There's some regional carriers in rural areas that offer the only coverage available. Like Commnet Wireless (2). These are few and far between and usually they have deployed 3G to their whole footprint. The Big Three are building out native coverage to overlap with them. But by Murphy's Law someone with an Android 14 phone is going to discover that they can't call anything but 911. Ideally there would be a button prompt enabled in No Service situations to re-enable 2G. FCC rules mandate that cellphones must support fallback to null cipher if that's what's needed to connect an emergency call.
(1) https://www.t-mobile.com/support/coverage/t-mobile-network-e...
(2) https://www.cellularmaps.com/regional-carriers/commnet-wirel...
A US-only analysis of this seems not especially useful, since Android is used worldwide. If anything it is more popular outside of the US than inside of the US, making US-based analysis even less illuminating.
TLDR; Cellular providers make money by selling you new equipment, and they will claim a device is unsupported even when it's not true.
Getting rid of null ciphers is good though. It would be nice to also refuse weak, export, etc ciphers.
I don't think this setting does what you think it does. The description under this option has a big caveat: "For emergency calls, 2G is always allowed". So even when disabled, the phone can still use 2G networks.
It sounds like this new option is to actually disable all 2G functionality.
I'm pretty sure that it was intended that the OS UI would show you when your connection is unencrypted, but none of them do because that was undesired by state actors.
Also, even if encryption is enabled it's only for the radio part of the data transmission, not handset -> handset. Otherwise you would not be able to make calls to landlines, so isn't it already trivial for a Network Operators to decrypt your raw data? It would help for scenarios like an embassy mounting a fake base station to grab data about protestors outside it, I suppose.
Also, how can they tell if the encryption key is weakened by setting lots of bits to zero, like was done in the original version of GSM?
I would be happy to have that on a GrapheneOS phone for example, if I hadn't went with Apple.
Fix the issue now that GSM calls are rare...
This is great if the phone decides 3G or 2G connectivity is better, but I know the 4G network is faster (still slow). A downside is that if the 4G network is completely overwhelmed (e.g. on a festival), the phone might not receive phone calls or sms it'd receive if it could switch to 2G (happened to me. The phone had 4G connectivity, but SMS didn't work without allowing 2G).
i was running various jelly bean custom roms and band selection was a common feature iirc
2G is long dead.
I'll be honest. The stuff in this article is good, if a little underwhelming, but I feel a large amount of distrust for Google nowadays, to the point where what would've felt like unnecessary pessimism now feels only rational to me.
Ever since Google dropped WEI into our lives, I feel like they should not be allowed to be a part of any security efforts in any standards body or ecosystem. How long until carriers try to limit devices that don't support Google Play or Apple remote attestation of some kind?
I don't know what to think or do anymore.
If not, it’s way less interesting.
Missed opportunity to call them Mal-in-the-Middle attacks.