GSM phone encryption blown wide open

At last: a reason to move to 3G

The encryption system used on 850 million GSM phones has been blown wide open by Israeli scientists. The result is that with a small radio receiver and laptop it is possible to intercept and listen to an individual's phone calls and even make a call as if it was coming from their phone. This is possible thanks to a flaw in the GSM code, explained Professor Eli Biham of the Technion Institute of Technology in Haifa. "They have got the error connection code and encryption the wrong way around," he told us. The error correction code is sent with every packet of data from the phone to identify it and so make assimilation of the different packets at the other end smoother. Otherwise the phone call would be extremely noisy. This code is sent unencrypted however while the rest of the data is encrypted making listening in to a phone conversation impossible. Prof Biham explained that by picking up a phone call in progress - easily done - and then reading the error correction codes, it is possible to piece together the encrypted parts of a phone conversation together within a fraction of a second. While the conversation is still encrypted, GSM's security can be broken fairly easily with a laptop running a code-breaking algorithm. Until now however, it has been necessary to record conversations and then break the code and then subsequently try to apply this to later phone calls. With the exact encrypted conversation running through a laptop however, it is possible to listen in in real-time, says Biham. What's more, by reversing the process someone can make a call seemingly from an individual's number. Prof Biham says he sent the research - actually put together by two of his students Elad Barkan, and Nathan Keller - to the GSM Association a few months ago. The Association hasn't been back to him but he says he is confident it knows what to do. The GSM Association has accepted there is a flaw but is downplaying the security breach. It said an upgrade in July 2002 had effectively removed the problem, although Biham claims to be able to decrypt even the most recent GSM phones. The Association also said that the hole could only be exploited with complex and expensive technology and that it would take a long time to target individual callers. Again, Biham disagrees however. "It is not too sophisticated. Even small companies with the right expertise could do this. You would need a radio receiver and transmitter and something to apply the attack algorithm - a laptop or computer. I don't know how to build it but it shouldn't be too hard. It's not a large machine." As for targeting individual callers, this is also a lot easier that the Association makes out, Biham contends. "To listen to a particular transmission, you would need to know the number of the phone because it is not transmitted, but if you have that, it is simple." You do need to be in the same cell as the caller though. Otherwise, he says, it would be a matter of listening in to all the conversation in one cell. But with each call crackable within a fraction of a second, this is not the most convoluted process and one the right phone had been located, it would be easier the next time. If, however, you were in the next room as the caller, the process would be extremely easy - and this is the most worrying development of the new research. Biham explained that for the problem to be eliminated, a lot of the hardware in the network would have to be changed and something done to every single phone. He says this would be an extremely difficult task and feels it is more likely that the phone companies will simply move on to the next generation of 3G phones, which do not contain the flaw. And so we may finally have found a reason to move onto the expensive, unreliable and over-engineering 3G networks - privacy. Could we soon find ourselves in the position where mobile companies warn us about people listening in to our phone calls in order to save themselves from financial meltdown?

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan

Security star Fortinet sets price for IPO

Investors still have taste for tech.



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *