Tobias Engel & SRLabs Disclose SS7 Location Tracking at 31C3
Tobias Engel and SRLabs demonstrated at 31C3 that SS7 design flaws allow global subscriber location tracking, call interception, and SMS 2FA theft using legally obtainable access to the signaling network.
01Video Presentation & Conference Keynote
02Deep-Dive Technical Analysis
By sending SS7 MAP-ATI requests to home location registers, attackers retrieve a target's current cell ID coordinates anywhere on earth; MAP-SRI-for-SM requests divert incoming SMS, capturing one-time-passcode 2FA tokens; UpdateLocation calls enable call interception via rogue roaming. The demonstration used a homebrew gateway costing under EUR 1,500 connected through a roaming hub with no Global Title whitelist — the implicit trust of 1988 exploited with commodity hardware.
03Vulnerability & Exploit Flow
Unverified MAP-ATI cell location query & MAP-MT-ForwardSM interception.
04Recommended Defense & Mitigation Protocol
Deploy GSMA Category 1, 2, and 3 SS7 Firewalls with velocity checking.
05Security Impact & Geopolitical Consequence
Triggered GSMA FS.11/FS.40 signaling firewall guidelines, 3GPP TS 33.210 interconnect protection profiles, and a wave of national CERT mandates for MNO signaling firewalls.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.