T-Mobile Wi-Fi Calling Was Vulnerable to Trivial MITM Attack 24
wiredmikey writes "A vulnerability discovered by researchers at UC Berkeley enabled attackers to eavesdrop on and modify calls and text messages sent using T-Mobile's 'Wi-Fi Calling' feature. According to Jethro Beekman and Christopher Thompson, both UC Berkeley graduate students, when an affected Android device connected to a server via T-Mobile's Wi-Fi Calling feature, it did not correctly validate the server's security certificate, exposing calls and text messages to a 'man-in-the-middle' (MiTM) attack. ... '[An attacker] could record, block and reroute SIP traffic. The attacker could change it by faking a sender or changing the real-time voice data or message content. He could fake incoming traffic and he can impersonate the client with forged outgoing traffic,' the report, released Tuesday, said. Beekman and Thompson said they notified T-Mobile of their discoveries in December 2012, and worked with the mobile operator to confirm and fix the problem. As of March 18, all affected T-Mobile customers have received the security update fixing the vulnerability, the researchers said."
By 'did not correctly validate,' they mean that the certificate was self-signed and the client blindly trusted any certificate with the common name it was expecting.
Y U No Tell DoJ? (Score:3)
Re: (Score:1)
Of course.. (Score:4, Insightful)
Re: (Score:2)
Re: (Score:3)
they get it, they just don't want to spend $$$$ to fix every little thing when there is no ROI
wifi calling was a product aimed at the cheapest end of the phone market. people willing to put up with trying to find a wifi spot to make a call instead of just buying more minutes. all to save $20 or so per month.
you don't make PROFIT by spending lots of money on your cheapest customers
Re: (Score:2)
Now it does, but some years ago, there was an option ($10 or $20/per month -- it changed) to make the calls made through Wifi calling free and unrestricted. There are probably some customers with this option grandfathered in.
However, you are right about international use. It's great for avoiding roaming charges.
Re: (Score:2)
You're both right and wrong. TMOUS customers like myself can use WiFi Calling all day long and never take a hit on minutes. The catch is you don't get this capability turned on by default; you have to call customer service and ask for it. I have it and use it even though I have the Unlimited/Unlimited/Unlimited plan for my HTC One S.
Why do I use it if I have unlimited minutes? Because I work at a nuclear power plant which, by virtue of being in the middle of nowhere *and* working inside a concrete buildi
Re: (Score:2)
No, that's a very different vulnerability. What you're talking about would allow any v
Re: (Score:2)
I take my previous comment back, somebody did understand that this is about the self-signed cert!
I'll go ahead and simplify your post though... you can use a self-signed cert, so can I, so can a nigerian prince, the problem is nobody knows who's who and we can all authenticate against each other's certs leading to an authentication party!
Re: (Score:2)
Am I the only one who read self-signed cert and assumed that was the problem? DNS & SSL couldn't have less to do with this. It even states this in the last line of the article.
How to check? (Score:3)
What'd've been useful: details of how/what to check to determine if your phone uses the vulnerable software, and what would indicate you've received an update. I tend not to use the WiFi calling anyway, but it'd be nice to be able to confirm the update. Looking at it my phone's still using the original release of the WiFi Calling app and hasn't had it's firmware updated since May 2012.
Cyanogen (Score:1)
Re: (Score:1)
Re: (Score:1)
Re: (Score:1)
Is it the TMOUS WiFi Calling app or some generic SIP client app? The two are not the same.
Re: (Score:1)
I don't believe WiFi Calling for TMOUS is available on any of the CM builds. You can get *other* WiFi calling apps (i.e. typical SIP client stuff) but nothing that will work like the TMOUS app. Please correct me if I'm wrong here because I'd love to be running CM instead of the older Sense builds I'm forced to run to use the TMOUS app.
Re: (Score:1)
Re: (Score:2)
I believe it's GAN-Lite. Not 100% sure.
Re: (Score:1)
Are you referring to official CM ROM's or one-offs? Because I've never seen *any* CM ROM with the TMOUS WiFi Calling app included. How could they when it's a proprietary app owned and controlled by TMOUS?