Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

International Cellular Roaming – Am I Secure?

By Sean Lawless on November 21, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

Many firms have strict international travel policies in relation to the use of technology. These policies tend to be more skewed towards countries with greater state control over communications networks and specifically the internet. However, the reality is that you are vulnerable whenever your device is roaming internationally. When roaming, local providers use a global interconnection network to get you back to your home provider. Most traffic on this network uses the SS7 protocol which is known to be vulnerable to location tracking, eavesdropping, SMS interception, etc. This is nothing particularly new or eye-opening for security experts.

What is somewhat new is the Long-Term Evolution (LTE) standard. The first commercial device that was LTE capable was introduced in 2011 but LTE did not become readily available until 2013-2014. With the adoption of the LTE standard, the global interconnection network traffic was supposed to switch to a new more secure protocol named Diameter. In theory, Diameter is more secure because it supports the use of Internet Protocol Security (IPsec) for IP traffic. IPsec authenticates and encrypts each packet of IP traffic. However, while the implementation of IPsec is mandatory with Diameter, its use is optional. This means that many of the vulnerabilities that were present previously under the SS7 protocol can still be leveraged today under Diameter.

Researches from Nokia Bell Labs and Aalto University in Finland ran several experiments to show the potential vulnerabilities still present under Diameter. They presented their finding recently at the Black Hat Europe security conference in London.

International Travel Policies, while often seen as inconvenient and overly precautious, are geared to help protect you and your firm from these technology short-comings. So the next time you are on an international business trip and missing your favorite firm connected device, blame the hackers, not your CSO.

Click here for additional information.

Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo