Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?


Compared to this? Ridiculously hard. A5/1, while severely compromised, still requires heavy IOPS and computing power to break quickly with rainbow tables (see Kraken).

Even worse: this allows for trivial spoofing. You're far, far away from doing that with SMS.


Actually, SMS spoofing is arguably easier than WhatsApp spoofing.


Compared to sniffing data over public wifi, pretty hard.


Armed with this blog post and a laptop, you could start spying on IM traffic in your local coffee shop in five minutes. I don't know where you'd even begin with spying on SMS, but I bet that in the least it requires substantially more specialized equipment.


Yeah, it requires specialized equipment, but that's really the biggest barrier. From a protocol standpoint it isn't really any better.


I'm no SMS engineer, but I'm pretty sure SMS is stuffed in one of the ping packets used to keep the phone connected to the cell towers.


It's sent on the control channel, not the payload channel. But that's not the important bit - This is: to sniff wifi you need a computer with wifi and a freely available, easy to use program. To sniff GSM you need a rather elaborate setup.

It's not that it's "hard" to sniff SMS in a crypto-sense, it's just that that bar is a lot higher that sniffing unencrypted wifi traffic.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: