Sources: We were pressured to weaken mobile security in the 80's
aftenposten.no
aftenposten.no
It seems curious that the intelligence community would be so vocal in such a directly attributable manner when simpler means of interception exist, and when many other reasons could be given for reducing the key size (e.g. cost seems an obvious one, given we're talking about the 80s here), not to mention that A5/1 itself had major flaws that puts it on the level of WEP in terms of the ease with which it could (and still can) be cracked.
This sounds like you're too young to remember that the "modern context" is what's actuall "ancient" -- it has been around since the fifties -- with several mass surveillance scandals along the way back in those decades.
As for the "ancient story" -- people in their early forties were active in the eighties tech world man. We still use tons of technologies from that era. Nothing ancient about it.
You do realize that the NSA spent most of the cold war trying to keep good cryptography out of civilian and foreign hands, right? The day after Rivest, Shamir, and Adleman published their paper, government agents showed up and put police tape around their lab. Also, this:
https://www.schneier.com/blog/archives/2008/01/nsa_backdoors...
And this:
http://www.usnews.com/usnews/news/articles/950403/archive_01...
Conclusion: The GSM networks in USA implement only few of the protection measures observed in other GSM networks.
Encryption algorithms:
AT&T T-Mobile
A5/0 45% 17% (ie: unencrypted)
A5/1 55% 83%http://arstechnica.com/tech-policy/2013/12/archaic-but-widel...
Does anyone know if LTE security is that much better? I imagine that even if the ciphers are good, there are probably a ton of ways for agencies like NSA or even FBI to intercept the calls before being encrypted, even without warrants.
It would be interesting to know if LTE, being packed based, is is susceptible to attacks such as there: http://boingboing.net/2008/06/19/listen-in-on-encrypt.html
But yes, the access provider can still tap the line.
Hm, 1999? http://cryptome.org/a51-crack.htm
Also, imo, the main problem with the GSM or mobile security schemes is, that they seem to have been _deliberatly_ weakened and/or use ciphers that were known to be insecure.
This news just reaffirms what a lot of people have been suspecting all along.
But is SNOW better than KASUMI aka A5/3? Why not just use AES? When I see non-standard and untested encryption algorithms, I think of the NSA and GCHQ. In any event, that's why I want E-ULTRA (the LTE communications protocol) implemented in GNU Radio: to disable SNOW 3G and null ciphers.
I should also note that, from what I can tell, in GSM/LTE all keys (including that for the link between the cell and the tower) are (statically/algorithmically) derived from the symmetric private key shared between the SIM and the service provider's Home Subscriber Server. Which, if I understand correctly, means it would be trivial to decrypt any surreptitiously intercepted but encrypted communications by using a NSL or subpoena to obtain those keys from the service provider or the access provider (assuming it wasn't already lawfully intercepted by the access provider of course). I assume that also holds true for any Joe Blow with subpoena power and the ear of a sympathetic judge (think "Doe subpoena"). So make sure your service is from a company located in an unfriendly nation, even if your access already is!
But if they would have just used (ephemeral) Diffie-Hellman for the cell-to-tower communications, they couldn't do that. Which is why when I see any GSM/LTE standards, I think of the NSA and GCHQ. The same goes for IPsec and the magic numbers used in some of these encryption algorithms.
Edit: more technical and legal discussion of consequences
http://blog.cryptographyengineering.com/2013/05/a-few-though...
TL;DR: GSM security is a joke. LTE is okay, except for two critical issues: One, an attacker can jam LTE and cause a downgrade to GSM. Two, it doesn't offer forward secrecy, so an attacker can record your traffic, obtain the private key from your carrier, and decrypt it. It's a reasonable assumption that NSA and your local sigint agency routinely make copies of your carrier's key database.
Edit: Reword last sentence.
"Indeed, my spies inform me that there was a terrific row between the NATO signals agencies in the mid 1980's over whether GSM encryption should be strong or not. The Germans said it should be, as they shared a long border with the Evil Empire; but the other countries didn't feel this way. and the algorithm as now fielded is a French design."
https://groups.google.com/forum/#!msg/uk.telecom/TkdCaytoeU4...