Re: Instant Ciphertext-Only Cryptnalysis of GSM Encrypted Communication

From: Douglas A. Gwyn (DAGwyn_at_null.net)
Date: 09/06/03


Date: Sat, 06 Sep 2003 08:22:41 -0400

Mok-Kong Shen wrote:
> What was meant also indirectly is: With all the work
> on security by the people in the cellphone business, why
> isn't a general attempt undertaken to e.g. leave
> some space in memory such that a user could do some
> programming of his own, for example, to do some encryption
> for his SMS?

?? You don't get security by letting the end user program
the processor.

In fact there have been cellular telephones that support
various forms of cryptosecurity. But you need to be part
of the key management system.

> As an aside, in a past thread of the group someone claimed
> that the more modern types of cellphones maintain contact
> with base stations even if switched off by the user, unless
> the battery is removed. (An article in the German
> newspaper Computer Zeitung long ago had an interview
> with someone of BSI who also recommended the removal
> of batteries in cases needed.) This would enable constant
> tracking of people, excepting those who take the pain
> to remove batteries. (This is fine for the children,
> though. I read that in UK there is now business offering
> finding the location of children to parents.)

Actually it's not fine for anybody. If a business can
track your kids, so can a stalker.
The requirement for tracking was imposed by government(s)
without much notice being paid by the news media.

> BTW, another very dumb question: It is said that there
> are export and non-export version of the encryption
> algorithm involved. Is it that there again the US export
> regulations are playing a role? If yes, is eventually
> Kasumi also subject to US regulations (it's a
> Japanese developement, though, if I don't err)?

Not just US regulations.
The US has for the most part employed different modulation
systems from the Europeans, not usually out of considerations
of preventing technology transfer. The original US analog
scheme was pushed out the door despite expert testimony of
the *ease* of intercept, basically a CB radio with different
crystal. The FCC's response was to push for legislation
outlawing interception, instead of requiring that a secure
design be used. The whole subject is rather sickening.
Products sold within the US are subject to US regulations.

> Anyway, it seems that the subject line of this thread
> is a good reminder of the (trivial) fact that, for stuffs
> that are really critical, anything short of end-to-end
> encryption can never be good.

Or that even end-to-end encryption might not be sufficient.



Relevant Pages

  • Re: Random election thoughts
    ... streamlining govt and removing taxes and regulations from business would be the best way to fix it. ... I don't know the US tax system but I am an expert on the Canadian one and any company making such a ridiculous net loss as people like AIG say they are making would not be paying tax anyway. ... In the case of business in general regulations often only add extra expense and paperwork which does nothing to increase efficiency, employ people, or generate extra taxes. ... Creating federal jobs is never a good thing. ...
    (rec.sport.pro-wrestling)
  • Re: Win32 Changes Spacely -> Highlander
    ... Not literally without, but not *controlling* commerce. ... I glad you don't believe the "Government is Evil" mantra floating ... virtual maze of regulations that govern just about any business decision. ...
    (borland.public.delphi.non-technical)
  • Re: Multi-layered PKI implementation
    ... I think I have a grasp on the basics of PKI as it relates to X.509 ... Suppose a business wants to ... dual key encryption has little to offer over more ... Unlike real physical keys to doors, he does not have to carry ...
    (Debian-User)
  • Re: OT: dominos continue to topple
    ... I want to sell them. ... wasn't anyone around to enforce the regulations. ... the 1920s when there was no regulation of business or financial markets. ... saw what the results of free market capitalism were in 1929. ...
    (rec.crafts.metalworking)
  • Re: Angry Smokers Cancel $3 million of Bookings!
    ... regulations in a jurisdiction, then the business may not have the ... it stops the business that wants to cater to a smoking business from ... the old people wanted to smoke and couldn't quite see that just ...
    (rec.travel.cruises)

Loading