Hacker News new | past | comments | ask | show | jobs | submit login

I think this vulnerability potentially has the biggest real-world impact. This has been shown in a couple of proof-of-concepts… Merging this into public repos would have zero positive impact, I think.



I'm inclined to agree with you there. Anyone that wanted to do it could figure it out anyway from the standards docs and broadcast the right data in the SIBs, but it is probably better not available as a "click and run" type setup.

Although in saying that, this is unlikely to change any time soon, as the idea of CB/PWS is to provide an emergency message that can be highly time sensitive in some scenarios (earthquake, tsunami, etc.) without delays due to authentication etc. Failing to show the message could be higher risk than showing a false message in a very localised area (based on what someone with an SDR can send.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: