Letting old technology connect to unknown networks is never a good idea and here's a great example of that, courtesy of Google's Android security and privacy team, involving reaching too far back in time than what is safe.
Even newer 5G smartphones are able to drop down to the now ancient 2G standard, which was first implemented in Finland 33 years ago. That's called "backwards compatibility" in tech jargon, and on the face of it, a useful feature providing connectivity in case the newer mobile radio signalling protocols are not available.
However, using 2G also means you open up a can of vulnerabilities.
Enter the SMS Blasters! As the name implies, these devices are as Google says readily available on the Internet and are easy for attackers to use, to fire off Short Messaging Service (SMS) text message spam campaigns.
Said SMS Blasters are basically miniature cellular phone sites, often called Stingrays, Dirtboxes, IMSI (International Mobile Subscriber Identity, a code that IDs every phone user on a network) catchers, and rogue or false base stations (RFBs and FBSs).
They're small enough to fit into backpacks, and perfect to carry around in public spaces. SMS Blaster attacks also give a new meaning to "war driving" a term which the older geeks in the audience will recognise (I hope).
An SMS Blaster activates a bogus 4G or 5G network, that does one thing only: it tells a victim's phone to downgrade to 2G, and offers up a network running that old mobile signalling standard to connect to.
The attack drops newer security features in newer protocols such as mutual authentication, Google says, and forces connections to be unencrypted.
This enables Person-in-the-Middle (PitM) attacks to inject SMS payloads. Massive malicious campaigns are possible easily and cheaply, with hundreds of thousands of messages being sent.
Phishing, public safety alerts, you name it.
Attackers can do pretty much anything possible with SMS attacks, as they're bypassing the telco networks and able to send fully fake messages pretending to be legit senders, as they're not filtered at all.
As you can imagine, this type of attack is liable to become popular, and Google said they're taking place in lots of countries, such as France, Norway, Thailand and Vietnam.
Google is now relaying the mobile phone industry organisation GSMA's fraud and security group's warning about SMS Blasters targeting Android phones, but the vulnerability is there in any phone that supports 2G.
The 2G vulnerability has been known for some years now, exacerbated by lack of awareness and more importantly, users not being able to turn off support for the older protocol.
There will no doubt be defensive messaging from telco industry organisations on this soon, explaining how they take subscriber security seriously and why they haven't, as it appears, been slack and slow to respond effectively to a really bad vulnerability that affects millions of users around the world.
Google said that from Android version 12 running on devices that follow the Radio HAL (hardware abstraction layer) 1.6+ specification, users can turn off 2G support; Android 14 on devices with Radio HAL 2.0 and higher can also switch off the null cipher feature that enables 2G SMS Blasters to transmit payloads to smartphones.
Apple doesn't provide the same level of control, but enabling Lockdown Mode disables 2G at the cost of functionality loss.

Long story short, if you were looking for a reason to upgrade your phone, being able to do away with 2G support seems quite high on the list. Not that upgrading will work in every case. Last year, the Electronic Frontier Foundation looked into the issue, and weren't impressed with Samsung not implementing the Android security measures of being able to turn off 2G and/or disabling null ciphers (which switch off encryption).
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.