|
|
|
|
|
by ticoombs
984 days ago
|
|
HA! In a serious note, this will most likely never be patched. SS7 vulnerabilities have been know for even longer but the sheer effort needed to collaborate between every single company, manufacturer and policy makers make it a non starter. Also having the possibility of making it so all old phones no longer get these messages could also be an accessibility problem that gets whomever tries to run with it kicked out of office. With current climates being 3/4 years max in office with the possibility the next person will scrap whatever you do... makes it a hard problem to solve. |
|
Over time it would supplant the old one and the vast majority of people would get the secure alert today.
During an emergency you’d send both but spoofs would only be able to hit old phones that don’t receive software updates / don’t support the secure variant.
Securing is also pretty simple since the government could just publish the public key they’ll use for signing these alerts and OS vendors could refresh that key on a regular basis.