[HN Gopher] British duo arrested for SMS phishing via homemade c...
       ___________________________________________________________________
        
       British duo arrested for SMS phishing via homemade cell tower
        
       Author : skilled
       Score  : 199 points
       Date   : 2024-06-11 05:40 UTC (17 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | usr1106 wrote:
       | Cloudflare turnstyle making government resources inaccessible
       | (it's always an endless loop of clicking that I am human on my
       | mobile)
        
         | randunel wrote:
         | Same here, I cannot access that website, it's an infinite
         | turnstile loop. Same issue with hibp, as far as I can see.
        
           | moomin wrote:
           | Pretty ironic considering it's the City of London Police
           | website.
           | 
           | If malicious clients want to try their luck, I'd say let
           | them.
        
         | Traubenfuchs wrote:
         | You are probably using the suspicious setup Cloudflare wants to
         | lock out.
         | 
         | Please try again with Google (R) Chrome (TM), no experience
         | manipulating addons (e.g. adblockers), no VPN and from a non-
         | non-friendly country.
        
           | mdp2021 wrote:
           | It is not that, it works on some odd setups.
        
           | jeroenhd wrote:
           | Works fine on Firefox from a custom Android ROM through a VPN
           | here. Last time I checked a post where people complained
           | about Cloudflare, even Ladybird for Android made it through.
           | You need cookies and Javascript, but that's all you need to
           | pass the technical checks it seems.
           | 
           | Cloudflare likes to block things like Tor and CGNAT because
           | of the abuse and unidentifiability those networks provide,
           | and maybe there's a filter on some enemy states set up by the
           | British government, but they really don't seem to care all
           | that much about what you're running on your phone. Blocks
           | seem to be largely network-based in my experience.
        
           | tgv wrote:
           | I can access with Firefox, macOS, UBlock Origin.
        
           | cqqxo4zV46cp wrote:
           | This is absurdly dishonest. I don't use Chrome. I use a VPN
           | sometimes, when I'm travelling, in a DigitalOcean IP range
           | (which has a dubious reputation). I don't live in the US or
           | Europe, which is often Californian for 'a list of trusted
           | countries'. I've never, once, ever, had an issue with
           | CloudFlare.
           | 
           | The regular vocal super-minority of people that have this
           | issue need only expose the fact that they're running Lynx on
           | their Gentoo-powered toaster, upside down, on the
           | international space station.
        
         | pheggs wrote:
         | how certain are you actually that you are not an android? :)
        
           | szundi wrote:
           | We are bio androids anyway
        
           | happymellon wrote:
           | This comment instantly made me think of this.
           | 
           | https://en.m.wikipedia.org/wiki/The_6th_Day
           | 
           | Apparently it was also Terry Crews acting debut.
        
         | Perz1val wrote:
         | Lets me in on my microg lineageos with brave browser
        
         | jgrahamc wrote:
         | If you hit a problem like this I'd like to hear about it. If
         | you're willing I an take a HAR file and pass it on to the
         | Turnstile team and they can see why.
        
       | gravescale wrote:
       | That's a pretty clever way to be very stupid! Anyone who reports
       | the message (forward it to 7726, spells SPAM) to a network tips
       | the network off that messages are landing on subscribers devices
       | that didn't come through their system.
       | 
       | And I guarantee there are devices listening into, characterising
       | and locating radio emitters in major cities at the very least.
        
         | vasco wrote:
         | Yeah if you run a private antenna either the police or some men
         | from your country's equivalent to FCC will come to your door
         | and politely ask you to stop, if they are having a good day,
         | most likely confiscate some of the equipment as well. And
         | that's just for emitting anything on reserved spectrum or with
         | too much power, not even for crime.
        
           | GordonS wrote:
           | I guess you could hoover up traffic at a location for a few
           | hours, then move to another location and keep going like that
           | without getting caught.
        
             | vasco wrote:
             | Listening isn't illegal so you can do that without moving.
             | People move just to listen to different things with limited
             | range, one form of it is called wardriving if you're doing
             | it to wifi for example.
        
               | GordonS wrote:
               | I'm fairly sure in the UK it's illegal, tho I don't know
               | for certain. But even if not, you could be arrested for
               | conspiracy to commit fraud (or similar).
        
               | seabass-labrax wrote:
               | That's not true - it is indeed illegal to listen in to
               | radio transmissions which are not intended for you. Doing
               | so is a criminal offence punishable by an unlimited
               | summary fine (the precise amount is determined based on
               | the offender's personal income and other circumstances).
               | 
               | https://www.legislation.gov.uk/ukpga/2006/36/section/48
        
               | mnw21cam wrote:
               | Correct. That's one reason why LiveATC has recordings of
               | air traffic control radio calls from most countries, but
               | not the UK.
        
               | gravescale wrote:
               | You can't send a phishing SMS from a receive-only device.
               | Any mobile tower must have an active transmitter (at the
               | very least, so the handset knows what network it thinks
               | it's connected to!).
               | 
               | Transmitting on a licensed mobile service band without
               | the license is a very good way to earn a knock on your
               | door.
               | 
               | Eavesdropping on tower-to-handset comms is illegal too
               | (in the UK), but it's not very practical to find just a
               | receiver, unless they already know almost exactly where
               | it is and are able to do a TEMPEST-like attack on the
               | local oscillator or something. So as long as you keep
               | quiet and don't do anything to indicate you're listening,
               | such as, posting on Twitter about it or you do crime
               | based on it, you'll get away with it. However, a receiver
               | can't bump a victim handset down to a primitive-enough
               | protocol, so all you'll get is encrypted content and
               | maybe a smidge of metadata (I'm not sure exactly what is
               | and isn't encrypted for each "G").
        
             | miki123211 wrote:
             | The Polish democratic opposition used to do this in the
             | 80's, during the communist era. As far as I remember, their
             | technique relied on balloons, they would attach a homemade
             | antenna and tape player to a balloon, set it on a timer and
             | release the balloon into the air. Before the transmission
             | started, they'd be long gone and the balloon would have
             | drifted far from the original site, making the perpetrators
             | much harder to track down. As a bonus, they'd get an
             | antenna high up in the air (which is good for reception),
             | which was also hard to disable, even if you managed to
             | pinpoint its location.
        
             | lxgr wrote:
             | Very unlikely. You'd probably be walking all over some
             | other cell that's reusing that frequency in the new
             | location, causing detectable issues.
        
         | Havoc wrote:
         | > And I guarantee there are devices listening into,
         | characterising and locating radio emitters in major cities at
         | the very least.
         | 
         | Not convinced there is that level of sophistication at play
        
           | Scramblejams wrote:
           | And if there is, they're probably not going to be burning
           | those resources on little people problems like phishing.
        
             | relaxing wrote:
             | Burning resources? By turning on their spectrum analyzer
             | and letting it log what it hears?
        
               | Scramblejams wrote:
               | "Burning" in the opsec sense. Disclosing the existence
               | and extent of their data collection by letting too many
               | non-cleared peeps in on the secret.
        
           | gravescale wrote:
           | I don't know if it was involved here, but "spectrum
           | monitoring" (that's the keyword for more information about
           | equipment you can get and who the expected customers are) is
           | definitely a thing that is done in many places, and not
           | _only_ by the military, but also by police and regulators. It
           | 's not clear where the mast was installed (the CoL police
           | aren't specifically limited to that very small area and one
           | arrest was South London and one was Manchester) but if it was
           | in central London, as a glaring terrorist target with an
           | airport (London City) and heliport, I'd be very, very
           | surprised if there's nothing watching the spectrum. Whether
           | the operators of the spendy gear would share the information
           | up for such "petty" crime, I don't know.
           | 
           | And there's always the Ham community who really, really hate
           | spectrum abusers.
        
             | GJim wrote:
             | > spectrum monitoring".... is definitely a thing that is
             | done in many places
             | 
             | Not by Ofcom it isn't!
             | 
             | (At least, certainly not on any scale as far as RF
             | interference/spoofing is concerned).
        
               | implements wrote:
               | Ringway Manchester (YT radio enthusiast) has a good video
               | about OFCOM DF monitoring:
               | https://www.youtube.com/watch?v=lMUwIpWvnbE - may have
               | been scaled back now, though.
        
               | gravescale wrote:
               | Come to think of it, the mobile operators themselves have
               | a large national network of radio receivers with lots of
               | fancy time-of-flight, phased array multi-path, multi-band
               | capabilities.
               | 
               | Maybe these days Ofcom can just ask them if they are
               | interested in something specific.
        
               | giantg2 wrote:
               | They also rent space on the towers for other people's
               | equiptment.
        
         | guerby wrote:
         | In France it's 33700 to report SMS spam to the authorities
         | 
         | https://www.33700.fr/informations-pratiques/signaler-un-mess...
        
           | seabass-labrax wrote:
           | Is it supposed to stand for something in the French language
           | as 7726 does in English?
        
             | codetrotter wrote:
             | The 0 button doesn't have any letters associated with it.
             | So I doubt it.
        
               | colanderman wrote:
               | Historically Q and Z lived on 0.
        
               | codetrotter wrote:
               | Looking at
               | https://en.wikipedia.org/wiki/Telephone_exchange_names I
               | see a few different mappings over time.
               | 
               | I like the fact that some of the earliest mappings had 0
               | mapped to "OPER" ("Operator"), because it makes me
               | imagine that this number 33700 is like some
               | interpretation of 337 and then shouting twice for the
               | "operator" (as in, the literal physical person that used
               | to sit and connect calls using wires and a patch board).
               | 
               | Taking this further then, and given that:
               | 
               | - 3 is assigned to any of the three letters DEF, and
               | 
               | - 7 is assigned to any of the three letters PRS,
               | 
               | we could invent the following meaning:
               | 
               | DES = "Declaration d'Envoi de Spam". (Lit. "Declaration
               | of sending of spam", as in a report about spam sending).
               | 
               | The double 0 is, as mentioned, in our invented meaning
               | like shouting "Operator! Operator!"
               | 
               | And with this invented meaning it's like we are shouting
               | for help from the operator to deal with this spam :D
               | 
               | Of course here I'm starting with 337 and backronyming
               | "DES" to a plausible but probably weird sentence. If it
               | was a real, the French would probably have worded the
               | original sentence quite differently and the resulting
               | number would be different as well.
               | 
               | (Also, looking at the article I'm not sure if any
               | European countries also had 0 used for "OPER" or not.
               | Guess I'll have to travel to some museums in France and
               | have a look at some old phones with my own eyes at some
               | point.)
        
       | mastermedo wrote:
       | Why does this work? How simple is it to follow the sms protocol,
       | I thought there were spam filters in place on the phones to
       | prevent receiving any traffic from towers which are not
       | registered to a well known network provider (or what have you).
        
         | jeroenhd wrote:
         | SMS is sent in some leftover space in the mobile data channel,
         | there's very little verification to that up until relatively
         | recent standards.
         | 
         | If you can pretend to be a 2G/3G tower and jam the real tower,
         | you can force phones to connect to you and you can send
         | whatever calls and texts you want.
         | 
         | This is mostly a 2G issue. Modern Android devices, and perhaps
         | iOS devices, have a toggle to disable 2G for this reason.
         | 
         | With fully compliant 5G, even police IMSI catchers become
         | pretty difficult to use.
        
           | andyjohnson0 wrote:
           | > This is mostly a 2G issue. Modern Android devices, and
           | perhaps iOS devices, have a toggle to disable 2G for this
           | reason.
           | 
           | My Android phone, Motorola Edge 20, has a setting for
           | preferred network type. Options are 5G/4G/3G/2G, 4G/3G/2G,
           | 3G/2G, or 2G only. Doesn't seem to be a way to disable 2G or
           | 3G, even though most networks here (UK) no longer support
           | them.
        
             | jeroenhd wrote:
             | For phones that support it, there's a separate toggle for
             | disabling 2G. I don't think the preference setting you're
             | referring to has the same effect. If I recall correctly,
             | The separate 2G toggle goes down to the modem especially
             | rather than just being configuration.
             | 
             | I do have my phone set to 4G+5G only through that same
             | screen, though, as my modem lacks the 2G toggle as well. If
             | there are missing options in the dropdown, try dialing
             | *#*#4636#*#* and see if you can configure it through there.
             | 
             | I don't know exactly what determines what configuration is
             | exposed to the UI, it's possible your modem simply lacks
             | support for disabling entire generations of cellular
             | technology.
        
               | Scoundreller wrote:
               | I believe the SIM supports all kinds of rules for what
               | networks and xG should be visible to the user.
               | 
               | I know for a fact a local network has 3G here, but it's
               | not exposed on my phone to choose, presumably because it
               | knows there's 4G and 5G and carriers don't want some dolt
               | camping on 3G and eating more mhz/bit. I used to camp on
               | 3G because Canada sent out too many dumb "emergency
               | alerts" for custody disputes 1000km away, but those only
               | operated over LTE, not 3G.
               | 
               | People don't believe me when I say you can see, and
               | sometimes connect to, US networks from a tall building in
               | Toronto from over the lake because Canadian SIMs have
               | rules/conditions to hide them, but if you put in an
               | overseas SIM, you'll see them on a scan.
               | 
               | Have also had a world of a time with a French SIM refuse
               | to connect to a Canadian tower because it _really_
               | preferred the US towers (lower roaming costs maybe?).
        
               | blacksmith_tb wrote:
               | My Pixel 6a has a toggle in settings labeled "Allow 2G".
               | It does have a note saying it may help you connect in
               | situations where reception is poor, and that it may
               | potentially be used for emergency calls even if you turn
               | it off.
        
             | lxgr wrote:
             | Huh, are you sure that's true?
             | 
             | I was under the impression that most European countries
             | were keeping 2G around for legacy applications and voice
             | calls on roaming (until VoLTE roaming and emergency calls
             | finally become equally reliable), shutting down 3G if
             | anything?
        
           | lxgr wrote:
           | I've always found that a weird characterization. It's sent in
           | the signaling channel, but why is that "leftover"? The
           | channel is still established for the SMS, and it's not like
           | that channel bandwidth would go unused otherwise.
           | 
           | It's like saying "postcards are delivered in the leftover
           | part of the mail truck unused by letters and parcels" :)
        
             | zinekeller wrote:
             | > I've always found that a weird characterization. It's
             | sent in the signaling channel, but why is that "leftover"?
             | The channel is still established for the SMS, and it's not
             | like that channel bandwidth would go unused otherwise.
             | 
             | In modern standards, it is indeed not a "leftover"
             | (although RCS exists which is another can of worms), but
             | originally it was transmitted in a best-effort manner using
             | what is essentially a "hack" on SS7 (unlike phone calls
             | which is guaranteed reception - or at least not going
             | through).
        
               | lxgr wrote:
               | I don't think this was ever true, unless I'm
               | misunderstanding what you mean by "best-effort" or
               | "hack".
               | 
               | In GSM, SMS are delivered either over the SDCCH (when no
               | voice call is happening simultaneously) or the SACCH
               | (when a voice call is already in progress). In the latter
               | case, you might argue that they're piggy-backing onto
               | existing resources, but in the former, there are
               | definitely dedicated resources being allocated
               | specifically for SMS delivery.
               | 
               | SMS delivery has also always been reliable, both on the
               | lower level (both SDCCH and SACCH are reliable) and the
               | upper one (the phone reports successful delivery back to
               | the sending SMSC), so while there are no timing
               | guarantees (is that what you mean by best-effort?),
               | delivery always eventually succeeds once resources are
               | available.
               | 
               | The protocol even goes to significant lengths to ensure
               | timely (re)delivery in case various error scenarios, such
               | as a full inbox on a phone or a phone being out of
               | reception.
               | 
               | While 140 bytes aren't much, reliability is actually
               | great, until you add spam filtering, roaming, and inter-
               | network delivery to the mix, when things can quickly go
               | off the rails. (One unexpected consequence of how it's
               | implemented is that for mutual reachability, it doesn't
               | only matter what operators the sender and recipient have
               | a contract with, but also in which network the recipient
               | is currently roaming.)
        
               | TeMPOraL wrote:
               | > _SMS delivery has also always been reliable, both on
               | the lower level (both SDCCH and SACCH are reliable) and
               | the upper one (the phone reports successful delivery back
               | to the sending SMSC), so while there are no timing
               | guarantees (is that what you mean by best-effort?),
               | delivery always eventually succeeds once resources are
               | available._
               | 
               | That's the opposite of my experience in the early 2000s.
               | I mean, the whole reason you'd always enable delivery
               | reports is because delayed delivery or failed delivery
               | were almost a daily occurrence. Anyone who sent SMS blind
               | would quickly learn to either enable delivery reports, or
               | just start calling people more.
        
         | LZ2DMV wrote:
         | The problem is mostly the insecure defaults. Every modern phone
         | is configured to be backward compatible and connect to an older
         | generation of network if a newer generation is not present
         | (like in the case of being deliberately jammed by an
         | adversary). In 2G, mutual authentication is not existent, it
         | happens only one way - only the network authenticates the
         | handset. If you are close enough to the victim (only screaming
         | louder, i.e. more power than the legitimate network, but from a
         | significant distance doesn't work, because of the RTT of the
         | signal - TDMA-based systems are very time-sensitive in nature),
         | nothing prevents you from operating your own mobile
         | infrastructure and disable any encryption (i.e. in 2G, during
         | the handshake, you just say A5/0 - no encryption, to the
         | handset) - you can not enable encryption anyway, because you do
         | not have the corresponding key that is on the SIM card, only
         | the legitimate carrier has that.
         | 
         | Whether or not the victim will be notified about the absence of
         | encryption, depends on the state of a single bit on the SIM
         | card [1]. In 99% of the cases, there is no warning that the
         | handset is currently using A5/0.
         | 
         | From now on, you are at the grace of the rogue network operator
         | - they can send you anything from any number, sit in the middle
         | of every call and capture every frame of data.
         | 
         | I don't think the current level of technological education of
         | the general public is enough for most of them to know why it is
         | important to force your phone to work only with modern network
         | standards and that is what police and other government agencies
         | interested in operating IMSI catchers exploit.
         | 
         | [1] http://blog.taddong.com/2011/02/does-your-phone-warn-you-
         | whe...
        
           | seabass-labrax wrote:
           | > ...that is what police and other government agencies
           | interested in operating IMSI catchers exploit.
           | 
           | Is encryption really significant to whether or not the police
           | are able to monitor cellular phones? As bandwidth is already
           | centrally allocated, there is a limited number of legal
           | cellular network operators, and a competent authority could
           | already compel (indeed, _could have_ already compelled)
           | mobile operators to provide master keys and diversification
           | information under the Snooper Charter 2016[1].
           | 
           | https://www.legislation.gov.uk/ukpga/2016/25/
        
             | LZ2DMV wrote:
             | This implies compliance with the law and a formal
             | procedure, and an authority might not always follow the law
             | for various reasons. At least the use of encryption means
             | one is less likely to be a subject of surveillance in an
             | unlawful manner.
             | 
             | Consider intelligence operation abroad, for example.
        
       | cjrp wrote:
       | Slightly more detail on The Register:
       | https://www.theregister.com/2024/06/10/two_arrested_in_uk_ov...
       | 
       | Sounds like they were using a Stingray-esque device, as the
       | police do.
        
         | skilled wrote:
         | I have emailed mods to ask for a link update so your comment
         | can be demoted, and more room given for discussion. Thanks for
         | pointing it out, did not see/check when submitting.
        
         | dang wrote:
         | Thanks! We've changed to that from
         | https://www.cityoflondon.police.uk/news/city-of-london/news/...
         | now.
        
       | jack_riminton wrote:
       | For those unaware the "City of London" is in fact a small part of
       | London, what you might call downtown, and they have their own
       | police force. fwiw they're regarded as a very competent police
       | force
        
         | cjk2 wrote:
         | apart from the financial crimes unit...
        
         | fragmede wrote:
         | GCP Grey on the city of London: https://youtu.be/LrObZ_HZZUc
        
           | mintplant wrote:
           | Map Men on London's 32 boroughs:
           | https://www.youtube.com/watch?v=daeB46Z4fjs
        
           | jack_riminton wrote:
           | As a londoner, even I learned several things from that video.
           | And it's done by an American!
        
             | oakesm9 wrote:
             | He's american, but moved to the UK to study and then become
             | a Physics teacher in London. I think he's been London based
             | for all of his YouTube career.
        
         | LAC-Tech wrote:
         | _fwiw they 're regarded as a very competent police force_
         | 
         | What makes them different?
        
           | jack_riminton wrote:
           | Well it's a reputation, so it's hard to quantify. But
           | anecdotally I've heard from numerous people who had dealings
           | with that they were very competent (compared to most British
           | forces presumably).
           | 
           | I've also heard that their average level of policeman is more
           | educated , ie many holding degrees, masters etc. I presume
           | this must be due to the nature of the work they're most known
           | for ie combatting complex fraud, organised crime etc
        
             | walthamstow wrote:
             | They have about 1 officer per 10 people living there which
             | helps quite a bit
             | 
             | For reference, the Met has 33k officers for 10m people
        
               | OJFord wrote:
               | Because policing is all about who's _resident_ in the
               | territory covered?
        
               | walthamstow wrote:
               | Is that what I said? Nope
        
               | r-w wrote:
               | Good point, bad tone :)
        
               | Steve44 wrote:
               | There is one very important caveat about the population
               | of the City though.
               | 
               | Whilst there are only 8,600 residents, there are
               | apparently over 600,000 commuters working there every
               | day.
               | 
               | https://www.cityoflondon.gov.uk/about-us/about-the-city-
               | of-l...
        
           | bloqs wrote:
           | They have different branding from the rest of the police
           | forces!
        
           | mytailorisrich wrote:
           | The City of London is very small, safe (quick look online
           | returns that the crime rate is " _73% lower than London and
           | 67% lower than national average_ "), and very rich, and
           | obviously right in the middle of a top world city. So I am
           | guessing that their police force is well resourced, able to
           | attract "top talent", and not bogged down by anti-social and
           | petty crime.
        
             | LAC-Tech wrote:
             | I'm always suspicious of low crime rates - often it means
             | people don't bother reporting crimes as they know nothing
             | will happen.
             | 
             | IE, if I get robbed in the City of London is it even worth
             | calling the police?
        
               | mytailorisrich wrote:
               | Why would there be a difference in reporting in the City
               | vs the rest of London?
        
               | andylynch wrote:
               | The City Police have a very, small patch and little
               | violent crime, but are geared up to deal with IRA/ISIS-
               | type threats. Part of this means they have surveillance
               | coverage of virtually the entire areas. It also mean that
               | they can get anywhere very, very quickly.
        
               | cannonpr wrote:
               | Yes it is, a friend had their laptop stolen, the police
               | tracked down the offenders within 2 hours and returned
               | the items. What they also don't tell you is that it's a
               | dystopian panopticon and runs on a slightly different
               | legal system than the rest of the U.K.
        
               | LAC-Tech wrote:
               | Impressive! TBH I'd rather that dystopia than the one
               | where people are constantly having their things stolen
               | with zero recourse.
        
             | gadders wrote:
             | It's also mostly an office district. Not many people live
             | there. It's mostly a ghost town at night and weekends.
        
           | razakel wrote:
           | Their focus is more on complex financial crimes, so they're a
           | bit better educated than your typical cop.
        
         | justinclift wrote:
         | > fwiw they're regarded as a very competent police force
         | 
         | That's not at all the reputation they have. They've been acting
         | as an extension of the copyright lobby for years:
         | 
         | * https://torrentfreak.com/new-uk-police-unit-announces-two-
         | ar...
         | 
         | * https://www.vice.com/en/article/bvn4nw/cops-
         | arrest-3-people-...
         | 
         | * https://www.cityoflondon.police.uk/news/city-of-
         | london/news/...
         | 
         | There are probably hundreds of instances of them doing stuff
         | like the above, that was just the results from a quick search.
        
           | jack_riminton wrote:
           | _Personal opinion may vary_
        
           | socksy wrote:
           | To be fair, a police force doing stuff you don't like doesn't
           | necessarily mean that they're incompetent at doing those
           | things
        
             | justinclift wrote:
             | Sure. But their reputation is pretty much "police force for
             | hire" rather than anything to do with competence.
        
               | dubcanada wrote:
               | But isn't that what police are? I don't see a ton of
               | volunteer police...
        
           | Doe-_ wrote:
           | The City is also unique in that businesses represent the
           | majority of the voters in its council elections.
           | 
           | Moreover, the council is also the police authority, which
           | could explain a more active copyright infringement force.
        
           | andylynch wrote:
           | It's not a conspiracy; the City of London police, alongside
           | normal local duties, have a national responsibility for many
           | kinds of economic and cyber crime.
           | 
           | This almost certainly comes from long experience
           | investigating fraud and other financial crimes amongst the
           | businesses and people based there, to a degree and level of
           | complexity not found in other regions of the UK.
           | 
           | For instance they host Action Fraud for the entire country.
           | 
           | If you want to talk about enforcement priorities, contact
           | your PCC, or better yet, right now, your local candidates.
        
         | euroderf wrote:
         | It's more like an autonomous enclave free of any control by
         | Parliament. The Guardian plumbs the depths once in a while,
         | such as in this article:
         | https://www.theguardian.com/commentisfree/2011/oct/31/corpor...
        
           | walthamstow wrote:
           | It's not the Wild West, the laws of the UK Parliament apply
           | to people and companies in the City.
           | 
           | In that piece Monbiot tries to blame the Corporation for the
           | 2008 crash, which is laughable.
        
             | euroderf wrote:
             | This article and others say the Corporation pretty much
             | does as it pleases. There's a "conspiracy theory" that says
             | that the City instigated Brexit to avoid EU jurisdiction.
        
       | tiku wrote:
       | Why is sms such a crappy protocol that this is even possible?
        
         | sunbum wrote:
         | SMS isn't a protocol. Attacks like these are done via 2G. Which
         | is really why most people should disable it if they can.
        
         | dotancohen wrote:
         | Because it dates to a time when such attacks were infeasible.
         | GPS is very similar in that regard. Even HTTPS was uncommon
         | back when I was in university. NASA spacecraft still
         | communicate over unencrypted channels.
         | 
         | Mindsets were different then.
        
           | fragmede wrote:
           | not just mindsets, but the computing power available. These
           | days, my smartphone is millions of times more powerful and
           | the computation to do TLS encryption on every website I visit
           | is trivial for a computer that fits in the palm of my hand.
           | Way back when, the 1 or 2 kilobytes or so a modern RSA
           | private key (PEM format) would take up on disk was meaningful
           | when you only had 4 megabytes of RAM and CPUs ran in the
           | megahertz range.
        
           | oldgradstudent wrote:
           | > GPS is very similar in that regard.
           | 
           | GPS originated as a military protocol and has some level of
           | encryption and authentication, but this is not available to
           | the general public.
        
             | GJim wrote:
             | GPS *had* no encryption or authentication; indeed, such
             | security is only a recent addition to the L2 frequency.
             | 
             | USK: Galileo also has authentication available on its
             | civilian frequencies.
        
               | lxgr wrote:
               | > such security is only a recent addition to the L2
               | frequency
               | 
               | Is that already available? I thought GPS L2C didn't
               | include authentication yet.
        
           | nanna wrote:
           | Also to a dumb phone it doesn't matter whether an SMS
           | contains a phishing link because it has no way of accessing
           | it. Until the advent of smart phones SMS phishing was a non-
           | issue.
        
         | est wrote:
         | encryption was _expensive_ in GSM days.
         | 
         | People seem to forget that dedicated TLS acceleration hardware
         | was a thing not long ago.
        
         | robaato wrote:
         | It was a hack to use "unused" control/signalling paths - see
         | https://en.wikipedia.org/wiki/SMS
         | 
         | Effectively came "for free" for mobile operators...
        
           | lxgr wrote:
           | That's a common misconception. The signaling channels used
           | aren't "unused" - they're literally set up and torn down to
           | deliver SMS!
        
             | aidenn0 wrote:
             | I think you meant to end that with "phone calls" rather
             | than "to deliver SMS?" SS7 was used for that, but had a
             | significant amount of idle time since most phone calls are
             | much longer than the time needed to setup the connection.
        
               | lxgr wrote:
               | I do indeed mean SMS, but I was focusing more on the air
               | interface. There, SMS definitely consume resources in the
               | same way that calls do (although of course at a very
               | different rate: SDCCH uses 0.8 kbit/s, as opposed to 13
               | kbps for full rate voice/CSD traffic channels).
        
               | aidenn0 wrote:
               | But the signaling channels weren't used to send SMS
               | before SMS existed (which the original statement of
               | "unused" implied).
        
       | Infinity315 wrote:
       | Slightly off topic, but this is demonstrated in a show called Mr.
       | Robot. I find it insanely cool that the hacking in Mr. Robot
       | closely resembles real life.
        
         | NilMostChill wrote:
         | IIRC they hired a bunch of real life professional white hats to
         | consult.
         | 
         | https://en.wikipedia.org/wiki/Mr._Robot#Technical_accuracy
        
       | mdp2021 wrote:
       | > _Most phone providers are part of a scheme that allows
       | customers to report suspicious text messages for free by
       | forwarding it to 7726. If you forward a text to 7726, your
       | provider can investigate the origin of the text and arrange to
       | block or ban the sender, if it's found to be malicious_
       | 
       | It would be useful to have a list of Countries/operators adopting
       | the 7726 ("SPAM") number. It seems also some European Countries
       | do.
        
         | slowmotiony wrote:
         | How do you forward a text?
        
           | orra wrote:
           | Often there's a long click menu in your SMS app to do it.
           | 
           | But all that really does is copy the body into a new SMS.
           | There's no metadata to indicate it's forwarded, as you
           | suspect.
           | 
           | This means texting 7726 is a two step process. First you send
           | the body. You immediately get a response asking for the phone
           | number of the spam sender, so then you sent that.
        
             | lxgr wrote:
             | Does the phone number even matter for tracing? As far as I
             | understand SMS delivery, it's not authenticated at all.
             | 
             | I suppose it can be used to help the operator identify the
             | actual incoming message in their logs?
        
               | toast0 wrote:
               | Source number authorization depends on how the messages
               | get to the carrier and how the carrier has things setup.
               | At the end of the day, there's a lot of trust though; and
               | a lot of connections would be difficult/expensive to
               | confirm that the connection is authorized to send
               | messages from the sources they're using.
               | 
               | Think of BCP38 for IP spoofing, but for number spoofing.
               | If you get an appropriate country mobile number from a
               | carrier in that country, are you going to pay for a
               | portability lookup to confirm that carrier is the
               | authorized carrier for that number? Does that carrier
               | check source numbers for all of the connections they
               | have?
               | 
               | Some of the aggregators are good at checking sources, and
               | some aren't, but aggregators are often authorized to send
               | messages from many different countries, so they're likely
               | to have their connections unchecked, because keeping the
               | list updated is hard. It's like IP transit, but a lot
               | worse.
        
         | doophus wrote:
         | Would this even work in the article's situation, where
         | someone's MITMing SMS?
        
           | mdp2021 wrote:
           | If you believe the cell you are under is compromised, further
           | action should be performed under a different cell.
           | 
           | Actually, I would like to have an option to identify the
           | cells devices are connected to.
        
             | mminer237 wrote:
             | CellMapper is an app on Android to do this: https://play.go
             | ogle.com/store/apps/details?id=cellmapper.net...
        
         | mminer237 wrote:
         | All major US carriers do.
        
       | shiroiushi wrote:
       | People in the UK still use SMS?
        
         | mdp2021 wrote:
         | > _still use SMS?_
         | 
         | Instead of? If you have to send text to an occasional user,
         | what do you think should be used?
         | 
         | The article is about /receiving/ messages supposedly from
         | firms. How should they have sent it?
        
           | lrvick wrote:
           | Maybe something with at least TLS like email.
        
             | mdp2021 wrote:
             | The issue with those kind of messages is sender
             | authentication, not content confidentiality.
        
         | porker wrote:
         | The National Health Service communicates with people via SMS.
         | The NHS has an app, but doesn't send notifications through it.
         | 
         | My guess is because our population can all cope with SMS by
         | now, but anything more...
        
           | denton-scratch wrote:
           | HMRC also seems to require an SMS-capable device for 2FA.
           | Using the HMRC website is a soul-destroying adventure through
           | severe speed-bumps, short session timeouts, and 72-hour
           | delays. It's the epitome of awful, large-scale British public
           | computer-system acquisition.
        
         | Havoc wrote:
         | People not so much but services yes
        
         | johneth wrote:
         | It's almost exclusively used by businesses and government to
         | send notifications.
         | 
         | They use SMS because it's a baseline that every phone, smart or
         | dumb, has. No need to have an email address, no need to have an
         | app.
         | 
         | Most people use Whatsapp / Messenger / social media / to a
         | lesser extent iMessage.
        
           | denton-scratch wrote:
           | > because it's a baseline that every phone, smart or dumb,
           | has
           | 
           | My phone is an IP phone. It doesn't do SMS. Did you mean
           | "mobile phone"?
           | 
           | > No need to have an email address
           | 
           | I'm pretty sure that more people have an email address but no
           | SMS capability, than have SMS but no email capability.
        
             | johneth wrote:
             | > My phone is an IP phone. It doesn't do SMS. Did you mean
             | "mobile phone"?
             | 
             | UK landlines are transitioning to VoIP. SMS messages sent
             | to UK landlines are read out by a text-to-speech system
             | (well, my parents' does).
        
               | denton-scratch wrote:
               | Yes; mine does that too. Have you ever tried to use one
               | of those TTS systems? They can just about read standard
               | international English; anything more interesting, like
               | someone's name, and they fall back to spelling-out the
               | letters.
        
       | bloqs wrote:
       | This is the police force for the ancient financial district in
       | London called the City of London. Best explanation:
       | https://youtu.be/LrObZ_HZZUc
        
         | scoot wrote:
         | The former financial district. The financial district has long
         | since migrated to Canary Wharf and, since Brexit, increasingly
         | overseas.
        
           | gadders wrote:
           | Companies are moving back out of the Wharf to the City.
           | 
           | >>and, since Brexit, increasingly overseas
           | 
           | And this isn't even remotely true.
        
       | ReptileMan wrote:
       | Trivial to make one - you just need a SDR and encryption key
       | (harder to obtain, but probably could be found on the black
       | market).
        
         | bestbuyer__ wrote:
         | This is giving off HackerNews DropBox vibes :)
        
         | lxgr wrote:
         | You don't need any key for GSM, since the network/base station
         | only started authenticating itself to the phone/SIM with 3G.
         | 
         | That's why it would be good to shut down GSM at some point: It
         | would raise the difficulty of such attacks significantly.
         | 
         | What I don't understand is how they managed to actually
         | intercept any SMS with an IMSI catcher. They'd need to get the
         | network to send these through their infrastructure, so I wonder
         | how that worked?
         | 
         | Update: Ah, they were just sending out texts themselves, not
         | intercepting anything.
        
       | swiftcoder wrote:
       | I enjoyed the "Sorry, there was a technical problem. Please try
       | again." when I tried to reject cookies
        
       | exabrial wrote:
       | Oh good, we better make sure we tie our bank accounts to SMS
        
         | dang wrote:
         | Could you please stop posting unsubstantive comments and
         | flamebait? You've unfortunately been doing it repeatedly. It's
         | not what this site is for, and destroys what it is for.
         | 
         | If you wouldn't mind reviewing
         | https://news.ycombinator.com/newsguidelines.html and taking the
         | intended spirit of the site more to heart, we'd be grateful.
        
       | robbyiq999 wrote:
       | What interests me is the intelligence and innovation of this. You
       | would think these bad actors would fair well doing societal good
       | using their skills and not resort to crime.
        
         | dubcanada wrote:
         | Why does that interest you? This is fairly common.
        
         | ChrisMarshallNY wrote:
         | That's always been the case. Dumb crooks don't last long.
         | 
         | As to why they choose this way, over a "legitimate" (like dark
         | pattern writing, or PID mining) vocation, there are many
         | reasons.
         | 
         | I suspect that a big one, is the "blackball" effect, that
         | having a conviction on your record will create. Once we are
         | convicted, then we become unhireable, in many industries, so
         | it's not like we have a choice. Also, the pay for nefarious
         | work can be quite good.
        
           | rthnbgrredf wrote:
           | Can confirm. Have read many articles about known gang members
           | and drug lords. It usually starts with doing some dumb things
           | at younger age and then struggle to find and keep a legal
           | job.
        
         | RIMR wrote:
         | Think about the "innovation" here. Learning to set up your own
         | cell tower is quite a feat, but how are you going to monetize
         | it? Are you going to start your own cell provider and try to
         | compete with the existing major players? Or are you going to
         | use the tech for some fast capital right now?
         | 
         | If the goal was to learn just enough about cell tech to exploit
         | it for profit, then a legal approach is off-the-table because
         | of the extraordinary effort needed to ever get anything off the
         | ground.
        
       | Scoundreller wrote:
       | > For example, EE has stopped tens of millions of scam SMS
       | messages since stepping up its anti-spam filter in 2021.
       | 
       | So, they blocked like 2% ?
        
         | vdfs wrote:
         | https://xkcd.com/1161/
        
       | tamimio wrote:
       | Building a homemade BTS (Base Transceiver Station) is easy. I
       | remember making one back in 2011 with a USRP SDR. Nowadays, you
       | can even create a 5G network, not just LTE. There's plenty of
       | good open-source software available. Paired with an SDR, you are
       | good to go. The rest is just some scripting to automate some
       | tasks, probably how they flooded the SMS.
        
         | stainablesteel wrote:
         | so why do i pay for cell phone service? you're saying most
         | people can just point some metal out of their window and the
         | neighborhood would be happy?
        
           | nexuist wrote:
           | Wait till you find out about diesel generators!
        
           | Elv13 wrote:
           | The phone part is no different. It's easy to run your own
           | FreeSWITCH or Asterisk server at home and connect a cellphone
           | using Wireguard. It costs ~0.5$ US per month to get nearly
           | unlimited everything. Calls and SMS work just fine. The
           | problem is always mobility. You need either Wifi or some of
           | those odd reseller brand ultra cheap pre-paid plans (like "1$
           | for the first 200mb" plans). Then you need to make sure only
           | the voice/sms is allowed to use the data and you get a 2$
           | nationwide working cellphone. You can also share someone else
           | plan by having them leaving their Phone wifi hotspot on.
           | 
           | As for reliability, well, that's your problem now, good luck!
           | 
           | > point some metal out of their window and the neighborhood
           | would be happy?
           | 
           | You might, but the FCC won't
        
           | tamimio wrote:
           | You pay for the coverage and the infrastructure they built.
           | 
           | > you're saying most people can just point some metal out of
           | their window and the neighborhood would be happy
           | 
           | Technically? Yes, you can do it in a few hours, or as a
           | weekend project if you've never done it before. Just grab a
           | full-duplex SDR; you don't need to go for expensive ones like
           | the USRP. Get a BladeRF or LimeSDR, download the software,
           | and set up the station. The problem lies with the
           | regulations. Depending on where you live, you might face
           | hefty charges for violating spectrum rules, and they are
           | actively looking for such violations by the way. One of the
           | proofs of concept we did with the regulators here in Canada
           | involves using a drone to detect these violations. It's just
           | a matter of time before they find you.
        
             | toomuchtodo wrote:
             | Is there a reason cellular tower base stations don't have
             | this spectrum surveillance capability? With such broad
             | coverage, it would be straightforward to triangulate and
             | report coarse location of unlicensed broadcasting.
        
               | ogurechny wrote:
               | I suppose they totally have that capacity, because
               | cellular networks depend on fair play of thousands of
               | devices sharing access to a part of the spectrum in a
               | given area. Constant stats gathering has to be vital for
               | detection of hardware faults and coverage problems in
               | very complex city networks. Stations can even ask mobile
               | devices to work as remote probes, and report immediate
               | signal levels for each station they can receive.
               | Operators have all the incentives to snitch on anything
               | suspicious or broken to both the regulatory body, and the
               | security services (who probably reply "oh, it's ours"
               | most of the time).
        
               | nickpsecurity wrote:
               | Prior leaks or reports... can't recall which... said the
               | service providers could trace people with pinpoint
               | accuracy. Way better than GPS. The cops were using it. I
               | think it was in a law enforcement portal with some
               | telecoms, too.
               | 
               | The other trick was how more things are designed to stay
               | on even when they look off. An older one with older
               | phones would make it answer silently so you didn't know
               | if they were listening.
               | 
               | There's so many risks with telecoms that high-assurance
               | security (a) said keep cell phones away from anything
               | security-critical and (b) used Red-Black separation where
               | whatever connects to untrusted line never had any
               | plaintext, just encrypted. Seperation kernels, like
               | INTEGRITY-178B and seL4, were invented to hopefully do
               | that with software.
        
       | Havoc wrote:
       | I do wonder whether this is the right move. Sure law breaking
       | must be punished, but seems like precisely the skillset & mindset
       | you'd want on your side if you were potentially heading towards
       | confrontation in a world of cyber, drones and asymetric
       | warfare...
        
         | wongarsu wrote:
         | Depends on the sentence he gets. They did just write about his
         | name and skillset in a national newspaper. If he only serves a
         | year or two that can end up as a positive for his career.
        
         | andylynch wrote:
         | I'm sure the folks from Cheltenham can find them if they want a
         | chat.
         | 
         | But given these guys appear to have been running this as part
         | of a bigger spam/fraud game rather than for curiosity/ general
         | mischief they might be too far in the poacher category for the
         | gamekeepers.
        
         | ptero wrote:
         | To me, this is the right move. The skillset needed to build
         | such RF endpoints is not that rare. Any decent EE college
         | graduate should be able to rig one up with an off the shelf
         | software-defined radio and some literature review. If all they
         | did were to build it for laughs and boasts I would hope they
         | would just be yelled at and threatened with a sizeable fine
         | next time they try such spectrum violations.
         | 
         | But they apparently phished a lot of information with the
         | intent to defraud folks, which in my book completely changes
         | the proper response. My 2c.
        
       | coretx wrote:
       | The A/51 rainbow tables can be found here:
       | https://opensource.srlabs.de/projects/a51-decrypt/files It can be
       | made to work using a 10 bucks RTLSDR for RX. Had they used a
       | legal provider for the TX, they would not have been caught.
       | 
       | This smells like yet another case of children at work and police
       | officers trying to sell themselves as super heroes. This is
       | getting old.
        
       ___________________________________________________________________
       (page generated 2024-06-11 23:02 UTC)