home.social

#ss7 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ss7, aggregated by home.social.

fetched live
  1. SS7, il protocollo del 1970 che ha tradito i soldati USA: come l’Iran ha tracciato le truppe americane in Medio Oriente

    Un'indagine di Mobile Surveillance Monitor, ripresa dal Financial Times, sostiene che l'Iran abbia sfruttato le debolezze del protocollo SS7 e dati di ad-tech commerciale per localizzare personale militare USA in Iraq e Bahrain prima e durante il conflitto con Israele e Stati Uniti.

    insicurezzadigitale.com/ss7-il

  2. #Iran abused mobile networks' #vulnerabilities to locate #US #military in the #MiddleEast, report says
    The Iranian government exploited #SignalingSystem7, or #SS7, protocols for 2G & 3G networks that has long been backbone of how #cellular networks connect to each other to route subscribers’ calls and texts around world, the newspaper reported, citing research by the Mobile Surveillance Monitor, as well as anonymous government officials with knowledge of the spy campaign.
    techcrunch.com/2026/07/14/iran

  3. #SS7 strikes again. Must be hard for the US to be the victim of vulnerabilities they used themselves for ages.

    Iran Abused Mobile Networks' Vulnerabilities To Locate US Military In Middle East - Slashdot tech.slashdot.org/story/26/07/

  4. @evacide this is a good issue (for eff) - with no click exploits are you actually at fault? the domain creep here is about apps like pegasus, less personal and more money motivated, less hackers and more like nation state efforts - that may be a bigger threat, the phone has another os. opsec effort required #policies #ss7 baseband #cloned phones #geofence #pkt cap #binaries #hashdeep #dfir

  5. Позвонить бесплатно: история взлома аналоговой телефонии. Часть 2

    В прошлой статье мы подробно разобрали феномен цветных коробок (в первую очередь голубых) для взлома аналоговых телефонных сетей в США. В этой части мы поговорим, какие варианты взломов практиковали в нашей стране.

    habr.com/ru/companies/beget/ar

    #ОКС7 #SS7 #Blue_Box #2ВСК #2600_Гц #аналоговый_телефон #ТФоП #Bell #АТС #DTMF

  6. Позвонить бесплатно: история взлома аналоговой телефонии. Часть 1

    Фрикинг — это слегка устаревший термин, который означает взлом телефонных сетей для бесплатных звонков. Главным образом фрикинг относят к взлому аналоговых сетей, которых ныне почти не осталось, а потому термин стал неактуален. Но. Но в США 1960–1980-х годов это была целая культура, сравниваемая с сегодняшними хакерами. А в позднем СССР масштаб подобных взломов стал общенациональной проблемой. Как вообще можно взломать аналоговую телефонную сеть и позвонить бесплатно? Присаживайтесь поудобнее, сейчас вы все узнаете.

    habr.com/ru/companies/beget/ar

    #ОКС7 #SS7 #Blue_Box #2ВСК #2600_Гц #аналоговый_телефон #ТФоП #Bell #АТС #DTMF

  7. Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say

    The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.

    #cybersecurity #diameter #israel #location-tracking #privacy #security #ss7 #surveillance
    techcrunch.com/2026/04/23/surv

  8. Interesting and comprehensive report about sophisticated telecom surveillance campaigns involving mobile operator signaling infrastructure citizenlab.ca/research/uncover and identifying three gateways to surveillance (019Mobile, Airtel Jersey, Tango Networks UK) #3gpp #gsm #gsma #ss7 #diameter

  9. @TimWardCam @neil

    That would be difficult for kids, because it requires lifting the handset, and demonstrating a sense of timing.

    #SS7

  10. Эпические баги: как один Break положил телефонную сеть по всему США в 1990 г

    В подразделении, где я работаю, есть традиция - новичку при онбординге вручается ссылка на Wiki с легендарными багами, приведшими к заметным последствиям. Недавно мне пришла в голову идея сделать такую же страницу, но уже со ссылками на Хабр, потому что на русском о багах пишут с бОльшим огоньком. Но, увы, оказалось, что каскадному падению серверов AT&T 15 января 1990 года внимание как-то не уделено. А ведь история получилась, прямо-таки эпическая. Итак, 15 января 1990 года из-за одной строчки кода телефонная сеть AT&T получила 9 часов даунтайма, 70 миллионов несовершенных звонков, а общий убыток насчитали в $60 миллионов еще не инфляционных долларов. И нет, там не было неудачного релиза, развернутого сразу и везде. Все было гораздо интереснее.

    habr.com/ru/companies/beget/ar

    #4ESS #SS7 #эпический_баг #ошибка #каскадный_сбой #телекоммуникации #тестирование #1990 #надёжность

  11. Someone just attempted to activate #Signalapp on my phone number (I received the SMS verification code all the sudden). Even if they would have some #SS7 hack going on where they can get a duplicate of the SMS, I actually do have a registration lock enabled. (*)

    However, it could also be someone making a mistake entering their phone number during setup.

    *) support.signal.org/hc/en-us/ar

  12. The year is 2027. Email is #unreliable; little gets past #Gmail filters without a contract to receive your #email. #Governments don't stop it because (a) they have a contract, and (b) they don't understand how email works. Or worked.

    #Tech companies finally realize that #SS7 is #insecure. Phone calls and texts can't be #trusted. Machine-learning-generated ("AI") audio and video means video and voice calls are doubly cursed - too many #FAANG executives have had embarrassing public #failures, falling #victim to the corporate equivalent of the grandparent #scam.

    Few people use #TOTP, because the tech #companies don't promote it, they each call it something else and make it work differently, and they all want you to use their "app" rather than the standard 3-line script that can generate the correct code given a key and the current timestamp. The technically-minded try to educate their relatives and friends as part of the free-tech-support assumption, but no one cares.

    #Account #recovery now involves waiting at home to sign for an envelope delivered by the lowest-cost (and therefore bribe-able) courier to the #registered home address of the account. Millions each year lose their email, #photos, videos, "purchased" digital #content, password vaults, etc because they've moved since they set up the account, or they have a P.O. box and companies don't believe those #exist.

    The #internet is a vast digital #wasteland - wait, a saviour onstage: "Walled Garden-Net!".

    Burn it.

  13. [Перевод] Хороший, Плохой, Расширенный: SS7 атака с использованием расширенных тэгов

    Есть два типа операций в SS7, друг мой: безобидные... и те, что держат револьвер... ... Это, конечно, утрирование. Однако, как и герои спагетти-вестернов, операции в SS7 предстают перед нами в полном своем разнообразии и глубине, и иногда их сложно распарсить, а главное - обработать безопасно для абонента. Неверная обработка операций (команд) в SS7 (они же PDUs), несет за собой серьезные риски и потенциально может привести к угрозам уровня уязвимостей нулевого дня, открывая широкий спектр возможных атак.

    habr.com/ru/articles/982196/

    #ss7 #asn1 #сетевые_атаки #tcap #сигнальные_протоколы

  14. Privacy Cell warnt vor unsicheren 2G/3G-Netzen (SS7-anfällig) & IMSI-Catchern – checkt deine Mobilfunkprotokolle für mehr Sicherheit! 📱🔍 Open-Source-App auf F-Droid. f-droid.org/en/packages/com.st #Privacy #FOSS #Datenschutz #SS7
    #MeeMeep xD

  15. 🔍 frontal enthüllt: First WAP-Software trackt Smartphones weltweit heimlich via #SS7 Lücke – Red Bull-Chefs, Vatikan-Journalisten & mehr betroffen! Dubiose Deals auf Überwachungsmessen. Schockierende Recherche! 📱🕵️‍♂️ youtube.com/watch?v=zcnw-RGcoP4 #TelefonÜberwachung #Datenskandal #Privatsphäre #Investigativ #LighthouseReports #FirstWAP #ZDF

    yewtu.be/watch?v=zcnw-RGcoP4

  16. @HonkHase This is why most carriers have since quite a while implemented #SS7 firewalls. German mobile carriers certainly have this since years. Anyways, a good way of opening the focus wide on the surveillance other than #chatcontrol. Also a good point in time to remember that since 2013 (Ed Snowdens releases) more than a decade has passed, and so has technology.

  17. The Surveillance Empire That Tracked World Leaders, a Vatican Enemy, and Maybe You

    "Inside the hidden world of First Wap, whose untraceable tech has targeted politicians, journalists, celebrities, and activists around the globe."

    #SS7 #Altamides #MassSurveillance

    motherjones.com/politics/2025/

  18. Wann wird sich endlich um #SS7 gekümmert? 😤🔥

    #KRITIS Sektor #IT und #TK

    frontal - die Doku: Dein Handy als Spion: Heimlich überwacht?

    "Mit #Überwachungstechnik einer Sicherheitsfirma sollen jahrelang Tausende Mobiltelefone weltweit geortet und getrackt worden sein. Das legen ein Datensatz und eine Undercover-Recherche nahe."
    zdf.de/video/dokus/frontal-dok

  19. @ycombinator this is the #ss7 security leak that has been presented in a #ccc talk i think in the year 2014.

    What was the app called, that could identify such SS7 network interceptions?

    #surveillance #backdoor #exploit

  20. "Operating from their base in Jakarta, where permissive export laws have allowed their surveillance business to flourish, First Wap’s European founders and executives have quietly built a phone-tracking empire, with a footprint extending from the Vatican to the Middle East to Silicon Valley.

    It calls its proprietary system Altamides, which it describes in promotional materials as “a unified platform to covertly locate the whereabouts of single or multiple suspects in real-time, to detect movement patterns, and to detect whether suspects are in close vicinity with each other.”

    Altamides leaves no trace on the phones it targets, unlike spyware such as Pegasus. Nor does it require a target to click on a malicious link or show any of the telltale signs (such as overheating or a short battery life) of remote monitoring.

    Its secret is shrewd use of the antiquated telecom language Signaling System No. 7, known as SS7, that phone carriers use to route calls and text messages. Any entity with SS7 access can send queries requesting information about which cell tower a phone subscriber is nearest to, an essential first step to sending a text message or making a call to that subscriber. But First Wap’s technology uses SS7 to zero in on phone numbers and trace the location of their users.

    First Wap emphasizes that its technology is used by law enforcement to “fight against organized crime, terrorism and corruption.” It sells Altamides directly, as well as through third-party resellers."

    motherjones.com/politics/2025/

    #CyberSecurity #Surveillance #FirstWap #Altamides #SS7 #Privacy #LocationData

  21. @dougmerritt

    Per various customers I overheard talking about this in a parking lot, the problem would vary by which cell tower you were connecting to at a given time.

    Some said text would work, but not calls.

    They messed up something wrt to SIM id and routing.

    #SS7

  22. ⚠️ Researchers identify a new SS7 encoding attack used by a surveillance vendor to bypass defenses and access mobile subscriber data.

    Read: hackread.com/researchers-ss7-e

    #CyberSecurity #SS7 #Vulnerability #Telecom #Surveillance