Forgot your password?

typodupeerror

Comment: This is not a 'vulnerability' (10 yr GSM veteran) (Score 1) 102

by Kodack (#32591508) Attached to: AT&T Breach May Be Worse Than Initially Thought

I have worked on GSM networks for a living for over a decade and I am calling BS on this yellow editorial.

What the author is suggesting is the wireless equivalent of hacking by Physical Level Access. No OS in the world can be 'secure' if you gain physical access to the machine it's running on. The idea that somebody can deduce your name and address, drive to your residence and get your mobile to attach to their pico cell for purposes of mining your data is ludicrous.

1. IMSI is nothing special. It is nothing more than the entry the Home Location Register (HLR) uses to store information about your profile. Information like which Visitor Location Register (VLR) you are attached to, if you're roaming, what your phone number (MSISDN) is etc.

It does NOT contain any information about you, your name, your home address, your billing etc.
In order to view the IMSI profile in the HLR you would have to hack into ATT, Tmobile etc cellular network, know where to find the HLR's IP, how to log into it, and what commands to run to query the subscriber profile. Even if you did all that all you'd get out of it is a phone number......

There are MULTIPLE levels of security to secure the cellular network from unauthorized users gaining access to the switching equipment.
Firewall, VPN, Sitekey, multiple levels of logins and passwords requiring passing through multiple un NAT/PAT subnets.

If you had that kind of access you could do far more than look up somebody's phone number.

2. Even if someone had your IMSI, and knew where you lived, and set up a pico cell to try to trick your phone..... Your phone would not authenticate to the pico cell without a proper KI value. The KI is not something you can just look up and copy. Even having your IMSI, they can't get around the fact that GSM is encrypted and they don't have the key.

They would also not be able to make your mobile hand over to their pico cell because there is no handover to that non existant BTS in the Base Station Controller or BSC. Phones don't just attach willy nilly to any old radio signal.

3. If a person wanted to go through that much trouble to find out info about you they might as well break into your home and replace your Iphone with one that has spyware preinstalled, it would be FAR EASIER than trying to hack/spoof the network.

And lastly your IMSI, MSISDN, SIM, KI, CCID, IMEI, any of that stuff does not link to your name, home address, or your account. That information is on the customers billing network, usually handled by a 3rd party vendor. Gaining any of that information would require hacking yet another set of computer systems.

In summary.

1. Your IMSI is not a secret someone can use to come after you.
2. The HLR doesn't have any personal identifiable information about you.
3. Someone can't sit out side your house and sniff all your secrets by tricking your phone.
4. There are much easier ways to do these things if they really wanted your information. You are much more likely to be keylogged and exposed by using trojan software.

Comment: Why would anybody want to buy a mobile carrier? (Score 1) 670

by Kodack (#32444916) Attached to: iPad Bait and Switch — No More Unlimited Data Plan

1. Phone carriers carry huge costs associated with their infrastructure.

ATT is not just a handset, it is a network, a series of hundreds of switching centers, hundreds of thousands of radio sites, support infrastructure etc etc. One does not simply "buy them out".

2. Say you had several billion dollars and convinced ATT to walk away from their cash cow, Do you then have any idea how much money it costs to operate that infrastructure?

Mobile carriers have small margins. The only real profit they make is from value added services like data and various subscriber options. It's a thin margin business unless you do it in high enough volume and with an existing infrastructure.

ATT doesn't want to spend money expanding their networks to support more data, it's not going to get them new customers or make the existing ones pay more. So they get to profit by squeezing as many mobiles on as they can and make the consumers use less bandwidth by charging them an arm and a leg for doing more than checking email.

Think of it like this. If ATT were an airliner, it wouldn't save them money to fly faster jets. The best way they could make money would be to sit people 2 to a seat and make you contractually obligated to fly every month for 2 years with them.

Apple is smarter than that. They are in a high margin business right now selling iphones that cost $100 to make for $300-$600. They don't even have to eat the MFG costs, they just outsource it to China. Apple is lean and mean, they design, others build, you buy, they laugh all the way to the bank. Why would they WANT ATT?

Comment: There definately IS a female G-Spot (Score 1) 392

by Kodack (#30672492) Attached to: New Research Suggests G-Spot Doesn't Exist

When I read about a study like this it really makes me wonder about the people who formed these conclusions. There was a similar debate in the recent past about the female orgasm being fake as well.

I'm going to be frank and if you are easily offended stop reading now.

I'm not a doctor or a sex therapist but I have a girlfriend and together we both have first hand experience with the g-spot. I am not going to debate whether it is a separate nerve bundle or the physiology or lack there of. My argument in favor of it existing is one of experience. Without getting graphic, there are several ways for a woman to reach orgasm, and dependent upon how she is stimulated, it will result in different types of orgasm. Both in intensity, and physical and biological responses such as increased secretions and the color and texture of them.

When the gspot is stimulated and induces an orgasm, the excretions that result are unlike those obtained from any other stimulation. The color is different, and it comes from a different place in the vagina. The smoking gun is that it can not be replicated by stimulating her in any other way than that spot.

My opinion is that there is a nerve bundle that stimulates a woman similar to the prostate on a man, the result of which is a thick white fluid, almost like paste being excreted. Clitoral and vaginal orgasms do not result in this type of excretion.

I'm not arguing the mechanics of the g-spot, only the results. If it were non-existant then the orgasm would be as well, since the orgasm is real the spot must be as well.

PC Games (Games)

EA Shutting Down Video Game Servers Prematurely 341

Posted by Soulskill
from the sixty-dollar-yearly-fee dept.
Spacezilla writes "EA is dropping the bomb on a number of their video game servers, shutting down the online fun for many of their Xbox 360, PC and PlayStation 3 games. Not only is the inclusion of PS3 and Xbox 360 titles odd, the date the games were released is even more surprising. Yes, Madden 07 and 08 are included in the shutdown... but Madden 09 on all consoles as well?"
Space

Big Dipper "Star" Actually a Sextuplet System 88

Posted by kdawson
from the toil-and-trouble dept.
Theosis sends word that an astronomer at the University of Rochester and his colleagues have made the surprise discovery that Alcor, one of the brightest stars in the Big Dipper, is actually two stars; and it is apparently gravitationally bound to the four-star Mizar system, making the whole group a sextuplet. This would make the Mizar-Alcor sextuplet the second-nearest such system known. The discovery is especially surprising because Alcor is one of the most studied stars in the sky. The Mizar-Alcor system has been involved in many "firsts" in the history of astronomy: "Benedetto Castelli, Galileo's protege and collaborator, first observed with a telescope that Mizar was not a single star in 1617, and Galileo observed it a week after hearing about this from Castelli, and noted it in his notebooks... Those two stars, called Mizar A and Mizar B, together with Alcor, in 1857 became the first binary stars ever photographed through a telescope. In 1890, Mizar A was discovered to itself be a binary, being the first binary to be discovered using spectroscopy. In 1908, spectroscopy revealed that Mizar B was also a pair of stars, making the group the first-known quintuple star system."

Comment: If people have issues with the Gestapo why haven't (Score 1) 511

by Kodack (#30178702) Attached to: AU Senator Calls Scientology a "Criminal Organization"

You got to love their stance "If people had problems with the church why didn't they take it up with church officials? We have a dedicated department...."

It's like an SS officer saying "If people have problems with the Gestapo why haven't they taken them up with us? We have a dedicated group of individuals that deal with people like them. And by deal I mean assassinate"

Like anybody who's suffered torture is going to complain to their torturers.....

disingenuous

Comment: 3G 64kbps channel? (Score 1) 112

by Kodack (#30079136) Attached to: How To DDoS a Federal Wiretap

That's an analog landline convention. They are talking about 3G which isn't getting to the world the same way a voice call would so there are no channels like there would be for say an analog call at 64kbps trunking and SS7 sent via a signaling link.

I think if you sent so much information you saturated your available bandwidth that any messages not picked up by CALEA also would fail to be delivered. I don't know what 'device' they picked up to do this testing since CALEA is a standard not a box. But I'm guessing that they found a flaw with it, not with the CALEA standard.

Booze is the answer. I don't remember the question.

Working...