Beware: govts are tapping your 3G calls

An increasing number of governments around the world are using call interception devices to pick up both 2G and 3G mobile phone calls, according to Les Goldsmith, CEO of call interceptor distributor ESD Group.

Interceptor

A mobile phone call interceptor device (Credit: ESD Group)

"People have this misconception that if they're using a 3G phone their call cannot be intercepted because the 3G network provides them with a bit more security," Goldsmith said.

Mobile phone interception devices range in price from around US$100,000 for interceptors from Russia or Israel to around US$3.3 million for the devices offered by ESD Group. ESD Group only sells the devices to government agencies and Goldsmith said the company had sold interception devices in more than 16 countries.

The interceptors can store thousands of numbers in their databases and often break the security afforded by 3G encryption by forcing calls made on 3G down to the much less secure 2G spectrum.

"What the interceptors do is, when you dial a number, join the call and act as a base station instead of Telstra or Optus or the carrier you're with," he said. "The interceptor will inform the phone that you cannot make a call using 3G — it will trick your phone into switching back to 2G instead of 3G."

The cheaper interceptors can record between one and two calls at once, while the more expensive devices can record between 20 and 30 calls at one time.

If you are concerned your call may have been intercepted, Goldsmith said there were a few tell-tale signs to let people know when someone is listening in on their call.

"There are a few things that give it away, one is if their phone indicates 3G connectivity in standby mode, but when they make the call it drops to 2G," he said. "About 80 per cent of interceptors work that way. There are some instances, however, [where] they actually keep the call in 3G but turn the encryption off."

If your monthly phone bill indicates you made a phone call in a foreign country you haven't visited, that's another sign your phone has been tapped.

"Say the interceptor is in China and you're in Australia, if there's a roaming agreement between the network in China and the network in Australia, they can actually program your phone number into the interceptor in China and force every phone call you make to roam through a base station in China," Goldsmith said. "If your call seems to be delayed or it is taking longer to connect, that is a sign it may be being rerouted."

Goldsmith said that even if communication moves to a new standard such as Long Term Evolution, as long as GSM was still available on phones, it would be a vulnerability.

"If everything is still using the GSM protocol and the handset can do 3G and 2G then it will be able to drop back, and if it can drop back it is still vulnerable."

Avoiding the tap

Many organisations are combating the threat of call interception by using encrypted phones. Goldsmith says around 80 per cent of sales of phones with encryption in Australia are to corporations in the finance, legal and mining sectors, many of whom are travelling through Asia.

"China is definitely a big one and is one that is always mentioned. Just about everyone says 'I will be going to China'," he said.

CryptoPhone

CryptoPhone 400 (Credit: ESD Group)

ESD's CryptoPhone utilises voice over IP and uses AES-256 Twofish algorithms for encryption. The device is based on the HTC HD Mini platform. Goldsmith said that since it looks like just another phone it avoids intense scrutiny of customs officers overseas.

Goldsmith admits that the balance between law enforcement agencies being able to do their job and an individual's right to privacy is precarious.

"When we sell the products to secure calls we're doing it under the understanding that person purchasing the product won't use it for a criminal act," he said, adding that there are currently no restrictions on people purchasing encrypted phones within Australia.

"It's something when we introduced the product we did ask law enforcement what was done and we were told that scrutiny of [phone calls] would be an invasion of privacy," he said. "There have been cases before where individuals have in fact purchased crypto phones and then used them in activities that are not legitimate."

The Australian Federal Police was questioned on the legality of encrypted phones but had not responded at the time of writing.

Talkback

The ESD Group is not a manufacturer, we are a distributor of GSM Interceptors and GSMK Cryptophones. www.cryptophone.com.au

esdgroupesdgroup July 23rd, 2010
Report offensive content Reply (0) (0)

Hi guys, sorry about that. We've remedied it.

Suzanne Tindal, News Editor.

stindalstindal July 23rd, 2010
Report offensive content Reply (0) (0)

I note that legitimate government agencies have no need for these devices when operating in their own country. They can just get a warrant and go straight to the carrier to get the contents of the calls, no interception and decryption required.

So who are really using these devices and why? Are they for corporate spying or for government agencies operating outside the law?

thomasbeaglethomasbeagle July 27th, 2010
Report offensive content Reply (0) (0)

Hi, it might seem like an easy task to approach the network but in reality agencies monitoring calls do not want the networks to be aware of who they are targeting. Most agencies prefer to operate completely independent to the network operators. Many of the officials I know in Asia try avoiding interceptors by using new sim cards and handsets. So In this case network monitoring is not going to be accurate if the person switches networks. Network monitoring also has a limited target locating ability because it only provides the cell tower information and does not accurately show the location on a map of the target.

esdgroupesdgroup July 27th, 2010
Report offensive content Reply (+1) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

michael kors purse http://www.michaelkorshandbags-online.com/#37 ZLlrPzyxFdu

35 minutes ago by YJyqTygeShm on Kodak files for bankruptcy, sues Samsung

Google closes Motorola buy: http://t.co/9ezoLnSg

War talk dominates #AusCERT 2012 - http://t.co/WbuTt174 - #security #cyber

Nuance launches in car voice activated platform (Zack Whittaker ZDNet) http://t.co/9mFEA93c

Sage simplifies SMB payment management http://t.co/gbAKq1ku

A farewell to democracy: Kaspersky http://t.co/zE2SAGol via @zdnetaustralia

Private Cloud: 'Everyone’s got one. Where's yours?': Promising the business a cloud delivered within your own ... http://t.co/jCsDqPlj

BYOD: What the people think http://t.co/hR1pokPG

@ZDNet
R they joking? iPhone only way 2 go!
New 5 out in October (we think) & will kill all copycat phones, AGAIN!!

Android's biggest security flaws - Security - News - ZDNet Australia http://t.co/6nYZRvhh
@sjshock

Google: We now own Motorola Mobility http://t.co/oeFgovzl

@dougsteelman RT @dellsecureworks : Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Androi…http://t.co/BE4LmItr

EMC hones focus on hybrid cloud, big data http://t.co/To6Qpsz4 #bigdata #XBRL #GRC $$

#Security researcher Tim Vidas of @DellSecureworks outlines some concerns with the #Android operating system: http://t.co/gV8MgCiN

Article and Infographic: Retailers attracting the next-gen customer http://t.co/UL3E2Fct #socialmedianews

adgtqMkWiDg //www.2012chanelbagsforsale.com]chanel handbags RKaOBd krFiudOGrBw //www.2012chanelbagsforsale.com]chanel outlet GQXRRYsDNI...

5 hours ago by rfcdvpmubn on Deakin Uni opts for Cisco Unified Computing

“@Techmeme: TiVo streaming coming to iOS this summer (@jasonogrady / ZDNet) http://t.co/07L0ndoD ” < wonder if it will work in AU

Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Android operating system: http://t.co/lA4t9ffu

Why I (now) hate Apple | ZDNet - http://t.co/f5v6BWxu

A farewell to #democracy: (according to)> #Kaspersky http://t.co/82GeK5Ik via @zdnetaustralia

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

6 hours ago by Doubt on National Botnet Network coming: Earthwave

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

6 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

What is it [url=http://vintage-erotic.com/] retro xxx movies [/url]? And why all this it is possible to look free of charge?

6 hours ago by Drienlyinhibe on Australian police swoop on Warez community

Windows 8 includes enhanced multi-monitor support http://t.co/ZVfVHntw

This story has been voted 10 times in the last 24 hours!

6 hours ago, CeBIT 2012 opens: photos

Android users, you think only Apple are having security problems. See what is your major problem.
http://t.co/cjJYSOJw #infosec

RT @my_CISB: Android users, you think only Apple are having security problems. See what is your major problem.
http://t.co/cjJYSOJw #infosec

This story has been voted 15 times in the last 24 hours!

7 hours ago, Lenovo ThinkPad 3G tablet (32GB)

RT @aimee_maree: "For Buytaert, Drupal owes much of its success to being open source" http://t.co/RdnHB2y9 #Drupal

Malware charges users for free Android apps on Google Play - http://t.co/Zhnf2rtw

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

7 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

@TaschaD More information: http://t.co/8rfUsQJ0 I guess I shall simply go without.

RT @zdnetaustralia: The Westpac board have gone paperless using iPads and a secure, home-grown app environment: http://t.co/F1d17bvF ^LH

Chrome overtakes IE: does it matter? http://t.co/JRvKsVdn

"For Buytaert, Drupal owes much of its success to being open source" http://t.co/RdnHB2y9 #Drupal

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

Microsoft's big bet: Windows 8's 'too many cooks' problem http://t.co/8AdrUAWA

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

Will Windows Phone's bumpy start eventually lead to success? http://t.co/OSmxT8k6

@Wellsie777 @zdnetaustralia can be done http://t.co/jIlgdXJ4 I once had 2 phones with the same number without even trying!

ルブタンは彼が彼の靴に女性が感じる方法を好む、 クリスチャンルブタンポンプ これは彼がそれらを...

8 hours ago by Coiffboarieri on Reservoir blogs: Fan fakes Tarantino diary

US, Australia team up on cybersecurity - Security - News - #ZDNet Australia http://t.co/rG2aTskD

RT @justinbarbour: Great piece from @joshgnosis that looks at @DobellThommo's claim that his phone was cloned. http://t.co/DpK6bJE7 #auspol

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

10 hours ago by debsteele on Vic scraps HealthSMART system

Interesting - no mention of Win 98/ME/2000 ... which heralded Internet access for millions of users ? I thought Win 98/ME would be the mo...

11 hours ago by gouranga on Microsoft admits Vista was 'cheesy'

An Application like Good from Good Technologies does the same thing, working with the enterprise email server and is off the shelf.

11 hours ago by Helpdesk123 on Westpac board goes paperless with iPads

Never mind a "B+" version, go for "C" and put in a few extras. I'd like a high speed ADC (100Msps) but that's just me... Final size? Equ...

12 hours ago by sa_penguin on Raspberry Pi architect mulls design change

what a non-story. these thing happen all the time. is zdnet short on material?

13 hours ago by paulwrussell on Spotify launch suffers redirect bungle

4 months old phone died. Took 6 weeks, three visits to the authorised repairer (Fonebiz) to "fix it". 2nd hand untested parts used, I say...

13 hours ago by paracin on Sony Ericsson Xperia Arc S

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

14 hours ago by ramnet on Microsoft admits Vista was 'cheesy'

If Vista is cheesy, Metro is an over-ripe Stilton.

14 hours ago by meski on Microsoft admits Vista was 'cheesy'

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

14 hours ago by rant rant rant on National Botnet Network coming: Earthwave

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

18 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

1 day ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

1 day ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

1 day ago by anonymuos on Microsoft admits Vista was 'cheesy'

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar