Feeds

MAJOR HACK: Voda femtocells open phones up to intercept

Pass within 50m of one, they own your phone

Best practices for enterprise data

Updated Security researchers claim to have uncovered a serious security hole in Vodafone's mobile network.

Security shortcomings in the femtocell technology supplied by the mobile phone giant create a means to extract information that would allow hackers to intercept calls or impersonate users that connect through a compromised device, The Hacker's Choice (THC) claims.

Femtocells are home routers that use broadband connections to improve mobile coverage, allowing calls to be made indoors more easily. Vodafone's Sure Signal Femto equipment is marketed to consumers and small businesses and costs around £160.

THC claims to have reverse-engineered the Sagem-manufactured kit and discovered a way for any subscriber to use a femtocell. A second vulnerability creates a means for hackers to grab secret subscriber information from Vodafone (specifically IMSI - international mobile subscriber identity - data from Home Location Register and authentication systems). Because of this second security shortcoming, it's possible to turned a hacked femtocell into an interception device, the researchers claim.

The grey hats claim that the approach can be used to compromise Vodafone UK accounts in order to either intercept or make calls at the expense of victims. Access to a victim's voicemail would also be possible. All these hacks would only work once a victim had been tricked into using a compromised base station, something that can happen automatically, but only over a short distance of around 50m, within range of the device.

The root cause of the problem is that the allegedly insecure base station kit is assigned functions normally restricted to carriers' core network authentication systems.

"The femtocell contains a Mini-RNC/Node-B, which is not a real RNC [Radio Network Controller] nor a Node-B. It's something in-between," the security researchers explain. "The mini-RNC can request real encryption keys and authentication vectors for any Vodafone UK customer from the Vodafone core network (like a real RNC). The Vodafone core network still authenticates every single phone (like a Node-B)."

Technical details of the hack are listed in a blog post by THC here.

Another separate group of researchers plans to give a talk on femtocell hacks at the upcoming Black Hat conference in Las Vegas later this month.

We asked Vodafone to comment on the research, but have yet to hear back from the mobile phone giant. We'll update this story as and when we hear more. ®

Updated to add

We finally heard back from Vodafone to the effect that the vuln in question is an old one and was patched in 2010. By then the story was all over the place, so we thought it was worth another headline.

Recommendations for simplifying OS migration

More from The Register

next story
Trying to sell your house? It'd better have KILLER mobile coverage
More NB than transport links to next-gen buyers - study
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Scotland's BIG question: Will independence cost me my broadband?
They can take our lives, but they'll never take our SPECTRUM
NBN Co adds apartments to FTTP rollout
Commercial trial locations to go live in September
Samsung Z Tizen OS mobe is post-phoned – this time for good?
Russian launch for Sammy's non-droid knocked back
Speak your brains on SIGNAL-FREE mobile comms
Readers chat to the pair who flog the tech
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?