Technology news and Jobs arrow VIRTUALISATION arrow You can help break GSM encryption
You can help break GSM encryption E-mail
by David Heath   
Wednesday, 02 September 2009
There is a project underway to employ distributed computers to compute rainbow tables for GSM decryption.  Download the code and join in, if you're interested!

As reported previously serious issues with GSM encryption are widely known, however it was generally assumed that one needed either lots of money or lots of time to decrypt the highest-level A5/1 encryption standard used by the inner sanctum of friendly countries (unfortunately Australia was always condemned to use the completely-broken A5/2 standard).

At the recent Hacking at Random conference in mid-August, security researcher Karsten Nohl from Virginia Tech outlined a new project to harness as many computing resources around the world to calculate "Rainbow Tables" allowing a quick lookup of the plaintext, given an encrypted text fragment.  This is a drastic simplification, but I'm sure you'll get the gist – instead of having to attempt to decrypt the material, it can simply be used to look into a reverse-translation table.

For Nohl's project, the Rainbow table will be huge – estimated at 128 Petabytes; clearly this will need to be distributed across a large number of computers around the world.

Interviewed recently on CNET, Nohl said "We're not creating a vulnerability but publicizing a flaw that's already being exploited widely. Clearly we are making the attack more practical and much cheaper, and of course there's a moral question of whether we should do that."

So, assuming you'd like to be involved, what do you need?  Simple – any modern PC with a NVIDIA video card which supports the CUDA development environment.  If you fit the bill, head to the project website and download the code (still currently in alpha).

What will this mean?  Obviously, that any call (or data connection) can be accessed and decrypted.  Also, this rather hurts some of the payment services based on GSM standards – Gpay for instance.

I wonder if this will FINALLY spur the telcos and the GSM organisation to actually create a viable encryption protocol. 

The current one is broken.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter