New LTE Attacks Can Snoop On Messages, Track Locations, and Spoof Emergency Alerts (zdnet.com) 28
An anonymous reader quotes a report from ZDNet: A slew of newly discovered vulnerabilities can wreak havoc on 4G LTE network users by eavesdropping on phone calls and text messages, knocking devices offline, and even spoofing emergency alerts. Ten attacks detailed in a new paper by researchers at Purdue University and the University of Iowa expose weaknesses in three critical protocol operations of the cellular network, such as securely attaching a device to the network and maintaining a connection to receive calls and messages. Those flaws can allow authentication relay attacks that can allow an adversary to connect to a 4G LTE network by impersonating an existing user -- such as a phone number. Although authentication relay attacks aren't new, this latest research shows that they can be used to intercept message, track a user's location, and stop a phone from connecting to the network. By using common software-defined radio devices and open source 4G LTE protocol software, anyone can build the tool to carry out attacks for as little as $1,300 to $3,900, making the cost low enough for most adversaries. The researchers aren't releasing the proof-of-concept code until the flaws are fixed, however.
Hard and Made Harder (Score:3)
Security is the red haired step child. Everyone pretends to care about him but he gets shafted every time.
(Yes, I have red hair, and for some reason a lot of security protocol people seem to as well)
Re: (Score:2)
Lets not forget the NSA moles who undermine the system such that they can always put up their own listening post without having to go through the trouble of a central tap or stealing keys.
Re: (Score:2)
Well, there's some evidence that red haired people are more sensitive to pain, and I can see how that might make them more interested in security.
Reminds me of the old GSM Encryption debacle (Score:2)
Reminds me of the old GSM Encryption debacle.
This is going to be good!
Didn’t we tacitly know this already? (Score:2)
Given that police are able to use Stingrays for monitoring and intercepting traffic, why would anyone believe the protocol was otherwise secure? ... anyone other than members of Congress, I mean.
Re: (Score:2)
My prepaid plan is 2G, you insensitive clod.
Get a better prepaid plan.
Re: Didn’t we tacitly know this already? (Score:3)
The Stingray only costs $100k because it is sold to governments. It really is a $50 SDN.
Re: (Score:2)
More like 4.0 but you get the point. Something about this smells, like it was intentional.
And intentional towards only a very small % of phone users. At least GSM is not the "red haired stepchild" of the telcos.
If you want to see who/where did it, you only need to check about 5 countries - or do you want to blame Russia?
Re: 3G Forever (Score:2)
Actually. When I visit tourists spots I turn off LTE because it is in fact faster to use 3G which everyone else isn't using.
Nice try (Score:2)
But I'm still on a 3G smartphone.
Being thrifty with an obsolete handset has its merits!