The Register® — Biting the hand that feeds IT

Feeds

Voda: Femtocell phone-hacking vuln was fixed in 2010

News International scandal stirs interest in old backdoor

Magic Quadrant for Enterprise Backup/Recovery

Vodafone said that claims of a vulnerability involving its femtotell base station technology relate to a flaw it fixed a year ago.

Security shortcomings in Vodafone's femtocell signal booster technology create a possible means for hacker to intercept calls or impersonate users that connect via a compromised device, The Hacker's Choice (THC) claims. THC claims to have reverse-engineered allegedly insecure base station kit, so turning hacked femtocells into an interception device in the process. The bug ultimately stems from default root passwords on a insecure device console.

The research was first published in a blog on Tuesday, rapidly reaching notoriety in the process. In a statement, Vodafone said that the underlying security bug was actually fixed as long ago as last year.

Overnight on July 12, a claim appeared that hackers had found security loopholes in Vodafone Sure Signal which could compromise the security of Vodafone's network. This is untrue: the Vodafone network has not been compromised.

The claims regarding Vodafone Sure Signal, which is a signal booster used indoors, relate to a vulnerability that was detected at the start of 2010. A security patch was issued a few weeks later automatically to all Sure Signal boxes. As a result, Vodafone Sure Signal customers do not need to take any action to secure their device. We monitor the security of all of our products and services on an ongoing basis and will continue to do so.

It seems that the flaw involve relates to a bug publicised at the time that has since become more noteworthy – partly because of the ongoing News International voicemail hacking scandal. THC's website was private last year, but opened up to the public earlier this week. ®

Magic Quadrant for Enterprise Backup/Recovery

Anonymous Coward

Internet journalism:

Post story. Wait for someone to check the facts for you later.

4
0

O really?

"...the Vodafone network has not been compromised [that we know of, but if we did know it had been compromised we would definitely tell you, honest!]"

There fixed it for you.

2
0

RTFA

The OP reflashed his device and took the geoloc components out completely!

He stated that he had recently tok his device to france and set it up in paris and it worked.

Another commentor mentioned that VF now check packet latency and if it too big they cut you

off so no trips to .au folks.

The problem with such simplistic barriers is this device is NFG for anyone who gets thier internet via a RF relay (such as some folks in the highlands).

Also how does an update get to a box that has been reflashed with a new/modified O/S?

VF should hire more techs and less PR staff.

1
0

More from The Register

 breaking news
UK telcos chuck another £1m at online child abuse watchdog
Web enforcers IWF gain power to seek and destroy illegal content
 breaking news
Pttow! Ofcom kicks hams out of MoD bands
Geet off my land, you, you ... 'secondary user'
 breaking news
UK.gov's £530m bumpkin broadband rollout: 'Train crash waiting to happen'
Whitehall whispers of damning watchdog report next month
Google launches broadband balloons, radio astronomy frets
A careless Loon could blind the square kilometre array
 breaking news
MySpace zaps millions of teens' tearful rants, causes wave of angst
'Your crappy redesign SUCKS, I wanna read my blogs' screech users
 breaking news
Microsoft Office 365 on iPhone NOW: No, we're not making this up
Word, Excel, Powerpoint for your pocket-stroker
Increased cell phone coverage tied to uptick in African violence
'Significantly and substantially increases the probability of violent conflict'
 breaking news
EU signs off on eCall emergency-phone-in-every-car plan
GPS and a mobe in every car - do you suppose the NSA would fancy that?