Berkeley CSUA MOTD:Entry 53607
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/04/03 [General] UID:1000 Activity:popular
4/3     

2009/12/29-2010/1/19 [Computer/SW/Security] UID:53607 Activity:nil
12/29   Sounds like the GSM encryption key has been recovered via a
        brute force attack:
        http://www.nytimes.com/2009/12/29/technology/29hack.html
2025/04/03 [General] UID:1000 Activity:popular
4/3     

You may also be interested in these entries...
2012/8/26-11/7 [Computer/SW/Security] UID:54465 Activity:nil
8/26    Poll: how many of you pub/priv key users: 1) use private keys that
        are not password protected 2) password protect your private keys
        but don't use ssh-agent 3) use ssh-agent:
        1) .
        2) ..
        3) ...
	...
2012/8/7-10/17 [Computer/SW/Security] UID:54455 Activity:nil
8/6     Amazon and Apple have lame security policies:
        http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all
        "First you call Amazon and tell them you are the account holder, and
         want to add a credit card number to the account. All you need is the
         name on the account, an associated e-mail address, and the billing
         address. "
	...
2012/7/18-8/19 [Health/Men, Computer/SW/Security] UID:54438 Activity:nil
7/18    "Largest penis record holder arouses security suspicions at airport"
        http://www.csua.org/u/x2f (in.news.yahoo.com)
        \_ I often have that same problem.
        \_ I think the headline writer had some fun with that one.
           \_ One time when I glanced over a Yahoo News headline "U.S. busts
              largest-ever identity theft ring" all I saw was "U.S. busts
	...
2012/4/23-6/1 [Computer/SW/WWW/Browsers] UID:54360 Activity:nil
4/19    My Firefox 3.6.28 pops up a Software Update box that reads "Your
        version of Firefox will soon be vulnerable to online attacks."  Are
        they planning to turn off some security feature in my version of
        Firefox?
        \_ Not as such, no, but they're no longer developing this version,
           so if a 3.6.x-targeted hack shows up, you're not going to get
	...
2011/11/8-30 [Computer/SW/Security, Computer/SW/OS/Windows] UID:54218 Activity:nil
11/8    ObM$Sucks
        http://technet.microsoft.com/en-us/security/bulletin/ms11-083
        \_ How is this different from the hundreds of other M$ security
           vulnerabilities that people have been finding?
           \_ "The vulnerability could allow remote code execution if an
               attacker sends a continuous flow of specially crafted UDP
	...
2011/11/11-30 [Computer/SW/Security] UID:54224 Activity:nil
11/11   MacOSX's Sandbox security hole:
        http://preview.tinyurl.com/7ph2wtg [arstechnica]
	...
2011/2/10-19 [Computer/SW/Security] UID:54034 Activity:nil
2/9     http://www.net-security.org/secworld.php?id=10570
        Summary: iPhone passwd storage is unsafe after all
	...
Cache (3695 bytes)
www.nytimes.com/2009/12/29/technology/29hack.html
KEVIN J OBRIEN Published: December 28, 2009 BERLIN -- A German computer engineer said Monday that he had deciphered and published the secret code used to encrypt most of the world's digital mobile phone calls, saying it was his attempt to expose weaknesses in the security of global wireless systems. The action by the encryption expert, Karsten Nohl, aimed to question the effectiveness of the 21-year-old GSM algorithm, a code developed in 1988 and still used to protect the privacy of 80 percent of mobile calls worldwide. "We are trying to push operators to adopt better security measures for mobile phone calls." The GSM Association, the industry group based in London that devised the algorithm and represents wireless companies, called Mr Nohl's efforts illegal and said they overstated the security threat to wireless calls. "This is theoretically possible but practically unlikely," said Claire Cranton, an association spokeswoman. She said no one else had broken the code since its adoption. "What he is doing would be illegal in Britain and the United States. To do this while supposedly being concerned about privacy is beyond me." While the disclosure does not by itself threaten the security of voice data, one analyst said companies and governmental organizations should take the same steps to ensure the security of their wireless conversations as they do with antivirus software for computer files. "Organizations must now take this threat seriously and assume that within six months their organizations will be at risk unless they have adequate measures in place to secure their mobile phone calls," said Stan Schatt, a vice president for health care and security at the technology market researcher ABI Research in New York. University of Virginia, is a widely consulted encryption expert who waged a similar campaign this year that prodded the DECT Forum, a standards group based in Bern, to upgrade the security algorithm for 800 million cordless home phones. Mr Nohl has now set his sights on GSM, whose second-generation digital technology is still the most widely used wireless-communications standard in the world. About 35 billion of the world's 43 billion wireless connections use GSM; it is used by about 299 million consumers in North America. In August, at a hackers' forum in Amsterdam, Mr Nohl challenged other computer hackers to help him crack the GSM code. He said about 24 people, some members of the Chaos Computer Club, which is based in Berlin, worked independently to generate the necessary volume of random combinations until they reproduced the GSM algorithm's code book -- a vast log of binary codes that could theoretically be used to decipher GSM phone calls. During an interview, Mr Nohl said he took precautions to remain within legal boundaries, emphasizing that his efforts to crack the GSM algorithm were purely academic, kept within the public domain, and that the information was not used to decipher a digital call. "We are not recommending people use this information to break the law," Mr Nohl said. "What we are doing is trying to goad the world's wireless operators to use better security." Mr Nohl said the algorithm's code book was available on the Internet through services like BitTorrent, which some people use to download vast quantities of data like films and music. He declined to provide a Web link to the code book, for fear of the legal implications, but said its location had spread by word of mouth. The GSM algorithm, technically known as the A5/1 privacy algorithm, is a binary code -- which is made exclusively of 0's and 1's -- that has kept digital phone conversations private since the GSM standard was adopted in 1988.