I had the opportunity to attend Blackhat Europe 2017 in London last week. What follows are some of my notes and observations.
Nota bene: this is all very subjective and not necessarily complete. You have been warned :-)
tl;dr
Diameter, the successor to SS7, used in 4G/LTE mobile networks has all the same vulnerabilities and a new/unproven code base likely to contain additional bugs.
Take-away: telecom protocols tend to be super complex and have a huge attack surface.
In case you haven't heard of the SS7 attacks:
First things first: turn off BlueTooth and leave it that way!
Bluetooth, again, is an old-school telecoms protocol, thus very complex and "sporting" a huge attack surface (the spec is 2822 pages long!)
Bluetooth stacks are big code bases that have received too little review and scrutiny due to lack of economic incentives. In hindsight, it is not surprising that almost all implementations are full of (security) bugs.
The BlueBorne attack vector can potentially affect all devices with Bluetooth capabilities, estimated at over 8.2 billion devices today.
More info
It’s scary, banks are getting compromised all the time. Nation state actors used to be primarily after confidential information. However, analysis of attacks on South Korean banks (and bitcoin exchanges!) shows that these actors (North Korea in particular) are also getting into large-scale theft and bank robbery.
Attackers compromise financial organizations and then perform reconnaissance for months and years(!) before striking. Detecting intrusion / compromise and subsequent incident response is crucial to limiting damage.
I never imagined intel would be this stupid / irresponsible; maybe there’s more behind this? Time for tinfoil hats?
In summary: everything humans produce is imperfect, don’t trust anything.
It is a miracle we don’t have major industrial control hazards / incidents on a daily basis
Major attack vectors:
The researchers showed how to inject specially-crafted ladder logic code into Programmable Logic Controllers (PLCs). The hack generates encoded radio signals that can then be received by ordinary AM radios in order to exfiltrate sensitive data from air-gapped networks.