Earlier quoted context omitted.
It's pretty clearly a deliberate backdoor.
And that is supported by the known past actions of "some government authorities". This is definitely not the first time the US government has deliberately sabotaged crypto.
Vulnerabilities in TETRA radio networks
61–70 of 91 posts
Re: Vulnerabilities in TETRA radio networks
#62Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...
What do you mean lasted? If it is an intentional backdoor, it was vulnerable (to those who knew the backdoor) from day 1, so it was never secure let alone 30 years.
Re: Vulnerabilities in TETRA radio networks
#63Earlier quoted context omitted.
> And yet this one lasted 30 years. Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities. So indeed, there is something to debate. But I guess it helps only against those with limited resources, not against nation states.
Is it still true that nation states are at the forefront of innovation and the largest security threats? At least in the United States, I'd be surprised to learn that their best and brightest minds are working in three letter government agencies when they can work in industry for more money and less bureaucracy.
Re: Vulnerabilities in TETRA radio networks
#64Earlier quoted context omitted.
I'm inclined to agree. I'm not comfortable with the way this unfolded. > The Dutch NCSC (NCSC-NL) was informed in December 2021, after which meetings were held with the law enforcement and intelligence communities, as well as with ETSI and the vendors. Shortly afterwards, on 2 February 2022, preliminary advice was distributed to the various stakeholders and CERTs. The remainder of 2022 and the first half of 2023 were…
Depends on who the stakeholders were.
I know "bad guys" is a harsh phrasing, but when it comes to encrypted communication, they are literally the definition of the adversary. Anybody in intelligence that doesn't play for my team is a "bad guy". And since everybody belongs to multiple conflicting teams, even a person who plays on one of my teams is a "bad guy" from the perspective of my other teams.
If the first place you go with a disclosure is to the intelligence community, you are hurting users.
Re: Vulnerabilities in TETRA radio networks
#65What exactly were TETRA radios used for? I assume they were government/infra related, but then I don't understand why they'd need to backdoor the keying
https://www.rcrwireless.com/19980309/archived-articles/dolph...
Re: Vulnerabilities in TETRA radio networks
#66Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...
Re: Vulnerabilities in TETRA radio networks
#67Earlier quoted context omitted.
> And yet this one lasted 30 years. Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities. So indeed, there is something to debate. But I guess it helps only against those with limited resources, not against nation states.
Is it still true that nation states are at the forefront of innovation and the largest security threats? At least in the United States, I'd be surprised to learn that their best and brightest minds are working in three letter government agencies when they can work in industry for more money and less bureaucracy.
Re: Vulnerabilities in TETRA radio networks
#68Earlier quoted context omitted.
And yet this one lasted 30 years. That's far longer than most open encryption algorithms continue to be deemed secure. Obviously you can debate wether having it 'appear' secure for longer before someone publishes details of the flaw is more important or not...
> And yet this one lasted 30 years. Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities. So indeed, there is something to debate. But I guess it helps only against those with limited resources, not against nation states.
No, the main goal is to obfuscate just how incompetent the authors of the spec are, and how clearly they illustrate Dunning-Kruger.
Re: Vulnerabilities in TETRA radio networks
#69Earlier quoted context omitted.
The researchers added a footnote explicitly refuting the claim that 32 bit keys were secure 25 years ago, too. > The Midnight Blue researchers have since demonstrated real-life exploitations of some of the vulnerabilities, for example at the 2023 Blackhat Conference in Las Vegas (USA). They have shown that TETRA communications secured with the TEA1 encryption algorithm can be broken in one minute on a regular commerc…
In the mid-late 90s, 40-bit encryption was common due to US export control restrictions, and even then, that was thought to be insecure against a nation state attacker. In 1998, the EFF built a custom DES Cracker[0] for around $250k that could crack a 56-bit DES message in around 1 week. As was the custom at the time, they published the source code, schematics, and VHDL source in a printed book to evade (and, I guess…
The EFF's legal challenge was essentially that if crypto is a munition, then this printed book explaining the crypto is also at least as much of a munition, if not more so. They gave the judge the choice between deciding that a printed book is some sort of deadly tool, or deciding that crypto wasn't conceptually a munition. Strangely, the judge ruled in the EFF's favor.
Re: Vulnerabilities in TETRA radio networks
#70Earlier quoted context omitted.
> And yet this one lasted 30 years. Main goal of security through obscurity is the hindrance. Make it slower and harder to to detect possible vulnerabilities. So indeed, there is something to debate. But I guess it helps only against those with limited resources, not against nation states.
> Main goal of security through obscurity is the hindrance No, the main goal is to obfuscate just how incompetent the authors of the spec are, and how clearly they illustrate Dunning-Kruger.
If you agree that it obfuscates the meaning of the author’s work, then it also slows down other things recursively…