Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

EVER BEEN TO SANTO DOMINGO? OUR CELL PHONE HAS

September 8, 2008

Apparently, cell phone cloning (not the animal kind) is a reality. We know, because we’ve had first hand experience. If you can believe it, we have a cell phone without a camera. Because we have several computer forensics testifying experts here, we decided to get a camera-less phone to take to our local courthouse, which is camera-free. It is rarely used and sits on John’s desk connected to a charger for most of its operational life. After one recent court visit, our staff was distraught that they couldn’t contact us via our “court” phone. Mysteriously, the number was no longer in service. As it turned out, Verizon had killed the phone access.

After being transferred to Verizon’s fraud department, we learned that the phone had been cloned and was making calls from the Dominican Republic. Imagine our surprise that we weren’t the ones on the beach making those calls. The bad news is that there was a security vulnerability for our Palm Treo 700p that allowed someone to “sniff” the ESN (Electronic Serial Number) and phone number of the phone. Armed with those two bits of information, the bad guys could program those values into another phone so it looked just like ours. The good news is that the phone now has the security patch and Verizon’s fraud department shut the service down as part of their fraud detection program. Apparently, their computers know that we don’t normally make a boatload of calls from the Dominican Republic. More’s the pity.

There were over $400 worth of roaming calls made from Santo Domingo within a two day period. Our account has been credited and they’ll probably never catch the responsible party. John even called our friend and local police detective to report the incident. His reaction was “Cool! I’ve read about that, but never knew it could actually be done.” He’s also a forensic examiner so hi-tech is in his blood. Thanks for all the sympathy Detective!

And remember to keep your cell phone patched!

E-mail:      Phone:          703-359-0700