Exposing The Flaw In Our Phone System

Exposing The Flaw In Our Phone System

Source: YouTube · Veritasium · published Sep 21, 2024 · 31:54

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

We demonstrated how SS7 vulnerabilities can be exploited to intercept phone calls, texts, and two-factor authentication codes—showing that even a normal-looking phone can be compromised remotely. 0:27

Key Takeaways:
• SS7, the backbone of 2G/3G networks, allows attackers to intercept calls and messages by exploiting weak authentication and roaming protocols 1:59.
• Attackers can reroute calls to a controlled number, making it appear as if the victim received the call when they didn’t 3:33.
• SMS two-factor authentication codes can be stolen in seconds during interception, enabling account takeover 18:26.
• Location tracking via SS7 is possible without GPS, pinpointing users to within a hundred meters in urban areas 21:45.
• Real-world cases, like the abduction of Princess Latifa, show SS7 attacks can be used to locate and target individuals 22:48.

SS7 remains a serious threat due to its widespread use and lack of global replacement, despite being vulnerable to abuse. Users should avoid SMS-based 2FA and use encrypted messaging apps like Signal or WhatsApp 30:14.

Sources:

  • 0:27 SS7 vulnerabilities allow remote call and message interception.
  • 1:59 Blue Box and SS7 origins show historical roots of phone network hacking.
  • 3:33 Call rerouting exploits roaming and GT trust systems.
  • 18:26 SMS two-factor codes can be stolen in seconds.
  • [21:45](https:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

  • This is Linus from Linus Tech Tips and we hacked the phone
    network in order to spy on him. - That's pretty messed up Derek. I slept easier not knowing that. - We intercepted his phone calls and stole his two-factor passcodes. Is that your number Linus? - Yeah, but I didn't get,
    mine didn't even ring. - We didn't touch his phone. We didn't send him an
    email or a text, nothing. We did it all remotely
    and the worst part is it could happen to you. - I think I'm really
    surprised that, no offense, but like you guys did it. (Derek Laughing) Well, you're not a career
    criminal hacker mastermind, necessarily.
  • No, indeed. - But here it is, a normal looking and feeling device with no,
    you know, obvious problem with it and you just receive my call instead of me receiving it. Just what, like on comm…