Archive for the ‘Technology’ Category
GSM calls are now fully eavesdroppable !!
The Encryption Codes presently used for GSM communications i.e A5/1 64 Bit encryption codes have been published as a “Torrent File” by security researcher Karsten Nohl and his team of 20 colleagues in December 2009. Now this is very scary for the billions of GSM phone users around the world, as their communications over the air waves could be cracked in real time using these codes. The GSM association(on its website) has already announced a new standard A5/3, which should replace the earlier A5/1 standard.
But the upgradation to the new standard requires huge costs and am not sure how many GSM service providers in India specially the major players like Airtel,Vodafone,BSNL and MTNL have started the migration to this new standard. Have they ?? Is the government monitoring the completion of the upgradation? Iam not sure of this !!!!
For those guys interested in reading about the GSM A5 cracking and the history , i managed to gather a list of links
| Title | URL | Date |
| A Practical-Time Attack on the A5/3 Cryptosystem Used in Third Generation GSM Telephony | http://cryptome.org/a5-3-attack.pdf | 12 January 2010 |
| A5/3 and GEA3 Algorithms | http://cryptome.org/a53-gea3/a53-gea3.htm | 21 January 2007 |
| Interception of GSM Cellphones | http://cryptome.org/gsm-spy.htm | 11 April 2005 |
| GSM Interceptor | http://cryptome.org/gsm-interceptor.htm | 15 September 2003 |
| GSM Crack Paper by Barkan, Biham, Keller | http://cryptome.org/gsm-crack-bbk.pdf | 9 September 2003 |
| Weak GSM Crypto Cracked Again | http://cryptome.org/gsm-crack.htm | 5 September 2003 |
| Real Time Cryptanalysis of A5/1 on a PC | http://cryptome.org/a51-bsw.htm | 27 April 2000 |
| ETSI 3GPP Kasumi Cipher Specs | http://cryptome.org/kasumi.zip | 11 April 2000 |
| SDA Releases GSM Voice-Privacy Algorithm A5/1 | http://www.scard.org/gsm/ | 16 December 1999 |
| GSM Assures Tappable ID | http://cryptome.org/gsm121099.htm | 11 December 1999 |
| GSM A5/1 Cracked | http://cryptome.org/a51-crack.htm | 6 December 1999 |
| GSM A5/2 Published | http://cryptome.org/gsm-a512.htm | 23 October 1999 |
| GSM Security Questions | http://cryptome.org/gsm-joke.htm | 21 October 1999 |
| A5/1 Pedagogical Implementation | http://cryptome.org/jya/a51-pi.htm | 10 May 1999 |
| Critique of GSM Data Protection Directive R(95)4 | http://cryptome.org/jya/gsm-r(95)4.htm | 1 November 1998 |
| GSM Intercept News | http://cryptome.org/jya/gsm102898.htm | 28 October 1998 |
| GSM Trace Scandal Exposed | http://cryptome.org/jya/gsm-scandal.htm | 13 July 1998 |
| Swiss Commission Against Swisscom GSM Trace | http://cryptome.org/jya/swisscom-nix.htm | 6 July 1998 |
| Cryptanalysis of Alleged A5 Stream Cipher / On Random Mappings and Random Permutations |
http://cryptome.org/jya/a5-hack.htm | 3 May 1998 |
| GSM Crack by Chaos Computer Club | http://cryptome.org/jya/gsm-chaos.htm | 27 April 1998 |
| GSM MoU Association Response to Cloning | http://cryptome.org/jya/gsm-mou.htm | 21 April 1998 |
| GSM Clone News | http://cryptome.org/jya/gsm042098.txt | 20 April 1998 |
| Crack A5 | http://cryptome.org/jya/crack-a5.htm | 18 April 1998 |
| GSM Cloning FAQ | http://www.isaac.cs.berkeley.edu/isaac/gsm-faq.html | 14 April 1998 |
| GSM Algorithm A3A8 | http://www.scard.org/gsm/a3a8.txt | 14 April 1998 |
| GSM Purposely-Weakened Crypto Cracked | http://cryptome.org/jya/gsm-weak.htm | 14 April 1998 |
| GSM Cellphones Cloned | http://cryptome.org/jya/gsm-cloned.htm | 13 April 1998 |
| GSM System Security Study | http://cryptome.org/jya/gsm061088.htm | 3 March 1997 |

Twitter- Easy,Friendly and Dangerous !!
“Twitter” is all over the news in the Indian Media, specially got its attention when Mr Shashi Tharoor, MP, Minister of State(External Affairs) tweeted “Cattle Class” and “Holy cow” issues. He has more than 10,000 followers now(http://twitter.com/ShashiTharoor). Many of my friends, created their twitter accounts soon after these articles about “Twitter” broke out.
Few days back, i was telling my colleagues ”What Twitter is all about” and how it’s presently being used by individuals for microblogging/social communication as well as organisations for their social marketing . Its become one of the most powerful tools, which provides real time updates about events happening across the world . For eg. During the Mumbai terror attacks, twitter was extensively used for posting of updates by the personnel,who were trapped inside the hotel and those all around the locations where terrorist attacked. Look at a snapshot of twitter during Mumbai Terror Attacks.

Tweets during Mumbai Terror attacks
The “Realtime” power of this platform did attract Google and Facebook , who tried their best to buy out twitter , but in vain. Facebook thereafter integrated a similar platform of its own. Google has now integrated Twitter’s “Tweets” into their search results.
For all those who must be wondering, why Twitter’s Tweets are so important in search ill explain. There is always a time lag between the time of posting of a news article by a news agency and the time the article gets listed in the google search results.
This time lag may vary depending upon the ranking of the website from 5 mins to 15 days.Previously Google was not in a position to return any search results on such realtime queries. Google now queries the key words on the Twitter platform and provides twitter search results embedded inside the webpage, which also keeps updating itself every milli second. You can also go to http://search.twitter.com directly to search for any real time tweets on any specific subject or topic .For eg. I just searched for “Chelsea” in Google. Amongst the results , even the tweets from the twitter are embedded on the search page.
A report by US military intelligence has claimed that the messaging application Twitter could be used by terrorists as an operational tool. Intelligence agencies are now monitoring this platform as future terror attacks will be aided by high technology gadgets and applications like Blackberry,Twiiter,YouTube(encrypted videos) etc.
The report into the increasing security implications of mobile technology envisaged terrorists using Twitter messages, or Tweets, to communicate and share images and locations of future terrorist attacks. “Twitter is already
used by some members to post and/or support extremist ideologies and perspectives,” the report said.
“For example, there are multiple pro and anti Hezbollah Tweets. In addition, extremist and terrorist use of Twitter could evolve over time to reflect tactics that are already evolving in use by ‘hacktivists’ and activis for surveillance. This could theoretically be combined with targeting.”
It notes that Twitter was used extensively by protestors at the recent Republican National Convention to identify the location of police and security guards in an effort to get around them. The report envisages Twitter also being used to identify the location of targets. It cites Tweets from US troops stationed overseas that could be used as information for
selective attacks.
“l’m in Bagram waiting for a flight to Camp Salemo by Kwost in the volatile east of Afghanistan near the Paki border. Hot days cold nights,” was one Tweet cited from an American soldier in Afghanistan that was posted on a publically available forum.Use of Twitter has been gaining ground fast and it is already being used in criminal cases, as well as updating work groups in business about changing goals.
So now you can imagine, a platform which has become a global search platform for “Realtime news” in such a short time due to its simplicity and user friendliness, has also become a powerful and dangerous tool which can aid terrorists for real time communications.


The future of MySQL and Java ?
Definition of ”Oracle” : (esp. in ancient Greece) an utterance, often ambiguous or obscure, given by a priest or priestess at a shrine as the response of a god to an inquiry. Source : Dictionary.com
In trying to keep up with the real meaning ,Oracle Corporation , is really trying hard acquire Sun Microsystems , in an attempt that would give straight competition to IBM, the global leader in System Solutions and Engineering and reach the top . After the recent clearance by the U.S. Department of Justice for the deal , the open source communities were deliberating the future of MySql and Java. Thanks to EU, that it has presented its objections to the proposed acquisition. To this Oracle has publicly claimed that the hyper-protective bureaucrats of the EU’s Commission have demonstrated “profound misunderstanding of both database competition and open source dynamics”
However there are mixed responses to this merger. Ecommerce Journal says that Oracle’s previous acquisitions of “InnoDB” and “BerkeleyDB” did not affect their licensing policies and further supported the development and support to these two products. SAP has real concerns about customer choice in the database market and the future open licensing of Java.
Open Database Alliance, united its efforts to ensure that Sun’s MySQL database software would live on as a cheaper and open source alternative, really did attract the EU’s regulators
MySql , an open source database is presently being used by facebook,amazon and even this blog site, hosted by wordpress. Millions of websites which are hosted using linux and mysql, do not incur anycosts for the OS and the database saving about 2000-4000 US $. So there is a real worry about the open licensing of the MySql post acquisition.
I feel that MySQL should be separated from the deal and allowed to be spin off as an separate independent company to pursue its mission. Iam sure Larry Ellision would dump the deal in such a case. lets wait and watch
Mozilla Unveils Aurora Concept Browser
Mozilla has changed the way people access internet using their browsers.
After the release of Firefox Ver 3, which has started capturing the browser market,displacing the Internet Explorer’s strong hold, now it is planning to unveil a new concept browser, named “Aurora”. The Mozilla Labs foundation is requesting people to contribute ideas and design for its upcoming browser.
Creating your own fonts
I think this is one of the first online sites which allows users to create their own font types, who are not satisfied with the existing fonts available in applications like Photoshop,Corel Draw etc.
A nice video demonstrating the ease with which , you can create your own font is posted below
Introduction to FontStruct from fontstruct on Vimeo.
Send free fax within US using drop.io
A very exciting startup which seems to make life comfortable to those people who want to share files,voice recording,links or any type of media such as photos,pdf files etc without any hangups of creating an account or registration process.
Steps for using:
- Give a name to your drop
- upload the media
- set the duration the drop would be available
- drop it / save it
- send it media as fax if it is a document or send as an MMS if it is a voice recording
One can also receive free fax, provided a predetermined format of a cover page is sent before the actual fax is sent.
Now coming to some important issues of security,since the service is free I can actually perform a DOS attack on the FAX machines of those people or companies whom i dont like, without actually leaving any of my details on the website……I hope these concerns will be addressed by the founders with some checks and balances
Save Knowledge Save Wikipedia
A German Publisher Bertelsmann,is planning to publish a single volume of the Wikipedia(the most popular articles ) for a cost of US $32. Now this seems to be a good business plan , but a risky plan for the publisher.After Wikipedia was launched in 2001, the major publishers of encyclopedia i.e, Britannica and others saw a plummeted sales year over year.
The book is planning to include most visited 50000 articles from wikipedia under the GNU-FDL license .
I sincerely hope that this publisher atleast donates 50% of his net proceeds to the foundation.
Also Wikipedia has been facing a lot of criticism over the authenticity of the articles. Some of the countries like China have also blocked access to wikipedia articles. Few Universities do not accept the citations of the Wikipedia articles in their students work.
Some Statistics of the Wikipedia i collected from the internet:
- 7th most visited website as per Alexa ranking as on today
- Nearly 4 million articles in 200 languages
- 4000 new articles a day
- 2 billion pageviews a month
- Traffic volumes doubling every four months
A Web Site stats.grok.se to display statistics has been created by Wikipedia admin Henry.
The raw statistics are also available for further research at http://dammit.lt/wikistats/
Now if this is the kind of growth for wikipedia in about 7 years, how is it going to sustain without going commercial? The community doesnot want Wikipedia to go commercial , as it might no longer be available freely and may even be available to those who can afford to pay a subscription . Currently , it is running on the various voluntary donations from all over the world. The Wikimedia foundation requires around 5 million dollars/year to sustain the website.Presently it is able to collect only 1.1 dollars/year. So how is it going to sustain, is the main worry?? So all those people who use wikipedia for their work and research, please step forward to donate before this Knowledge Bank shuts down.
Chinese CISCO Switches – FBI concerns
I just recently read an article talking about FBI concerns about counterfiet CISCO Network switches made in China , sold by the Gold/Silver Partners of CISCO to US Federal government agencies.This information was based on a presentation made by the FBI on an investigation into the incident wherein this fraud came to light.Now whether there is a hidden objective behind this or not is noy yet known. The switches have been sold to numeorous government agencies. Now this can be a real concern in India also.Now the question is when these sales are executed through the Gold/Silver partners of CISCO, how does the government check this whether these are OEM certified or look alikes??? First of all we do not have adequate expertise in the Government Quality Control Systems , which are going to do this.How does CISCO check , whether the gold /Silver partners are not selling any counterfiet Switches?? Are there any checks in place…I dont think so that this happens cos i never heard of such a thing.A Network switch in a government organisation can be very dangerous as it can give access to the complete network thereafter. Moreover, how will you know if there is any malicious program running inside these network switches? these questions do not have any answers or are there any???
Now ill tell you something interesting , I have a broadband connection from MTNL(National ISP) wherein they have given me a Chinese broadband modem. I regularly see that , in my router there are lots of intrusions from IP addresses originating from China..Infact i do not know how many people have actually seen their Broadband log while working in the night or left ideal for few hours. Chinese are really proactive in network intrusions and hacking (A Sports site , thought to be associated with CNN has been hacked yesterday by a Chinese University) in protests against Olympic Torch boycott movement in certain European countries.
Counterfeit equipment from China..How do you check???
I just recently read an article talking about FBI concerns about counterfiet CISCO Network switches made in China , sold by the Gold/Silver Partners of CISCO to US Federal government agencies.This information was based on a presentation made by the FBI on an investigation into the incident wherein this fraud came to light.Now whether there is a hidden objective behind this or not is noy yet known. The switches have been sold to numeorous government agencies. Now this can be a real concern in India also.Now the question is when these sales are executed through the Gold/Silver partners of CISCO, how does the government check this whether these are OEM certified or look alikes??? First of all we do not have adequate expertise in the Government Quality Control Systems , which are going to do this.How does CISCO check , whether the gold /Silver partners are not selling any counterfiet Switches?? Are there any checks in place…I dont think so that this happens cos i never heard of such a thing.A Network switch in a government organisation can be very dangerous as it can give access to the complete network thereafter. Moreover, how will you know if there is any malicious program running inside these network switches? these questions do not have any answers or are there any???
Now ill tell you something interesting , I have a broadband connection from MTNL(National ISP) wherein they have given me a Chinese broadband modem. I regularly see that , in my router there are lots of intrusions from IP addresses originating from China..Infact i do not know how many people have actually seen their Broadband log while working in the night or left ideal for few hours. Chinese are really proactive in network intrusions and hacking (A Sports site , thought to be associated with CNN has been hacked yesterday by a Chinese University) in protests against Olympic Torch boycott movement in certain European countries.
Something has to be done!!!!!!
Bored of text search……do some visual search
There are certain things, which really win your heart for the first time you see…and this is what impressed me. You must be tired of the traditional text search which most of the search engines offer presently. But the days are coming soon, when the search would be visual. Visual means, it can be through movement of your eyes or sifting through the graphical results which are retreived.
Searchme.com is one such site developed by an Australian programmer, which is simply superb.After you see the site for yourself, think ahead, what if the sifting of the images , can be done using your eyeball movements. Isnt it unbeleivable, but its true , it is possible. “Gazeeyes” is that technology . Ill write about that in the next article.This site definetly has a long future ahead and the developer Franz Enzenhofer has done a really nice job……so which company is gonna aquire this site ???? Hurry up!!!!






