logoalt Hacker News

immibislast Wednesday at 10:55 PM0 repliesview on HN

"SS7 redirection attacks" means, more concretely, "hacking into some phone company that's connected to the one you want to redirect, and using that system to send false data to the one you want to redirect".

It's BGP hijacking but for the phone system. If Comcast is connected to Verizon, and I want to hack your connection to Google, and you're on Verizon, one of my options is to hack Comcast and have Comcast tell Verizon that Comcast has a really fast connection to Google. It might let me intercept your traffic if circumstances are good; it's also fraudulent and illegal through and through. If caught, I will go straight to federal prison.

(Of course the analogy isn't 100%. The set of things you can do by hacking one side of a SS7 link is not identical to the set of things you can do by hacking one side of a BGP link - in particular, there's no BGP roaming. But it's a similar principle.)