British duo arrested for SMS phishing via homemade cell tower
theregister.com
theregister.com
> you're saying most people can just point some metal out of their window and the neighborhood would be happy
Technically? Yes, you can do it in a few hours, or as a weekend project if you’ve never done it before. Just grab a full-duplex SDR; you don’t need to go for expensive ones like the USRP. Get a BladeRF or LimeSDR, download the software, and set up the station. The problem lies with the regulations. Depending on where you live, you might face hefty charges for violating spectrum rules, and they are actively looking for such violations by the way. One of the proofs of concept we did with the regulators here in Canada involves using a drone to detect these violations. It’s just a matter of time before they find you.
The other trick was how more things are designed to stay on even when they look off. An older one with older phones would make it answer silently so you didn’t know if they were listening.
There’s so many risks with telecoms that high-assurance security (a) said keep cell phones away from anything security-critical and (b) used Red-Black separation where whatever connects to untrusted line never had any plaintext, just encrypted. Seperation kernels, like INTEGRITY-178B and seL4, were invented to hopefully do that with software.
For law enforcement they have multiple levels of collecting location data. Of course, your location is sent to Google or Apple etc as you move around. Even your searches for destinations in stuff like Google Maps, even incognito in Google Maps, reports your search, live, to law enforcement if they request it. Often with sketchy legal justifications to the third party.
If a target is moving around a city, they can be followed live on the array of cameras everywhere, accessible remotely. Many with facial recognition. Others in populated areas collecting all kinds of information. Wifi broadcasts, bluetooth devices, any RFID, all collected, stored and combined. This is how they are able to use a form of geo fencing requests to find out who was in an area at a specific time, potentially interacting with the target.
Networks of interactions at a global scale get revealed this way.
It just goes on and on too. Go to a rural area and maybe everyone has front door cameras. LE can access them remotely.
In fact, your entire ISP connection can be man in the middle decrypted and parts overwritten in transit, if given access at the ISP level.
While working in iCloud typing notes or watching YouTube videos, they can control your live sessions, watch you compose a document... Choose which videos you are recommended. Choose the advertisements you see.
The possibilities for them really are endless and all of this happens in many cases. It is a surveillence state.
True and sad. The only thing keeping LE from using those means is the lack of equipment, lack of knowledge and burocracy.
Kernel up used to be the most, targeted layers. I’ve been out of the field a few years. I don’t know how many black hats use 0-days on basebands in practice.
As for reliability, well, that's your problem now, good luck!
> point some metal out of their window and the neighborhood would be happy?
You might, but the FCC won't
It would be useful to have a list of Countries/operators adopting the 7726 ("SPAM") number. It seems also some European Countries do.
But all that really does is copy the body into a new SMS. There's no metadata to indicate it's forwarded, as you suspect.
This means texting 7726 is a two step process. First you send the body. You immediately get a response asking for the phone number of the spam sender, so then you sent that.
I suppose it can be used to help the operator identify the actual incoming message in their logs?
Think of BCP38 for IP spoofing, but for number spoofing. If you get an appropriate country mobile number from a carrier in that country, are you going to pay for a portability lookup to confirm that carrier is the authorized carrier for that number? Does that carrier check source numbers for all of the connections they have?
Some of the aggregators are good at checking sources, and some aren't, but aggregators are often authorized to send messages from many different countries, so they're likely to have their connections unchecked, because keeping the list updated is hard. It's like IP transit, but a lot worse.
Actually, I would like to have an option to identify the cells devices are connected to.
Put it in your dialer for detailed info. It used to be able to show real signal levels instead of bars once activated but now this is where we are. Need a little test kit to get the full info. May need to re-enter or reboot to exit the mode. Depends on the phone.
I’ve been in a lot of bad signal areas proposing repeaters or diagnosing issues and used it.
So, they blocked like 2% ?
And I guarantee there are devices listening into, characterising and locating radio emitters in major cities at the very least.
https://www.33700.fr/informations-pratiques/signaler-un-mess...
I like the fact that some of the earliest mappings had 0 mapped to "OPER" ("Operator"), because it makes me imagine that this number 33700 is like some interpretation of 337 and then shouting twice for the "operator" (as in, the literal physical person that used to sit and connect calls using wires and a patch board).
Taking this further then, and given that:
- 3 is assigned to any of the three letters DEF, and
- 7 is assigned to any of the three letters PRS,
we could invent the following meaning:
DES = "Déclaration d'Envoi de Spam". (Lit. "Declaration of sending of spam", as in a report about spam sending).
The double 0 is, as mentioned, in our invented meaning like shouting "Operator! Operator!"
And with this invented meaning it's like we are shouting for help from the operator to deal with this spam :D
Of course here I'm starting with 337 and backronyming "DES" to a plausible but probably weird sentence. If it was a real, the French would probably have worded the original sentence quite differently and the resulting number would be different as well.
(Also, looking at the article I'm not sure if any European countries also had 0 used for "OPER" or not. Guess I'll have to travel to some museums in France and have a look at some old phones with my own eyes at some point.)
Not convinced there is that level of sophistication at play
And there's always the Ham community who really, really hate spectrum abusers.
Not by Ofcom it isn't!
(At least, certainly not on any scale as far as RF interference/spoofing is concerned).
Maybe these days Ofcom can just ask them if they are interested in something specific.
I don’t think spectrum monitoring capability is all that secret. Certainly anyone with the knowledge to set up their own BTS should recognize the possibility they could be triangulated.
Transmitting on a licensed mobile service band without the license is a very good way to earn a knock on your door.
Eavesdropping on tower-to-handset comms is illegal too (in the UK), but it's not very practical to find just a receiver, unless they already know almost exactly where it is and are able to do a TEMPEST-like attack on the local oscillator or something. So as long as you keep quiet and don't do anything to indicate you're listening, such as, posting on Twitter about it or you do crime based on it, you'll get away with it. However, a receiver can't bump a victim handset down to a primitive-enough protocol, so all you'll get is encrypted content and maybe a smidge of metadata (I'm not sure exactly what is and isn't encrypted for each "G").
But given these guys appear to have been running this as part of a bigger spam/fraud game rather than for curiosity/ general mischief they might be too far in the poacher category for the gamekeepers.
But they apparently phished a lot of information with the intent to defraud folks, which in my book completely changes the proper response. My 2c.
If you can pretend to be a 2G/3G tower and jam the real tower, you can force phones to connect to you and you can send whatever calls and texts you want.
This is mostly a 2G issue. Modern Android devices, and perhaps iOS devices, have a toggle to disable 2G for this reason.
With fully compliant 5G, even police IMSI catchers become pretty difficult to use.
My Android phone, Motorola Edge 20, has a setting for preferred network type. Options are 5G/4G/3G/2G, 4G/3G/2G, 3G/2G, or 2G only. Doesn't seem to be a way to disable 2G or 3G, even though most networks here (UK) no longer support them.
I do have my phone set to 4G+5G only through that same screen, though, as my modem lacks the 2G toggle as well. If there are missing options in the dropdown, try dialing *#*#4636#*#* and see if you can configure it through there.
I don't know exactly what determines what configuration is exposed to the UI, it's possible your modem simply lacks support for disabling entire generations of cellular technology.
I know for a fact a local network has 3G here, but it’s not exposed on my phone to choose, presumably because it knows there’s 4G and 5G and carriers don’t want some dolt camping on 3G and eating more mhz/bit. I used to camp on 3G because Canada sent out too many dumb “emergency alerts” for custody disputes 1000km away, but those only operated over LTE, not 3G.
People don’t believe me when I say you can see, and sometimes connect to, US networks from a tall building in Toronto from over the lake because Canadian SIMs have rules/conditions to hide them, but if you put in an overseas SIM, you’ll see them on a scan.
Have also had a world of a time with a French SIM refuse to connect to a Canadian tower because it really preferred the US towers (lower roaming costs maybe?).
I was under the impression that most European countries were keeping 2G around for legacy applications and voice calls on roaming (until VoLTE roaming and emergency calls finally become equally reliable), shutting down 3G if anything?
It’s like saying “postcards are delivered in the leftover part of the mail truck unused by letters and parcels” :)
In modern standards, it is indeed not a “leftover” (although RCS exists which is another can of worms), but originally it was transmitted in a best-effort manner using what is essentially a "hack" on SS7 (unlike phone calls which is guaranteed reception - or at least not going through).
In GSM, SMS are delivered either over the SDCCH (when no voice call is happening simultaneously) or the SACCH (when a voice call is already in progress). In the latter case, you might argue that they're piggy-backing onto existing resources, but in the former, there are definitely dedicated resources being allocated specifically for SMS delivery.
SMS delivery has also always been reliable, both on the lower level (both SDCCH and SACCH are reliable) and the upper one (the phone reports successful delivery back to the sending SMSC), so while there are no timing guarantees (is that what you mean by best-effort?), delivery always eventually succeeds once resources are available.
The protocol even goes to significant lengths to ensure timely (re)delivery in case various error scenarios, such as a full inbox on a phone or a phone being out of reception.
While 140 bytes aren't much, reliability is actually great, until you add spam filtering, roaming, and inter-network delivery to the mix, when things can quickly go off the rails. (One unexpected consequence of how it's implemented is that for mutual reachability, it doesn't only matter what operators the sender and recipient have a contract with, but also in which network the recipient is currently roaming.)
That's the opposite of my experience in the early 2000s. I mean, the whole reason you'd always enable delivery reports is because delayed delivery or failed delivery were almost a daily occurrence. Anyone who sent SMS blind would quickly learn to either enable delivery reports, or just start calling people more.
Whether or not the victim will be notified about the absence of encryption, depends on the state of a single bit on the SIM card [1]. In 99% of the cases, there is no warning that the handset is currently using A5/0.
From now on, you are at the grace of the rogue network operator - they can send you anything from any number, sit in the middle of every call and capture every frame of data.
I don't think the current level of technological education of the general public is enough for most of them to know why it is important to force your phone to work only with modern network standards and that is what police and other government agencies interested in operating IMSI catchers exploit.
[1] http://blog.taddong.com/2011/02/does-your-phone-warn-you-whe...
Is encryption really significant to whether or not the police are able to monitor cellular phones? As bandwidth is already centrally allocated, there is a limited number of legal cellular network operators, and a competent authority could already compel (indeed, could have already compelled) mobile operators to provide master keys and diversification information under the Snooper Charter 2016[1].
Consider intelligence operation abroad, for example.
As to why they choose this way, over a "legitimate" (like dark pattern writing, or PID mining) vocation, there are many reasons.
I suspect that a big one, is the "blackball" effect, that having a conviction on your record will create. Once we are convicted, then we become unhireable, in many industries, so it's not like we have a choice. Also, the pay for nefarious work can be quite good.
If the goal was to learn just enough about cell tech to exploit it for profit, then a legal approach is off-the-table because of the extraordinary effort needed to ever get anything off the ground.
This smells like yet another case of children at work and police officers trying to sell themselves as super heroes. This is getting old.
Effectively came "for free" for mobile operators...
Mindsets were different then.
GPS originated as a military protocol and has some level of encryption and authentication, but this is not available to the general public.
USK: Galileo also has authentication available on its civilian frequencies.
This was a long time ago, but I distinctly remember the encrypted P(Y)-code and anti-spoofing being operative in the mid 1990s.
Is that already available? I thought GPS L2C didn't include authentication yet.
People seem to forget that dedicated TLS acceleration hardware was a thing not long ago.
If malicious clients want to try their luck, I’d say let them.
https://en.m.wikipedia.org/wiki/The_6th_Day
Apparently it was also Terry Crews acting debut.
Please try again with Google (R) Chrome (TM), no experience manipulating addons (e.g. adblockers), no VPN and from a non-non-friendly country.
Cloudflare likes to block things like Tor and CGNAT because of the abuse and unidentifiability those networks provide, and maybe there's a filter on some enemy states set up by the British government, but they really don't seem to care all that much about what you're running on your phone. Blocks seem to be largely network-based in my experience.
The regular vocal super-minority of people that have this issue need only expose the fact that they’re running Lynx on their Gentoo-powered toaster, upside down, on the international space station.
Edit: No VPN, no Tor, no add-blocking, Javascript & cookies enabled. The only suspect is old hardware and slowly maintained software (although updated only recently by the vendor)
You have mail.
Sounds like they were using a Stingray-esque device, as the police do.
That's not at all the reputation they have. They've been acting as an extension of the copyright lobby for years:
• https://torrentfreak.com/new-uk-police-unit-announces-two-ar...
• https://www.vice.com/en/article/bvn4nw/cops-arrest-3-people-...
• https://www.cityoflondon.police.uk/news/city-of-london/news/...
There are probably hundreds of instances of them doing stuff like the above, that was just the results from a quick search.
Moreover, the council is also the police authority, which could explain a more active copyright infringement force.
Generally a "police force for hire" is more associated with corruption, or were you not picking up on that?
This almost certainly comes from long experience investigating fraud and other financial crimes amongst the businesses and people based there, to a degree and level of complexity not found in other regions of the UK.
For instance they host Action Fraud for the entire country.
If you want to talk about enforcement priorities, contact your PCC, or better yet, right now, your local candidates.
In that piece Monbiot tries to blame the Corporation for the 2008 crash, which is laughable.
The City is not an autonomous enclave free from Parliamentary control.
The Corporation is some kind of acquisitive out-of-democratic-control alien dropped into the middle of London finance. OTOH the City is just another rich men's club I guess. Nice that its democracy for company-entities.
What makes them different?
IE, if I get robbed in the City of London is it even worth calling the police?
I’ve also heard that their average level of policeman is more educated , ie many holding degrees, masters etc. I presume this must be due to the nature of the work they’re most known for ie combatting complex fraud, organised crime etc
For reference, the Met has 33k officers for 10m people
Whilst there are only 8,600 residents, there are apparently over 600,000 commuters working there every day.
https://www.cityoflondon.gov.uk/about-us/about-the-city-of-l...
>>and, since Brexit, increasingly overseas
And this isn't even remotely true.
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
Instead of? If you have to send text to an occasional user, what do you think should be used?
The article is about /receiving/ messages supposedly from firms. How should they have sent it?
They use SMS because it's a baseline that every phone, smart or dumb, has. No need to have an email address, no need to have an app.
Most people use Whatsapp / Messenger / social media / to a lesser extent iMessage.
My phone is an IP phone. It doesn't do SMS. Did you mean "mobile phone"?
> No need to have an email address
I'm pretty sure that more people have an email address but no SMS capability, than have SMS but no email capability.
UK landlines are transitioning to VoIP. SMS messages sent to UK landlines are read out by a text-to-speech system (well, my parents' does).
My guess is because our population can all cope with SMS by now, but anything more...
That’s why it would be good to shut down GSM at some point: It would raise the difficulty of such attacks significantly.
What I don’t understand is how they managed to actually intercept any SMS with an IMSI catcher. They’d need to get the network to send these through their infrastructure, so I wonder how that worked?
Update: Ah, they were just sending out texts themselves, not intercepting anything.