Hacker News new | ask | show | jobs
by akerro 3849 days ago
AIMSICD is very faulty. I made full code review in my spare time and tests on OpenBTS. It can't detect SilentSMS even if they claim it can. It doesn't detect fake BTSs nor connections using them. You can connect to fake BTS, make calls, send texts, it doesn't detect anything suspicious. This project sounds serious, but it doesn't do anything. Moreover it sends data about fake BTSs to remote service - OpenCellId (they get data about cells from OCID). Recently all of this what I say here was proven on their issue board on Github.

https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/iss...

Next week I will put my hands on SnoopSnitch.

1 comments

This is SecUpwN, the project maintainer of mentioned app. Let me say this: Before discrediting an eager project like ours, RTFM! Obviously you closed your eyes the whole time when doing the "full code review", otherwise you would have read:

* https://github.com/SecUpwN/Android-IMSI-Catcher-Detector#war...

* https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/blo...

* What is the first thing popping up in our app? Right, our DISCLAIMER!

Bummer, huh? Furthermore, where are your contributions to below Issue?

* https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/iss...

Everyone with a pair of eyes is able to clearly see the warnings, disclaimers and statements all over our project that our app is still in ALPHA development. And if you really are a skilled developer and not just a troll wanting to discredit our app in favour of making another one more popular (which I think you actually are), you'd have contributed. But you're just a fake "security researcher", ranting on public sites about an open source project where everyone is invited and very welcome to add a bit to make it better. Next time, please think twice before publishing shit like yours above.