Hacker News new | ask | show | jobs
by tomlongson 3848 days ago
Android IMSI-Catcher Detector: https://secupwn.github.io/Android-IMSI-Catcher-Detector/

SnoopSnitch: https://play.google.com/store/apps/details?id=de.srlabs.snoo...

3 comments

AIMSICD is very faulty. I made full code review in my spare time and tests on OpenBTS. It can't detect SilentSMS even if they claim it can. It doesn't detect fake BTSs nor connections using them. You can connect to fake BTS, make calls, send texts, it doesn't detect anything suspicious. This project sounds serious, but it doesn't do anything. Moreover it sends data about fake BTSs to remote service - OpenCellId (they get data about cells from OCID). Recently all of this what I say here was proven on their issue board on Github.

https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/iss...

Next week I will put my hands on SnoopSnitch.

This is SecUpwN, the project maintainer of mentioned app. Let me say this: Before discrediting an eager project like ours, RTFM! Obviously you closed your eyes the whole time when doing the "full code review", otherwise you would have read:

* https://github.com/SecUpwN/Android-IMSI-Catcher-Detector#war...

* https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/blo...

* What is the first thing popping up in our app? Right, our DISCLAIMER!

Bummer, huh? Furthermore, where are your contributions to below Issue?

* https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/iss...

Everyone with a pair of eyes is able to clearly see the warnings, disclaimers and statements all over our project that our app is still in ALPHA development. And if you really are a skilled developer and not just a troll wanting to discredit our app in favour of making another one more popular (which I think you actually are), you'd have contributed. But you're just a fake "security researcher", ranting on public sites about an open source project where everyone is invited and very welcome to add a bit to make it better. Next time, please think twice before publishing shit like yours above.

I have used both apps before.

SnoopSnitch only works on specific Qualcomm chipsets. If you want to use IMSI-catcher detectors, make sure it actually works with your specific chipset.

AIMSICD eats a decent amount of battery as it really needs GPS to be useful as a historical data source.

Both of these apps are available on F-Droid for those that prefer that distribution method.