The Long Term Evolution (LTE) standard for mobile communication, also known as 4G, was designed to overcome the security flaws of previous standards and is used by millions of people around the world.
However, researchers have now discovered vulnerabilities in LTE that allow hackers to hijack browsing, redirecting users to malicious websites, and gain the ability to spy on their online activity to see which websites they visit via LTE devices.
The researchers described three attack methods on website . The first two are passive attacks that perform identity mapping and website fingerprinting. However, the most dangerous is the third attack, which the team has dubbed "aLTEr."
What is aLTEr?
'ALTEr' is an active attack that abuses the data link layer of LTE. It allows hackers to monitor users' browsing and redirect network requests via DNS hijacking.
How feasible is aLTEr?
This method has some limitations to make it work, such as requiring around $4000 worth of equipment to work and the LTE device having to be within a 1 mile radius of the attacker.
So, the good news is that performing an aLTEr attack in real-world scenarios is quite difficult. However, that doesn't take away from the fact that aLter is very much doable for someone with the right resources.
What makes matters worse is the fact that this security flaw cannot be fixed, as this weakness is built into the LTE standard itself.
How to avoid aLTEr?
The simplest way to avoid aLTer is by using HTTPS. Always remember to check for “Secure” next to the address bar and don’t trust a site that says “Not Secure” in your browser.
