Interesting People mailing list archives
IP: Re: Cypherpunks break GSM digital cell phone encryption
From: Dave Farber <farber () cis upenn edu>
Date: Sat, 18 Apr 1998 07:53:59 -0400
From: Sky Dayton <sky () earthlink net>
Comment: The Time article originally forwarded to IP appeared lacking in
specifics (vintage Time), and it wasn't clear if they had hacked into a
conversation, or just managed to clone the account. This seems to clear it
up; the conversation is secure, but the phone account can be hijacked. At
least that's how I'm reading it.
Hats off to Time for again sensationalizing a simple issue, a la their
"Cyberporn" and "Web of Death" cover stories. I think I summarized it well
in my bLink column:
http://www.earthlink.net/blink/vault/issue14/skywriting.html
Sky
--
Delivered-To: ip-sub-1 () majordomo pobox com X-Sender: farber () linc cis upenn edu Date: Fri, 17 Apr 1998 08:25:36 -0400 To: ip-sub-1 () majordomo pobox com From: Dave Farber <farber () cis upenn edu> Subject: IP: Re: Cypherpunks break GSM digital cell phone encryption )from RISKS) Sender: owner-ip-sub-1 () majordomo pobox com Reply-To: farber () cis upenn edu Date: Thu, 16 Apr 1998 09:53:26 +1000 From: Stewart Fist <fist () zip com au> Subject: Re: Cypherpunks break GSM digital cell phone encryption Declan McCullagh <declan () well com> quotes TIME Magazine, April 20, 1998 as reporting: " Now crooks scanning the airwaves can remotely tap into a
call
and duplicate the owner's digital ID. "We can clone the phones," brags Marc Briceno, who organized the cracking. His advice: manufacturers shouldstick topublicly vetted codes that a bunch of geeks can't crack in their sparetime."My understanding is that they managed to crack the code on the SIM or smart card, not any radio-transmitted information. They repeatedly asked the card to identify itself, and so cracked it by brute force. The article also says: ``What was even more intriguing than the security threat, however, was that cracking the code yielded a tantalizing hint
that a
digital key used by GSM may have been intentionally weakened during thedesignprocess to permit government agencies to eavesdrop on cellular telephone conversations.'' This has been known for years. The use of GSM in Australia, for instance,wasblocked on the day of the official launch because the security and police services wanted an easier code to break. At that time, I understand, they just switched encryption off. This was also widely reported in Europe at the time, and openly admitted. The original A5 encryption was promoted as being "NATO level security" which was a bit of overkill for a mobile phone that is probably going to be used with an insecure wireline link, and often used in public places. Now it appears that they've cut the 64-bit key down to an effective
54-bit by
adding trailing zeros to make it easier to crack. It would still be a
pretty
healthy sort of encryption even at this level however. Stewart Fist, 70 Middle Harbour Road, Lindfield, 2070, N.S.W, Australia +61 2 9416 7458 http://www.theaustralian.com.au/techno/columns/fist.htm-- Kathy Johnson - Assistant to the Chairman | Voice: 818-296-2402 EarthLink Network, Inc. | Fax: 818-296-4139 kathy () earthlink net | 3100 New York Drive
http://www.earthlink.net | Pasadena, CA 91107
-- Sky Dayton, Founder & Chairman | Voice: 626-296-3072 EarthLink Network, Inc. | Fax: 626-296-4139 sky () earthlink net | 3100 New York Drive http://home.earthlink.net/~sky | Pasadena, CA 91107
Current thread:
- IP: Re: Cypherpunks break GSM digital cell phone encryption Dave Farber (Apr 18)
