1. winfire's Avatar
    Every smart phone has a secondary OS, which can be hijacked by high-tech hackers
    By Andrew Rosenblum Posted 08.27.2014 at 1:00 pm

    Unencrypted Connection Les Goldsmith

    Like many of the ultra-secure phones that have come to market in the wake of Edward Snowden's leaks, the CryptoPhone 500, which is marketed in the U.S. by ESD America and built on top of an unassuming Samsung Galaxy SIII body, features high-powered encryption. Les Goldsmith, the CEO of ESD America, says the phone also runs a customized or "hardened" version of Android that removes 468 vulnerabilities that his engineering team team found in the stock installation of the OS.
    His mobile security team also found that the version of the Android OS that comes standard on the Samsung Galaxy SIII leaks data to parts unknown 80-90 times every hour. �That doesn't necessarily mean that the phone has been hacked, Goldmsith says, but the user can't know whether the data is beaming out from a particular app, the OS, or an illicit piece of spyware. �His clients want real security and control over their device, and have the money to pay for it.

    To show what the CryptoPhone can do that less expensive competitors cannot, he points me to a map that he and his customers have created, indicating 17 different phony cell towers known as ?interceptors,? detected by the CryptoPhone 500 around the United States during the month of July alone. �Interceptors look to a typical phone like an ordinary tower. �Once the phone connects with the interceptor, a variety of ?over-the-air? attacks become possible, from eavesdropping on calls and texts to pushing spyware to the device.

    ?Interceptor use in the U.S. is much higher than people had anticipated,? Goldsmith says. �?One of our customers took a road trip from Florida to North Carolina and he found 8 different interceptors on that trip. �We even found one at South Point Casino in Las Vegas.?

    Who is running these interceptors and what are they doing with the calls?
    Who is running these interceptors and what are they doing with the calls? �Goldsmith says we can?t be sure, but he has his suspicions.

    ?What we find suspicious is that a lot of these interceptors are right on top of U.S. military bases. �So we begin to wonder ? are some of them U.S. government interceptors? �Or are some of them Chinese interceptors?? says Goldsmith. �?Whose interceptor is it? �Who are they, that's listening to calls around military bases? �Is it just the U.S. military, or are they foreign governments doing it? �The point is: we don't really know whose they are.?

    Ciphering Disabled Les Goldsmith

    Interceptors vary widely in expense and sophistication ? but in a nutshell, they are radio-equipped computers with software that can use arcane cellular network protocols and defeat the onboard encryption. �Whether your phone uses Android or iOS, it also has a second operating system that runs on a part of the phone called a baseband processor. �The baseband processor functions as a communications middleman between the phone?s main O.S. and the cell towers. �And because chip manufacturers jealously guard details about the baseband O.S., it has been too challenging a target for garden-variety hackers.

    ?The baseband processor is one of the more difficult things to get into or even communicate with,? says Mathew Rowley, a senior security consultant at Matasano Security. �?[That?s] because my computer doesn't speak 4G or GSM, and also all those protocols are encrypted. �You have to buy special hardware to get in the air and pull down the waves and try to figure out what they mean. �It's just pretty unrealistic for the general community.?

    But for governments or other entities able to afford a price tag of ?less than $100,000,? says Goldsmith, high-quality interceptors are quite realistic. �Some interceptors are limited, only able to passively listen to either outgoing or incoming calls. �But full-featured devices like the VME Dominator, available only to government agencies, can not only capture calls and texts, but even actively control the phone, sending out spoof texts, for example. �Edward Snowden revealed that the N.S.A. is capable of an over-the-air attack that tells the phone to fake a shut-down while leaving the microphone running, turning the seemingly deactivated phone into a bug. �And various ethical hackers have demonstrated DIY interceptor projects, using a software programmable radio and the open-source base station software package OpenBTS ? this creates a basic interceptor for less than $3,000. �On August 11, the F.C.C. announced an investigation into the use of interceptors against Americans by foreign intelligence services and criminal gangs.

    An ?Over-the-Air? Attack Feels Like Nothing

    Whenever he wants to test out his company?s ultra-secure smart phone against an interceptor, Goldsmith drives past a certain government facility in the Nevada desert. �(To avoid the attention of the gun-toting counter-intelligence agents in black SUVs who patrol the surrounding roads, he won't identify the facility to Popular Science). �He knows that someone at the facility is running an interceptor, which gives him a good way to test out the exotic ?baseband firewall? on his phone. �Though the baseband OS is a ?black box? on other phones, inaccessible to manufacturers and app developers, patent-pending software allows the GSMK CryptoPhone 500 to monitor the baseband processor for suspicious activity. �

    So when Goldsmith and his team drove by the government facility in July, he also took a standard Samsung Galaxy S4 and an iPhone to serve as a control group for his own device.

    ?As we drove by, the iPhone showed no difference whatsoever. �The Samsung Galaxy S4, the call went from 4G to 3G and back to 4G. �The CryptoPhone lit up like a Christmas tree.?

    Though the standard Apple and Android phones showed nothing wrong, the baseband firewall on the Cryptophone set off alerts showing that the phone?s encryption had been turned off, and that the cell tower had no name ? a telltale sign of a rogue base station. ��Standard towers, run by say, Verizon or T-Mobile, will have a name, whereas interceptors often do not.

    Some devices can not only capture calls and texts, but even actively control the phone and send spoof texts.
    And the interceptor also forced the CryptoPhone from 4G down to 2G, a much older protocol that is easier to de-crypt in real-time. �But the standard smart phones didn?t even show they?d experienced the same attack. �

    ?If you've been intercepted, in some cases it might show at the top that you've been forced from 4G down to 2G. �But a decent interceptor won't show that,? says Goldsmith. �?It'll be set up to show you [falsely] that you're still on 4G. �You'll think that you're on 4G, but you're actually being forced back to 2G.?

    So Do I Need One?

    Though Goldsmith won?t disclose sales figures or even a retail price for the GSMK CryptoPhone 500, he doesn?t dispute an MIT Technology Review article from this past spring reporting that he produces about 400 phones per week for $3,500 each. �So should ordinary Americans skip some car payments to be able to afford to follow suit?

    It depends on what level of security you expect, and who you might reasonably expect to be trying to listen in, says Oliver Day, who runs Securing Change, an organization that provides security services to non-profits.

    ?There's this thing in our industry called ?threat modeling,? says Day. �?One of the things you learn is that you have to have a realistic sense of your adversary. Who is my enemy? �What skills does he have? �What are my goals in terms of security??

    If �you?re not realistically of interest to the U.S. government and you never leave the country, then the CryptoPhone is probably more protection than you need. Goldsmith says he sells a lot of phones to executives who do business in Asia. �The aggressive, sophisticated hacking teams working for the People?s Liberation Army have targeted American trade secrets, as well as political dissidents.

    Day, who has written a paper about undermining censorship software used by the Chinese government, recommends people in hostile communications environments watch what they say over the phone and buy disposable ?burner? phones that can be used briefly and then discarded.

    ?I'm not bringing anything into China that I'm not willing to throw away on my return trip,? says Day.

    Goldsmith warns that a ?burner phone? strategy can be dangerous. �If Day were to call another person on the Chinese government?s watch list, his burner phone?s number would be added to the watch list, and then the government would watch to see who else he called. �The CryptoPhone 500, in addition to alerting the user whenever it?s under attack, can ?hide in plain sight? when making phone calls. �Though it does not use standard voice-over-IP or virtual private network security tools, the CryptoPhone can make calls using just a WI-FI connection -- it does not need an identifiable SIM card. �When calling over the Internet, the phone appears to eavesdroppers as if it is just browsing the Internet.

    Copyright � 2014 Popular Science. A Bonnier Corporation Company. All rights reserved. Reproduction in whole or in part without permission is prohibited.

    Ok so does this affect us too and if so what can we do about it?

    Posted via CB10
    93Aero, shaleem and jmrat24 like this.
    09-02-14 03:43 AM
  2. 93Aero's Avatar
    Interesting read thanks for posting.

    Posted via CB10
    09-02-14 05:10 AM
  3. Ment's Avatar
    There is a discussion on baseband vulnerabilities in this thread http://forums.crackberry.com/blackbe...phones-949685/

    Slides of the talk by the Accuvant guys at Blackhat 2014 here http://files.accuvant.com/web/file/7...ale-BH2014.pdf
    09-02-14 05:26 AM
  4. shaleem's Avatar
    I firmly believe that total and complete security for any device is a fantasy. Any entity with the funds to pursue it, can figure out ways to keep tabs on any communication.
    alternator77 likes this.
    09-02-14 09:27 AM
  5. nah.uhh's Avatar
    Off topic: Will cb10 app ever support html tags? Man, that post was hard to read
    09-02-14 09:38 AM
  6. adamlau's Avatar
    I didn't even read it and scrolled down to view the comments. C'mon CB10...Give us HTML support!
    09-02-14 01:07 PM
  7. winfire's Avatar
    Sorry about the html tags I didn't put them there. I just copied everything from popular science website and they were hidden till I posted and yeah the tags aren't visible on Crackberry as it looks normal on the website. So come on CB10 this issue needs addressing

    Posted via CB10
    09-03-14 01:38 AM
  8. TeaBoy's Avatar
    how Vulnerable are blackberry phones?
    09-03-14 05:27 PM
  9. Old_Mil's Avatar
    Anyone have any further information on this? I travel extensively and have a lot of important information on my BlackBerry. I have chosen the blackberry ecosystem specifically because of the security failings of Android and iOS but if cell phone interceptors are capable of taking information off my Z10 while I am driving that is going to be a problem.
    09-06-14 09:14 AM
  10. red72's Avatar

    This is my post with poor title about the article on MSN. It did seem like anyone really cared.

    Posted via CB10
    09-06-14 10:25 AM
  11. Old_Mil's Avatar
    Appreciate it, Red. I've turned encryption on and downloaded the Prism Break email encryption program.

    Posted via CB10
    red72 likes this.
    09-06-14 01:23 PM
  12. TgeekB's Avatar
    It's probably the military or something similar. I wouldn't lose sleep over it but that's just me.

    Q10, N5, N10.
    09-06-14 03:17 PM
  13. adamlau's Avatar
    I would and have lost sleep over this. But then again, securing network communications is part of my job. Outside of custom chipsets, the only feasible workaround at this point is to tunnel under a VPN service (enabling Connect to Mobile Network if required) while making calls via encrypted VoIP sessions. This is easily accomplished.
    09-07-14 07:53 PM
  14. katiepea's Avatar
    how Vulnerable are blackberry phones?
    Just as vulnerable as any other phone. Read the article.
    alternator77 likes this.
    09-07-14 10:49 PM
  15. katiepea's Avatar
    Off topic: Will cb10 app ever support html tags? Man, that post was hard to read
    There is a flaw in bb10 that makes content like this not doable with cascades.
    09-07-14 10:51 PM
  16. kg4icg's Avatar
    You know what is funny, cdma systems don't have this problem with all the handshaking going on between phone and carrier systems that it belongs too. Why you cant use a Verizon phone on Sprint and vice / versa.
    09-08-14 09:04 AM
  17. red72's Avatar
    You know what is funny, cdma systems don't have this problem with all the handshaking going on between phone and carrier systems that it belongs too. Why you cant use a Verizon phone on Sprint and vice / versa.
    My understanding though is that all carriers do share cell towers. That's where roaming charges come from? Anyone else?
    09-08-14 02:37 PM
  18. RyanGermann's Avatar
    I thought these towers have to somehow trick or force the device into unencrypted 2g mode... so setting your mobile network settings in bb10 to 3g, HSPA and LTE only should offer some protection, right?

    Posted via CB10
    09-08-14 02:42 PM
  19. jpvj's Avatar
    I read the original article is from popsci.com and has never been confirmed by any other source. The article has just been references over and over again. That's how modern journalism works.

    Cryptophone's PR department might have been involved in this story - the timing is very convenient :-)
    09-08-14 03:38 PM
  20. medic22003's Avatar
    Alex Jones talks about it a lot and it's not just the military. Some city police department are doing it too. Chicago has it all over in statues and such apparently. It ain't good. Missouri did just pass a constitutional amendment that stated the citizens of the state have a right to be secure in electronic personal information as well as the rest of the stuff in the 4th amendment of the us constitution. It's real and it's just evil let alone unconstitutional.

    Posted via CB10
    09-23-14 07:34 PM
  21. INFOmuzRON's Avatar

    Posted via CB10
    09-23-14 07:42 PM
  22. medic22003's Avatar
    Yep. And yet people still don't get what a big deal government spying is. Doesn't matter if you have nothing to hide. They shouldn't be looking without a good reason and a warrant.

    Posted via CB10
    09-23-14 07:50 PM

Similar Threads

  1. Using the passport to makea phone calls?
    By ChainPunch in forum BlackBerry Passport
    Replies: 13
    Last Post: 09-07-14, 04:11 PM
  2. Short Ringtone during call
    By bbudyn in forum Ask a Question
    Replies: 3
    Last Post: 09-02-14, 02:49 AM
  3. BlackBerry Guardian says Rhapsody app might be harmful
    By AnimalPak200 in forum More for your BlackBerry 10 Phone!
    Replies: 2
    Last Post: 09-01-14, 09:11 PM
  4. Could the massive iCloud hack lead to a mass exodus of celebs to BlackBerry?
    By saintforlife in forum General BlackBerry News, Discussion & Rumors
    Replies: 1
    Last Post: 09-01-14, 04:19 PM
  5. Calls isnt responding error
    By Minhaaj Rehman in forum BlackBerry OS
    Replies: 2
    Last Post: 09-01-14, 03:17 PM