many SMS Delivery Reports were needed to create the model? I saw this "We repeated the classification for every combination of locations in our dataset, with sample sizes varying from 100 to 500"
I think getting 100 messages from a (series of) unknown number(s) would be alarming, but after reading this, I now know that it's a sign that I need to ... get a new burner phone and increase the size of my security detail? :^)
Delivery reports are best effort. The phone just sends them, but if the reception fails they are lost.
I live in a country with excellent mobile coverage, worked in the GSM industry already in the 1990s and have seen double delivery or missing report only less than a handfull of times in 25 years.
When I travel abroad I'm shocked how bad the network is in some industry countries. Many bizarre things happen as the parent writes, but not only related to SMS.
Edit: Above explanation is shortened. Of course there are always at least 2 hops: Sender to SMSC, SMSC recipient. I guess both hops are either confirmed or best effort. But it's been 28 years since my GSM training...
As a high volume SMS sender in a previous job, I can say this is pretty untrue. Plenty of carriers or intermediaries would block or spoof delivery reports.
I found that requesting delivery reports tended to increase actual delivery, but receiving a delivery report didn't provide any meaningful indication of receipt and lack of receiving a delivery report similarly didn't provide meaningful information.
Couldn't you just add a delay from the device?
Unless the receiving (target) phone knows the location of each of the senders, it won't be able to vary the delays in a way that perfectly cancels out the signal. The only hope is to raise the noise floor enough that it would take an impractical number of texts to find the phone's location, which should definitely be possible with random delays.
It works by leveraging SMS Delivery Reports, which are transmitted back to the sender when the network delivers the SMS to the recipient. The sender can request these reports, and there is no way for the recipient to prevent them.Cellular baseband software is ultra-closed-source. So no, you can't.
"I don't have a mobile phone and the law doesn't require me to have one"
Or have 1 cell phone line that you give out as your number, set it up with an app to auto-forward SMS to an e-mail address and calls your actual cell phone, and put that phone in a locked garage in the middle of Iowa.
Whenever a website asks me for a phone number I just make up random digits. Have never run into problems. Credit card companies definitely don't care what phone number I give to merchants.
The DMV also required a stupid SMS confirmation just to renew my car registration.
I use virtual numbers for pretty much everything, but yeah, welcome to 2023.
https://firstpoint911.wpenginepowered.com/wp-content/uploads...
In the Preparation phase, the adversary repeatedly sends multiple (silent) SMS, with Delivery Reports enabled, to the victim while observing their respective locations.
This is a cool paper, but hard to actually implement it
There is unfortunately no way to block silent SMSes without disabling the entire messaging service (this is by design).
96% accuracy to what? Can someone tell me what page, or the blurb around this?