MindBytes

Random musings on Technology and Management

Archive for the ‘Technology’ Category

GSM calls are now fully eavesdroppable !!

with one comment

http://www.stockabbigliamentounisex.it/news/wp-content/uploads/karsten-nohl.jpgThe Encryption Codes presently used for GSM communications i.e A5/1 64 Bit encryption codes have been published  as a “Torrent File” by security researcher Karsten Nohl and his team of 20 colleagues in December 2009.  Now this is very scary for the billions of GSM phone users around the world,  as their communications over the air waves could be cracked in real time using these codes. The GSM association(on its website) has already announced  a new standard A5/3, which should replace the earlier A5/1 standard.

But the upgradation to the new standard  requires huge costs and am not sure how many GSM service providers in India specially the major players like Airtel,Vodafone,BSNL and MTNL have started the migration to this new standard. Have they ?? Is the government monitoring the completion of the upgradation?  Iam not sure of this !!!!

For those guys interested in reading about the GSM A5 cracking and the history , i managed to gather a list of links

Title URL Date
A Practical-Time Attack on the A5/3 Cryptosystem Used in Third Generation GSM Telephony http://cryptome.org/a5-3-attack.pdf 12 January 2010
A5/3 and GEA3 Algorithms http://cryptome.org/a53-gea3/a53-gea3.htm 21 January 2007
Interception of GSM Cellphones http://cryptome.org/gsm-spy.htm 11 April 2005
GSM Interceptor http://cryptome.org/gsm-interceptor.htm 15 September 2003
GSM Crack Paper by Barkan, Biham, Keller http://cryptome.org/gsm-crack-bbk.pdf 9 September 2003
Weak GSM Crypto Cracked Again http://cryptome.org/gsm-crack.htm 5 September 2003
Real Time Cryptanalysis of A5/1 on a PC http://cryptome.org/a51-bsw.htm 27 April 2000
ETSI 3GPP Kasumi Cipher Specs http://cryptome.org/kasumi.zip 11 April 2000
SDA Releases GSM Voice-Privacy Algorithm A5/1 http://www.scard.org/gsm/ 16 December 1999
GSM Assures Tappable ID http://cryptome.org/gsm121099.htm 11 December 1999
GSM A5/1 Cracked http://cryptome.org/a51-crack.htm 6 December 1999
GSM A5/2 Published http://cryptome.org/gsm-a512.htm 23 October 1999
GSM Security Questions http://cryptome.org/gsm-joke.htm 21 October 1999
A5/1 Pedagogical Implementation http://cryptome.org/jya/a51-pi.htm 10 May 1999
Critique of GSM Data Protection Directive R(95)4 http://cryptome.org/jya/gsm-r(95)4.htm 1 November 1998
GSM Intercept News http://cryptome.org/jya/gsm102898.htm 28 October 1998
GSM Trace Scandal Exposed http://cryptome.org/jya/gsm-scandal.htm 13 July 1998
Swiss Commission Against Swisscom GSM Trace http://cryptome.org/jya/swisscom-nix.htm 6 July 1998
Cryptanalysis of Alleged A5 Stream Cipher /
On Random Mappings and Random Permutations
http://cryptome.org/jya/a5-hack.htm 3 May 1998
GSM Crack by Chaos Computer Club http://cryptome.org/jya/gsm-chaos.htm 27 April 1998
GSM MoU Association Response to Cloning http://cryptome.org/jya/gsm-mou.htm 21 April 1998
GSM Clone News http://cryptome.org/jya/gsm042098.txt 20 April 1998
Crack A5 http://cryptome.org/jya/crack-a5.htm 18 April 1998
GSM Cloning FAQ http://www.isaac.cs.berkeley.edu/isaac/gsm-faq.html 14 April 1998
GSM Algorithm A3A8 http://www.scard.org/gsm/a3a8.txt 14 April 1998
GSM Purposely-Weakened Crypto Cracked http://cryptome.org/jya/gsm-weak.htm 14 April 1998
GSM Cellphones Cloned http://cryptome.org/jya/gsm-cloned.htm 13 April 1998
GSM System Security Study http://cryptome.org/jya/gsm061088.htm 3 March 1997

Written by ramkinavy

February 15, 2010 at 5:09 pm

Posted in iNFOSEC, Mobile

Twitter- Easy,Friendly and Dangerous !!

leave a comment »


“Twitter” is all over the news in the Indian Media, specially  got its attention when Mr Shashi Tharoor, MP, Minister of State(External Affairs)  tweeted “Cattle Class” and “Holy cow” issues. He has more than 10,000 followers now(http://twitter.com/ShashiTharoor).  Many of my friends, created their twitter accounts soon after these  articles about “Twitter” broke out.

Few days back, i was telling my colleagues  ”What Twitter is all about” and how it’s presently being used by individuals for microblogging/social communication as well as organisations for their social marketing . Its become one of the most powerful tools, which provides real time updates about events happening across the world . For eg. During the Mumbai terror attacks, twitter was extensively used for posting of updates by the personnel,who were trapped inside the hotel and those all around the locations where terrorist attacked. Look at a snapshot of twitter during Mumbai Terror Attacks.

Tweets during Mumbai Terror attacks

The “Realtime” power of this platform did attract Google and Facebook , who tried their best to buy out twitter , but in vain. Facebook thereafter integrated a similar platform of its own.    Google has now integrated Twitter’s “Tweets” into their search results.

For all those who must be wondering, why Twitter’s Tweets are so important in search ill explain. There is always a time lag between the time of posting of a news article by a news agency and the time the article gets listed in the google search results.

This time lag may vary depending upon the ranking of the website from 5 mins to 15 days.Previously Google was not in a position to return any search results on such realtime queries.  Google  now queries the  key words on the Twitter platform and provides  twitter search results embedded inside the webpage, which also keeps updating itself  every milli second. You can also go to http://search.twitter.com directly to search for any real time tweets on any specific subject or topic .For eg. I just searched for “Chelsea” in Google. Amongst the results , even the tweets from the twitter are embedded on the search page.

A report by US military intelligence has claimed that the messaging application Twitter could be used by terrorists as an operational tool. Intelligence agencies are now monitoring this platform as future terror attacks will be aided by high technology gadgets and applications like Blackberry,Twiiter,YouTube(encrypted videos) etc.

The report into the increasing security implications of mobile technology envisaged terrorists using Twitter messages, or Tweets, to communicate and share images and locations of future terrorist attacks. “Twitter is already
used by some members to post and/or support extremist ideologies and perspectives,” the report said.

“For example, there are multiple pro and anti Hezbollah Tweets. In addition, extremist and terrorist use of Twitter could evolve over time to reflect tactics that are already evolving in use by ‘hacktivists’ and activis for surveillance. This could theoretically be combined with targeting.”

It notes that Twitter was used extensively by protestors at the recent Republican National Convention to identify the location of police and security guards in an effort to get around them. The report envisages Twitter also being used to identify the location of targets. It cites Tweets from US troops stationed overseas that could be used as information for
selective attacks.

“l’m in Bagram waiting for a flight to Camp Salemo by Kwost in the volatile east of Afghanistan near the Paki border. Hot days cold nights,” was one Tweet cited from an American soldier in Afghanistan that was posted on a publically available forum.Use of Twitter has been gaining ground fast and it is already being used in criminal cases, as well as updating work groups in business about changing goals.

So now you can imagine, a platform which has become a global search platform for “Realtime news” in such a short time  due to its simplicity and user friendliness, has also become a powerful and dangerous tool which can aid terrorists for real time communications.

Written by ramkinavy

February 8, 2010 at 1:04 am

The future of MySQL and Java ?

leave a comment »

Definition of  ”Oracle” :  (esp. in ancient Greece) an utterance, often ambiguous or obscure, given by a priest or priestess at a shrine as the response of a god to an inquiry. Source : Dictionary.com

In trying to keep up with the real meaning ,Oracle Corporation , is really trying hard  acquire  Sun Microsystems , in an attempt that would give straight competition to IBM, the global leader in System Solutions and Engineering and reach the top . After the recent clearance by the U.S. Department of Justice for the deal , the open source communities were deliberating the future of MySql and Java. Thanks to EU, that it has presented its objections to the proposed acquisition. To this  Oracle has publicly claimed that the hyper-protective bureaucrats of the EU’s Commission have demonstrated “profound misunderstanding of both database competition and open source dynamics”

However there are mixed responses to this merger. Ecommerce Journal says that Oracle’s previous acquisitions of “InnoDB” and “BerkeleyDB” did not affect their licensing policies and further supported the development and support to these two products. SAP has real concerns about customer choice in the database market and the future open licensing of Java.

Open Database Alliance, united its efforts to ensure that Sun’s MySQL database software would live on as a cheaper and open source alternative, really did attract the EU’s regulators

MySql , an open source database is presently being used by facebook,amazon and even this blog site, hosted by wordpress. Millions of websites which are hosted using linux and mysql, do not incur anycosts for the OS and the database saving about 2000-4000 US $.  So there is a real worry about the open licensing of the MySql post acquisition.

I feel that MySQL should be separated from the deal and allowed to be spin off as  an separate independent company to pursue its mission. Iam sure Larry Ellision would dump the deal in such a case. lets wait and watch

Written by ramkinavy

November 13, 2009 at 8:57 am

Posted in Database, Opinion

Mozilla Unveils Aurora Concept Browser

leave a comment »

Mozilla has changed the way people access internet using their browsers.

After the release of Firefox Ver 3, which has started capturing the browser market,displacing the Internet Explorer’s strong hold, now it is planning to unveil a new concept browser, named “Aurora”. The Mozilla Labs foundation is requesting people to contribute ideas and design for its upcoming browser.

Written by ramkinavy

August 7, 2008 at 7:29 am

Posted in Technology

Creating your own fonts

leave a comment »

I think this is one of the first online sites which allows users to create their own font types, who are not satisfied with the existing fonts available in applications like Photoshop,Corel Draw etc.

A nice video demonstrating the ease with which , you can create your own font is posted below

Introduction to FontStruct from fontstruct on Vimeo.

Written by ramkinavy

May 17, 2008 at 1:33 am

Posted in Technology

Send free fax within US using drop.io

leave a comment »

A very exciting startup which seems to make life comfortable to those people who want to share files,voice recording,links or any type of media such as photos,pdf files etc without any hangups of creating an account or registration process.

Steps for using:

  1. Give a name to your drop
  2. upload the media
  3. set the duration the drop would be available
  4. drop it / save it
  5. send it media as fax if it is a document or send as an MMS if it is a voice recording

One can also receive free fax, provided a predetermined format of a cover page is sent before the actual fax is sent.

Now coming to some important issues of security,since the service is free I can actually perform a DOS attack on the FAX machines of those people or companies whom i dont like, without actually leaving any of my details on the website……I hope these concerns will be addressed by the founders with some checks and balances

Written by ramkinavy

May 16, 2008 at 11:51 pm

Save Knowledge Save Wikipedia

leave a comment »

A German Publisher Bertelsmann,is planning to publish a single volume of the Wikipedia(the most popular articles ) for a cost of US $32. Now this seems to be a good business plan , but a risky plan for the publisher.After Wikipedia was launched in 2001, the major publishers of encyclopedia i.e, Britannica and others saw a plummeted sales year over year.
The book is planning to include most visited 50000 articles from wikipedia under the GNU-FDL license .

I sincerely hope that this publisher atleast donates 50% of his net proceeds to the foundation.

Also Wikipedia has been facing a lot of criticism over the authenticity of the articles. Some of the countries like China have also blocked access to wikipedia articles. Few Universities do not accept the citations of the Wikipedia articles in their students work.

Some Statistics of the Wikipedia i collected from the internet:

  • 7th most visited website as per Alexa ranking as on today
  • Nearly 4 million articles in 200 languages
  • 4000 new articles a day
  • 2 billion pageviews a month
  • Traffic volumes doubling every four months

A Web Site stats.grok.se to display statistics has been created by Wikipedia admin Henry.
The raw statistics are also available for further research at http://dammit.lt/wikistats/

Now if this is the kind of growth for wikipedia in about 7 years, how is it going to sustain without going commercial? The community doesnot want Wikipedia to go commercial , as it might no longer be available freely and may even be available to those who can afford to pay a subscription . Currently , it is running on the various voluntary donations from all over the world. The Wikimedia foundation requires around 5 million dollars/year to sustain the website.Presently it is able to collect only 1.1 dollars/year. So how is it going to sustain, is the main worry?? So all those people who use wikipedia for their work and research, please step forward to donate before this Knowledge Bank shuts down.


Written by ramkinavy

May 16, 2008 at 10:50 pm

Posted in Management, Technology

Chinese CISCO Switches – FBI concerns

leave a comment »

I just recently read an article talking about FBI concerns about counterfiet CISCO Network switches made in China , sold by the Gold/Silver Partners of CISCO to US Federal government agencies.This information was based on a presentation made by the FBI on an investigation into the incident wherein this fraud came to light.Now whether there is a hidden objective behind this or not is noy yet known. The switches have been sold to numeorous government agencies. Now this can be a real concern in India also.Now the question is when these sales are executed through the Gold/Silver partners of CISCO, how does the government check this whether these are OEM certified or look alikes??? First of all we do not have adequate expertise in the Government Quality Control Systems , which are going to do this.How does CISCO check , whether the gold /Silver partners are not selling any counterfiet Switches?? Are there any checks in place…I dont think so that this happens cos i never heard of such a thing.A Network switch in a government organisation can be very dangerous as it can give access to the complete network thereafter. Moreover, how will you know if there is any malicious program running inside these network switches? these questions do not have any answers or are there any???

Now ill tell you something interesting , I have a broadband connection from MTNL(National ISP) wherein they have given me a Chinese broadband modem. I regularly see that , in my router there are lots of intrusions from IP addresses originating from China..Infact i do not know how many people have actually seen their Broadband log while working in the night or left ideal for few hours. Chinese are really proactive in network intrusions and hacking (A Sports site , thought to be associated with CNN has been hacked yesterday by a Chinese University) in protests against Olympic Torch boycott movement in certain European countries.

Written by ramkinavy

May 5, 2008 at 2:05 am

Posted in China, iNFOSEC

Counterfeit equipment from China..How do you check???

leave a comment »

China

I just recently read an article talking about FBI concerns about counterfiet CISCO Network switches made in China , sold by the Gold/Silver Partners of CISCO to US Federal government agencies.This information was based on a presentation made by the FBI on an investigation into the incident wherein this fraud came to light.Now whether there is a hidden objective behind this or not is noy yet known. The switches have been sold to numeorous government agencies. Now this can be a real concern in India also.Now the question is when these sales are executed through the Gold/Silver partners of CISCO, how does the government check this whether these are OEM certified or look alikes??? First of all we do not have adequate expertise in the Government Quality Control Systems , which are going to do this.How does CISCO check , whether the gold /Silver partners are not selling any counterfiet Switches?? Are there any checks in place…I dont think so that this happens cos i never heard of such a thing.A Network switch in a government organisation can be very dangerous as it can give access to the complete network thereafter. Moreover, how will you know if there is any malicious program running inside these network switches? these questions do not have any answers or are there any???

Now ill tell you something interesting , I have a broadband connection from MTNL(National ISP) wherein they have given me a Chinese broadband modem. I regularly see that , in my router there are lots of intrusions from IP addresses originating from China..Infact i do not know how many people have actually seen their Broadband log while working in the night or left ideal for few hours. Chinese are really proactive in network intrusions and hacking (A Sports site , thought to be associated with CNN has been hacked yesterday by a Chinese University) in protests against Olympic Torch boycott movement in certain European countries.

Something has to be done!!!!!!

Written by ramkinavy

April 22, 2008 at 6:40 pm

Posted in Technology

Tagged with ,

Bored of text search……do some visual search

with one comment

searchme.com

Searchme.com

There are certain things, which really win your heart for the first time you see…and this is what impressed me. You must be tired of the traditional text search which most of the search engines offer presently. But the days are coming soon, when the search would be visual. Visual means, it can be through movement of your eyes or sifting through the graphical results which are retreived.

Searchme.com is one such site developed by an Australian programmer, which is simply superb.After you see the site for yourself, think ahead, what if the sifting of the images , can be done using your eyeball movements. Isnt it unbeleivable, but its true , it is possible. “Gazeeyes” is that technology . Ill write about that in the next article.This site definetly has a long future ahead and the developer Franz Enzenhofer has done a really nice job……so which company is gonna aquire this site ???? Hurry up!!!!

Written by ramkinavy

April 21, 2008 at 5:27 pm

Posted in Technology

Tagged with ,

Follow

Get every new post delivered to your Inbox.