Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Security flaw makes every Android device on AT&T and Verizon's wireless vulnerable
Neowin.net ^ | Saturday, October 17, 2015 | By Manish Singh

Posted on 10/17/2015 8:27:34 PM PDT by Swordmaker

A newly found security flaw could be affecting every Android device on AT&T or Verizon’s wireless network, according to an advisory posted by the Carnegie Mellon University CERT database. The vulnerability in question targets LTE wireless networks and takes advantage of the way some US carriers have implemented the technology on their respective networks. Users on T-Mobile network are reportedly not affected.

A group of South Korean researchers, on Friday, reported about a vulnerability that puts a large pool of Android devices -- every version of Android including Marshmallow -- in the United States at risk. If exploited, attackers could circumvent Session Initiation Protocol (SIP), often used in voice calls and instant messaging, to gain access to a victim's device. The attackers could then initiate the denial of service (DDoS) attacks on a wireless network. The access to a victim's network opens door to a number of sophisticated and serious attacks such as bypassing the VoLTE's accounting system to freely use the bandwidth, and wiretapping the victim's calls and messages.

The security flaw largely lies in the way LTE technology works. LTE uses packet switching instead of older circuit switching to transfer data across the Internet. Packet switching is more network and cost efficient, and also more reliable. Furthermore, the mechanism makes it possible for the system to detect if a network route is faulty and automatically finds another way to send the data. However, it is also prone to a number of new vulnerabilities.

"[...] We considered security issues and possible attacks related to VoLTE call service after legitimate IMS registration. However, an attacker can also utilize a SIP REGISTER message to perform other attacks. If there are vulnerabilities in the registration phase, an attacker can control all access to a victim’s VoLTE service. For example, she can carry out an imposter attack or even wiretapping,”

ACM researchers.

A spokesperson for T-Mobile acknowledged the existence of the aforementioned security flaw, and told ZDNet that they have resolved the issue. As per the researchers, Apple’s iPhones aren’t affected with this vulnerability. A Google spokesperson told the publication that they would roll out a fix for the said flaw for Nexus devices in their monthly security patch in November.

Source: CERT via ZDNet | Android logotype printed on paper and placed in the sand image by Shutterstock


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: androids; applepinglist; att; cellphones; myphonesucks; verizon

1 posted on 10/17/2015 8:27:34 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ThunderSleeps; dayglored; ShadowAce; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; ...
A SERIOUS VULNERABILITY has been discovered on all Android phones and on all versions of the OS including Marshmallow on AT&T and Verizon networks which will allow a hacker to take over the Android phone to be taken over or a denial of service attack. iPhones are not affected. Android devices on T-Mobile are not affected. Google says a patch will be rolled out in November, but guaranteed to be available only for Nexus devices. Apple users of Android devices beware! — PING!

Ping to dayglored, Shadow Ace, and ThunderSleeps for your ping lists.


Serious vulnerability found for all
AT&T and Verizon Android phones
Ping!

The Latest Apple/Mac/iOS Pings can be found by searching Keyword “ApplePingList” on Freerepublic’s Search.

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 10/17/2015 8:36:42 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

I still use a dumb phone...


3 posted on 10/17/2015 8:39:26 PM PDT by MeshugeMikey ("Never, Never, Never, Give Up," Winston Churchill ><>)
[ Post Reply | Private Reply | To 2 | View Replies]

To: MeshugeMikey
I still use a dumb phone...

Same here, and I often forget to turn the thing on.

The fetish with 24/7 "being in touch" is rather pathetic.

It is amusing to watch other diners taking smartphone pics of their dinners as they are served, no doubt to immediately post to some effete website.

4 posted on 10/17/2015 8:48:12 PM PDT by doorgunner69
[ Post Reply | Private Reply | To 3 | View Replies]

To: dennisw

Yet another reason to avoid Apple.

Oh, wait, never mind.


5 posted on 10/17/2015 8:49:15 PM PDT by IncPen (Not one single patriot in Washington, DC.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: doorgunner69

My Favorite..

2 couples dining together....all four diners staring intently....at their Phones...and uttering nary a word....to one another.

my other favorite...a Bicyclist,,,Texting,, while riding ....hands free of course


6 posted on 10/17/2015 8:51:34 PM PDT by MeshugeMikey ("Never, Never, Never, Give Up," Winston Churchill ><>)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

Important vulnerability information that deserves immediate attention.
Android users weep in hopeless dispair, knowing there is readily available repair.
Android hate smug Apple even more.


7 posted on 10/17/2015 9:00:51 PM PDT by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Glad I'm safe on the T-Mobile network, though slightly ironically, if you have a Nexus device on Google's service, you'll sweep in and out of both AT&T and Verizon's networks (as well as T-Mobile and others.)

A Google spokesperson told the publication that they would roll out a fix for the said flaw for Nexus devices in their monthly security patch in November.

And this is the reason why I have a Nexus device...

8 posted on 10/17/2015 9:01:18 PM PDT by kingu (Everything starts with slashing the size and scope of the federal government.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doorgunner69

Makes you wonder if People ever communicate the old way anymore, like talking. How was your day? Did you hear me? Oh are you talking to me?


9 posted on 10/17/2015 9:14:58 PM PDT by easternsky
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

Deliberate lack of security is hardly a flaw...and we all know the NSA has ALL of Hillary’s emails, too:

AT&T/Verizon-NSA partnership shows why government and businesses shouldn’t mix
POSTED AT 5:01 PM ON AUGUST 16, 2015 BY TAYLOR MILLARD

http://hotair.com/archives/2015/08/16/attverizon-nsa-partnership-shows-why-government-and-businesses-shouldnt-mix/

NSA Spying Relies on AT&T’s ‘Extreme Willingness to Help’

https://www.propublica.org/article/nsa-spying-relies-on-atts-extreme-willingness-to-help

Surveillance ‘partnership’ between NSA and telcos points to AT&T, Verizon

http://www.cnet.com/news/surveillance-partnership-between-nsa-and-telcos-points-to-at-t-verizon/

New Details Show Broader NSA Surveillance Reach
Programs Cover 75% of Nation’s Traffic, Can Snare Emails

http://www.wsj.com/articles/SB10001424127887324108204579022874091732470

U.S., British intelligence mining data from nine U.S. Internet companies in broad secret program

http://www.washingtonpost.com/investigations/us-intelligence-mining-data-from-nine-us-internet-companies-in-broad-secret-program/2013/06/06/3a0c0da8-cebf-11e2-8845-d970ccb04497_story.html


10 posted on 10/18/2015 4:01:45 AM PDT by jacknhoo (Luke 12:51. Think ye, that I am come to give peace on earth? I tell you, no; but separation.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 109ACS; aimhigh; bajabaja; Bikkuri; Bobalu; Bookwoman; Bullish; Carpe Cerevisi; DarthDilbert; ...
Seems to be part network vulnerability, part device/OS vulnerability. Keep your ears open... — ANDROID PING!

Android Ping!
If you want on or off the Android Ping List, Freepmail me.

11 posted on 10/19/2015 6:14:02 AM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 2 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson