• Announcements

    • Reminder - MoDaCo position on illegal content   07/30/15

      ILLEGAL CONTENT I'd like to just reaffirm MoDaCo's position regarding piracy and illegal content in the light of some recent questions / postings. Posts will be censored by myself or my moderation team if the contain or link to: Illegal / pirated / cracked software or sites that host such softwareNintendo emulators / ROMs or sites hosting them (in light of Nintendo's legal stance)CUSTOM ROMS You may discuss and post links to custom device ROMs on MoDaCo, provided the following rules are adhered to: ROMs must not contain any illegal 3rd party software (this includes trial versions included without permission)ROMs must give full credit to the original authorISSUES If you have any issues with this policy, please contact PaulOBrien directly via PM.
    • Reminder: Selling items on the forum directly is not allowed   07/30/15

      Please note that selling items on the forum directly is not allowed by the forum rules. There is a forum for eBay auctions whereby you can list the items on eBay and link to them there. This is the ONLY forum for this type of activity. You may also advertise links to the eBay forum in your signature. Please note that selling directly in contravention of these rules will result in a warning / suspension / ban.
Sign in to follow this  
Followers 0

GSM security problem

8 posts in this topic

Posted

A special device called an International Mobile Equipment Identification (IMSI) catcher pretends to the mobile phones in its vicinity to be a legitimate base station of the mobile phone network.

This is possible because while the mobile phone has to authenticate itself to the mobile telephone network, the network does not authenticate itself to the mobile phone.

This blatant flaw in GSM security was intentionally introduced to facilitate eavesdropping without the knowledge or cooperation of the mobile phone network.

Once the mobile phone has accepted the IMSI catcher as its base station, the IMSI catcher can deactivate GSM encryption using a special flag.

Do you know any smartphone that can detect this special flag?

0

Share this post


Link to post
Share on other sites

Posted

What exactly do you mean by the 'flag' ?

The C500 has a registry entry for 'LastUserIMSI'

0

Share this post


Link to post
Share on other sites

Posted

GSM Encryption? Since when? GSM security is provided via timeslots which makes it extremely difficult to listen into without a psuedo-base station (as above). GSM has no encryption built in.......

0

Share this post


Link to post
Share on other sites

Posted

remember "bourne supremacy"? he made a copy of the sim and therefor able to listen to thier conversations. i think that's for real.

0

Share this post


Link to post
Share on other sites

Posted

remember "bourne supremacy"? he made a copy of the sim and therefor able to listen to thier conversations. i think that's for real.

I don't think so. That would mean two devices on the network at the same time with the same sim id and same IMEI (GSM uses IMEI as part of its security/authentication) methods. I wish people would at least come up with some opinion which is based in fact rather than complete guesswork being passed off as fact.......................

0

Share this post


Link to post
Share on other sites

Posted

I don't think so. That would mean two devices on the network at the same time with the same sim id and same IMEI (GSM uses IMEI as part of its security/authentication) methods.  I wish people would at least come up with some opinion which is based in fact rather than complete guesswork being passed off as fact.......................

<{POST_SNAPBACK}>

That's absolutely true! Even if you can Mimic the function of the BTS/Cellsite... its useless because the ciphering key is stored on the SIM (chip-embeded)and to the network database. If you are to ask the mobile to authenticate thru the dummy BTS, it would only respond if you have the authentic data from the Network wich the phone provided on its First Time Location Update. This SIM data are hard-coded first hand before the SIM even made to the market. These same keys are used for authentication and encryption of voice plus the timeslot issues & hoping you have to resolve . Its a one-way encryption so... good luck! :)

At least you guys have an idea about the issues of "Garci". Its either the unit it self is hardware-tweaked or the other line is in a fixed network.. thru air-tapped... nah! close to IMPOSSIBLE. :D

0

Share this post


Link to post
Share on other sites

Posted (edited)

please see http://news.bbc.co.uk/1/hi/technology/4738219.stm

for anyone who is potentially a target of phone attack, may i suggest cryptophone. it is what we use, has no backdoors, open code to verify encryption, and is the only safe phone system i know off.

plus, if you dont want to spend

Edited by 4andy
0

Share this post


Link to post
Share on other sites

Posted

Using encryption on a phone will automatically get certain agencies interested in your phone calls :D

If you have this on a phone and take it across a border you are, technically, undertaking an illegal act unless you supply the relevent keys to the appropriate authorities. Beware!!!

0

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now
Sign in to follow this  
Followers 0

MoDaCo is part of the MoDaCo.network, © Paul O'Brien 2002-2015. MoDaCo uses IntelliTxt technology.