Sponsored By

Were Vodafone Femtocells Hacked?Were Vodafone Femtocells Hacked?

Modern cellular networks can generally be counted on for fairly good security, which is why this story was shocking.

Michael Finneran

July 15, 2011

1 Min Read
No Jitter logo in a gray background | No Jitter

Modern cellular networks can generally be counted on for fairly good security, which is why this story was shocking.

Modern cellular networks can generally be counted on for fairly good security, which is why it was shocking to read that hackers were able to rewrite the software in Vodafone Sure Signal femtocells allowing them to be used to record any voice call made through them. Not only that, the hacked femtocells could then be used to place calls or send SMS messages on somebody else's SIM card once their phone is registered with the hacked femtocell.

According to The Hacker's Choice (THC), the exposure stems from the fact that all the Vodafone femtocells use the same root password. Based on that, the culprits were able to access the core software of the device and rewrite it; the details are provided on their Wiki.

This was not a simple project. There are a number of safeguards on the femtocells, including one that would allow Vodafone to access and disable it remotely. The function was hardware based, but they claim to have been able to thwart it with a soldering iron.

In a press release issued July 13, Vodafone says, "The claims regarding Vodafone Sure Signal...relate to a vulnerability that was detected at the start of 2010. A security patch was issued a few weeks later automatically to all Sure Signal boxes."

We’ll be watching this story as it develops.

About the Author

Michael Finneran

Michael F. Finneran, is Principal at dBrn Associates, Inc., a full-service advisory firm specializing in wireless and mobility. With over 40-years experience in networking, Mr. Finneran has become a recognized expert in the field and has assisted clients in a wide range of project assignments spanning service selection, product research, policy development, purchase analysis, and security/technology assessment. The practice addresses both an industry analyst role with vendors as well as serving as a consultant to end users, a combination that provides an in-depth perspective on the industry.

His expertise spans the full range of wireless technologies including Wi-Fi, 3G/4G/5G Cellular and IoT network services as well as fixed wireless, satellite, RFID and Land Mobile Radio (LMR)/first responder communications. Along with a deep understanding of the technical challenges, he also assists clients with the business aspects of mobility including mobile security, policy and vendor comparisons. Michael has provided assistance to carriers, equipment manufacturers, investment firms, and end users in a variety of industry and government verticals. He recently led the technical evaluation for one of the largest cellular contracts in the U.S.

As a byproduct of his consulting assignments, Michael has become a fixture within the industry. He has appeared at hundreds of trade shows and industry conferences, and helps plan the Mobility sessions at Enterprise Connect. Since his first piece in 1980, he has published over 1,000 articles in NoJitter, BCStrategies, InformationWeek, Computerworld, Channel Partners and Business Communications Review, the print predecessor to No Jitter.

Mr. Finneran has conducted over 2,000 seminars on networking topics in the U.S. and around the world, and was an Adjunct Professor in the Graduate Telecommunications Program at Pace University. Along with his technical credentials, Michael holds a Masters Degree in Management from the J. L. Kellogg Graduate School of Management at Northwestern University.