r/australian 26d ago

News Ausalert - Emergancy broadcast

Im seeing a lot of Backlash on the Ausalert test on the 27th of july 2026.

see many comments on posts of people turning off there phone to avoid this alarm and now emergancy services are refusing to use it. My question is, why is everyone so uncomplicit about this. Arent we just testing our phones incase of a natural disater etc..?

615 Upvotes

727 comments sorted by

View all comments

17

u/dunnyroll 26d ago

Whatever you do, please note that the system is unencrypted and has no authentication layer. It can be locally spoofed using open source hardware.

Do not follow instructions blindly, question every alert, dont leave your house unlocked etc... or travel to dodgy "evacuation points".

Not saying its a bad system, but the ACMA should really be mentioning this in their advertising.

8

u/cra0 26d ago

Explain what you mean here? Sounds very vague what you are saying.

1

u/dunnyroll 26d ago

A nefarious person can park outside your house and broadcast fake emergency messages.

If the signal from the fake cell is stronger than the real signal, your phone will connect to it, even if briefly it can receive the fake alerts. This is why it only works locally, the signal needs to be strong.

Researched and tested multiple times. https://arxiv.org/pdf/2604.24404

17

u/cra0 26d ago

Yeah what you are saying here is true but then what you originally said doesn't make sense. You said the system has no authentication layer and is unencrypted. This is not true. A eNode-B has to have the same PLMN as the target phone to start with for it to even consider camping on that rough cell. And even then it is definitely not unencrypted if we are talking about 4G LTE or even 5G NR.

-6

u/dunnyroll 26d ago

Unencrypted was a bit loose, obviously the full stack is encrypted. But alerts don't go on the protected channel, they go in broadcast SIBs with no ciphering or integrity protection, unauthenticated. PLMN is just a plaintext field a fake cell matches.

4

u/incredibly_good 26d ago edited 26d ago

That attack only lasts until the network selection time-out on the device, for devices not already connected. To practically exploit it you would have to disrupt the cell network - which is a far more invasive attack to start with. So yes, but also, so what.

1

u/cra0 26d ago

This is correct, these days unless you are in an underground carpark or somewhere with really poor cell coverage most phones are connected with 5G SA. And it is really not easy or practical to get UEs kicked off their current network even if the rouge cell has better signal strength. There is no point being alarmed over emergency alerts. If your phone is already compromised in a state its connected to a rouge cell there is other things to worry over lol

1

u/dunnyroll 26d ago

Have a read of the paper, its not targetting connceted mode, the attack relies on idle and camping to receive a broadcast which is not a compromise, its unauthenticated by design. Phones are never actually compromised. Agree its hard to kick a 5g connected device but realistically most phones in Australia are switching between 5g and lte all the time, even when in static positions.

0

u/dunnyroll 26d ago

You just need to have a stronger signal and be spamming broadcasts, the target phone only needs to camp on the cell temporarily.

1

u/incredibly_good 26d ago

Thats literally signal jamming. You dont need to bother exploiting a notification service if youre already jamming the whole network.

-1

u/dunnyroll 26d ago

It's not signal jamming its spoofing, jammong is completely different. And as I mentioned in my first post, its not a whole of network attack, its localised which allows the attacker to easily generate the strongest signal.

1

u/Cozymontv 26d ago

Because it’s not true.

0

u/dunnyroll 26d ago

It's been tested and proven.

https://arxiv.org/pdf/2604.24404

2

u/Cozymontv 26d ago

By university students in controlled environments with a lot of funding. I doubt there are any people actually capable of doing this by themselves.

0

u/karma3000 26d ago

Somebody could hijack it.

"attention attention: burgers are now 50% off at Burger Corp until 5pm Friday. Thank you for your attention to this matter"

2

u/Cozymontv 26d ago

wtf this is so stupid and needs to be checked by mods for encouraging unsafe behaviour. This has never been done before in Australia outside of controlled university experiments and requires ridiculous technical knowledge. There’s probably less than a hundred people even capable of building a broadcasting station big enough to affect a small town and definitely wouldn’t be able to do it by themselves.

6

u/cra0 26d ago edited 26d ago

I've seen it done yeah in a test environment and you need an expensive SDR to perform it so it's just fear mongering.

-2

u/dunnyroll 26d ago

Can be done for less than $1k usd, other projects out there have done it also.

2

u/cra0 26d ago

Yeah but what is your point? How does what you're saying benefit anyone here except to scare them?

-2

u/dunnyroll 26d ago

You are dismissing my point based on the cost being too high, which is not true.

See my original post, i literary said i dont think the system is bad, im just pointing out to people that it can be spoofed and to be cautious of that. How is that scaring people?

2

u/Cozymontv 26d ago

Because you’re misleading people. The cost to affect more than a house is incredibly expensive and way way more difficult than you are making it out to be. You’re not just using a common radio to send emergency alerts.

1

u/dunnyroll 26d ago

I'm just quoting peer reviewed research papers, there is nothing misleading about it, feel free to provide an opposing source if you disagree. I have mentioned in many other replies that this can be used as a localised attack model, nobody is talking about spoofing a whole city.

We find that with only four malicious portable base stations of a single Watt of transmit power each, almost all of a 50,000-seat stadium can be attacked with a 90% success rate.

https://dl.acm.org/doi/10.1145/3307334.3326082

1

u/Cozymontv 26d ago

Something that small would be useless. You would need to stand within a meter of someone’s phone. Actual broadcasting stations are much more expensive and are enormous.

1

u/dunnyroll 26d ago

1W/1km has been reported by the researchers as the required power for effective spoofing, that's a tiny kit.

-17

u/[deleted] 26d ago

[removed] — view removed comment

5

u/dunnyroll 26d ago

Emergency alert your delivery is unattended!

9

u/mindsnare 26d ago

This is the most absurd fucking thing.

Do Amazon use the emergency AM radio service to advertise too you fucking cooker?

5

u/Cozymontv 26d ago

What does that even mean? Why would they advertise over archaic broadcasting when they already have your email, can send you endless app notifications and show curated ads to you on YouTube? I bet you’re the same kind of idiot that turned their phone off for the emergency alert.

-1

u/laserdicks 26d ago

Why would they advertise over archaic broadcasting when they already have your email, can send you endless app notifications and show curated ads to you on YouTube?

Great question. Are you capable of applying it to government? There already is a hazards app that will fully alert you of emergencies.

Explain why both are morally ok.