TIL your phone apparently does no or easily spoofed authentication of the identity of the base station it decides to connect to. Anyone know more about this and how it's possible?

all 3 comments

sorted by: hot top controversial new old
[–] 7 points 4 months ago*

I need to learn more about this. A family member got a fraudulent text from a bank... It was actually the right short code for the bank but the content of the message was just a little off-seeming. I can't remember if it was poor grammar or a spelling error or why we were suspicious of it. I've always wondered how that was possible. I know short codes can technically be spoofed but I've always read that it's difficult and unlikely.

What a fascinating (but horrible) story this is. Thanks for sharing!

  • source
  • [–] 2 points 4 months ago

    Been around for a while, typically Stingrays - basically just fake cell towers

  • source
  • [+] 2 points 3 months ago* (last edited 5 days ago)