Huge GSM flaw allows hackers to listen in on voice calls
neowin.net
neowin.net
A direct link to the presentation:
http://www.scribd.com/doc/18668509/HAR2009-Cracking-A5-GSM-E...
The long and the short of it, they're going to take the academic result that you can precompute A5 and use a GPU cluster to build a rainbow table cracking implementation.
This result is a couple steps away from apocolyptic, but not all the way there:
* They haven't subverted GSM base stations (this is going to turn out to be doable, though). They can't pick a phone at random.
* They aren't publishing the GNU Radio code to sniff GSM. There are several free GSM projects, but putting the pieces together still requires talent, unlike wifi cracking.
* Regardless of whether these attacks are ever used in the wild, this will probably have a big effect on financial security, where GSM is used as a safe out-of-band authentication mechanism.
Base station security is a separate matter. Why do you think A5/1 influences that?
If I remember right, even Applied Cryptography managed to call out A5 as bad.
If you're going to announce a hack, announce the hack. If you're not, don't. Why go through the same song-and-dance every time?
My Sideproject++ gotta do something with all these EC2 nodes laying around.