• plz1
    link
    fedilink
    English
    223 days ago

    I don’t understand why cell phones don’t authenticate the towers they connect to. Is this really just a “standards lag behind modern security” thing, or is it on purpose to allow these Stingray devices to be used?

    • @[email protected]
      link
      fedilink
      7
      edit-2
      3 days ago

      why cell phones don’t authenticate the towers they connect to.

      I believe it’s because they assume it’s not necessary because it was until now

      • prohibitively expensive, but now a “tower” is less than 2k EUR e.g. https://www.crowdsupply.com/ukama/ukama
      • prohibitively complex, see above, namely you don’t need to be a TelCo engineer to get it going
      • probably illegal, namely you needed (and I bet still need in most places) wireless band allocation before you could deploy anything

      … so I imagine there was no authentication because there was no practical threat beside so “fun” examples in CCC or DEF Con.

      • @[email protected]
        link
        fedilink
        42 days ago

        The use of Stingray by US law enforcement has been challenged on grounds that the law enforcement agencies have no spectrum license. Those challenges seem not to have found success.

        On the other hand, prisons in the US have been stopped from operating cell phone jammers on prison grounds, on the same complaint of no spectrum license.

    • @[email protected]
      link
      fedilink
      22 days ago

      IMEI/IMSI are collected (and immediately linked, hence deanonymized even if SIM was inserted only once) by cell tower operators. Just not bring your device, period.

      • plz1
        link
        fedilink
        English
        12 days ago

        Yeah, I agree with that personally, but realistically, “your phone was near a place” is not the same as “you were involved”. If they hijack a phone onto a Stingray, they can get way more info than just IMEI.