A guide to mobile data network SS7 and its vulnerabilities, which can be exploited to track cell phone users and intercept their communications
Kim Zetter / Wired : Tweets: @mattk Tweets: Matt K / @mattk : I guess we all need to talk about it more until someone fixes it http://twitter.com/...
Context & Ripple Effects
Kim Zetter's guide lands at the peak of a multi-year disclosure arc: researchers first showed tested techniques to decrypt calls and texts over SS7's telephony protocol in late 2014, and weeks before this piece Karsten Nohl demonstrated on 60 Minutes that a phone number alone was enough to eavesdrop on calls and texts. The guide matters because it converts those demonstrations into a plain-language map of how the global carrier signaling system leaks location, messages, and authentication codes.
The stakes are institutional as much as technical: a year later, after DHS flagged the flaws, Verizon and AT&T's lobbying group would dismiss them as "theoretical" in a document to Congress, and by 2019 Ars Technica reported the protocol remained flawed partly because the FCC leaned on telecom industry advice — the same industry whose networks were exposed.
First-order effects
- Any actor who learns a subscriber's phone number can, per the documented techniques, geolocate their device, intercept calls and texts, and harvest the SMS two-factor codes that guard email and web accounts — with carriers unable to distinguish legitimate roaming signals from attacks.
- Carriers and handset-dependent services bear the immediate exposure: every subscriber on SS7-routed international roaming inherits the vulnerability regardless of which operator they pay.
Second-order effects
- Carrier trade groups are pushed into a defensive posture rather than a remediation one — the Verizon-AT&T lobbying group's "theoretical" framing to Congress shows incumbents managing political risk instead of patching a protocol they don't control unilaterally.
- Attack surface migrates down the stack: once signaling is understood as compromised, attackers move to adjacent layers, as the later SimJacker flaw exploited from a SIM card by a private contractor working with governments demonstrates.
Third-order effects
- If the pattern holds, mobile network security stays structurally weak wherever a decades-old trust-based protocol underpins international roaming — regulators deferring to industry advice means fixes arrive endpoint-by-endpoint rather than network-wide, leaving geolocation and interception capabilities available to state-adjacent private actors, as Citizen Lab's later research on roaming-signaling exploits confirmed.
- Two-factor authentication delivered over the compromised channel becomes a systemic liability, pushing account-security design toward out-of-band methods for anyone who takes SS7's documented weaknesses seriously.
The trend: Mobile network signaling is hardening into a persistent surveillance layer: as long as SS7-era protocols anchor international roaming and regulators defer to carrier advice, tracking and interception remain a serviceable capability for governments and their private contractors.