4 ms·
The call of Kraken, GSM cracking software
- vgurgov 16y agoI dont know much about GSM protocols. Can somebody here explain what might be possible applications for this thing? Would it be possible to decode recorded GMS calls around you? Is it significant vulnerability?
- sbierwagen 16y ago1.) Listening in on GSM calls. 2.) Yep. 3.) Well, kinda. It's a motivated attacker attack. You have to be within radio range, and the attacker has to have specialized equipment and knowledge. It's not like an internet vulnerability, where one guy in Russia can exploit every single unpatched system in the world; this requires a bit of fieldwork. I wouldn't be worried unless you work for Apple, or something.
- trin_ 16y agointerestingly enough its rather cheap to do this now and is becoming cheaper every year. i doubt that this will only be a concern for apple employees as industrial espionage seems to be quite lucrative.
- ianso 16y agoA5/1 protects the over-the-air voice stream in GSM. Details on the protocol and cryptosystem: http://everything2.org/user/Jetifi/writeups/GSM http://everything2.org/user/Jetifi/writeups/GSM I don't think this is quite as big a deal as it's made out to be, since that A5/1 and /2 were both broken almost a decade ago, and most GSM providers have replaced these two ciphers with others since then. It might still be useful in places outside of Europe and the US though.
- Rod 16y agoFrom last year's Chaos event: http://events.ccc.de/congress/2009/Fahrplan/events/3654.en.html http://events.ccc.de/congress/2009/Fahrplan/events/3654.en.h... "From the total lack of network to handset authentication, to the "Of course I'll give you my IMSI" message, to the iPhone that really wanted to talk to us. It all came as a surprise -- stunning to see what $1500 of USRP can do. Add a weak cipher trivially breakable after a few months of distributed table generation and you get the most widely deployed privacy threat on the planet."
- antirez 16y agoIs it possible to use a common phone to sniff the GSM traffic? Or something like a GNU-radio capable external device is absolutely required? GSM and GSM security are interesting topics but really hard to touch with your hands because of the difficulty of reading what's passing over the air. The more hackers will have access to equipments, the more secure will be our conversations in the long run.
- chris_l 16y agoTo use a regular phone you would have to reverse-engineer a significant part of the (low-level) software, est. cost > $1m Even then you would have to get lucky with the hardware, as it is not designed to sniff all the meta data and pass it up for capture. It might do some of the stuff in hardware that you want done in software.
- antirez 16y agoThanks for the clarification