Re: Facepalm
It feels a *little* over-egged if I’m honest. There’s some truly interesting and impressive work in there, particularly around the engineering side. Winning the race condition between the UE and gNB is far from trivial!
On the impact front they’ve gunned for headlines a bit. They can capture the SUCI from <20m away. At that distance you may as well take the lad’s photo and run it through a reverse image search if you want to ID him. The SUCI is useless for that purpose - that’s its entire function! The SUCI can be abused as a session identifier, but not a permanent device identifier. You can say “this SUCI moved from the office at 123 Blah Street to Wetherspoons at lunchtime” but you can’t correlate that with other movements on other days, or even as they state themselves, between the UE going into and out of a lift/other poor signal area. If the UE loses signal and needs to handshake again, it’s using a new SUCI.
If they’d managed to get a SUPI then that would be proper news! Not a great analogy, but think of it a bit like sniffing a TLS handshake (the SUCI in this example) vs the private key (the SUPI). The SUCI is expected to be exposed by design.
The attacks were mostly performed against non-realistic gNBs (basically test gear). When they used a proper one they discovered that they absolutely hammer bandwidth so there was no “slack” for them to inject messages and their success rate (already not great at 80%) tanked. Tbf attacks only get better, but there’s still a lot of getting better to do :D
They say that the benefit of their attack is it doesn’t require a rogue base station so it’s much harder to passively detect (they can use beam forming etc to ensure only the target UE “sees” their messages). Then, the only interesting actual attack (4G downgrade) uses a rogue base station :D The downgrade is interesting, but there’s no evidence it works on anything recent, and it’s wholly detectable.
Finally, the UEs weren’t exactly brand spanking new. Pixel 7?! Sure, plenty of people outside of the US/Western Europe etc are using older models, but are they even supported any more?
Like I say, great engineering, shit sample sizes, poor headline grab.