HomeSecuritySaudi Arabia spies on mobile phones through vulnerabilities in SS7

Saudi Arabia spies on mobile phones through vulnerabilities in SS7

SS7

Security experts and specialists have long warned of flaws in mobile phone networks around the world, and now a complaint alleges that the Saudi Arabian government is exploiting these vulnerabilities to spy on its citizens in the United States .

This is the latest tactic the country has used to spy on the movements of its citizens in other countries. The kingdom has faced accusations that it plants powerful spyware on devices to access the phones of dissidents and activists to monitor their activities. One such example is Washington Post columnist Jamal Khashoggi, who was murdered by agents of the Saudi regime. The kingdom has also reportedly placed spies on Twitter to monitor critics of the regime.

According to the Guardian, a cache of data discovered contained millions of Saudi Arabian citizens’ locations over a four-month period starting in November. The location requests were made by Saudi Arabia’s three largest mobile phone carriers, believed to be under the auspices of the government. They exploited weaknesses in SS7 to find the locations.

SS7 is a set of protocols for routing and directing calls and messages between networks. So a T-Mobile , for example, can call an phone or send a message to a friend who has Verizon, even when they are in another country. According to security experts, attackers exploit vulnerabilities in these protocols to gain access to the calls and messages of network users. SS7 also allows the location of devices in densely populated cities to be determined by making a PSI (Public Subscriber Information Request). These PSI requests usually ensure that the user is charged correctly for the services they use. However, when the requests are made at an unspecified time or in large numbers, they indicate that the user may be being tracked.

However, despite warnings from experts about the existence of flaws, America's largest mobile network providers have not done much to address the situation.   

A Democratic lawmaker is blaming the Federal Communications Commission for failing to force mobile carriers to take action. A spokesman for the FCC, the agency responsible for regulating mobile networks, did not respond to a request for comment.

SS7 fix

Solving the problems in SS7 won't happen overnight, but without oversight and constant pressure from a regulator, providers wo n't make these changes on their own.

Experts say the same firewalls that mobile carriers have put in place could potentially filter out malicious traffic and prevent some abuse. But an FCC task force tasked with understanding the risks posed by the SS7 flaws in 2016 acknowledged that the vast majority of SS7 traffic is legitimate. In other words, this proposal isn’t a viable solution if it also blocks actual requests from carriers.

Mobile network providers have been less than eager to move forward with fixes to their SS7 issues. Only AT&T has commented, telling The Guardian that it has implemented “ security to block location-based messages from roaming partners.” To what extent remains unclear, as is whether such measures will help. Few experts have expressed faith in newer systems such as Diameter, a similar routing protocol for 4G and 5G networks, given that there have already been a number of vulnerabilities in the newer system.

End-to-end encrypted apps like Signal and WhatsApphave made it harder for spies to monitor calls and messages. But even they aren't completely secure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS