Summary
The core message of the provided session segment is that a very simple telco bug can become a nation-scale tracking capability when it appears inside complex, under-scrutinized infrastructure. The speaker describes finding a vulnerability in Telia’s Norwegian subsidiary while researching how phishing groups deliver mass text-message scams. During a follow-up call with an NRK reporter, both parties happened to be using Telia, and the vulnerability revealed itself: when the speaker called the reporter, Telia’s network echoed back the cell tower to which the reporter’s phone was connected. With a quick AI-assisted script that converted the returned data into a Google Maps URL, the speaker could locate the reporter at the NRK office.
The speaker then explains the technical mechanism without dwelling on unnecessary protocol detail. Phone-call signaling contains headers similar in spirit to HTTP headers, including the P-Access-Network-Info field. According to 3GPP specifications, this header is meant for internal telco use, especially for logging call detail records, or CDRs. CDRs capture who called whom and where a phone was connected when the call was made, and the speaker shows that law enforcement training material from an FBI presentation describes how such records can support prosecutions using cell-phone location data. In Telia’s case, a feature apparently introduced to support lawful interception was misrouted so that location data reached the caller instead of remaining inside the telco environment.
The talk’s emphasis then shifts from the single vulnerability to the role of AI and attention in vulnerability research. The speaker argues that modern infrastructure rests on old, obscure components that few people understand end-to-end, and that security has partly depended on attackers not looking closely enough. AI changed the speaker’s own research workflow by helping interpret obscure telco headers, locate documentation, and find the FBI training slides. The speaker frames this as evidence that AI can direct more attention toward overlooked systems, increasing the likelihood that simple but serious vulnerabilities will be discovered.
Finally, the speaker connects the Telia issue to nation-state interest in telecom infrastructure. They cite Wall Street Journal reporting that U.S. lawful-intercept systems at AT&T and Verizon were hacked by China, later reporting that Chinese spies had affected more than 80 countries, and a Norwegian security report referencing Salt Typhoon in Norwegian infrastructure. As a further example of neglected systems, the speaker describes seeing an AT&T server banner for Alcatel Lucent 3.0.3 during a test call and finding the version first indexed in January 2014, suggesting, though not proving, an old or insufficiently maintained component inside major telecom infrastructure.
Key Topics
5 key topics from Harrison Sand at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Audit lawful-intercept paths for unintended data exposure.
- Use AI to accelerate obscure protocol and documentation research.
- Inspect legacy telecom components that rarely receive security attention.
- Treat cell-tower metadata as highly sensitive location data.
- Validate whether internal headers can leak to external callers.
“we've relied on the lack of attention and engineering to kind of secure our world”

Harrison Sand
Security Researcher•Mnemonic
Up Next


Next in agenda
Inspiring the Next Generation of Digital Heroes


Also on ai security
AI: The Myth(os), truths, and what to do’s


Also on ai security
