Project

General

Profile

WikiStart » History » Revision 13

Revision 12 (admin, 02/19/2016 10:52 PM) → Revision 13/14 (fixeria, 01/21/2020 12:21 PM)

{{>toc}} 

 h1. security.osmocom.org - Mobile (in)security 

 {{>toc}} 

 


 This website is intended to collect information about publicly-known security issues and other bugs of mobile communications systems, with a particular focus on the 3GPP-specified protocol layers of GSM, GPRS, EDGE and WCDMA(UMTS). We collect information informationon issues at any protocol layer and at any of the interfaces, i.e. the Um air interface just as well as A-bis, A, IuB, C or any of the SS7/MAP/TCAP based core network interfaces. 

 The issues can roughly be divided in 
 * *Specification Issues*, which are problems resulting from how the specification is written. 
    Thus, all implementations will exhibit the same problem, as long as they are compliant with the 
    specification 
 * *Implementation Issues*, which are problems resulting from how a given standard/protocol is 
    implemented by a given vendor/manufacturer. 

 Many of those issues have been discovered by the Osmcocom developer team while working on software that is part of the Osmocom project, like [[OpenBSC:]], [[OsmocomBB:]], [[OsmoSGSN:]]. 


 "OpenBSC":http://openbsc.osmocom.org, "OsmocomBB":http://bb.osmocom.org/, "OsmoSGSN":http://openbsc.osmocom.org/trac/wiki/OsmoSGSN 


 h2. Intentions 


 


 The intention of this project is to bring more public awareness to the security issues of mobile communications.    Compared with the IT security community of the Internet, the mobile world has a lack of security culture, and particularly a lack of public disclosure processes.     Also, we see many self-proclaimed _mobile security experts_ abusing their power from knowing about issues that have never been properly publicly disclosed.    We want to bring more transparency into this field. 


 


 h2. Directory 

 

 * [report:1 List of currently-known issues] 
 * [[WillMyPhoneShowAnUnencryptetConnection|Will my phone show an unencrypted connection by displaying a ciphering indicatior]] 
 * [[A52_Withdrawal]] -- a brief history on how A5/2 was withdrawn and how long it took. 
 * [[GSMA_Security_Group]] -- some of the little public information that we found about the GSMA Security Group 
 * [[Ericsson_Minilink]] -- some information we gathered about a popular microwave backhaul system 


 


 h2. Miscellaneous 

 

 For a complete list of local wiki pages, see [[TitleIndex]]. 
Add picture from clipboard (Maximum size: 48.8 MB)