GSM Encryption Hacked

ZTE Tania

ZTE Tania

Windows Phone Mango

Fully equipped

Great for business and pleasure

More...
BlackBerry Bold 9790

BlackBerry Bold 9790

BlackBerry OS7

Powerful & Fully Featured

Smooth performance for browsing the web, running apps, working with documents, and enjoying multimedia

More...
Motorola RAZR

Motorola RAZR

The RAZR is back

Faster, Thinner, Smarter, Stronger

Dual-core 1.2GHz processor, 7.1mm body, MotoCast, and KEVLAR strong.

More...
HTC Sensation XL

HTC Sensation XL

Feel every beat

With Beats Audio

A multimedia superstar with Beats earphones included.

More...
HTC Titan

HTC Titan

Unlike anything you've ever held before

Office on the move

Windows Phone 7.5 (Mango). With a 4.7-inch screen and big virtual keyboard, the Titan is perfect for both work and play.

More...
HTC Radar

HTC Radar

Real time close

Windows Phone 7.5 (Mango)

Pull all your contacts and social networks together into one place to stay connected with friends and share instantly.

More...
BlackBerry Bold 9900

BlackBerry Bold 9900

Slim yet powerful

Touch and Type in harmony

The Bold 9900 is RIM's thinnest BlackBerry smartphone yet and as lightweight and durable as it is feature-packed.

More...
BlackBerry Curve 9360

BlackBerry Curve 9360

Socially aware

Sleek and stylish

The 9360 feels just right in your hand and with a ton of accessories you can really make it your own.

More...
HTC ChaCha

HTC ChaCha

Facebook integrated

Full qwerty Android

Share virtually anything with just one touch.

More...
ZTE Libra

ZTE Libra

Affordable Android

WiFi hotspot, Exchange email, Google Maps and much, much more all at an attractive price.

More...
ZTE MF30/MF60

ZTE MF30/MF60

Portable Internet

USB & WiFi for Windows and Mac

High speed, portable Internet access in your pocket.

More...
Motorola Defy +

Motorola Defy +

Lifeproof

Faster, smarter, richer

Scratch, dust and water-resistant. 1GHz processor, 5MP camera and great pre-loaded apps.

More...
Motorola Pro +

Motorola Pro +

Works and plays as hard as you do

Faster, smarter, richer

A powerful smartphone optimised for business but fun enough to use for your personal life.

More...
BlackBerry Curve 9380

BlackBerry Curve 9380

BlackBerry OS7

The 1st all-touch Curve

Easily capture and share your favourite moments with family, friends and colleagues.

More...
Novatel MiFi 3352

Novatel MiFi 3352

Intelligent Personal Mobile Hotspot

Portable High-Speed Internet

Carry the Internet with you stream media wirelessly from your SD card.

More...
HTC Sensation XE

HTC Sensation XE

With Beats Audio

Designed to impress

With custom Beats headphones, engineered to deliver extraordinary sound.

More...
HTC Rhyme

HTC Rhyme

Accessories to fit your life

Stay connected with those closest to you

Stylish, effortless technology.

More...
ZTE Skate

ZTE Skate

Affordable Android

WiFi hotspot, Exchange email, Google Maps and much, much more all at an attractive price.

More...
HTC Explorer

HTC Explorer

A design that fits your lifestyle

Keep in touch with the people who matter

Jump right into what's most important to you thanks to an improved lockscreen design.

More...
ZTE Tureis

ZTE Tureis

Full Qwerty 2.6-inch touchscreen

Android Gingerbread

Business and social features in a slim package.

More...
Frontpage Slideshow (standalone) | Copyright © 2006-2011 JoomlaWorks Ltd.

The GSM encryption algorithm A5/1, the code used to secure mobile phone communications, has been cracked by a German cryptographer, Karsten Nohl. Much has been made of this feat, which was done by capturing large amounts of encrypted signals and then subjecting them to a sustained attack (trying one key after another until one eventually worked) enlisting the help of members of the public throughout the world who ‘leant’ him the processing power of their PCs and games consoles! It was estimated that trying to hack the code would have taken over 100,000 years on a single PC – by enlisting a ‘botnet’ of networked public PCs they allegedly managed it in 3 months.

A stronger encryption method exists already, called A5/3, which uses 128-bit encryption over the 64-bit encryption used by A5/1, but operators need to upgrade their networks to support this stronger standard and there is a risk if they do so that older phones will no longer work. Upgrades are being rolled out, but for those that haven’t yet upgraded their network, this will hopefully serve as a push to do so: new services such as SMS banking could all provide attractive reasons for hackers to try to intercept your traffic.

It is important to appreciate that this applies to the GSM standard only: 2G communications – it does not apply to WCDMA (3G).

Although the method employed by Karsten requires that he be close enough to an individual’s phone to be able to record the traffic, with the cost of cellular equipment falling, for a few £1000 it is not beyond the means of the average hacker to purchase equipment to create a ‘fake’ base station and capture the traffic of all handsets that register with it: all it needs to be able to do is broadcast the appropriate 5-digit SIC of the network operator and operate at a higher power rate than any other towers in the area.
This is possible due to weaknesses in the GSM architecture – we have seen before (http://blog.brightpointuk.co.uk/introduction-mobile-data-technologies) that with GSM, phones are each assigned a specific ‘carrier’ on a set frequency and use this carrier to send encrypted data to the tower. However this carrier is only used for the user’s traffic (voice and data). The ‘behind-the scenes’ signalling done between the phone and the tower to monitor network registration and signal strength is all done over a reserved carrier, known as the SS7 carrier. This carrier is NOT encrypted – a GSM phone will talk to and register with any base station that identifies itself correctly.

In order to do this practically, all you need is some suitable radio hardware connected to a PC. OpenBTS is a free piece of software available for download that enables you to program the connected radio transceiver with frequency, power and SIC information (http://openbts.sourceforge.net/). Designed for setting up cheap networks in greenfield and third world areas, OpenBTS can be used to act as a cell site for GSM phones. When used in conjunction with AirProbe or WireShark, voice and signalling traffic can be isolated and the voice traffic sent to a PC for decryption. The decrypted traffic can then be passed to any IP PBX, such as Asterisk, where the voice call can be recorded and listened to via a PC Softphone.
I say that that is 'all' you would need - this is far from plug and play equipment we're talking about.

This is not the first time the A5/1 standard has been cracked, what differentiates this news is that Karsten has written out the entire A5/1 codeset – all possible input values and their encrypted counterparts – and posted it on the Internet: approximately 2TB of data. This enables the decryption of encrypted communications in ‘real time’ with suitable processing hardware.
Karsten’s motivation for doing this is allegedly an altruistic one – he wants networks to beef up security. He has certainly got a lot of public attention.

Vodafone, Orange, O2 and T-Mobile all use A5/1 on their 2G GSM networks in the UK.

NOTE - whilst Karsten Nohl has demonstrated the ability to intercept voice communications, should you be sending encrypted data over a GSM link (such as a VPN connection), once the GSM encryption has been removed, the encrypted VPN data will still be just that - encrypted, so don't take this news to mean that all data is now vulnerable to interception.