Does Wiretapping Require Cell Company Cooperation?
decora writes "Recently the dictator of Belarus, Alexander Lukashenko, accidentally admitted to wiretapping journalist Irina Khalip. Khalip is the wife of Andrei Sannikov, one of the many opposition presidential candidates who was imprisoned after the election in 2010. I am wondering how Lukashenko did this? Can a government tap a modern cellphone system without the company knowing? Or would it require cooperation, like when AT&T and others helped the NSA perform warrantless wiretapping on Americans?"
And isn't it the case now that stuff is embedded in all the major telecom hardware makers?
Dog is my co-pilot.
if you have the money and contacts. Covered on slashdot as far back as 2003 at least ...
Basically GSM can be made to switch to A5/0 i.e. disable encryption by use of a commercially available "IMSI catcher" device. Originally these sent a spoofed degraded signal to the base station to make it think A5/0 was needed (it uses less bandwidth), these days it seems they just act as base stations. Cellphones automatically lock onto the strongest base station, and GSM security authenticates the handset only, so such rogue base stations are not technically difficult to make.
The "degraded signal" method implies that A5/0 also kicks in naturally in areas of bad reception and anyone with appropriate scanner hardware could monitor calls in that area. You'd still have to deal with the frequency hopping though.
GSM has horrible security and carriers aren't exactly doing their best to make their networks secure either. A while ago you needed relatively expensive equipment (around $1000-2000) to be able to sniff on the network, but it's now been done with a few very cheap phones. There's a very informative presentation (with video) here. For this to work, you need to be close to the person you want to eavesdrop on however.
Actually it turns out the easiest way is simply to tell the corporation you want the information.
That's all it took here in the US and we were ostensibly a dictator-free country with laws against it. So in a country with a dictator, it's a no-brainer.
Look at Cisco/China etc.,
Expecting ethical behavior from a corporation is like a duck expecting a piggyback ride across a lake from an alligator.
This space available.
Why is this even a question for slashdot. A quick google will inform you that Belrus has a state owned telco.
Nuff said. They own the telco, they'd have access to all traffic across it.