T-Mobile quietly hardens part of its U.S. cellular network against snooping
washingtonpost.com
washingtonpost.com
Even if A5/3 weren't broken, there are still tower dumps and IMSI catchers, which are a whole lot easier to use than breaking encryption. Yes A5/3 is better than A5/1, but I call bullshit on this whole article.
Super pendantic, but the title is 'hardens' not 'makes hard'. If it's better, than it's been hardened. Might not be the best thing available, but that's the meaning of a comparative.
This is a pretty big conditional. But I still imagine intel agencies have broken KASUMI.
Do I just have a rosy outlook, or is T-mobile's limited marketshare such a problem that they're somehow disciplined into being an actually good mobile carrier?
Coverage is fine. Sometimes on road trips to the beach here in North Carolina we will lose service for say 5-10 miles when we are really in the middle of nowhere (the sprawling metropolis of Elizabeth City, NC in particular gives me trouble). This is acceptable in return for nearly 50% savings and not having to do business with AT&T/Verizon.
Actually if you go to the EU often t-mobiles included data and texting come in handy.
More recently, the Simple Choice plan they introduced last year which includes "free" international data roaming has ensured I stick with them for even longer. I travel quite a bit, so that + the wifi calling which works pretty much anywhere in the world has been a great thing.
It happens.
This was late 90s, so I think a 10 minute call cost like $150!
I have unlimited data, but as a strong supporter of net neutrality, I take issue with that.
[0]https://www.eff.org/deeplinks/2014/07/net-neutrality-and-glo...
The slam dunk for me is the JUMP (Just Upgrade My Phone) program which allows you to upgrade phones much more frequently and easily. Doesn't save much money, but I am tickled knowing that I will get new phones much more frequently now.
On top of coverage being bad, their plans are limited to around 10MB of data roaming per month. Yes, MB. That is only domestic though, if you're international you get unlimited data roaming. I guess that is what happens when you bad-talk other carriers then ask them about letting your customers roam on their networks.
That is, they inspect your traffic and don't charge your bandwidth quota for network traffic with TMobile-selected music streaming services (Spotify, Google Play, etc).
They do DPI for other purposes though, such as ensuring that you don't tether without paying (if you use a desktop browser user agent, it'll count your tethering quota separately -- even if you spoof the UA from your phone's browser), and for "caching" HTTP traffic (you'll see a 'X-Via: Harmony proxy' header on any HTTP traffic, on any port).
They also hijack DNS NXDOMAIN for ad-filled pages, with no usable opt out ("opt out" uses a cookie that uses javascript to serve the page anyway, then hide it with a fake nginx 404)
Been meaning to try to dump some traffic so I can see more of what's going on.
I don't know about T-Mobile's ways of detection, but AT&T is detecting[0] tethering users by checking the network packets TTL values: If you are tethering then the TTL on their side will be below the expected value of mobile OS's default TTL. There are apps which can hide your tethering usage by altering your device's default TTL. You should still use a mobile browser's UA string, of course.
[0] - http://www.redmondpie.com/bypass-network-carriers-tether-det...
Apparently some IP packets are more equal than others.
I don't know. There are some lines I'm willing to cross and feel completely ethical, and bypassing stupid arbitrary net-neutrality rules is one of them.
I paid for the data. There is no difference if I use the data request comes from my mobile device or if it comes from my laptop connected to my mobile device.
Price discrimination is not a god given right nor is it criminal (usually) to avoid. (I can't think of a case where avoiding price discrimination is criminal, but I'm sure there is)
It's really just a marketing technique. Even though music streaming can use a significant amount of data, it's at a safely capped rate. It's probably a lot more effective to market "unlimited music streaming" to the general populace than "500mb more data".
It's in the same vein as, "unlimited in-network calls".
I just feel like folks don't realize the fact that net neutrality has never purely existed, not since peering agreements were first established.
It makes it harder for other businesses to enter the same market, as their offerings will not be zero-rated without an agreement with T-Mobile.
Any measure that makes it more difficult for companies to complete will ultimately harm consumers in the long run. So the only people this benefits, ultimately, are the incumbent providers, because it makes their market less competitive. Startups, for one, definitely lose: http://avc.com/2014/01/vc-pitches-in-a-year-or-two/
Data caps on cellular data plans already exist, so getting uncapped data for specific services does only benefit the consumer.
Your generic "net neutrality is good" arguments don't apply here, where net neutrality has been broken for years. Net neutrality hasn't ever existed on the web, let alone cellular data plans, anyway.
Honestly, their music thing doesn't bother me too much. They included nearly every major service. It doesn't seem like they're playing favorites.
On one hand, it sounds reasonably "fair" for everyone involved. It seems that T-Mo is committed to impartiality (the site repeatedly mentions that all legal music services are eligible). They aren't double-dipping, since it's on top of the metered bandwidth you paid for (as opposed to charging the user for unlimited/unmetered data and then throttling services that don't pay up).
On the other hand, it's terribly opaque. Are they charging the streaming providers? Do the providers need to install dedicated proxies for T-Mo customers? Are they charging everyone the same? Is every service on the same terms? It's quite obvious that they have a cross-promotion deal with Rhapsody, but does Rhapsody get preferential treatment?
It seems that T-Mo are aiming for a compromise in regards to net neutrality. It doesn't seem too bad at this point, but there's always the risk of a slippery slope.
Oh, right.
Active attacks, involving a device called an “IMSI catcher,” may still be able to eavesdrop on individual calls by manipulating a phone’s security settings directly, without having to crack the encryption.
So, just hardens against passive eavesdropping (and only by upgrading to the latest standard, not by any specially devised method).
If they really wanted to be "progressive" they would allow the phone to display a cipher icon for proper encryption with the tower, which was always part of the GSM spec, but was abandoned very early on. I think your SIM card needs to support that as well, IIRC ...
So I would be interested to see what happens if you insert a SIM card with security checking turned on, into an iphone...
Clarification: Notification to null encryption still exists, and iirc then it's actually mandatory. It's just that you can disable the warning by setting a bit on the simcard which it seems nearly every operator in the world does. As it was so unused the majority of even vaguely modern phones don't seem to have bothered writing the code to handle it anyway.
iirc, India _only_ uses A5/0 as it's illegal for them to use crypto [someone please clarify and educate me].
I also enjoy their Simple Talk Network. $40 unlimited talk, text, mms, 3G. Sometimes my friends have hard time on their $120 Sprint or $140 ATT plan to get internet fast in places where SimpleTalk (T-mobile rebrand) works like a thunder!
The only time I’ve been on 2G with AT&T in the last few years was going through the BART tunnel in South Bay… haha.
I'm absolutely bloody agog that commercial first-world operators have taken until the end of 2014 to actually support this -I think it was ratified into the specification around 2001 if not earlier.
Also, for all you tinfoil wearers out there, you might like the fact that the original specification for A5/3 was altered to make it more hardware friendly. In 2010 it was realized that this actually made it extremely easy [1] to recover the session key (if not in real time) [2].
[1] core2due in a couple of hours easy, see the abstract [2]. [2] http://eprint.iacr.org/2010/013
http://security.stackexchange.com/questions/334/advantages-a...
Integrating support for these algorithms on the device side ends up being a high hurdle. Doing anything at scale is inevitably harder than you expect it to be. If it was a simple change, people would make it.