TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/
Vulnerabilities in TETRA radio networks
11–20 of 91 posts
Re: Vulnerabilities in TETRA radio networks
#12Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
Re: Vulnerabilities in TETRA radio networks
#13TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/
This is IMHO a very unfair TLDR; . The news is that the researchers claim that there is deliberate backdoor, which ETSI denies. If it is true, there cannot be any further trust in other proprietary parts as well.
Re: Vulnerabilities in TETRA radio networks
#14Re: Vulnerabilities in TETRA radio networks
#15What exactly were TETRA radios used for? I assume they were government/infra related, but then I don't understand why they'd need to backdoor the keying
It's essentially a surreptitious version of what the US did in the 1990s with "export ciphers".
Re: Vulnerabilities in TETRA radio networks
#16> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment. Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the…
Re: Vulnerabilities in TETRA radio networks
#17Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
You can't easily put backdoors in cryptographic algorithms that can be audited
Re: Vulnerabilities in TETRA radio networks
#18Re: Vulnerabilities in TETRA radio networks
#19Re: Vulnerabilities in TETRA radio networks
#20Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.