Researchers Demo New GSM Attacks at Chaos Communications Congress
First time accepted submitter aeturnus writes "A new attack on the GSM mobile communications protocol has been demonstrated by Karsten Nohl and Luca Melette of Security Research Labs, based off their previously published attacks around vulnerabilities in the GSM A5/1 encryption protocol. This new attack, which Nohl indicates already in use by criminals, allows an attacker to simulate a GSM mobile and use it to make calls and send text messages. Nohl also discussed protective measures users should take against these attacks, and others in use by intelligence communities around the world." This was just one of many presentations at the 28th Chaos Communications Congress.
Too bad they didn't demonstrate it at the US Congress instead, I'd love to hear some intercepted conversations between a few Senators and their puppet-masters.
Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
FALSE!
--
Sent from my Fake Mobile Handheld
From the summary, it doesn't sound like there are actually particularly feasible protective measures to use on a routine basis. All I see is some discussion of the "Catcher Catcher" software, which can be used to estimate the likelihood of an "IMSI catcher" being used in the vicinity. But this isn't something most users can practically use on a routine basis.
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
Maybe stuff like Lookout Mobile can trap those premium SMS messages and at least warn you.
But this is a cat and mouse game now, and we'll have to explore how to punish the carriers and operators that enable fraudulent services by permitting them to bill victims. That's about the only way to deal with this sometimes.
deleting the extra space after periods so i can stay relevant, yeah.
So with all these attacks on GSM, isn't it a good idea for the US to stick with the old standards?
I was a victim. I kept getting charged for calls that were made at odd hours of the day. The solution was to simply change my phone number. After that, no more crazy charges.
RIP TRICERATOPS, YOU NEVER EXISTED