Feeds

MAJOR HACK: Voda femtocells open phones up to intercept

Pass within 50m of one, they own your phone

Top 5 reasons to deploy VMware with Tegile

Updated Security researchers claim to have uncovered a serious security hole in Vodafone's mobile network.

Security shortcomings in the femtocell technology supplied by the mobile phone giant create a means to extract information that would allow hackers to intercept calls or impersonate users that connect through a compromised device, The Hacker's Choice (THC) claims.

Femtocells are home routers that use broadband connections to improve mobile coverage, allowing calls to be made indoors more easily. Vodafone's Sure Signal Femto equipment is marketed to consumers and small businesses and costs around £160.

THC claims to have reverse-engineered the Sagem-manufactured kit and discovered a way for any subscriber to use a femtocell. A second vulnerability creates a means for hackers to grab secret subscriber information from Vodafone (specifically IMSI - international mobile subscriber identity - data from Home Location Register and authentication systems). Because of this second security shortcoming, it's possible to turned a hacked femtocell into an interception device, the researchers claim.

The grey hats claim that the approach can be used to compromise Vodafone UK accounts in order to either intercept or make calls at the expense of victims. Access to a victim's voicemail would also be possible. All these hacks would only work once a victim had been tricked into using a compromised base station, something that can happen automatically, but only over a short distance of around 50m, within range of the device.

The root cause of the problem is that the allegedly insecure base station kit is assigned functions normally restricted to carriers' core network authentication systems.

"The femtocell contains a Mini-RNC/Node-B, which is not a real RNC [Radio Network Controller] nor a Node-B. It's something in-between," the security researchers explain. "The mini-RNC can request real encryption keys and authentication vectors for any Vodafone UK customer from the Vodafone core network (like a real RNC). The Vodafone core network still authenticates every single phone (like a Node-B)."

Technical details of the hack are listed in a blog post by THC here.

Another separate group of researchers plans to give a talk on femtocell hacks at the upcoming Black Hat conference in Las Vegas later this month.

We asked Vodafone to comment on the research, but have yet to hear back from the mobile phone giant. We'll update this story as and when we hear more. ®

Updated to add

We finally heard back from Vodafone to the effect that the vuln in question is an old one and was patched in 2010. By then the story was all over the place, so we thought it was worth another headline.

Security for virtualized datacentres

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
EE buys 58 Phones 4u stores for £2.5m after picking over carcass
Operator says it will safeguard 359 jobs, plans lick of paint
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Google+ GOING, GOING ... ? Newbie Gmailers no longer forced into mandatory ID slurp
Mountain View distances itself from lame 'network thingy'
Vodafone to buy 140 Phones 4u stores from stricken retailer
887 jobs 'preserved' in the process, says administrator PwC
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
Comcast exec: No, we haven't banned Tor. I use it. You're probably using it
Keep in mind if, say, your Onion browser craps out on Xfinity
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.