City
Epaper

New smartphone vulnerability could let hackers track your location

By IANS | Updated: July 30, 2023 20:25 IST

San Francisco, July 30 Researchers have discovered a new vulnerability in text messaging that may enable attackers to ...

Open in App

San Francisco, July 30 Researchers have discovered a new vulnerability in text messaging that may enable attackers to trace users' location.

The research group, led by Evangelos Bitsikas, a US-based-Northeastern University PhD student, exposed the flaw by applying a sophisticated machine-learning programme to data gleaned from the relatively primitive SMS system that has driven texting in mobile phones since the early 1990s, reports Northeastern Global News.

"Just by knowing the phone number of the user victim, and having normal network access, you can locate that victim," said Bitsikas.

"Eventually this leads to tracking the user to different locations worldwide," he added.

SMS security has improved marginally since its inception for 2G networks three decades ago, according to Bitsikas. When users get a text message, their phone instantly sends a notification to the sender, which is essentially a receipt of delivery.

A hacker would use Bitsikas' approach to send several text messages to users' telephones. The timing of their automated delivery replies would enable the hacker to triangulate their location -- regardless of whether their communications are encrypted, according to the report.

"Once the machine-learning model is established, then the attacker is ready to send a few SMS messages. The results are fed into the machine-learning model, which will respond with the predicted location," Bitsikas said.

Moreover, the report mentioned that Bitsikas has discovered no evidence that the vulnerability, which has so far been exploited through Android operating systems, is actively being exploited.

"This does not mean that (hackers) aren’t going to make use of it later on," Bitsikas said.

The procedure might be difficult to scale. In order to do this, the attacker will need to have Android devices in multiple locations sending messages every hour and calculating the responses. A collection of fingerprints can take days or weeks, depending on how many are sought by the attacker, the report said.

Meanwhile, over two-thirds (68 per cent) of manufacturing companies hit by ransomware attacks globally had their data encrypted by hackers, according to the report by Sophos.

This is the highest reported encryption rate for the sector over the past three years and is in line with a broader cross-sector trend of attackers more frequently succeeding in encrypting data.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: congresspitrodadelhimodideepikabjpwest-bengaldeepika-padukoneajay-devgnthakur
Open in App

Related Stories

NationalGold Prices Dip Across India on May 16: Check City-Wise Rates Here

Entertainment‘Excited to Be Ayesha Again’: Rakul Preet Singh on De De Pyaar De Anniversary and Sequel

NationalJammu and Kashmir: Congress MLA Ghulam Ahmed Mir's Escort Vehicle Collides With Truck on Jammu-Srinagar Highway; 2 Injured

NationalDelhi: Four-Storey Building Tilts in Shahdara; Authorities Issue Notice to Vacate

National"I Regret Posting That Very Personal Opinion": Kangana Ranaut Deletes Post About Trump after JP Nadda's call

Technology Realted Stories

TechnologyHPCL empowers 28 startups with Rs 27 crore investment: Hardeep Puri

TechnologySouth Korea holds bilateral trade talks with 14 partners at APEC meeting

TechnologyKochi to host fourth Global Marine Symposium

TechnologyMizoram govt to expand digital services for public benefit, smart governance: CM Lalduhoma

TechnologyEmami's Q4 profit falls 41.9 pc QoQ, revenue drops 8.3 pc