Android intègre désormais des protections anti-Stingray : elles varient selon les smartphones – fr.softonic.com

Android devices are gaining enhanced security protections against Stingray devices—also known as IMSI catchers—though the implementation and effectiveness of these features vary significantly depending on the specific hardware and software version of each smartphone. These mobile surveillance tools are designed to masquerade as legitimate cell towers, tricking nearby mobile devices into connecting to them to intercept traffic or track user locations. Modern Android updates now allow users to disable 2G connectivity, a legacy protocol that lacks robust encryption and mutual authentication, making it the primary vector for such surveillance.

According to official Android security documentation, the ability to restrict 2G network access is a critical step in mitigating the risk posed by rogue base stations. Because Stingray devices often force a phone to “downgrade” its connection from a secure 4G or 5G network to a less secure 2G signal, disabling this capability removes the vulnerability at the source. However, this feature is not universally available across the entire Android ecosystem; it typically requires newer hardware that supports the Android 12 operating system or later, and even then, device manufacturers (OEMs) may choose whether or not to include the toggle in their specific user interface.

How Stingray Devices Intercept Mobile Traffic

Stingrays, or International Mobile Subscriber Identity (IMSI) catchers, exploit fundamental weaknesses in cellular network architecture. By broadcasting a signal stronger than that of legitimate local towers, these devices force handsets to perform a “location update” or handshake, during which the phone reveals its unique identifiers. Once the connection is established, the operator of the Stingray can intercept metadata, track movement, or, in some cases, monitor call content and SMS messages.

The Electronic Frontier Foundation (EFF) notes that these devices have been utilized by various law enforcement agencies and, in some instances, unauthorized third parties to conduct wide-area surveillance. Because mobile devices are programmed to prioritize connectivity, they are often unable to distinguish between a genuine carrier tower and a malicious interceptor that mimics the broadcast parameters of a known network.

The Role of 2G Protocols in Modern Security

The 2G protocol, originally deployed in the early 1990s, suffers from an inherent lack of mutual authentication. While modern 4G LTE and 5G networks require the phone to verify the identity of the tower, 2G does not; the phone blindly trusts any tower that signals it is the strongest in the area. This architectural flaw is the primary reason security researchers have long advocated for the complete sunsetting of 2G networks.

In response to these risks, Google introduced a software-level override in Android 12. By navigating to Settings > Network & Internet > SIMs, users on supported devices may see an option to “Allow 2G.” Disabling this toggle effectively instructs the radio firmware to ignore all 2G signals, thereby preventing the phone from ever being forced into a downgrade attack. As reported by Ars Technica, this feature is a direct countermeasure to the persistent threat of IMSI catchers that rely on legacy network protocols.

Fragmentation and Implementation Challenges

The primary hurdle for widespread protection against Stingrays is the diversity of the Android hardware market. Because Android is an open-source platform, manufacturers like Samsung, Motorola, and Xiaomi often customize the network settings menus. Consequently, the “Allow 2G” toggle may be absent on some devices, even if they are running a compatible version of the Android OS.

Furthermore, some users may find that disabling 2G impacts their ability to maintain cellular service in rural or remote areas where 4G and 5G infrastructure is not yet fully deployed. For these users, the trade-off between heightened security and network availability remains a significant consideration. The GSMA, which represents the interests of mobile operators worldwide, continues to work on industry-wide standards to phase out legacy protocols, but complete global abandonment of 2G is expected to take several more years.

Next Steps for Mobile Privacy

As cellular standards evolve, the industry is moving toward “Zero Trust” architectures that require constant verification of network components. In the interim, users concerned about localized surveillance should check their device settings to see if 2G restriction is available. For those whose devices do not offer the feature, keeping software updated to the latest security patch level remains the most effective way to protect against other known baseband vulnerabilities.

Next Steps for Mobile Privacy

The next major industry update regarding network security is expected during the upcoming 3GPP (3rd Generation Partnership Project) plenary sessions, where specifications for 6G security protocols are currently under development. Readers are encouraged to monitor official security bulletins from their device manufacturer for updates regarding baseband security enhancements. We invite you to share your experiences with these settings in the comments section below.

Leave a Comment