Vulnerabilities in TETRA radio networks
cryptomuseum.com
Vulnerabilities in TETRA radio networks
1–10 of 91 posts
Re: Vulnerabilities in TETRA radio networks
#2Re: Vulnerabilities in TETRA radio networks
#3Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the vulnerability without also telling exploiters. Aren't they often one and the same? What's a reasonable approach here?
Re: Vulnerabilities in TETRA radio networks
#4Re: Vulnerabilities in TETRA radio networks
#5Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
Re: Vulnerabilities in TETRA radio networks
#6Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
Re: Vulnerabilities in TETRA radio networks
#7TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/
It's kind of like saying...
Vendor: "We support up to 1 zillion bit encryption!"
User: "What's the default out of the box?"
Vendor: "10 bit"
Re: Vulnerabilities in TETRA radio networks
#8Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
You can't easily put backdoors in cryptographic algorithms that can be audited
/s
Re: Vulnerabilities in TETRA radio networks
#9TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/
Everybody plays the espionage game, Europe really is no exception, they just like to use the US to keep their hands (mostly) clean.
Re: Vulnerabilities in TETRA radio networks
#10> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment. Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the…