Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Plausible. Only Rogers still has working 2G.
 help



It doesn't matter what the network is doing; the phone needs to disable 2g. There's various ways to get the phone to downgrade to 2g otherwise, eg https://montsecure.com/files/2021_downgrade.pdf

Android has it as a toggle: https://source.android.com/docs/security/features/cellular-s...

iPhone disables it for phones in lockdown mode.


And if you have a modern enough SIM+phone combo, it won’t even display the 2g network as an available network, nor 3G on my device.

I wonder if this mostly hit international SIMs, since they wouldn’t be running the same level of SIM code to prefer various network locks like a local SIM.

Helps you stay under the radar and gov services over SMS is a lot more advanced outside of Canada if you want to do some fraud.


>And if you have a modern enough SIM+phone combo, it won’t even display the 2g network as an available network, nor 3G on my device.

Source? It might just be that your carrier retired its 2g/3g network, not that the phone/sim refuses 2g/3g connections. If some cell tower popped up claiming to 2g/3g, your phone still might happily connect.


source = Rogers SIM in me phone

my Telus/Bell SIM shows the 3G network tho


Unfortunately, I think there's no way for a SIM card to indicate to the phone that it would like it to please never connect to any 2G (or any non-mutually-authenticated) network.

Absent that, maybe this happens via a carrier profile (or equivalent mechanism)?


Ah, so the attack might depend on whether your phone is set to allow roaming or not. Maybe.

But I only have an option for data roaming on/off, not roaming entirely.


I don't think that matters, since the phone has no way of knowing from the SIM card alone whether it should still connect to 2G networks or not.

It sounds like a good idea to at least restrict 2G connections to non-roaming scenarios, but then you have the next practical problem: How does your baseband know that you're abroad?

Sure, all solvable at the application layer (the phone could use location heuristics to figure out where it is etc.), but not trivial and full of edge cases that could easily result in your phone mysteriously not connecting while abroad or, worse, not being able to make an emergency call or similar.


I also kinda figure there’s some magic running to “stick” to your home network where available/visible because of international border areas and people historically getting regularly upset about being roaming charges despite never leaving their home country.

SIMs can define both their home network (both implicitly since the IMSI starts with MCC/MNC of the issuer/home network, and explicitly in the form of a list of "equivalent networks", which is useful for MVNOs with their own MNC that don't want the "roaming" icon to show up) and a ranked list of preferred roaming networks. The phone should usually define those.

Of course, in some situations you might only get signal from across the border, and then none of these mechanisms can help.


I’d add in some high buildings in Toronto, if I did a network scan with a foreign SIM, I could see some US networks from over the lake, but with a Rogers SIM, they would not be visible in the scan.

That's incredible, here in Australia they not only shut down all 2G networks almost a decade ago, but they've already shut down 3G as well!

Although now looking at Wikipedia there are a lot more 2G networks sticking around than I realised, still hard for me to believe given what's happened here!


You do realize it’s a fake 2g/3g network and most phones don’t care. They will happily connect to whatever they support.

Only if they’re not already connected to a better network, no?

Funny enough its the tower that tells the cellphone modem which network is "better" and it does this in an unencrypted cell reselection message. So it is easy to force a phone to select 2G.

https://efforg.github.io/rayhunter/heuristics.html#lte-sib67...


Huh, I was going to say that this can't possibly be the case for the newer standards, but it seems like it really is the case even in 4G/LTE...

Hopefully devices at least ignore it when 2G is deactivated entirely, for those where that's possible.


Of course I realise that, but that’s irrelevant to my point.

The point was that I’m surprised how many real 2G networks there still are, and that one still exists in Canada at all.


Which is interesting in that they very publicly shut down the 3G network last year.

Probably some IoT/M2M contracts. Telus/Bell has really cut down on the spectrum allotted to their 3G that’s still up, and I doubt much is still assigned on Rogers’ 2G side.



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: