Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re:what it means (Score 2, Interesting) 141

Disclaimer: I could be totally wrong ;D

All your attacks depends on being able to steal credentials and be able to impersonate the phone at a later stage, but the way I've been told it works is that after the initial Location Update, the phone never talks to the network as itself. That is, after the initial connection, the phone is handed a set of temporary IDs (one time pad-style), so each subsequent page is to a different number that only the phone and the network is supposed to know. Once the phone is running low on these temporary IDs it retrieves a set of new ones.

#2 is the most blatant flaw in terms of interception: GSM never authenticates who it's talking to, if there's a network in range it is assumed to be friendly.

Slashdot Top Deals

"If I do not want others to quote me, I do not speak." -- Phil Wayne

Working...