Critical vulnerabilities in SS7 telephony protocol found; tested techniques can decrypt cell phone calls and texts
Craig Timberg / Washington Post :
Context & Ripple Effects
This Washington Post report is the opening move in what became a half-decade arc of SS7 coverage. The disclosure that tested techniques can decrypt cell calls and texts set the stage for security expert Karsten Nohl's on-air eavesdropping demonstration two years later, which showed the same attacks work knowing nothing but a phone number.
The story also framed the political fight that followed: when DHS flagged the protocol's flaws, [[a:920724|Verizon and AT&T's lobbying group dismissed them as "theoretical" in a document sent to Congress]], and by 2019 the FCC's reliance on telecom industry advice had left the protocol still flawed after decades.
First-order effects
- Mobile subscribers' voice calls and text messages are directly exposed: the demonstrated decryption and tracking techniques mean carrier networks cannot guarantee the confidentiality of ordinary phone traffic.
Second-order effects
- US carriers are forced into a defensive posture rather than a remediation one — their lobbying arm's 'theoretical' framing to Congress shows the commercial incentive is containment of the issue, not protocol replacement.
Third-order effects
- Because SS7 underpins SMS-based authentication, its weaknesses migrate into other industries: attackers who can intercept texts can capture two-factor banking codes and empty customer accounts, making telecom's legacy security problem everyone else's fraud problem — and leaving SMS two-factor itself on borrowed time.
The trend: Global telecom security is drifting toward a structural reckoning where signaling protocols designed before hostile access existed — SS7 chief among them — get patched piecemeal while regulators defer to the carriers they oversee.