gsm security

Matthias Weiler weiler.matthias at gmail.com
Tue Jan 3 23:59:16 UTC 2012


Dear List,

going through last years 28c3 talks a came across a talk [1] (and it's
summary [2]) about GSM (in-)security. Naturally I thought about
replicant handles and could handle those issues.

* silent SMS
The user has to be notified about them.

* IMSI-Catcher
Discovering those seems to be non-trivial (but I'm not into the topic at
all) but should be thought about.

* turning off GSM
It's just a work-around but it might help in many situations. There is a
"2G only" option but no "3G only".

Am I right that as the firmware is free software, any change should be
possible in theory at least, or are there parts that are in hardware and
unreachable for us?

And are there links between replicant and osmocom? It seems like the
projects could benefit a lot from each other. Because as they say on
their wiki:
> In short: By using OsmocomBB on a compatible phone, you are able to
> make and receive phone calls, send and receive SMS, etc. based on
> Free Software only.

Your thoughts and answers are appreciated a lot.

All the best,
Matthias


[1] https://www.youtube.com/watch?v=YWdHSJsEOck
[2]
http://www.h-online.com/security/news/item/28C3-New-attacks-on-GSM-mobiles-and-security-measures-shown-1401668.html


More information about the Replicant mailing list