7 ms·
GSM encryption broken
- Dilpil 17y agoLinks to a registration prompt. If anyone is really interested in reading this, google the URL.
- mrduncan 17y agoClickable: http://www.google.com/search?q=Code+That+Protects+Most+Cellphone+Calls+Is+Divulged http://www.google.com/search?q=Code+That+Protects+Most+Cellp... Deleting cookies for nytimes.com will also do the trick.
- atamyrat 17y agoFor more technical info, here's the link to presentation at CCC http://lists.lists.reflextor.com/pipermail/a51/attachments/20091228/3267f143/attachment-0001.pdf http://lists.lists.reflextor.com/pipermail/a51/attachments/2...
- stse 17y agoUnofficial video torrents can be found at http://rnmshot.dvrdns.org/ http://rnmshot.dvrdns.org/
- wendroid 17y agoI sent this to press@gsm.com, the email address of Claire Cranton, quoted in the article : Dear Ms. Cranton, http://www.nytimes.com/2009/12/29/technology/29hack.html?_r=1 http://www.nytimes.com/2009/12/29/technology/29hack.html?_r=... “This is theoretically possible but practically unlikely,” said Claire Cranton, a GSM spokeswoman, noting that no one else had broken the code since its adoption. “What he is doing would be illegal in Britain and the United States. To do this while supposedly being concerned about privacy is beyond me.” A set of incredible admissions. * This is theoretically possible but practically unlikely GSM 64bit encryption is broken. Not theoretically but actually. The likelihood of it happening to someone now depends on the value of the calls. * no one else had broken the code since its adoption. And now they have, that's the point * would be illegal in Britain and the United States I don't think criminals are deterred by such niceties and they are hardly likely to reveal their source while extorting money from me or making insider trades * To do this while supposedly being concerned about privacy is beyond me Knowing that my handset can be eavesdropped by people outside of the law is the ultimate privacy concern. That you don't understand this is beyond me. > The association noted that hackers intent on illegal eavesdropping would need a radio receiver system and signal processing software to process raw radio data, much of which is copyrighted. Again, copyright infringement would be very low on the list of criminal organisations. Your response beggars belief, except it is perfectly reasonable viewed through the lens of PR. Yours sincerely
- pavel_lishin 17y agoIs she saying that the raw radio data is copyrighted? Or the software? Because either way, wow.
- Zilioum 17y agoAs if people that want to listen to phone calls cared about copyright laws.
- stse 17y agoIt's not uncommon to stop publication of research by claiming copyright, patent, etc.
- pmjordan 17y agoPatents? Surely not. Their original intent was to have the technology out in the open. I suspect you're thinking of trade secrets.
- stse 17y agoThis topic is a few days old, but for the record. Yes patents: http://www.wired.com/politics/law/commentary/circuitcourt/2007/02/72819 http://www.wired.com/politics/law/commentary/circuitcourt/20... ...and by other means: http://www.wired.com/threatlevel/2008/08/injunction-requ/ http://www.wired.com/threatlevel/2008/08/injunction-requ/ http://www.wired.com/threatlevel/2009/06/atm-vendor-halts-talk/ http://www.wired.com/threatlevel/2009/06/atm-vendor-halts-ta... http://blog.washingtonpost.com/securityfix/2006/07/fbi_arrest_private_eye_speaker.html http://blog.washingtonpost.com/securityfix/2006/07/fbi_arres... http://www.wired.com/politics/law/news/2001/07/45298 http://www.wired.com/politics/law/news/2001/07/45298
- stse 17y agoSo you sent an e-mail to some public relations person at an interest group (gsm.ORG btw). You should approach your service provider or handset manufacturer, who (in theory) could take direct action as described in the presentation from ccc. This is one of the reasons for having an open phone.
- wrs 17y agoIf GSM was not already broken, how do all of these products work? http://www.google.com/search?q=gsm+passive+intercept http://www.google.com/search?q=gsm+passive+intercept The point of the presentation is not that GSM has been broken; it's to make it so blatantly, obviously, publicly broken that the public (i.e., corporate IT departments) will have to pay attention.
- tptacek 17y agoIt seems likely that to the extent that things like the GSS-ProA suitcase interceptors crack A5/1, they do it with special-purpose hardware. A practical software attack is news.
- deleted 17y ago[deleted]
- tptacek 17y agoIt's nice to see people still follow the old security PR playbook: http://chargen.matasano.com/chargen/2009/4/1/how-to-hidehhhandle-security-vulnerabilities-in-your-product.html http://chargen.matasano.com/chargen/2009/4/1/how-to-hidehhha... The "modern" game Microsoft plays is boring. It acknowledges and thanks researchers, often accepts worst-case assessments of impact, and fast-tracks fixes. What they don't understand is that our stories need an antagonist, someone we can name and pillory. Thanks, Claire Cranton at GSM.com, for giving us one.
- alyx 17y agoWhat does Microsoft have to do with the cracking of the GSM encryption code?
- tptacek 17y agoMicrosoft has more experience handling security disclosures than any other organization. The GSM manufacturers apparently have very little comparable experience. I'm just contrasting the two. (I upvoted you; it's a fair question.)
- deleted 17y ago[deleted]
- ojbyrne 17y agohttp://en.wikipedia.org/wiki/List_of_North_American_countries_by_population http://en.wikipedia.org/wiki/List_of_North_American_countrie...
- pavel_lishin 17y agoThat probably means there are 299 million wireless devices using GSM.
- acdha 17y ago"North America" includes more than the United States: http://en.wikipedia.org/wiki/North_America http://en.wikipedia.org/wiki/North_America
- jrockway 17y ago“What he is doing would be illegal in Britain and the United States.” Hmm, guess which two countries he is not doing this in. I am not sure how this is relevant, except to say, "oh fuck." (If you can't attack the argument, attack the person who's arguing.) To do this while supposedly being concerned about privacy is beyond me. Now I know for sure that I need to encrypt my calls in another way. Before this announcement, I figured it was handled for me; I didn't assume that criminals had already broken the crypto and had kept the information secret. Now I am sure they have, and that my non-encrypted calls are obviously being monitored. (I exaggerate a bit, but it's clear how this disclosure enhances my privacy.) Not sure why the GSM folks are taking this so seriously. Computers are fast. 64-bit encryption has been unsafe for nearly a decade. Everyone knows that this was going to happen eventually. Edit: after reading the slides, I am really amazed by this. I remember when I was a kid and I used to listen in on cordless phones and baby monitors with my radio scanner. It was really, really interesting. The thought of sitting on the train and listening to both sides of people's cell-phone calls appeals to me in a way that I can't quite explain.
- tptacek 17y agoIn fairness, or whatever, the problem with A5/1 isn't simply that it's got a 64-bit key, but that it's a uniquely bad stream cipher prone to linear equation-style attacks and precomputation. Nate, Colin, or Bruce may smack me down for saying this, but I don't think you can apply the same attacks to, say, RC5. For roughly a decade, pretty much anyone who attended more than one local 2600 meeting got the tech demo on snooping cell phone calls --- they were analog. Everything old is new again. It's nice that encrypted digital calls were so successful that the loss of their security is major news.
- jrockway 17y agoYeah, you are right. The impression that I got from the NYT article was that this was "given a trace and a bunch of computers, you can get the voice data... maybe, eventually", but the impression that I get from the talk is that it is actually realtime. That requires weaknesses in the crypto that are embarrassing for anything 1980s or 1990s vintage. I don't think this attack would be feasible if they used DES instead. (I will defer to you or cperciva for that one, however :)
- 3pt14159 17y agoHow is this news? I've known for months that a 100+ petabyte server and a massive rainbow table can crack the encryption of GSM phones.
- bartman 17y agoThey are down to ~2TB for rainbow tables, calculated on GPUs, making cracking feasible. Also, the code and knowledge is put into the public: http://reflextor.com/trac/a51/wiki http://reflextor.com/trac/a51/wiki
- jeremyw 17y agoTo clarify a few points (I had them confused): - If you have an iPhone 3G signal (for example), you're using UMTS (not GSM), which has longer encryption keys (128-bit) and an enhanced protocol. Brute-forcing this keyspace (as in the CCC paper) is unlikely, though they mention the cipher (KASUMI) is "academically broken". - Neither system has end-to-end privacy. Data is encrypted to your operator's equipment. All other hacks apply. NYT: In 2007, the GSM developed a 128-bit successor to the A5/1, called the A5/3 encryption algorithm, but most network operators have not yet invested to make the security upgrade. As far as I can determine, this is wrong. Europe has UMTS broadly deployed and the US came late to this party. For more: http://www.google.com/search?q=umts+encryption http://www.google.com/search?q=umts+encryption
- Dmatig 17y agoI'm not sure of the specific relevence to this article, since it was a good while ago i listened the details mostly escape my memory, but you can grab a good background on why GSM is insecure listening here: http://twit.tv/sn213 http://twit.tv/sn213
- cnvogel 17y agoThe summary of the talk given on the 26'th Chaos Communication Congress can be found on the 26c3 wiki, it includes a link to the slides: http://events.ccc.de/congress/2009/Fahrplan/events/3654.en.html http://events.ccc.de/congress/2009/Fahrplan/events/3654.en.h... Video recordings can be found on: http://events.ccc.de/congress/2009/wiki/Streaming#Unofficial http://events.ccc.de/congress/2009/wiki/Streaming#Unofficial (the ones on 26c3.ipv6only.org are good, but, as the name suggests, accessible via IPv6 only)
- teeja 17y agoHere goes another wave of plastic & silicon hitting the world's dumpgrounds. If we made less hardware and more software, the world would thank us for it.