President Speaking: Spoofing Alerts in 4G LTE Networks (2019) [pdf]
par.nsf.gov
par.nsf.gov
The problem was, it wasn't initiated through the auspices of the channels which are permitted to approve a message. So, it was "false" in the higher layer senses, not in the actual formal structure, more in the process chains.
Ronald Reagan hot-microphone "I declared war on Russia" as a sound check is a bit more in the "false" space. Or, that txt message Abraham Lincoln sent about trust on the internet.
To me, the falsity begs a layer question. If the lower layers are well formed, the falsity has to lie in the higher layer processes. It was a falsely authorised message. It was sent over the correct channels, injected by the correct endpoints. It just wasn't what had been approved to be sent. (if approved at all) -Thats not "false" thats "unapproved"
The problem is as much with the name, as with the formalisms around sending. If you want this to really be a presidential alert then wire it to some MFA which is bound to the current occupant of the role. If its just that guy getting his guy to call some guy who approves a tech at AT&T sending a message, then it shouldn't have been called a presidential message.
(hats off to the authors of the paper who did some stellar work on spoofing a send event, and show how it would work in a small radius of a transmitter in an event like a football game)
I get your point, but — it was not true, therefore it was false.
https://en.m.wikipedia.org/w/index.php?title=Law_of_excluded...
https://en.m.wikipedia.org/wiki/We_begin_bombing_in_five_min...
Just make the actual missle alert button big and red and have users confirm a prompt after clicking.
In Reagans case it is also about the "interface". If footage that leaved the set is not checked, because there is no delay, well then unchecked footage goes out.
Abraham Lincon is still alive ?
Or if you’re asking in earnest there’s a meme of the format:
“You can’t trust quotes on the internet - Abraham Lincoln” - the joke being Lincoln couldn’t have written the joke for the internet was not yet invented at the time of his passing.
However i am assuming that the european alert standard is based on an earlier protocol than LTE, does anyone have any info?
My guess is that some people weren't aware of the test and started calling their relatives asking questions.
Unless you turned that crap off.
Edit: At first I incorrectly mentioned 7T. 6T is my current phone. I should probably do something about that eventually as it doesn't get updates anymore. I see in the settings something for alerts but it doesn't open. I have no clue how I disabled them but I did.
It's going to be interesting times when you both cannot trust and cannot disable these sorts of push messages and alerts.
Was there ever a Presidential Alert before that test? Can they be disabled?
No, I'm thinking of all levels.
> Was there ever a Presidential Alert before that test?
I can recall two presidential alerts, both tests. This affirms my point about not getting anything useful.
> Can they be disabled?
I guess that depends on your phone. I've been able to on Android.
I guess so, but myself and roughly half the people I've talked to got the audible alert in Spanish but not in English. This doesn't seem quite successful to me, but where do I send my feedback?
Do we know if any of this has been patched since the paper in 2019? One could hope…
In a serious note, this will most likely never be patched. SS7 vulnerabilities have been know for even longer but the sheer effort needed to collaborate between every single company, manufacturer and policy makers make it a non starter.
Also having the possibility of making it so all old phones no longer get these messages could also be an accessibility problem that gets whomever tries to run with it kicked out of office.
With current climates being 3/4 years max in office with the possibility the next person will scrap whatever you do... makes it a hard problem to solve.
Over time it would supplant the old one and the vast majority of people would get the secure alert today.
During an emergency you’d send both but spoofs would only be able to hit old phones that don’t receive software updates / don’t support the secure variant.
Securing is also pretty simple since the government could just publish the public key they’ll use for signing these alerts and OS vendors could refresh that key on a regular basis.
That would mean hundreds of keys to manage and regularly update, with various entities at various levels of government needing their own keys, etc. It's not impossible, but it certainly wouldn't be pretty simple for OS vendors.
It’s a legitimate issue if the different levels of government are disfunctional / fighting with each other, but it’s better at that point to leave it as a political problem for them to solve.
Belgium isn't going to become unitary again because of a telecommunications standard.
Or French Polynesia, New Caledonia, in case of emergency they're going to send a message to mainland France to sign it and back? That's very impractical and better hope the emergency doesn't involve a problem with long-distance communications.
(...ach those pdfs...)