bk99.de entertain the web since 1997

Intelligence service ensured weak GSM encryption

Summary

According to the Norwegian newspaper Aftenposten, the British intelligence service pushed in the 1980s for GSM to be only weakly encrypted. Originally the standard was to offer 128 bits, but A5/1 ended up with an effective 54 bits; the British even wanted only 48 bits. Germany, fearing espionage by the Eastern Bloc, pushed for stronger encryption.

Ideas

  • Intelligence services influence standards so that they can listen in themselves.
  • Deliberately weakened encryption weakens it for everyone.
  • German and British interests were opposed on GSM.

Insights

  • Backdoors and deliberately weak methods ultimately benefit attackers as well.
  • Political compromises in standards have effects for decades.

Facts

  • The statements come from, among others, Jan Arild Audestad, who worked on GSM.
  • A5/1 uses 64 bits, 10 of which are set to zero, i.e. effectively 54 bits.
  • Telekom upgraded its network to A5/3 by the end of 2013.
  • With equipment costing little more than 100 euros, A5/1 calls could be intercepted from around 100 metres.

References

Critique

  • The account is based on contemporary witnesses who confirm each other, but not on documents.

Remarks

  • A5/1 has long been considered practically broken; LTE and 5G use considerably stronger methods.

Recommendations

  • Do not rely on mobile network encryption for confidential conversations; use end-to-end encrypted apps.
  • Disable 2G on mobile devices where the operating system allows it.

Read the original article

Search the Web Archive