Researchers Send Fake Presidential Alerts to Stadium of 50,000 Using LTE Vulnerability [View all]
Source: Gizmodo
PRIVACY AND SECURITY
Researchers Send Fake Presidential Alerts to Stadium of 50,000 Using LTE Vulnerability
Melanie Ehrenkranz
Yesterday 2:09pm Filed to: EMERGENCY ALERT SYSTEM
Researchers figured out a way to exploit the system that sends presidential emergency alerts to our phones, simulating their method on a 50,000 seat football stadium in Colorado with a 90 percent success rate.
Researchers at the University of Colorado Boulder published a paper this month that details how they were able to spoof attack the Wireless Emergency Alert (WEA) program, which can send out AMBER alerts, presidential alerts, and both extreme and severe threats to safety.
Emergency alerts are sent to every mobile device within range of the broadcasting cell tower. But the researchers note that a malicious cell tower channel is capable of fooling the system, and in turn sending out an inauthentic emergency alert to all devices within its range.
The researchers tested this LTE vulnerability by creating their own malicious cell tower channel using off-the-shelf hardware and open-source software to deploy their exploit, which in one instance was used in an experiment at Folsom Field at the University of Colorado Boulder.
The researchers didnt perform an actual attack on a live crowd at the stadium or on actual mobile devices, Eric Wustrow, a researcher on the paper, told Gizmodo in an email. The tests performed were instead done in isolated RF shield boxes, Wustrow said, and our analysis of Folsom Field was a combination of empirically gathered data and simulation. A screenshot from the paper below displays what these spoof attacks looked like on both a Samsung Galaxy S8 and an iPhone X.
-snip-
Read more:
https://gizmodo.com/researchers-send-fake-presidential-alerts-to-stadium-of-1835806990