Security Flaws in Encrypted Police Radios
schneier.com
schneier.com
Police tactical radios are an interesting case where denial of service and traffic analysis are genuinely threatening scenarios. Most modern crypto protocols aren't built to be secure from either. So right off the bat, you have a paper saying they can shut police tactical radios off for entire metro areas.
I'm not sure how true that is of digital domain RF in general, though.
The confidentiality flaws here seem to boil down to usability; the configuration and metadata used by this system is so brittle that trivial real-world setbacks preclude encryption; these happen so often that police teams don't even notice when encryption isn't enabled.
The sender and receiver (eventually) synchronise, and so they know where they're going to hop next, and can filter tightly around that channel.
The biggest problems with this system seems to be:
1) trying to retrofit digital & encrypted comms into currently used bands, requiring all sorts of horrible compromises to make it work.
2) Real-time voice (along with those compromises, and 'intelligibility-driven error correction') requires them to use a less capable encryption method. Accepting degraded voice signals means they can't reliably use MAC to avoid replay attacks.
3) User training and device usability are terrible. Combined with cargo-cult security ideas (must change keys fast good!) are worse.
[1] https://secure.wikimedia.org/wikipedia/en/wiki/Frequency-hop... [2] https://secure.wikimedia.org/wikipedia/en/wiki/Direct-sequen...
(secure is actually ∅ and clear is O; the police team got it backwards)
A crude example is a ham-radio fox hunt. A radio is hidden somewhere in a pre-agreed area and teams of foxhunters are set loose once the fox ready to go. If the fox is exactly one transmitter and its power is steady, it can still take the better part of an hour, for example, to locate a fox hidden within a one block area.
So increase the ability of the trackers, say with doppler direction finders mounted on roofs. Now the jammers can do the following things to continue to wreak havoc.
1) Vary the power in 3db steps, perhaps in a loose random fashion. Fox-hunting techniques include rotating an antenna and pinpointing where signal strength peaks.
2) Using carefully time-syncronized jamming boxes, scatter three or four of them around the area and have them turn take turns being on. Or have two out of three on in some overlapping way.
3) Combine 1&2.
4) Oh, make them mobile.
There's also a purely-passive direction finding thing for all radios (active or not); I remember a Dutch guy created a "fuzz meter" which would ID local cops; trivial to do with this description of the P25 protocol.