Do any embedded systems actually use it for sensitive phone calls? If they're just using it as data transport then they (hopefully) have TLS on top.
Do any embedded systems actually use it for sensitive phone calls? If they're just using it as data transport then they (hopefully) have TLS on top.
I hope not...
> then they (hopefully) have TLS on top.
I'd hope so too, especially given that many cellular modem modules have SSL/TLS support themselves (and they had already 10 years ago), so even a tiny microcontroller communicating by UART to the modem can do TLS.
But reality might be different... it would actually be interesting to see some real-world data about this. I think that some systems connect to special GPRS endpoints (not the usual ones) that connect them directly to some VPN network instead of using the public internet... (if I remember well, I've read this about some automotive systems). So they might actually rely on the VPN encryption for the Internet part, but the GPRS part would then be unsecured if the GPRS crypto is broken.
I imagine gprs will appear as an attack vector for … something
The authors give the above example in the abstract. It does not look like the typical use case for embedded systems. I would think embedded systems send and receive small amounts of non-critical data over GSM, hopefully encrypted, as the parent pointed out. But I may be wrong here - is there a real use case for attacking embedded systems using this method?
yeah, any IoT device that has been built with the assumption of GSM being not eavesdroppable. Cars and alarm systems come to my mind here.
Are we talking obsolete SSL ciphers?
my sweet summer child…
One, traces recorded 10 years ago can be decrypted now. Even if it's getting better now, 2014 era embedded systems barely had the capability to encrypt their traffic.
Two… GSM, GPRS, … the entire telco world … is sold as secure by merit of government standards body rubberstamp. How many government-related or …-regulated embedded systems are out there you think? And how many just took the "GSM → secure" checkbox?