Live data from Hacker News

Vulnerabilities in TETRA radio networks

cryptomuseum.com

31–40 of 91 posts

Re: Vulnerabilities in TETRA radio networks

#31
post #25
post #15

Earlier quoted context omitted.

They don't so much backdoor the keying as that they have 4 different cipher profiles, and the one approved for global rather than European use (TEA1) compresses the key from 80 to 32 bits. It's essentially a surreptitious version of what the US did in the 1990s with "export ciphers".

Which makes me question describing this as a "deliberate backdoor."

It's pretty clearly a deliberate backdoor.

Re: Vulnerabilities in TETRA radio networks

#33
post #25
post #15

Earlier quoted context omitted.

They don't so much backdoor the keying as that they have 4 different cipher profiles, and the one approved for global rather than European use (TEA1) compresses the key from 80 to 32 bits. It's essentially a surreptitious version of what the US did in the 1990s with "export ciphers".

Which makes me question describing this as a "deliberate backdoor."

It's deliberate in making the crypto so weak that our guys can decrypt their guys' radio traffic.

How's that not a backdoor?

Re: Vulnerabilities in TETRA radio networks

#34
post #26
post #18

The newsworthy item here is that this is an intentional backdoor. The wikipedia pages list the specific uses per country and department. https://en.wikipedia.org/wiki/Terrestrial_Trunked_Radio#Usag...

Do you remember when cryptography export was controlled? It was implemented by limiting key size to certain number of (effective) bits (of security). This suite is just a victim of that law, as it is a 1990s design.

It's not "just" a victim of that law unless they disclosed that the export cryptography protocol was trivially breakable. Export cryptography in the 1990s US was documented.

Re: Vulnerabilities in TETRA radio networks

#35
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

It's more of intentionally reducing the keyspace when generating keys. You can use weakly generated keys with industry-standard encryption algorithms. When your 4096-bit key is only 32 bits, it doesn't matter how well-trusted the algorithm is.

I just skimmed the paper but it looked to me like the key generation is the same in all profiles, but the TEA1 case has a key setup that compresses the generated key down to 32 bits.

Re: Vulnerabilities in TETRA radio networks

#36
post #22

> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment. Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the…

> It seems a strange belief that you can tell all the radio operators about the vulnerability without also telling exploiters I suspect that there was an update (or replacement) to the radios that was generally described as an ordinary update / maintenance.

Do you also suspect that the patch was generally ignored because nobody knew it was important?

Should the vendor be allowed to continue to sell models they know are compromised while their competition loses those contracts? Shouldn't there be some consequence for such fraud?

Re: Vulnerabilities in TETRA radio networks

#37
post #14

What exactly were TETRA radios used for? I assume they were government/infra related, but then I don't understand why they'd need to backdoor the keying

I think the most relevant use in the context of deliberate backdoor is its use by police and military forces. Apparently some energy providers also use it for remote controlling tasks (no voice).

Re: Vulnerabilities in TETRA radio networks

#38
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

It's more of intentionally reducing the keyspace when generating keys. You can use weakly generated keys with industry-standard encryption algorithms. When your 4096-bit key is only 32 bits, it doesn't matter how well-trusted the algorithm is.

The researchers found several problems. The backdoor seems intentional, but the others do not. They broke the TAA protocol.

Re: Vulnerabilities in TETRA radio networks

#39
post #26
post #18

The newsworthy item here is that this is an intentional backdoor. The wikipedia pages list the specific uses per country and department. https://en.wikipedia.org/wiki/Terrestrial_Trunked_Radio#Usag...

Do you remember when cryptography export was controlled? It was implemented by limiting key size to certain number of (effective) bits (of security). This suite is just a victim of that law, as it is a 1990s design.

Reading the wiki page, it seems to be a European standard. The law you are referring to sounds like a US law.

Re: Vulnerabilities in TETRA radio networks

#40
post #29

> Two of the vulnerabilities are deemed critical. One of them appears to be an intentional backdoor [...] Reading the contents of a firmware upgrade is not trivial though, as it is heavily encrypted and relies on a Trusted Execution Environment (TEE), embedded in the core processor of the radio.* I don't know whether the backdoor allegation is correct, but unfortunately we should treat opaque ostensible security with…

[flagged]
Post reply on HN