Scientists spot 4G bug that can help hackers impersonate you

Feb 23, 2020
Berlin: Researchers have found a serious vulnerability in LTE/4G mobile communication standard that can help hackers impersonate other phone users, take a streaming service subscription at your expense or publish secret company documents under someone else’s identity.

The vulnerability — which affects virtually all mobile phones, tablets and some connected household appliances — may also hamper investigations of law enforcement agencies because attackers can not only make purchases in the victim’s name but can also access websites using the victim’s identity.

For example, an attacker can upload secret company documents and to network operators or law enforcement authorities, it would look as if the victim is the perpetrator, said researchers from Ruhr-Universitat Bochum public university.

“An attacker can book services, for example stream shows, but the owner of the attacked phone would have to pay for them,” said Professor Thorsten Holz from Horst Gortz Institute for IT Security.

Only changing the hardware design would mitigate the threat.

The team is attempting to close the security gap in the latest mobile communication standard 5G, which is currently rolled out.

“Mobile network operators would have to accept higher costs, as the additional protection generates more data during the transmission. In addition, all mobile phones would have to be replaced and the base station expanded. That is something that will not happen in the near future,” said David Rupprecht.

The problem is the lack of integrity protection: data packets are transmitted encrypted between the mobile phone and the base station, which protects the data against eavesdropping.

However, it is possible to modify the exchanged data packets.

“We don’t know what is where in the data packet, but we can trigger errors by changing bits from 0 to 1 or from 1 to 0,” said Rupprecht.

By provoking such errors in the encrypted data packets, the researchers can make a mobile phone and the base station decrypt or encrypt messages.

They not only can convert the encrypted data traffic between the mobile phone and the base station into plain text, they can also send commands to the mobile phone, which are then encrypted and forwarded to the provider – such as a purchase command for a subscription.

The researchers from Bochum used so-called software-defined radios for the attacks.

These devices enable them to relay the communication between mobile phone and base station.

Thus, they trick the mobile phone to assume that the software-defined radio is the benign base station; to the real network, in turn, it looks as if the software-defined radio was the mobile phone.

For a successful attack, the attacker must be in the vicinity of the victim’s mobile phone, said the researchers. IANS

Calm restored in Hyderabad’s Puranapul after communal tension; Owaisi tours area

Hyderabad: Tension prevailed in the Puranapul area of Hyderabad following vandalism by unidentified persons at a place of worship and the subsequent attack on a nearby shrine. Ten people, including...

PM Modi inaugurates largest-ever Commonwealth speakers conference, highlights importance of Global South

New Delhi: At a time when the world is undergoing unprecedented transformation, Prime Minister Narendra Modi underscored the importance of the Global South charting new pathways. Inaugurating the 28th Conference...

Nepali Congress edges closer to split as top office bearers expelled

Kathmandu: The Nepali Congress appears to be heading towards a split after the establishment faction of the party, led by President Sher Bahadur Deuba, on Wednesday decided to expel three...

MP ‘honour killing’: Man kills daughter for eloping with relative

Bhind: In a suspected case of honour killing, a 21-year-old woman named Nidhi Dhanuk was allegedly shot dead by her father, Munnesh Dhanuk, in Khiriya Thapak village in Madhya Pradesh's...

Raj Thackeray criticizes SEC over new campaign rules, ‘mysterious’ PADU machines

Mumbai: As Maharashtra prepares for high-stakes elections across 29 municipal corporations on Thursday, MNS chief Raj Thackeray has launched a scathing attack on the State Election Commission (SEC). Raj Thackeray,...

Jose Mani dismisses UDF return buzz, reasserts loyalty to LDF

Kottayam: Kerala Congress (M) chairman Jose K. Mani on Wednesday firmly dismissed reports suggesting that his party was preparing to return to the Congress-led United Democratic Front (UDF), asserting that...

US designates Muslim Brotherhood branches as terrorists, cites Hamas links

Washington: The United States has designated the Egyptian, Lebanese and Jordanian branches of the Muslim Brotherhood as "terrorist organisations", citing in part what it described as their support for the...

Suvendu Adhikari to move court after his defamation notice deadline ends for CM Mamata Banerjee

Kolkata: Following the expiration of the defamation notice deadline issued by Suvendu Adhikari, the Leader of Opposition in the West Bengal Assembly, to Chief Minister Mamata Banerjee regarding her claims...

India’s Chabahar port project again facing choppy waters amidst US warning

New Delhi: While US President Donald Trump’s recent warning that any country trading with Iran could face an additional 25 per cent tariff has direct implications for India, any choppy...

French farmers hold protest in Paris against EU-Mercosur trade deal

Paris: Farmers in France drove some 350 tractors through Paris on Tuesday for the second time in a week to protest against an EU-Mercosur trade deal and low incomes.  ...

Suicide case: Bengaluru dental student harassed over skin tone, six lecturers sacked

Bengaluru: Investigation into the Bengaluru dental student suicide case has found that the girl took the extreme step allegedly due to humiliation at the hands of her lecturers over her...

US court orders immigration authorities to facilitate return of wrongfully deported Indian

Washington: A US federal court, in a one of its kind verdicts, has ordered immigration authorities to facilitate the return of an Indian national who was deported to India despite...

Read Previous

Finishing touches being given at the Motera Stadium for the Feb 24 “Namaste Trump” event in Ahmedabad . (Photo IANS/PIB)

Read Next

Samsung Galaxy A51: All rounder mid-range smartphone

WP2Social Auto Publish Powered By : XYZScripts.com