Slashdot Mirror


Cracking GSM

RobertM writes "Professor Eli Biham, one of the worlds most famous crypto analysts, together with two of his students presented an interesting paper on flaws in GSM at the IACR Crypto conference. The GSM association is not happy. Read more on theReg." There's also a Reuters article about the situation.

18 of 359 comments (clear)

  1. This is news? by dphoenix · · Score: 5, Funny

    I don't see how this is news, I've known about this for months, I heard them talking about it on their GSM pho- uh, nevermind.

  2. Related topic: GSM Forensics by Anonymous Coward · · Score: 4, Informative

    The International Journal of Digital Evidencehas a current article about GSM forensics.

  3. A patented crack? by henrygb · · Score: 4, Insightful
    Reuters is saying "the method is being patented and will be used only by law enforcement agencies, he said".

    1. Does DCMA and its cousins allow such methods to be patented?

    2. Will the phreakers care about patents?

    1. Re:A patented crack? by morcheeba · · Score: 4, Insightful

      3. Will any government respect the patents, or will they take the opportunity to bolster their own national security?

    2. Re:A patented crack? by Kombat · · Score: 5, Insightful

      Governments don't need to crack the signal. They can already listen in on the unencrypted conversation at the base station, or even central office. Vendors of cell equipment are required by law to provide these back doors to government and law enforcement. If they didn't, then they simply couldn't sell their equipment. I know - I used to work in the cell phone billing division of Nortel.

      --
      Like woodworking? Build your own picture frames.
  4. that is a road by Anonymous Coward · · Score: 5, Informative

    the UK M5 is a road. perhaps you mean MI5?

    1. Re:that is a road by troc · · Score: 5, Funny

      I have always suspected the M5 of being "more" than just a road. All those caravans must be up to something, the way they all travel in swarms to the same places at the same times. I firmly think the bad driving, weird lane usage, flat caps and children are all either a secret language or simply designed to throw us off the scent.

      Or maybe I need to take my pills.

      Troc :)

      --
      Troc's dubious podcast and blog: http://www.trocnet.net
  5. Patent protection? by nuggz · · Score: 4, Insightful

    Illegal interception of calls will be prevented by patenting the technology?

    I'm sure that a criminal really cares about patent infringements.

    Laws should not be used to shore up broken technology. This only impedes law abiding citizens, and does nothing to improve the protection against crime.

    This one arguement against gun control, make them illegal and only criminals will have guns.
    Make this illegal and only criminals will listen to your phone call.

  6. Hey! I know these people! by epsalon · · Score: 5, Informative

    Elad, Nathan, Eli Biham and Orr Dunkelman (which was not listed for some reason) are friends of mine at the Technion Israeli Institute of Technology. Their previous attack on A5/1 required a few hundred GB of HD space and dedicated telephony equipment to pull. A5/2 is a peace of cake in comparison. This new attack makes it ciphertext only. That means that you don't have to initiate a short call (for example) to the evesdropee or knowing some part of the call (like with voicemail) before breaking the encryption. It uses the signal correction mechanism to initialize itself.

    In general, this is no big news, because this equipment is hard to aquire and the benefits are not that great. In comparison, CDMA and TDMA don't (effectively) encrypt calls at all.

  7. the new 3G ad campaign by Alien+Being · · Score: 5, Funny

    "they can hear you now."

    "they can hear you now."

  8. Re:Risky? by epsalon · · Score: 4, Informative

    Nathan, Elad, and Eli Biham are not US citizens as far as I know...

  9. Instant Cryptanalysis by IRandom · · Score: 5, Informative

    The novelety of this attack is that it is instantanous. The cryptanalysis is done one when the call is being established (when the phone just rings) even before any any real conversation is being done.
    The exact details are still secret but the attack exploits a misuse of Error Correcting Codes (ECC - are used in communication protocols to correct random noise errors).
    It seems that instead of encrypting the conversation and then employing ECC, the GSM does it the other way thus leaking enough data for the cryptanalysis to be performed

  10. Reuters article more balanced by winkydink · · Score: 4, Informative

    At least they point out that the equipment required costs about $250k.

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

  11. REMOB anyone? *GOV CAN TAP YOU* by Anonymous Coward · · Score: 4, Interesting

    REMOB anyone?

    REMOB (Remote observation mode) is a TSPS console feature of the american telephone system to allow inward ops to monitor a suspected phone that might be "off the hook" prior to interrupting the line for "life or dire emergency" with the 500Hz tone and issuance of the frequently heard phrase "This is the att operator do you wish to disconnect this call you have an emergecy phone call from ...."

    but PRIOR to that for 30 second maximum bursts you get to hear an inverterted sound wave... which you can record.

    better... the fbi has is setup to cascade overlapping series of REMOB snippets so when one ends (on any CLASS capable ESS r5) another takes over.

    This way no interrupt chirp is heard by the victims, and lots of trivially "scrambled' speech can be secretly recorded.

    i have never ever ever seen this in print or any edoc in history of phreaking.

    I have seen telephon reps state to congree that REMOB did not exist.

    it exists.

    it does not take outside intercepts (ECHELON) as reported on 60 Minutes, or any NRO or NSA budgets,

    it only takes a 6 digit code and the correct connections to do REMOB.

    REMOB makes intercepting cell phones laughable in comparison.

    besides... the German Gov records ALL cell phones under that alleged statement that in theory it COULD intercept the airwaves anyways if they tried. Remeber the slashdot article?

    also the us gov allows no-warrant affixing of GPS locater emmitter bugs under your car frame under the assumption that it could visually track you from their air if they had the money anyways. Remember the Scott peterson case this summer? No initial warrant to put the gps bug on his car.

    recording and intercepting ALL cell phone traffic at the point of origin on the LAND LINES is what the fed gov assumes is their right!

    no need to mess with intercepts.

    July 1983 the us supreme court ruled the public had a right to intercept and use all radio trasmissions INCLUDING call phones. Then they pverturned it partly years later.

    today it is LEGAL for the cops to buy and sell equipment to record cell phones, but not the public across state borders. you have to build it from scratch yourself for your own hobbyist needs... and then its legal to use.

    but REMOB is far far more humorous.

    I know it exists.... first hand

  12. Re:Risky? by Zachary+Kessin · · Score: 4, Informative

    They are all infact at the Technion, Israel's high Tech-engineering school in Haifa. The DMCA is a US law, which applies to people in the USA. It has absolutly no effect on people outside the USA.

    Now in theory if they travel to the USA they could have a problem, and many Israelis do travel to the USA for one reason or another, but I don't think the US goverment will arrest an Israeli professor for publishing a paper.

    --
    Erlang Developer and podcaster
  13. Re:GSM ... and CDMA? by Andy+Dodd · · Score: 4, Informative

    "The question is can somebody deploy a off-the-shelf (or homebuilt) scanner and grab the conversations on-the-air? I know that a PR (pseudo random) number is used with the ESN and A-key to generate some keys for encrypting some of the communications, and that the voice channel is "scrambled", but is there a source where the security implications of this is discussed?"

    In theory, anything is possible.

    Off-the-shelf scanner - Definately not. Unless you're talking about high-end five-figure and even six-figure sums. A Rohde and Schwartz FSIQ would probably be 90% of the hardware needed to crack a CDMA signal, but FSIQs run $75k used ($120k or so new). An Agilent E4406A VSA starts at $32000 and cdmaOne and CDMA2000 options are extra $$$. And these might not even be sufficient for realtime monitoring and demodulation. It would be possible to build custom equipment for much less, but only a M.S. or Ph. D. in EE would be able to design a system to do adequate realtime demodulation of CDMA.

    Non-realtime (capture the signals and post-process them) - Much easier. The hardware is $1000-2000 off-the-shelf (see GNU Radio), and the software is $99 if you're a student (Matlab), although you'll still need thorough knowledge of CDMA and some communications systems background to write the demodulation algorithms.

    I don't know about the datastream-level encryption, but CDMA is much tougher to demodulate than the TDMA scheme used by GSM. (Given a captured baseband signal, I could probably tweak my old ECE 467 projects to demodulate GSM down to its datastreamin not too long, while CDMA would be a LOT harder.

    --
    retrorocket.o not found, launch anyway?
  14. Patented = Published = DCMA Unconstitutional? by G4from128k · · Score: 4, Interesting

    If this cracking method is indeed patented then it must be publicly released for anyone to read and understand. But public release would seem to violate DCMA and stifling the publication would seem to violate the constitutional underpinnings of the patent system (to encourage innovation by both granting monopolies and making inventions publicly accessible for further innovation). Does this make DCMA unconstitutional???

    --
    Two wrongs don't make a right, but three lefts do.
  15. Adjust your tinfoil hat, guy. by rjh · · Score: 4, Informative

    At great risk of sounding like the Voice of Reason (and God knows how Slashdotters hate that!), could you please present some evidence to back up your assertion that the United States and United Kingdom are colluding to break the laws of both nations?

    Look up the Federal laws: if it is illegal for a Federal agency to do $foo, then it is also illegal for a Federal agency to have a third party do $foo on their behalf.

    If I break into a home and see a kilo of cocaine lying around, I can then go to the DEA and tell them. They can use my testimony to get a warrant to search the home and impound the drugs. Why? Because I didn't commit the crime on their behalf; I came in entirely of my own accord; there was no understanding between the DEA and myself that "if I see any drugs, I'm going to bring them to your attention".

    But if the DEA asks me to break into a home, they'd better damn well have a warrant, otherwise they're breaking all manner of Federal laws.

    So what you're positing is there is a tacit understanding between the US and UK that each will spy on the other's citizens and share with each other the fruits of those actions. Hmm. This sounds mind-bogglingly stupid.

    Why?

    Free hint: this is a Federal crime.

    Free hint number two: the FBI and NSA do not get along.

    Free hint number three: the FBI is the one with the charter to spy on American citizens--not the NSA.

    Free hint number four: the FBI protects its jurisdictional turf very zealously.

    Free hint number five: the FBI is one of the nation's intelligence agencies, co-equal with the CIA and NSA. The FBI has no charter to collect intelligence from foreign sources; the CIA and NSA have no charter to collect intelligence from domestic sources.

    Free hint number six: if the NSA were to really be involved in this, the FBI would be doing a full-court-press investigation into the matter. (a), because it's a clear and massive violation of Federal law, and more importantly, (b) THE FBI DOES NOT SHARE ITS JURISDICTIONAL TURF.

    Period.

    So if you have any hard facts proving this tacit agreement, I'd love to hear it. If you have hard facts about it, then I'll talk to my FBI friends tomorrow and tell them about it.

    I guarantee you they'll be pissed off.