About cracking GSM: 1479_26C3.Karsten.Nohl.GSM.pdf(events.ccc.de)
events.ccc.de
About cracking GSM: 1479_26C3.Karsten.Nohl.GSM.pdf
http://events.ccc.de/congress/2009/Fahrplan/attachments/1479_26C3.Karsten.Nohl.GSM.pdf
4 comments
I don't know. This guy just reiterated things that were known years ago. And he claims he cracked GSM...
The difference is that they completed the computation of the rainbow tables, which are required to make this attack practical, and made them public (although the webserver with the torrent files is currently down: http://reflextor.com/torrents/). Of course theoretically this attack is known for quite some time, but making it practical by providing the equipment and rainbow tables is new.
Interesting enough they planned to do a workshop today, where you could bring your GSM data and they wanted to try to decrypt it. However, due to legal reasons they had to cancel it (http://events.ccc.de/congress/2009/wiki/The_demonstration_is...).
Interesting enough they planned to do a workshop today, where you could bring your GSM data and they wanted to try to decrypt it. However, due to legal reasons they had to cancel it (http://events.ccc.de/congress/2009/wiki/The_demonstration_is...).
The method (rainbow tables) is not new, no. There have been several efforts to produce a complete set of precomputed tables for GSM's A5/1 algorithm. What he did was finish the tables.
I haven't watched the video of the talk but I'm curious how he did it; I thought that some of the distributed-computation efforts were furthest along that path to completion.
Anyway, finishing and distributing the tables is not an insignificant achievement and makes A5/1 functionally much less secure, even if from a pure-math/academic perspective, the "break" occurred several years ago when the attack was first published.
Like many users and IT folks, I'm less interested in academic cryptography (though I find it interesting) than in the functional, in-the-wild side of things. The existence of a theoretical attack using precompute tables matters a lot more when those tables have actually been produced and distributed in a usable form. That's the case now, so that attack moves from being a theoretical one to a very real one.
The next step would be for someone to package the attack in the form of a script-kiddie-usable utility that would perform interception/decryption using an off-the-shelf GSM USB modem. I have my doubts that the mobile carriers and handset manufacturers will take any significant steps towards mitigation of A5/1 until it's not only broken in the academic and hacker communities, but the technology to intercept calls is in the hands of every moron with a casual interest in snooping. That seems to be how these things go; they'll drag their feet as long as possible, until the public pressure becomes unbearable.
I haven't watched the video of the talk but I'm curious how he did it; I thought that some of the distributed-computation efforts were furthest along that path to completion.
Anyway, finishing and distributing the tables is not an insignificant achievement and makes A5/1 functionally much less secure, even if from a pure-math/academic perspective, the "break" occurred several years ago when the attack was first published.
Like many users and IT folks, I'm less interested in academic cryptography (though I find it interesting) than in the functional, in-the-wild side of things. The existence of a theoretical attack using precompute tables matters a lot more when those tables have actually been produced and distributed in a usable form. That's the case now, so that attack moves from being a theoretical one to a very real one.
The next step would be for someone to package the attack in the form of a script-kiddie-usable utility that would perform interception/decryption using an off-the-shelf GSM USB modem. I have my doubts that the mobile carriers and handset manufacturers will take any significant steps towards mitigation of A5/1 until it's not only broken in the academic and hacker communities, but the technology to intercept calls is in the hands of every moron with a casual interest in snooping. That seems to be how these things go; they'll drag their feet as long as possible, until the public pressure becomes unbearable.
I was at the talk. He didn't claim he cracked GSM and went over the history of the development of A5 attacks. He explained that their work is the first time the data necessary to crack A5 has been made public.
This work is important because it is a major step towards producing a working open source real-time GSM cracker.
This work is important because it is a major step towards producing a working open source real-time GSM cracker.
Does this mean people will have to replace billions of phones with a new code?
Has anyone found a video of this talk yet?
ftp://ftp.ccc.de/congress/26C3/mp4/
has all the currently available official recordings of the 26c3. i think the gsm talk was labeled "gsm srsly" or sth like that
has all the currently available official recordings of the 26c3. i think the gsm talk was labeled "gsm srsly" or sth like that
[deleted]