Jump to content

"Fake" Cell Towers (Was Is this even possible?)


Ascertion

Recommended Posts

http://www.popsci.com/article/technology/mysterious-phony-cell-towers-could-be-intercepting-your-calls

 

 

Other than at the South Point Casino, does anyone know where these towers are located more specifically than the map they provide?

 

I saw references to GSM. Is it only for GSM networks where this is an issue?

Link to comment
Share on other sites

http://www.popsci.com/article/technology/mysterious-phony-cell-towers-could-be-intercepting-your-calls

 

 

Other than at the South Point Casino, does anyone know where these towers are located more specifically than the map they provide?

 

I saw references to GSM. Is it only for GSM networks where this is an issue?

I was wondering the same thing. I do seem to recall reading articles some time back detailing how GSM was far more vulnerable than CDMA.

 

Sent from my SM-N900P using Tapatalk

Link to comment
Share on other sites

A fellow chemist here at work who is also responsible for our IT just came over to me and showed me an MSN article on this same thing.  It was quoted from Popular Science.  Scarey stuff! 

 

http://money.msn.com/investing/post--mysterious-fake-cellphone-towers-found-across-us

Link to comment
Share on other sites

The fake towers are gsm. Kind of hard replicating the handshaking going on in cdma between phone and the system. Which is why no one can bring a Sprint phone on Verizon and vice/versa. Not without doing some major work in the phones.

  • Like 2
Link to comment
Share on other sites

There were talks about doing exactly this at Defcon a few years ago. They described all the details on how it can be done, why someone would do it, and offered recommendations to the GSM carriers on how to mitigate it. Essentially it's "stop using GSM and move to LTE ASAP"

  • Like 1
Link to comment
Share on other sites

  • 2 weeks later...

Here are a bunch more articles:

Some of this is just PR for the company selling a so-called "cryptophone," but I'm sure some of the issues being raised are also real. My understanding is that IMSI Catchers are GSM specific, so they might not target Sprint, but with Verizon being the biggest network in the country, I'm sure there's a CDMA equivalent.

 

Given that many of you guys are real experts in this area, my questions are:

  • Do the techniques described pass the smell test of technical feasibility?
  • Have you ever noticed anything which leads you to believe similar techniques are being used on the Sprint network?
  • Is this something you're worried about?
  • Anything you can do to avoid or deter being caught up in this kind of tracking/surveillance?
  • Like 1
Link to comment
Share on other sites

  • 3 months later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • large.unreadcontent.png.6ef00db54e758d06

  • gallery_1_23_9202.png

  • Posts

    • Definite usage quirks in hunting down these sites with a rainbow sim in a s24 ultra. Fell into a hole yesterday so sent off to T-Mobile purgatory. Try my various techniques. No Dish. Get within binocular range of former Sprint colocation and can see Dish equipment. Try to manually set network and everybody but no Dish is listed.  Airplane mode, restart, turn on and off sim, still no Dish. Pull upto 200ft from site straight on with antenna.  Still no Dish. Get to manual network hunting again on phone, power off phone for two minutes. Finally see Dish in manual network selection and choose it. Great signal as expected. I still think the 15 minute rule might work but lack patience. (With Sprint years ago, while roaming on AT&T, the phone would check for Sprint about every fifteen minutes. So at highway speed you could get to about the third Sprint site before roaming would end). Using both cellmapper and signalcheck.net maps to hunt down these sites. Cellmapper response is almost immediate these days (was taking weeks many months ago).  Their idea of where a site can be is often many miles apart. Of course not the same dataset. Also different ideas as how to label a site, but sector details can match with enough data (mimo makes this hard with its many sectors). Dish was using county spacing in a flat suburban area, but is now denser in a hilly richer suburban area.  Likely density of customers makes no difference as a poorer urban area with likely more Dish customers still has country spacing of sites.
    • Mike if you need more Dish data, I have been hunting down sites in western Columbus.  So far just n70 and n71 reporting although I CA all three.
    • Good catch! I meant 115932/119932. Edited my original post I've noticed the same thing lately and have just assumed that they're skipping it now because they're finally able to deploy mmWave small cells.
    • At some point over the weekend, T-Mobile bumped the Omaha metro from 100+40 to 100+90 of n41! That's a pretty large increase from what we had just a few weeks ago when we were sitting at 80+40Mhz. Out of curiosity, tested a site on my way to work and pulled 1.4Gpbs. That's the fastest I've ever gotten on T-Mobile! For those that know Omaha, this was on Dodge street in Midtown so not exactly a quiet area!
  • Recently Browsing

    • No registered users viewing this page.
×
×
  • Create New...