[HN Gopher] British duo arrested for SMS phishing via homemade c...
___________________________________________________________________
British duo arrested for SMS phishing via homemade cell tower
Author : skilled
Score : 199 points
Date : 2024-06-11 05:40 UTC (17 hours ago)
(HTM) web link (www.theregister.com)
(TXT) w3m dump (www.theregister.com)
| usr1106 wrote:
| Cloudflare turnstyle making government resources inaccessible
| (it's always an endless loop of clicking that I am human on my
| mobile)
| randunel wrote:
| Same here, I cannot access that website, it's an infinite
| turnstile loop. Same issue with hibp, as far as I can see.
| moomin wrote:
| Pretty ironic considering it's the City of London Police
| website.
|
| If malicious clients want to try their luck, I'd say let
| them.
| Traubenfuchs wrote:
| You are probably using the suspicious setup Cloudflare wants to
| lock out.
|
| Please try again with Google (R) Chrome (TM), no experience
| manipulating addons (e.g. adblockers), no VPN and from a non-
| non-friendly country.
| mdp2021 wrote:
| It is not that, it works on some odd setups.
| jeroenhd wrote:
| Works fine on Firefox from a custom Android ROM through a VPN
| here. Last time I checked a post where people complained
| about Cloudflare, even Ladybird for Android made it through.
| You need cookies and Javascript, but that's all you need to
| pass the technical checks it seems.
|
| Cloudflare likes to block things like Tor and CGNAT because
| of the abuse and unidentifiability those networks provide,
| and maybe there's a filter on some enemy states set up by the
| British government, but they really don't seem to care all
| that much about what you're running on your phone. Blocks
| seem to be largely network-based in my experience.
| tgv wrote:
| I can access with Firefox, macOS, UBlock Origin.
| cqqxo4zV46cp wrote:
| This is absurdly dishonest. I don't use Chrome. I use a VPN
| sometimes, when I'm travelling, in a DigitalOcean IP range
| (which has a dubious reputation). I don't live in the US or
| Europe, which is often Californian for 'a list of trusted
| countries'. I've never, once, ever, had an issue with
| CloudFlare.
|
| The regular vocal super-minority of people that have this
| issue need only expose the fact that they're running Lynx on
| their Gentoo-powered toaster, upside down, on the
| international space station.
| pheggs wrote:
| how certain are you actually that you are not an android? :)
| szundi wrote:
| We are bio androids anyway
| happymellon wrote:
| This comment instantly made me think of this.
|
| https://en.m.wikipedia.org/wiki/The_6th_Day
|
| Apparently it was also Terry Crews acting debut.
| Perz1val wrote:
| Lets me in on my microg lineageos with brave browser
| jgrahamc wrote:
| If you hit a problem like this I'd like to hear about it. If
| you're willing I an take a HAR file and pass it on to the
| Turnstile team and they can see why.
| gravescale wrote:
| That's a pretty clever way to be very stupid! Anyone who reports
| the message (forward it to 7726, spells SPAM) to a network tips
| the network off that messages are landing on subscribers devices
| that didn't come through their system.
|
| And I guarantee there are devices listening into, characterising
| and locating radio emitters in major cities at the very least.
| vasco wrote:
| Yeah if you run a private antenna either the police or some men
| from your country's equivalent to FCC will come to your door
| and politely ask you to stop, if they are having a good day,
| most likely confiscate some of the equipment as well. And
| that's just for emitting anything on reserved spectrum or with
| too much power, not even for crime.
| GordonS wrote:
| I guess you could hoover up traffic at a location for a few
| hours, then move to another location and keep going like that
| without getting caught.
| vasco wrote:
| Listening isn't illegal so you can do that without moving.
| People move just to listen to different things with limited
| range, one form of it is called wardriving if you're doing
| it to wifi for example.
| GordonS wrote:
| I'm fairly sure in the UK it's illegal, tho I don't know
| for certain. But even if not, you could be arrested for
| conspiracy to commit fraud (or similar).
| seabass-labrax wrote:
| That's not true - it is indeed illegal to listen in to
| radio transmissions which are not intended for you. Doing
| so is a criminal offence punishable by an unlimited
| summary fine (the precise amount is determined based on
| the offender's personal income and other circumstances).
|
| https://www.legislation.gov.uk/ukpga/2006/36/section/48
| mnw21cam wrote:
| Correct. That's one reason why LiveATC has recordings of
| air traffic control radio calls from most countries, but
| not the UK.
| gravescale wrote:
| You can't send a phishing SMS from a receive-only device.
| Any mobile tower must have an active transmitter (at the
| very least, so the handset knows what network it thinks
| it's connected to!).
|
| Transmitting on a licensed mobile service band without
| the license is a very good way to earn a knock on your
| door.
|
| Eavesdropping on tower-to-handset comms is illegal too
| (in the UK), but it's not very practical to find just a
| receiver, unless they already know almost exactly where
| it is and are able to do a TEMPEST-like attack on the
| local oscillator or something. So as long as you keep
| quiet and don't do anything to indicate you're listening,
| such as, posting on Twitter about it or you do crime
| based on it, you'll get away with it. However, a receiver
| can't bump a victim handset down to a primitive-enough
| protocol, so all you'll get is encrypted content and
| maybe a smidge of metadata (I'm not sure exactly what is
| and isn't encrypted for each "G").
| miki123211 wrote:
| The Polish democratic opposition used to do this in the
| 80's, during the communist era. As far as I remember, their
| technique relied on balloons, they would attach a homemade
| antenna and tape player to a balloon, set it on a timer and
| release the balloon into the air. Before the transmission
| started, they'd be long gone and the balloon would have
| drifted far from the original site, making the perpetrators
| much harder to track down. As a bonus, they'd get an
| antenna high up in the air (which is good for reception),
| which was also hard to disable, even if you managed to
| pinpoint its location.
| lxgr wrote:
| Very unlikely. You'd probably be walking all over some
| other cell that's reusing that frequency in the new
| location, causing detectable issues.
| Havoc wrote:
| > And I guarantee there are devices listening into,
| characterising and locating radio emitters in major cities at
| the very least.
|
| Not convinced there is that level of sophistication at play
| Scramblejams wrote:
| And if there is, they're probably not going to be burning
| those resources on little people problems like phishing.
| relaxing wrote:
| Burning resources? By turning on their spectrum analyzer
| and letting it log what it hears?
| Scramblejams wrote:
| "Burning" in the opsec sense. Disclosing the existence
| and extent of their data collection by letting too many
| non-cleared peeps in on the secret.
| gravescale wrote:
| I don't know if it was involved here, but "spectrum
| monitoring" (that's the keyword for more information about
| equipment you can get and who the expected customers are) is
| definitely a thing that is done in many places, and not
| _only_ by the military, but also by police and regulators. It
| 's not clear where the mast was installed (the CoL police
| aren't specifically limited to that very small area and one
| arrest was South London and one was Manchester) but if it was
| in central London, as a glaring terrorist target with an
| airport (London City) and heliport, I'd be very, very
| surprised if there's nothing watching the spectrum. Whether
| the operators of the spendy gear would share the information
| up for such "petty" crime, I don't know.
|
| And there's always the Ham community who really, really hate
| spectrum abusers.
| GJim wrote:
| > spectrum monitoring".... is definitely a thing that is
| done in many places
|
| Not by Ofcom it isn't!
|
| (At least, certainly not on any scale as far as RF
| interference/spoofing is concerned).
| implements wrote:
| Ringway Manchester (YT radio enthusiast) has a good video
| about OFCOM DF monitoring:
| https://www.youtube.com/watch?v=lMUwIpWvnbE - may have
| been scaled back now, though.
| gravescale wrote:
| Come to think of it, the mobile operators themselves have
| a large national network of radio receivers with lots of
| fancy time-of-flight, phased array multi-path, multi-band
| capabilities.
|
| Maybe these days Ofcom can just ask them if they are
| interested in something specific.
| giantg2 wrote:
| They also rent space on the towers for other people's
| equiptment.
| guerby wrote:
| In France it's 33700 to report SMS spam to the authorities
|
| https://www.33700.fr/informations-pratiques/signaler-un-mess...
| seabass-labrax wrote:
| Is it supposed to stand for something in the French language
| as 7726 does in English?
| codetrotter wrote:
| The 0 button doesn't have any letters associated with it.
| So I doubt it.
| colanderman wrote:
| Historically Q and Z lived on 0.
| codetrotter wrote:
| Looking at
| https://en.wikipedia.org/wiki/Telephone_exchange_names I
| see a few different mappings over time.
|
| I like the fact that some of the earliest mappings had 0
| mapped to "OPER" ("Operator"), because it makes me
| imagine that this number 33700 is like some
| interpretation of 337 and then shouting twice for the
| "operator" (as in, the literal physical person that used
| to sit and connect calls using wires and a patch board).
|
| Taking this further then, and given that:
|
| - 3 is assigned to any of the three letters DEF, and
|
| - 7 is assigned to any of the three letters PRS,
|
| we could invent the following meaning:
|
| DES = "Declaration d'Envoi de Spam". (Lit. "Declaration
| of sending of spam", as in a report about spam sending).
|
| The double 0 is, as mentioned, in our invented meaning
| like shouting "Operator! Operator!"
|
| And with this invented meaning it's like we are shouting
| for help from the operator to deal with this spam :D
|
| Of course here I'm starting with 337 and backronyming
| "DES" to a plausible but probably weird sentence. If it
| was a real, the French would probably have worded the
| original sentence quite differently and the resulting
| number would be different as well.
|
| (Also, looking at the article I'm not sure if any
| European countries also had 0 used for "OPER" or not.
| Guess I'll have to travel to some museums in France and
| have a look at some old phones with my own eyes at some
| point.)
| mastermedo wrote:
| Why does this work? How simple is it to follow the sms protocol,
| I thought there were spam filters in place on the phones to
| prevent receiving any traffic from towers which are not
| registered to a well known network provider (or what have you).
| jeroenhd wrote:
| SMS is sent in some leftover space in the mobile data channel,
| there's very little verification to that up until relatively
| recent standards.
|
| If you can pretend to be a 2G/3G tower and jam the real tower,
| you can force phones to connect to you and you can send
| whatever calls and texts you want.
|
| This is mostly a 2G issue. Modern Android devices, and perhaps
| iOS devices, have a toggle to disable 2G for this reason.
|
| With fully compliant 5G, even police IMSI catchers become
| pretty difficult to use.
| andyjohnson0 wrote:
| > This is mostly a 2G issue. Modern Android devices, and
| perhaps iOS devices, have a toggle to disable 2G for this
| reason.
|
| My Android phone, Motorola Edge 20, has a setting for
| preferred network type. Options are 5G/4G/3G/2G, 4G/3G/2G,
| 3G/2G, or 2G only. Doesn't seem to be a way to disable 2G or
| 3G, even though most networks here (UK) no longer support
| them.
| jeroenhd wrote:
| For phones that support it, there's a separate toggle for
| disabling 2G. I don't think the preference setting you're
| referring to has the same effect. If I recall correctly,
| The separate 2G toggle goes down to the modem especially
| rather than just being configuration.
|
| I do have my phone set to 4G+5G only through that same
| screen, though, as my modem lacks the 2G toggle as well. If
| there are missing options in the dropdown, try dialing
| *#*#4636#*#* and see if you can configure it through there.
|
| I don't know exactly what determines what configuration is
| exposed to the UI, it's possible your modem simply lacks
| support for disabling entire generations of cellular
| technology.
| Scoundreller wrote:
| I believe the SIM supports all kinds of rules for what
| networks and xG should be visible to the user.
|
| I know for a fact a local network has 3G here, but it's
| not exposed on my phone to choose, presumably because it
| knows there's 4G and 5G and carriers don't want some dolt
| camping on 3G and eating more mhz/bit. I used to camp on
| 3G because Canada sent out too many dumb "emergency
| alerts" for custody disputes 1000km away, but those only
| operated over LTE, not 3G.
|
| People don't believe me when I say you can see, and
| sometimes connect to, US networks from a tall building in
| Toronto from over the lake because Canadian SIMs have
| rules/conditions to hide them, but if you put in an
| overseas SIM, you'll see them on a scan.
|
| Have also had a world of a time with a French SIM refuse
| to connect to a Canadian tower because it _really_
| preferred the US towers (lower roaming costs maybe?).
| blacksmith_tb wrote:
| My Pixel 6a has a toggle in settings labeled "Allow 2G".
| It does have a note saying it may help you connect in
| situations where reception is poor, and that it may
| potentially be used for emergency calls even if you turn
| it off.
| lxgr wrote:
| Huh, are you sure that's true?
|
| I was under the impression that most European countries
| were keeping 2G around for legacy applications and voice
| calls on roaming (until VoLTE roaming and emergency calls
| finally become equally reliable), shutting down 3G if
| anything?
| lxgr wrote:
| I've always found that a weird characterization. It's sent in
| the signaling channel, but why is that "leftover"? The
| channel is still established for the SMS, and it's not like
| that channel bandwidth would go unused otherwise.
|
| It's like saying "postcards are delivered in the leftover
| part of the mail truck unused by letters and parcels" :)
| zinekeller wrote:
| > I've always found that a weird characterization. It's
| sent in the signaling channel, but why is that "leftover"?
| The channel is still established for the SMS, and it's not
| like that channel bandwidth would go unused otherwise.
|
| In modern standards, it is indeed not a "leftover"
| (although RCS exists which is another can of worms), but
| originally it was transmitted in a best-effort manner using
| what is essentially a "hack" on SS7 (unlike phone calls
| which is guaranteed reception - or at least not going
| through).
| lxgr wrote:
| I don't think this was ever true, unless I'm
| misunderstanding what you mean by "best-effort" or
| "hack".
|
| In GSM, SMS are delivered either over the SDCCH (when no
| voice call is happening simultaneously) or the SACCH
| (when a voice call is already in progress). In the latter
| case, you might argue that they're piggy-backing onto
| existing resources, but in the former, there are
| definitely dedicated resources being allocated
| specifically for SMS delivery.
|
| SMS delivery has also always been reliable, both on the
| lower level (both SDCCH and SACCH are reliable) and the
| upper one (the phone reports successful delivery back to
| the sending SMSC), so while there are no timing
| guarantees (is that what you mean by best-effort?),
| delivery always eventually succeeds once resources are
| available.
|
| The protocol even goes to significant lengths to ensure
| timely (re)delivery in case various error scenarios, such
| as a full inbox on a phone or a phone being out of
| reception.
|
| While 140 bytes aren't much, reliability is actually
| great, until you add spam filtering, roaming, and inter-
| network delivery to the mix, when things can quickly go
| off the rails. (One unexpected consequence of how it's
| implemented is that for mutual reachability, it doesn't
| only matter what operators the sender and recipient have
| a contract with, but also in which network the recipient
| is currently roaming.)
| TeMPOraL wrote:
| > _SMS delivery has also always been reliable, both on
| the lower level (both SDCCH and SACCH are reliable) and
| the upper one (the phone reports successful delivery back
| to the sending SMSC), so while there are no timing
| guarantees (is that what you mean by best-effort?),
| delivery always eventually succeeds once resources are
| available._
|
| That's the opposite of my experience in the early 2000s.
| I mean, the whole reason you'd always enable delivery
| reports is because delayed delivery or failed delivery
| were almost a daily occurrence. Anyone who sent SMS blind
| would quickly learn to either enable delivery reports, or
| just start calling people more.
| LZ2DMV wrote:
| The problem is mostly the insecure defaults. Every modern phone
| is configured to be backward compatible and connect to an older
| generation of network if a newer generation is not present
| (like in the case of being deliberately jammed by an
| adversary). In 2G, mutual authentication is not existent, it
| happens only one way - only the network authenticates the
| handset. If you are close enough to the victim (only screaming
| louder, i.e. more power than the legitimate network, but from a
| significant distance doesn't work, because of the RTT of the
| signal - TDMA-based systems are very time-sensitive in nature),
| nothing prevents you from operating your own mobile
| infrastructure and disable any encryption (i.e. in 2G, during
| the handshake, you just say A5/0 - no encryption, to the
| handset) - you can not enable encryption anyway, because you do
| not have the corresponding key that is on the SIM card, only
| the legitimate carrier has that.
|
| Whether or not the victim will be notified about the absence of
| encryption, depends on the state of a single bit on the SIM
| card [1]. In 99% of the cases, there is no warning that the
| handset is currently using A5/0.
|
| From now on, you are at the grace of the rogue network operator
| - they can send you anything from any number, sit in the middle
| of every call and capture every frame of data.
|
| I don't think the current level of technological education of
| the general public is enough for most of them to know why it is
| important to force your phone to work only with modern network
| standards and that is what police and other government agencies
| interested in operating IMSI catchers exploit.
|
| [1] http://blog.taddong.com/2011/02/does-your-phone-warn-you-
| whe...
| seabass-labrax wrote:
| > ...that is what police and other government agencies
| interested in operating IMSI catchers exploit.
|
| Is encryption really significant to whether or not the police
| are able to monitor cellular phones? As bandwidth is already
| centrally allocated, there is a limited number of legal
| cellular network operators, and a competent authority could
| already compel (indeed, _could have_ already compelled)
| mobile operators to provide master keys and diversification
| information under the Snooper Charter 2016[1].
|
| https://www.legislation.gov.uk/ukpga/2016/25/
| LZ2DMV wrote:
| This implies compliance with the law and a formal
| procedure, and an authority might not always follow the law
| for various reasons. At least the use of encryption means
| one is less likely to be a subject of surveillance in an
| unlawful manner.
|
| Consider intelligence operation abroad, for example.
| cjrp wrote:
| Slightly more detail on The Register:
| https://www.theregister.com/2024/06/10/two_arrested_in_uk_ov...
|
| Sounds like they were using a Stingray-esque device, as the
| police do.
| skilled wrote:
| I have emailed mods to ask for a link update so your comment
| can be demoted, and more room given for discussion. Thanks for
| pointing it out, did not see/check when submitting.
| dang wrote:
| Thanks! We've changed to that from
| https://www.cityoflondon.police.uk/news/city-of-london/news/...
| now.
| jack_riminton wrote:
| For those unaware the "City of London" is in fact a small part of
| London, what you might call downtown, and they have their own
| police force. fwiw they're regarded as a very competent police
| force
| cjk2 wrote:
| apart from the financial crimes unit...
| fragmede wrote:
| GCP Grey on the city of London: https://youtu.be/LrObZ_HZZUc
| mintplant wrote:
| Map Men on London's 32 boroughs:
| https://www.youtube.com/watch?v=daeB46Z4fjs
| jack_riminton wrote:
| As a londoner, even I learned several things from that video.
| And it's done by an American!
| oakesm9 wrote:
| He's american, but moved to the UK to study and then become
| a Physics teacher in London. I think he's been London based
| for all of his YouTube career.
| LAC-Tech wrote:
| _fwiw they 're regarded as a very competent police force_
|
| What makes them different?
| jack_riminton wrote:
| Well it's a reputation, so it's hard to quantify. But
| anecdotally I've heard from numerous people who had dealings
| with that they were very competent (compared to most British
| forces presumably).
|
| I've also heard that their average level of policeman is more
| educated , ie many holding degrees, masters etc. I presume
| this must be due to the nature of the work they're most known
| for ie combatting complex fraud, organised crime etc
| walthamstow wrote:
| They have about 1 officer per 10 people living there which
| helps quite a bit
|
| For reference, the Met has 33k officers for 10m people
| OJFord wrote:
| Because policing is all about who's _resident_ in the
| territory covered?
| walthamstow wrote:
| Is that what I said? Nope
| r-w wrote:
| Good point, bad tone :)
| Steve44 wrote:
| There is one very important caveat about the population
| of the City though.
|
| Whilst there are only 8,600 residents, there are
| apparently over 600,000 commuters working there every
| day.
|
| https://www.cityoflondon.gov.uk/about-us/about-the-city-
| of-l...
| bloqs wrote:
| They have different branding from the rest of the police
| forces!
| mytailorisrich wrote:
| The City of London is very small, safe (quick look online
| returns that the crime rate is " _73% lower than London and
| 67% lower than national average_ "), and very rich, and
| obviously right in the middle of a top world city. So I am
| guessing that their police force is well resourced, able to
| attract "top talent", and not bogged down by anti-social and
| petty crime.
| LAC-Tech wrote:
| I'm always suspicious of low crime rates - often it means
| people don't bother reporting crimes as they know nothing
| will happen.
|
| IE, if I get robbed in the City of London is it even worth
| calling the police?
| mytailorisrich wrote:
| Why would there be a difference in reporting in the City
| vs the rest of London?
| andylynch wrote:
| The City Police have a very, small patch and little
| violent crime, but are geared up to deal with IRA/ISIS-
| type threats. Part of this means they have surveillance
| coverage of virtually the entire areas. It also mean that
| they can get anywhere very, very quickly.
| cannonpr wrote:
| Yes it is, a friend had their laptop stolen, the police
| tracked down the offenders within 2 hours and returned
| the items. What they also don't tell you is that it's a
| dystopian panopticon and runs on a slightly different
| legal system than the rest of the U.K.
| LAC-Tech wrote:
| Impressive! TBH I'd rather that dystopia than the one
| where people are constantly having their things stolen
| with zero recourse.
| gadders wrote:
| It's also mostly an office district. Not many people live
| there. It's mostly a ghost town at night and weekends.
| razakel wrote:
| Their focus is more on complex financial crimes, so they're a
| bit better educated than your typical cop.
| justinclift wrote:
| > fwiw they're regarded as a very competent police force
|
| That's not at all the reputation they have. They've been acting
| as an extension of the copyright lobby for years:
|
| * https://torrentfreak.com/new-uk-police-unit-announces-two-
| ar...
|
| * https://www.vice.com/en/article/bvn4nw/cops-
| arrest-3-people-...
|
| * https://www.cityoflondon.police.uk/news/city-of-
| london/news/...
|
| There are probably hundreds of instances of them doing stuff
| like the above, that was just the results from a quick search.
| jack_riminton wrote:
| _Personal opinion may vary_
| socksy wrote:
| To be fair, a police force doing stuff you don't like doesn't
| necessarily mean that they're incompetent at doing those
| things
| justinclift wrote:
| Sure. But their reputation is pretty much "police force for
| hire" rather than anything to do with competence.
| dubcanada wrote:
| But isn't that what police are? I don't see a ton of
| volunteer police...
| Doe-_ wrote:
| The City is also unique in that businesses represent the
| majority of the voters in its council elections.
|
| Moreover, the council is also the police authority, which
| could explain a more active copyright infringement force.
| andylynch wrote:
| It's not a conspiracy; the City of London police, alongside
| normal local duties, have a national responsibility for many
| kinds of economic and cyber crime.
|
| This almost certainly comes from long experience
| investigating fraud and other financial crimes amongst the
| businesses and people based there, to a degree and level of
| complexity not found in other regions of the UK.
|
| For instance they host Action Fraud for the entire country.
|
| If you want to talk about enforcement priorities, contact
| your PCC, or better yet, right now, your local candidates.
| euroderf wrote:
| It's more like an autonomous enclave free of any control by
| Parliament. The Guardian plumbs the depths once in a while,
| such as in this article:
| https://www.theguardian.com/commentisfree/2011/oct/31/corpor...
| walthamstow wrote:
| It's not the Wild West, the laws of the UK Parliament apply
| to people and companies in the City.
|
| In that piece Monbiot tries to blame the Corporation for the
| 2008 crash, which is laughable.
| euroderf wrote:
| This article and others say the Corporation pretty much
| does as it pleases. There's a "conspiracy theory" that says
| that the City instigated Brexit to avoid EU jurisdiction.
| tiku wrote:
| Why is sms such a crappy protocol that this is even possible?
| sunbum wrote:
| SMS isn't a protocol. Attacks like these are done via 2G. Which
| is really why most people should disable it if they can.
| dotancohen wrote:
| Because it dates to a time when such attacks were infeasible.
| GPS is very similar in that regard. Even HTTPS was uncommon
| back when I was in university. NASA spacecraft still
| communicate over unencrypted channels.
|
| Mindsets were different then.
| fragmede wrote:
| not just mindsets, but the computing power available. These
| days, my smartphone is millions of times more powerful and
| the computation to do TLS encryption on every website I visit
| is trivial for a computer that fits in the palm of my hand.
| Way back when, the 1 or 2 kilobytes or so a modern RSA
| private key (PEM format) would take up on disk was meaningful
| when you only had 4 megabytes of RAM and CPUs ran in the
| megahertz range.
| oldgradstudent wrote:
| > GPS is very similar in that regard.
|
| GPS originated as a military protocol and has some level of
| encryption and authentication, but this is not available to
| the general public.
| GJim wrote:
| GPS *had* no encryption or authentication; indeed, such
| security is only a recent addition to the L2 frequency.
|
| USK: Galileo also has authentication available on its
| civilian frequencies.
| lxgr wrote:
| > such security is only a recent addition to the L2
| frequency
|
| Is that already available? I thought GPS L2C didn't
| include authentication yet.
| nanna wrote:
| Also to a dumb phone it doesn't matter whether an SMS
| contains a phishing link because it has no way of accessing
| it. Until the advent of smart phones SMS phishing was a non-
| issue.
| est wrote:
| encryption was _expensive_ in GSM days.
|
| People seem to forget that dedicated TLS acceleration hardware
| was a thing not long ago.
| robaato wrote:
| It was a hack to use "unused" control/signalling paths - see
| https://en.wikipedia.org/wiki/SMS
|
| Effectively came "for free" for mobile operators...
| lxgr wrote:
| That's a common misconception. The signaling channels used
| aren't "unused" - they're literally set up and torn down to
| deliver SMS!
| aidenn0 wrote:
| I think you meant to end that with "phone calls" rather
| than "to deliver SMS?" SS7 was used for that, but had a
| significant amount of idle time since most phone calls are
| much longer than the time needed to setup the connection.
| lxgr wrote:
| I do indeed mean SMS, but I was focusing more on the air
| interface. There, SMS definitely consume resources in the
| same way that calls do (although of course at a very
| different rate: SDCCH uses 0.8 kbit/s, as opposed to 13
| kbps for full rate voice/CSD traffic channels).
| aidenn0 wrote:
| But the signaling channels weren't used to send SMS
| before SMS existed (which the original statement of
| "unused" implied).
| Infinity315 wrote:
| Slightly off topic, but this is demonstrated in a show called Mr.
| Robot. I find it insanely cool that the hacking in Mr. Robot
| closely resembles real life.
| NilMostChill wrote:
| IIRC they hired a bunch of real life professional white hats to
| consult.
|
| https://en.wikipedia.org/wiki/Mr._Robot#Technical_accuracy
| mdp2021 wrote:
| > _Most phone providers are part of a scheme that allows
| customers to report suspicious text messages for free by
| forwarding it to 7726. If you forward a text to 7726, your
| provider can investigate the origin of the text and arrange to
| block or ban the sender, if it's found to be malicious_
|
| It would be useful to have a list of Countries/operators adopting
| the 7726 ("SPAM") number. It seems also some European Countries
| do.
| slowmotiony wrote:
| How do you forward a text?
| orra wrote:
| Often there's a long click menu in your SMS app to do it.
|
| But all that really does is copy the body into a new SMS.
| There's no metadata to indicate it's forwarded, as you
| suspect.
|
| This means texting 7726 is a two step process. First you send
| the body. You immediately get a response asking for the phone
| number of the spam sender, so then you sent that.
| lxgr wrote:
| Does the phone number even matter for tracing? As far as I
| understand SMS delivery, it's not authenticated at all.
|
| I suppose it can be used to help the operator identify the
| actual incoming message in their logs?
| toast0 wrote:
| Source number authorization depends on how the messages
| get to the carrier and how the carrier has things setup.
| At the end of the day, there's a lot of trust though; and
| a lot of connections would be difficult/expensive to
| confirm that the connection is authorized to send
| messages from the sources they're using.
|
| Think of BCP38 for IP spoofing, but for number spoofing.
| If you get an appropriate country mobile number from a
| carrier in that country, are you going to pay for a
| portability lookup to confirm that carrier is the
| authorized carrier for that number? Does that carrier
| check source numbers for all of the connections they
| have?
|
| Some of the aggregators are good at checking sources, and
| some aren't, but aggregators are often authorized to send
| messages from many different countries, so they're likely
| to have their connections unchecked, because keeping the
| list updated is hard. It's like IP transit, but a lot
| worse.
| doophus wrote:
| Would this even work in the article's situation, where
| someone's MITMing SMS?
| mdp2021 wrote:
| If you believe the cell you are under is compromised, further
| action should be performed under a different cell.
|
| Actually, I would like to have an option to identify the
| cells devices are connected to.
| mminer237 wrote:
| CellMapper is an app on Android to do this: https://play.go
| ogle.com/store/apps/details?id=cellmapper.net...
| mminer237 wrote:
| All major US carriers do.
| shiroiushi wrote:
| People in the UK still use SMS?
| mdp2021 wrote:
| > _still use SMS?_
|
| Instead of? If you have to send text to an occasional user,
| what do you think should be used?
|
| The article is about /receiving/ messages supposedly from
| firms. How should they have sent it?
| lrvick wrote:
| Maybe something with at least TLS like email.
| mdp2021 wrote:
| The issue with those kind of messages is sender
| authentication, not content confidentiality.
| porker wrote:
| The National Health Service communicates with people via SMS.
| The NHS has an app, but doesn't send notifications through it.
|
| My guess is because our population can all cope with SMS by
| now, but anything more...
| denton-scratch wrote:
| HMRC also seems to require an SMS-capable device for 2FA.
| Using the HMRC website is a soul-destroying adventure through
| severe speed-bumps, short session timeouts, and 72-hour
| delays. It's the epitome of awful, large-scale British public
| computer-system acquisition.
| Havoc wrote:
| People not so much but services yes
| johneth wrote:
| It's almost exclusively used by businesses and government to
| send notifications.
|
| They use SMS because it's a baseline that every phone, smart or
| dumb, has. No need to have an email address, no need to have an
| app.
|
| Most people use Whatsapp / Messenger / social media / to a
| lesser extent iMessage.
| denton-scratch wrote:
| > because it's a baseline that every phone, smart or dumb,
| has
|
| My phone is an IP phone. It doesn't do SMS. Did you mean
| "mobile phone"?
|
| > No need to have an email address
|
| I'm pretty sure that more people have an email address but no
| SMS capability, than have SMS but no email capability.
| johneth wrote:
| > My phone is an IP phone. It doesn't do SMS. Did you mean
| "mobile phone"?
|
| UK landlines are transitioning to VoIP. SMS messages sent
| to UK landlines are read out by a text-to-speech system
| (well, my parents' does).
| denton-scratch wrote:
| Yes; mine does that too. Have you ever tried to use one
| of those TTS systems? They can just about read standard
| international English; anything more interesting, like
| someone's name, and they fall back to spelling-out the
| letters.
| bloqs wrote:
| This is the police force for the ancient financial district in
| London called the City of London. Best explanation:
| https://youtu.be/LrObZ_HZZUc
| scoot wrote:
| The former financial district. The financial district has long
| since migrated to Canary Wharf and, since Brexit, increasingly
| overseas.
| gadders wrote:
| Companies are moving back out of the Wharf to the City.
|
| >>and, since Brexit, increasingly overseas
|
| And this isn't even remotely true.
| ReptileMan wrote:
| Trivial to make one - you just need a SDR and encryption key
| (harder to obtain, but probably could be found on the black
| market).
| bestbuyer__ wrote:
| This is giving off HackerNews DropBox vibes :)
| lxgr wrote:
| You don't need any key for GSM, since the network/base station
| only started authenticating itself to the phone/SIM with 3G.
|
| That's why it would be good to shut down GSM at some point: It
| would raise the difficulty of such attacks significantly.
|
| What I don't understand is how they managed to actually
| intercept any SMS with an IMSI catcher. They'd need to get the
| network to send these through their infrastructure, so I wonder
| how that worked?
|
| Update: Ah, they were just sending out texts themselves, not
| intercepting anything.
| swiftcoder wrote:
| I enjoyed the "Sorry, there was a technical problem. Please try
| again." when I tried to reject cookies
| exabrial wrote:
| Oh good, we better make sure we tie our bank accounts to SMS
| dang wrote:
| Could you please stop posting unsubstantive comments and
| flamebait? You've unfortunately been doing it repeatedly. It's
| not what this site is for, and destroys what it is for.
|
| If you wouldn't mind reviewing
| https://news.ycombinator.com/newsguidelines.html and taking the
| intended spirit of the site more to heart, we'd be grateful.
| robbyiq999 wrote:
| What interests me is the intelligence and innovation of this. You
| would think these bad actors would fair well doing societal good
| using their skills and not resort to crime.
| dubcanada wrote:
| Why does that interest you? This is fairly common.
| ChrisMarshallNY wrote:
| That's always been the case. Dumb crooks don't last long.
|
| As to why they choose this way, over a "legitimate" (like dark
| pattern writing, or PID mining) vocation, there are many
| reasons.
|
| I suspect that a big one, is the "blackball" effect, that
| having a conviction on your record will create. Once we are
| convicted, then we become unhireable, in many industries, so
| it's not like we have a choice. Also, the pay for nefarious
| work can be quite good.
| rthnbgrredf wrote:
| Can confirm. Have read many articles about known gang members
| and drug lords. It usually starts with doing some dumb things
| at younger age and then struggle to find and keep a legal
| job.
| RIMR wrote:
| Think about the "innovation" here. Learning to set up your own
| cell tower is quite a feat, but how are you going to monetize
| it? Are you going to start your own cell provider and try to
| compete with the existing major players? Or are you going to
| use the tech for some fast capital right now?
|
| If the goal was to learn just enough about cell tech to exploit
| it for profit, then a legal approach is off-the-table because
| of the extraordinary effort needed to ever get anything off the
| ground.
| Scoundreller wrote:
| > For example, EE has stopped tens of millions of scam SMS
| messages since stepping up its anti-spam filter in 2021.
|
| So, they blocked like 2% ?
| vdfs wrote:
| https://xkcd.com/1161/
| tamimio wrote:
| Building a homemade BTS (Base Transceiver Station) is easy. I
| remember making one back in 2011 with a USRP SDR. Nowadays, you
| can even create a 5G network, not just LTE. There's plenty of
| good open-source software available. Paired with an SDR, you are
| good to go. The rest is just some scripting to automate some
| tasks, probably how they flooded the SMS.
| stainablesteel wrote:
| so why do i pay for cell phone service? you're saying most
| people can just point some metal out of their window and the
| neighborhood would be happy?
| nexuist wrote:
| Wait till you find out about diesel generators!
| Elv13 wrote:
| The phone part is no different. It's easy to run your own
| FreeSWITCH or Asterisk server at home and connect a cellphone
| using Wireguard. It costs ~0.5$ US per month to get nearly
| unlimited everything. Calls and SMS work just fine. The
| problem is always mobility. You need either Wifi or some of
| those odd reseller brand ultra cheap pre-paid plans (like "1$
| for the first 200mb" plans). Then you need to make sure only
| the voice/sms is allowed to use the data and you get a 2$
| nationwide working cellphone. You can also share someone else
| plan by having them leaving their Phone wifi hotspot on.
|
| As for reliability, well, that's your problem now, good luck!
|
| > point some metal out of their window and the neighborhood
| would be happy?
|
| You might, but the FCC won't
| tamimio wrote:
| You pay for the coverage and the infrastructure they built.
|
| > you're saying most people can just point some metal out of
| their window and the neighborhood would be happy
|
| Technically? Yes, you can do it in a few hours, or as a
| weekend project if you've never done it before. Just grab a
| full-duplex SDR; you don't need to go for expensive ones like
| the USRP. Get a BladeRF or LimeSDR, download the software,
| and set up the station. The problem lies with the
| regulations. Depending on where you live, you might face
| hefty charges for violating spectrum rules, and they are
| actively looking for such violations by the way. One of the
| proofs of concept we did with the regulators here in Canada
| involves using a drone to detect these violations. It's just
| a matter of time before they find you.
| toomuchtodo wrote:
| Is there a reason cellular tower base stations don't have
| this spectrum surveillance capability? With such broad
| coverage, it would be straightforward to triangulate and
| report coarse location of unlicensed broadcasting.
| ogurechny wrote:
| I suppose they totally have that capacity, because
| cellular networks depend on fair play of thousands of
| devices sharing access to a part of the spectrum in a
| given area. Constant stats gathering has to be vital for
| detection of hardware faults and coverage problems in
| very complex city networks. Stations can even ask mobile
| devices to work as remote probes, and report immediate
| signal levels for each station they can receive.
| Operators have all the incentives to snitch on anything
| suspicious or broken to both the regulatory body, and the
| security services (who probably reply "oh, it's ours"
| most of the time).
| nickpsecurity wrote:
| Prior leaks or reports... can't recall which... said the
| service providers could trace people with pinpoint
| accuracy. Way better than GPS. The cops were using it. I
| think it was in a law enforcement portal with some
| telecoms, too.
|
| The other trick was how more things are designed to stay
| on even when they look off. An older one with older
| phones would make it answer silently so you didn't know
| if they were listening.
|
| There's so many risks with telecoms that high-assurance
| security (a) said keep cell phones away from anything
| security-critical and (b) used Red-Black separation where
| whatever connects to untrusted line never had any
| plaintext, just encrypted. Seperation kernels, like
| INTEGRITY-178B and seL4, were invented to hopefully do
| that with software.
| Havoc wrote:
| I do wonder whether this is the right move. Sure law breaking
| must be punished, but seems like precisely the skillset & mindset
| you'd want on your side if you were potentially heading towards
| confrontation in a world of cyber, drones and asymetric
| warfare...
| wongarsu wrote:
| Depends on the sentence he gets. They did just write about his
| name and skillset in a national newspaper. If he only serves a
| year or two that can end up as a positive for his career.
| andylynch wrote:
| I'm sure the folks from Cheltenham can find them if they want a
| chat.
|
| But given these guys appear to have been running this as part
| of a bigger spam/fraud game rather than for curiosity/ general
| mischief they might be too far in the poacher category for the
| gamekeepers.
| ptero wrote:
| To me, this is the right move. The skillset needed to build
| such RF endpoints is not that rare. Any decent EE college
| graduate should be able to rig one up with an off the shelf
| software-defined radio and some literature review. If all they
| did were to build it for laughs and boasts I would hope they
| would just be yelled at and threatened with a sizeable fine
| next time they try such spectrum violations.
|
| But they apparently phished a lot of information with the
| intent to defraud folks, which in my book completely changes
| the proper response. My 2c.
| coretx wrote:
| The A/51 rainbow tables can be found here:
| https://opensource.srlabs.de/projects/a51-decrypt/files It can be
| made to work using a 10 bucks RTLSDR for RX. Had they used a
| legal provider for the TX, they would not have been caught.
|
| This smells like yet another case of children at work and police
| officers trying to sell themselves as super heroes. This is
| getting old.
___________________________________________________________________
(page generated 2024-06-11 23:02 UTC)