Researchers Demonstrate How US Emergency Alert System Can Be Hijacked and Weaponized

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12L6Zdd2euzrk5WyGHDCN7UL0-BBSFM1G2xAt8Vp01vxGQ@mail.gmail.com>
'After an emergency alert was accidentally sent to Hawaii residents
last year, warning of an impending nuclear ballistic missile attack,
researchers at the University of Colorado Boulder were prompted to ask
the question: How easy would it be to exploit the nation's emergency
alert systems, wreaking havoc on the American public via fake or
misleading alerts? In short, they found that it wasn't very difficult
at all. Motherboard reports:

Their full study was recently unveiled at the 2019 International
Conference on Mobile Systems, Applications and Services (MobiSys) in
Seoul, South Korea. It documents how spoofing the Wireless Emergency
Alert (WEA) program to trick cellular users wasn't all that difficult.
To prove it, researchers built a mini "pirate" cell tower using
easily-available hardware and open source software. Using isolated RF
shield boxes to mitigate any real-world harm, they then simulated
attacks in the 50,000 seat Folsom Field at the University. 90 percent
of the time, the researchers say they were able to pass bogus alerts
on to cell phones within range. The transmission of these messages
from the government to the cellular tower is secure. It's the
transmission from the cellular tower to the end user that's open to
manipulation and interference, the researchers found. The
vulnerability potentially impacts not just US LTE networks, but LTE
networks from Europe to South Korea. '

-- source: https://tech.slashdot.org/story/19/06/26/2347257

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.