Skip to main content

Meet the $250 Verizon device that lets hackers take over your phone

femtocell verizon hack samsung
Femtocell Image used with permission by copyright holder

If you’ve never heard of a femtocell, now would be a good time to learn.

At the Black Hat hacker conference in Las Vegas, NV, on Wednesday, a pair of security researchers detailed their ability to use a Verizon signal-boosting device, a $250 consumer unit called a femtocell, to secretly intercept voice calls, data, and SMS text messages of any handset that connects to the device.

A femtocell is, basically, a miniature cell phone tower that anyone can use to boost their wireless signal in their home. Most of the major U.S. wireless carriers sell femtocells, as do other retailers, and they can typically be purchased for $150 to $250.

For a cell phone or tablet to connect to a femtocell, it must be within 15 feet of the device, and remain within 40 feet to maintain a connection, explains Doug DePerry of security firm iSEC Partners and one of the researchers who discovered the vulnerability. But when your device does connect to the femtocell, you will not know it.

femtocell-talk
Image used with permission by copyright holder

“Your phone will associate to a femtocell without your knowledge,” says DePerry. “This is not like joining a Wi-Fi network. You don’t have a choice.”

The iSEC Partners team, led by DePerry and fellow researchers Tom Ritter and Andrew Rahimi, successfully tapped into the root of two femtocells sold by Verizon and manufactured by Samsung, which allowed them to intercept SMS messages in real-time, and even record voice calls.

During a demonstration of their exploit, Ritter and DePerry showed how they could begin recording audio from a cell phone even before the call began. And the recording included both sides of the conversation. The duo also demonstrated how it could trick Apple’s iMessage – which encrypts texts sent over its network using SSL, rendering them unreadable to snoopers, including the NSA – into defaulting to SMS, allowing the femtocell to intercept the messages.

“If you block the SSL connection back home to Apple, iMessages fails over to SMS, which is plain text,” explains Ritter. “And that we can see just fine.”

In their final demonstration, DePerry and Ritter showed off their ability to “clone” a cell phone that runs on a CDMA network (like Verizon’s) by remotely collecting its device ID number through the femtocell, in spite of added security measures to prevent against cloning of CDMA phones. Once a phone is cloned to another handset – meaning the network thinks both phones are the same device, assigned to a single account – a hacker can make expensive phone calls (i.e. 1-900 numbers), or use excessive amounts of data, and the charges are all attributed to the cloning victim.

Because both the cloned phone and its evil twin device must be connected to a femtocell to work – “any femtocell,” says DePerry, not just one that’s been hacked – the cloning dangers are limited. However, when it comes to intercepting calls and text messages, the eavesdropping potential is significant – especially if someone with a hacked femtocell sets up camp in a heavily trafficked area, like Times Square, to listen in on passersby.

Fortunately for Verizon customers, the company has since issued a patch to all affected femtocells. Sprint currently offers a femtocell that is similar to the vulnerable models from Verizon, but the company has said it plans to discontinue the device. And while AT&T also offers femtocells, it requires an extra level of authentication that makes much of the iSEC Partner’s findings irrelevant. Still, says Ritter, the femtocell vulnerability is a major problem.

“It’d be easy to think this is all about Verizon,” says Ritter. “But this really about everybody. Remember, there are 30 carriers worldwide who have femtocells, and three of the four U.S. carriers.”

Ritter suggests that all carriers that offer femtocells require owners to provide a list of approved devices that are allowed to connect to their femtocell. And also prevent customers’ cell phones from connecting to any unauthorized femtocell.

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
The Google Pixel 8a is official. Here’s everything that’s new
Someone taking a phone call on the aloe Google Pixel 8a.

A week ahead of its annual developers' conference, Google has dropped a new budget phone in its Pixel-A series. The Google Pixel 8a retains the line’s signature look with a horizontal camera island at the back, but serves it in a package that embraces rounded corners and also happens to be fractionally smaller and lighter

The most meaningful changes are reserved for the display, silicon, and battery. The OLED screen’s size remains the same at 6.1 inches with a resolution of 1080 x 2400 pixels. However, the refresh rate has been increased to 120Hz, up from the Google Pixel 7a's 90Hz display. This HDR-ready panel offers a peak brightness of up to 2,000 nits and also features a fingerprint sensor underneath.

Read more
Apple has quietly killed its cheapest iPad
Three 2021 iPads are stacked on a table.

The iPad lineup has received a price bump after Apple quietly killed its cheapest iPad model. Apple’s 9th-generation iPad used to cost $329, but has been discontinued. At the same time, the company has reduced the 10th-gen iPad’s starting price by $100, which means it’s now priced at $349. As a result, getting the cheapest iPad means you'll now spend $20 more than before.

The 9th-gen Apple iPad was launched in 2021 with the A13 chipset and Apple's Center Stage featur,e but retained the same old design with the already-old Lightning port and home button. With Apple moving to a USB-C port on all devices to comply with EU laws, it was inevitable that Apple would discontinue the 9th-gen iPad this year. The iPhone SE remains the only Apple product with a home button and a Lightning port that's still available in the company's lineup.

Read more
Best iPhone 15 deals: How to get Apple’s latest iPhone for free
The display on a green iPhone 15.

The Apple iPhone lineup isn’t often a place to turn for a discount, as Apple deals can be somewhat difficult to come by. The best phone deals often turn up discounts on less premium brands, but there are some ways to save on the iPhone 15, which is Apple’s most recent iPhone release. You’ll find some of the best iPhone 15 deals scattered across retailers, which is why we’ve done some of the heavy lifting and organized them all below. Among the best iPhone deals you’ll find below are some impressive savings even if you don’t have an old device to trade-in.

You can also shop the best refurbished iPhone deals if you’re looking for ultimate savings, and there are plenty of iPhone 14 deals to shop if having the most recent iPhone release isn’t of importance to you.
Today's best iPhone 15 deals

Read more