Zocalo Technology News

Security researchers Don Bailey and Nick DePetrillo presented a paper on a cell phone exploit at the SOURCE conference in Boston this April that exposes serious fundamental weaknesses in the architecture of mobile phones. Bailey and DePetrillo have found ways to discover information that most cell users assume is private and known only to the cell provider. DePetrillo said. "If you go through entire number ranges and blocks, you'll get numbers for celebrities, executives, anyone. You can then track them easily using the geolocation information." At the heart of the work is the ability to access the caller ID database mobile providers use to match the names of subscribers to mobile numbers. This is the same database that contains the subscriber information for landlines, but most mobile users don't realize that their data is entered into this repository, Bailey said. Furthermore, these vulnerabilities are design flaws, and thus cannot be simply patched or mitigated with workarounds. Read more here.

Tagged in: Untagged