Live data from Hacker News

Vulnerabilities in TETRA radio networks

cryptomuseum.com

1–10 of 91 posts

Re: Vulnerabilities in TETRA radio networks

#3
> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment.

Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the vulnerability without also telling exploiters. Aren't they often one and the same? What's a reasonable approach here?

Re: Vulnerabilities in TETRA radio networks

#5
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

You can't easily put backdoors in cryptographic algorithms that can be audited

Re: Vulnerabilities in TETRA radio networks

#6
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

The bigger issue here is that there's an intentional vulnerability.

Re: Vulnerabilities in TETRA radio networks

#7

TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/

The question is, did things like emergency services actually use the higher levels, or did they just use TEA1?

It's kind of like saying...

Vendor: "We support up to 1 zillion bit encryption!"

User: "What's the default out of the box?"

Vendor: "10 bit"

Re: Vulnerabilities in TETRA radio networks

#8
post #4

Sounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.

You can't easily put backdoors in cryptographic algorithms that can be audited

^ this post brought to you by RSA, ANSI, ISO, NIST, the NSA, and the authors of DUAL_EC_DRBG

/s

Re: Vulnerabilities in TETRA radio networks

#9

TL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/

Hogwash, I think it's worth noting that this European system was intentionally backdoored.

Everybody plays the espionage game, Europe really is no exception, they just like to use the US to keep their hands (mostly) clean.

Re: Vulnerabilities in TETRA radio networks

#10

> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment. Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the…

[deleted]
Post reply on HN