Live data from Hacker News

Vulnerabilities in TETRA radio networks

cryptomuseum.com

41–50 of 91 posts

Re: Vulnerabilities in TETRA radio networks

#41
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure.

Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

Re: Vulnerabilities in TETRA radio networks

#42
post #29

> Two of the vulnerabilities are deemed critical. One of them appears to be an intentional backdoor [...] Reading the contents of a firmware upgrade is not trivial though, as it is heavily encrypted and relies on a Trusted Execution Environment (TEE), embedded in the core processor of the radio.* I don't know whether the backdoor allegation is correct, but unfortunately we should treat opaque ostensible security with…

[flagged]

That’s your interpretation? I read it as ‘show source, distrust the opaque and while this might be unintentional, don’t assume it is.’

Re: Vulnerabilities in TETRA radio networks

#43
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

> And yet this one lasted 30 years.

Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities.

So indeed, there is something to debate.

But I guess it helps only against those with limited resources, not against nation states.

Re: Vulnerabilities in TETRA radio networks

#44
post #16

> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment. Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the…

Immediate public disclosure.

I'm inclined to agree. I'm not comfortable with the way this unfolded.

> The Dutch NCSC (NCSC-NL) was informed in December 2021, after which meetings were held with the law enforcement and intelligence communities, as well as with ETSI and the vendors. Shortly afterwards, on 2 February 2022, preliminary advice was distributed to the various stakeholders and CERTs. The remainder of 2022 and the first half of 2023 were used for coordination and advisory sessions with stake­holders, allowing manufacturers to come up with firmware patches, updates or workarounds.

This reads to me as if malicious parties were notified some 18 months before users were notified.

Re: Vulnerabilities in TETRA radio networks

#45

Earlier quoted context omitted.

[flagged]

That’s your interpretation? I read it as ‘show source, distrust the opaque and while this might be unintentional, don’t assume it is.’

The last paragraph is probably what they were referring to.

Re: Vulnerabilities in TETRA radio networks

#47
post #8

Earlier quoted context omitted.

^ this post brought to you by RSA, ANSI, ISO, NIST, the NSA, and the authors of DUAL_EC_DRBG /s

... Which iirc was immediately identified as suspicious during auditing.

And yet became a official standard anyway, and was occasionally actually used, despite the fact that is was obviously backdoored to anyone who knew anything about (elliptic-curve) cryptography. (It's literally a textbook-exercise leaky RNG, of the sort that you would find under "Exercise: create a elliptic-curve-based RNG that leaks seed bits within N bytes of random data." in a actual cryptography textbook.)

Re: Vulnerabilities in TETRA radio networks

#48

TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/

It appears to be used for infrastructure, including things like power and transportation signals here in the US.

Re: Vulnerabilities in TETRA radio networks

#49

Earlier quoted context omitted.

... Which iirc was immediately identified as suspicious during auditing.

And yet became a official standard anyway, and was occasionally actually used, despite the fact that is was obviously backdoored to anyone who knew anything about (elliptic-curve) cryptography. (It's literally a textbook-exercise leaky RNG, of the sort that you would find under "Exercise: create a elliptic-curve-based RNG that leaks seed bits within N bytes of random data." in a actual cryptography textbook.)

You don't really need to understand elliptic curves to understand Dual EC. It's a public key RNG. The vulnerability is that there's a matching private key.

Re: Vulnerabilities in TETRA radio networks

#50
post #43

Earlier quoted context omitted.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

> And yet this one lasted 30 years. Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities. So indeed, there is something to debate. But I guess it helps only against those with limited resources, not against nation states.

This is analogous to physical security doors. They are considered passive security, since they are a deterrent, and are rated by the numbers of hours they are expected to hold up against hand tools.
Post reply on HN