Live data from Hacker News

Vulnerabilities in TETRA radio networks

cryptomuseum.com

51–60 of 91 posts

Re: Vulnerabilities in TETRA radio networks

#51

The interview that is linked[0] in the footnotes of the article with the person from ETSI is absolutely wild... Some excerpts: > kz (interviewer): How did it go about meeting those requirements, because that's the one they're saying has a backdoor in it. Was that the condition for export? > BM (ETSI): Backdoor can mean a couple of things I think. Something like you'd stop the random number generator being random, for…

The researchers added a footnote explicitly refuting the claim that 32 bit keys were secure 25 years ago, too.

> The Midnight Blue researchers have since demonstrated real-life exploitations of some of the vulnerabilities, for example at the 2023 Blackhat Conference in Las Vegas (USA). They have shown that TETRA communications secured with the TEA1 encryption algorithm can be broken in one minute on a regular commercial laptop and in 12 hours on a classic laptop from 1998 [III].

Re: Vulnerabilities in TETRA radio networks

#52
post #31
post #25

Earlier quoted context omitted.

Which makes me question describing this as a "deliberate backdoor."

It's pretty clearly a deliberate backdoor.

And that is supported by the known past actions of "some government authorities". This is definitely not the first time the US government has deliberately sabotaged crypto.

Re: Vulnerabilities in TETRA radio networks

#53
post #16

Earlier quoted context omitted.

Immediate public disclosure.

I'm inclined to agree. I'm not comfortable with the way this unfolded. > The Dutch NCSC (NCSC-NL) was informed in December 2021, after which meetings were held with the law enforcement and intelligence communities, as well as with ETSI and the vendors. Shortly afterwards, on 2 February 2022, preliminary advice was distributed to the various stakeholders and CERTs. The remainder of 2022 and the first half of 2023 were…

Depends on who the stakeholders were.

Re: Vulnerabilities in TETRA radio networks

#54

The interview that is linked[0] in the footnotes of the article with the person from ETSI is absolutely wild... Some excerpts: > kz (interviewer): How did it go about meeting those requirements, because that's the one they're saying has a backdoor in it. Was that the condition for export? > BM (ETSI): Backdoor can mean a couple of things I think. Something like you'd stop the random number generator being random, for…

The researchers added a footnote explicitly refuting the claim that 32 bit keys were secure 25 years ago, too. > The Midnight Blue researchers have since demonstrated real-life exploitations of some of the vulnerabilities, for example at the 2023 Blackhat Conference in Las Vegas (USA). They have shown that TETRA communications secured with the TEA1 encryption algorithm can be broken in one minute on a regular commerc…

In the mid-late 90s, 40-bit encryption was common due to US export control restrictions, and even then, that was thought to be insecure against a nation state attacker.

In 1998, the EFF built a custom DES Cracker[0] for around $250k that could crack a 56-bit DES message in around 1 week. As was the custom at the time, they published the source code, schematics, and VHDL source in a printed book to evade (and, I guess, mock) export restrictions.

0 - https://en.m.wikipedia.org/wiki/EFF_DES_cracker

Re: Vulnerabilities in TETRA radio networks

#55
post #8

Earlier quoted context omitted.

^ this post brought to you by RSA, ANSI, ISO, NIST, the NSA, and the authors of DUAL_EC_DRBG /s

... Which iirc was immediately identified as suspicious during auditing.

The assertion I was refuting was that they couldn't be easily inserted into an audited library, not that they wouldn't be detected.

Re: Vulnerabilities in TETRA radio networks

#56
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

It lasted 30 years in the sense it hasn't been publicly broken before.

We don't know how many intelligence agencies have found some of these and are happily listening in on "secure" communication, concealing that fact successfully.

Re: Vulnerabilities in TETRA radio networks

#57
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

The TEA1 key compression weakness may have been known to intelligence agencies as early as 2006. See https://www.cryptomuseum.com/radio/tetra/ under section "Compromise".

Re: Vulnerabilities in TETRA radio networks

#58

Earlier quoted context omitted.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

It lasted 30 years in the sense it hasn't been publicly broken before. We don't know how many intelligence agencies have found some of these and are happily listening in on "secure" communication, concealing that fact successfully.

Aren't these encrypted radios mostly for cops?

I mean, this is embarrassing - but who cares if the secret police are spying on the regular police?

Re: Vulnerabilities in TETRA radio networks

#59
post #43

Earlier quoted context omitted.

And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...

> And yet this one lasted 30 years. Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities. So indeed, there is something to debate. But I guess it helps only against those with limited resources, not against nation states.

Is it still true that nation states are at the forefront of innovation and the largest security threats? At least in the United States, I'd be surprised to learn that their best and brightest minds are working in three letter government agencies when they can work in industry for more money and less bureaucracy.

Re: Vulnerabilities in TETRA radio networks

#60

Earlier quoted context omitted.

It lasted 30 years in the sense it hasn't been publicly broken before. We don't know how many intelligence agencies have found some of these and are happily listening in on "secure" communication, concealing that fact successfully.

Aren't these encrypted radios mostly for cops? I mean, this is embarrassing - but who cares if the secret police are spying on the regular police?

Whose secret police are spying on the civilian police.

Is it more concerning if it’s the Russian secret police spying on the Kyiv police?

Post reply on HN