View Single Post
Fargus's Avatar
Posts: 1,217 | Thanked: 446 times | Joined on Oct 2009 @ Bedfordshire, UK
#57
Originally Posted by R-R View Post
How is the IMSI protected ?

Carriers usually don't care about the IMEI cause they let you change your phone (my understanding) but the IMSI is your account number which links to your usage, etc...

It would probably be easy to find where the IMEI is sent and change it on the fly with some LD_PRELOAD or other techniques, but I'm guessing that the IMSI is in the smart card and has some form of crypto handshake with the provider?

Or is this just a receipt for fun^W disaster?

EDIT: http://en.wikipedia.org/wiki/IMSI-catcher
Also interesting, we should make sure the N900 show that (!) when it's not using encryption!

Also interesting: http://www.gsm-security.net

EDIT2: Uhm, of course there is a handshake, no multi-IMSI backup for multi-line use hehe (unless someone give you the key stored in the SIM, which, won't happen! ;-)
But still, changing the IMEI could be useful for those stuck with data plans tied to a specific device!
Just a thought - some carriers send out new SIM cards on a regular basis. Are we sure that when this happens that the IMSI is migrated to the same number on the SIM? If not then I suppose we ought to allow for this possibility in any app requiring this functionality.

The other thought is when someone changes their account but retains their number etcetera. Not so much a technical issue but something worth thinking about as use-case.