• sunzu2@thebrainbin.org
    link
    fedilink
    arrow-up
    0
    ·
    3 days ago

    However, most cellphones will automatically attempt to use a downgraded connection (5G -> 4G) if they lose connection with the tower.

    Is 4g actually less secure?

    I thought it was fine… Down grade attack is done via 2g/3g which have no security

    • FauxLiving@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      3 days ago

      They downgrade to 2G, whose encryption is cracked trivially with modern hardware and there’s no tower authentication so it’s possible to have the phones connect through the css.

      Disable 2G (or use GrapheneOS) and you’ll mitigate this specific attack.

      3G and 4G have some flaws themselves(from Blackhat ‘17: https://youtu.be/BFkrK5kaH4o)

      • sunzu2@thebrainbin.org
        link
        fedilink
        arrow-up
        0
        ·
        3 days ago

        Damn… So 5g only should be used?

        I was operating under idea that 4g was better than 5g for privacy and security. I guess I need to hit the books again

        Never heard being

          • sunzu2@thebrainbin.org
            link
            fedilink
            arrow-up
            0
            ·
            3 days ago

            Ohh i am balls deep into privacy game.

            Just trying to sort out if 5g is better over 4g here for daily activities.

            5g uses more battery so I generally stay on 4g but if 4g is less secure, might need to go with 5g

            Also, doesnt 5g provide telco with with you position too?

            IE they can tell you are on 5th floor v 15th

            • FauxLiving@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              3 days ago

              Yeah, 5G uses beamforming so they know where you are with pretty high accuracy.

              Nothing will prevent them knowing your location, if you’re transmitting a signal it can be located with WWI level technology. But the providers do log that data so it can be available for law enforcement.