MindBytes

Random musings on Technology and Management

GSM calls are now fully eavesdroppable !!

with one comment

http://www.stockabbigliamentounisex.it/news/wp-content/uploads/karsten-nohl.jpgThe Encryption Codes presently used for GSM communications i.e A5/1 64 Bit encryption codes have been published  as a “Torrent File” by security researcher Karsten Nohl and his team of 20 colleagues in December 2009.  Now this is very scary for the billions of GSM phone users around the world,  as their communications over the air waves could be cracked in real time using these codes. The GSM association(on its website) has already announced  a new standard A5/3, which should replace the earlier A5/1 standard.

But the upgradation to the new standard  requires huge costs and am not sure how many GSM service providers in India specially the major players like Airtel,Vodafone,BSNL and MTNL have started the migration to this new standard. Have they ?? Is the government monitoring the completion of the upgradation?  Iam not sure of this !!!!

For those guys interested in reading about the GSM A5 cracking and the history , i managed to gather a list of links

Title URL Date
A Practical-Time Attack on the A5/3 Cryptosystem Used in Third Generation GSM Telephony http://cryptome.org/a5-3-attack.pdf 12 January 2010
A5/3 and GEA3 Algorithms http://cryptome.org/a53-gea3/a53-gea3.htm 21 January 2007
Interception of GSM Cellphones http://cryptome.org/gsm-spy.htm 11 April 2005
GSM Interceptor http://cryptome.org/gsm-interceptor.htm 15 September 2003
GSM Crack Paper by Barkan, Biham, Keller http://cryptome.org/gsm-crack-bbk.pdf 9 September 2003
Weak GSM Crypto Cracked Again http://cryptome.org/gsm-crack.htm 5 September 2003
Real Time Cryptanalysis of A5/1 on a PC http://cryptome.org/a51-bsw.htm 27 April 2000
ETSI 3GPP Kasumi Cipher Specs http://cryptome.org/kasumi.zip 11 April 2000
SDA Releases GSM Voice-Privacy Algorithm A5/1 http://www.scard.org/gsm/ 16 December 1999
GSM Assures Tappable ID http://cryptome.org/gsm121099.htm 11 December 1999
GSM A5/1 Cracked http://cryptome.org/a51-crack.htm 6 December 1999
GSM A5/2 Published http://cryptome.org/gsm-a512.htm 23 October 1999
GSM Security Questions http://cryptome.org/gsm-joke.htm 21 October 1999
A5/1 Pedagogical Implementation http://cryptome.org/jya/a51-pi.htm 10 May 1999
Critique of GSM Data Protection Directive R(95)4 http://cryptome.org/jya/gsm-r(95)4.htm 1 November 1998
GSM Intercept News http://cryptome.org/jya/gsm102898.htm 28 October 1998
GSM Trace Scandal Exposed http://cryptome.org/jya/gsm-scandal.htm 13 July 1998
Swiss Commission Against Swisscom GSM Trace http://cryptome.org/jya/swisscom-nix.htm 6 July 1998
Cryptanalysis of Alleged A5 Stream Cipher /
On Random Mappings and Random Permutations
http://cryptome.org/jya/a5-hack.htm 3 May 1998
GSM Crack by Chaos Computer Club http://cryptome.org/jya/gsm-chaos.htm 27 April 1998
GSM MoU Association Response to Cloning http://cryptome.org/jya/gsm-mou.htm 21 April 1998
GSM Clone News http://cryptome.org/jya/gsm042098.txt 20 April 1998
Crack A5 http://cryptome.org/jya/crack-a5.htm 18 April 1998
GSM Cloning FAQ http://www.isaac.cs.berkeley.edu/isaac/gsm-faq.html 14 April 1998
GSM Algorithm A3A8 http://www.scard.org/gsm/a3a8.txt 14 April 1998
GSM Purposely-Weakened Crypto Cracked http://cryptome.org/jya/gsm-weak.htm 14 April 1998
GSM Cellphones Cloned http://cryptome.org/jya/gsm-cloned.htm 13 April 1998
GSM System Security Study http://cryptome.org/jya/gsm061088.htm 3 March 1997

Advertisement

Written by ramkinavy

February 15, 2010 at 5:09 pm

Posted in iNFOSEC, Mobile

One Response

Subscribe to comments with RSS.

  1. hi, is it possible to use OTA and download new keys to insure secure conections …
    ?

    Ahmed Khallab

    October 19, 2010 at 6:41 pm


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.