Gabriel Gegenhuber @ Black Hat Europe 2024

In December, our colleague Gabriel Gegenhuber, researcher at University of Vienna and SBA Research, and Adrian Dabrowski (FH Campus Wien) held a talk together on WiFi Calling: Revealing Downgrade Attacks and Not-so-private private Keys at Black Hat Europe 2024.

VoWiFi (aka Wi-Fi Calling) is a convenient way for the customer to get better cell coverage while also externalizing the costs for the last mile to the customer without losing call revenue. On a technical level, this is standardized by using IPsec tunnels directly into the mobile network operator’s core network.

We found that for years, at least 140 million cellular customers worldwide were only using one of ten IPsec keys. Furthermore, a major phone chipset manufacturer allowed downgrades to key lengths well below the 3GPP specification: 768 bits, which is widely considered inadequate for a resourceful attacker.

Adrian Dabrowski
Black Hat Europe 2024
Presentation Slides
Corresponding papers and open source projects

(c) Florian Holzbauer

(c) Florian Holzbauer

(c) Florian Holzbauer