4 ms·
When an encryption algorithm is no longer secure, it gets phased out and any protocol that uses that algorithm eventually gets denied. Can someone explain why
by bvinc 8y ago
When an encryption algorithm is no longer secure, it gets phased out and any protocol that uses that algorithm eventually gets denied.
Can someone explain why older protocols like 2g with inadequate encryption can't be phased out? Or why there isn't even an effort or attempt or option to disable it?
- supertrope 8y agoIt’s not just the ciphers that were weak to begin with. It’s also the lack of mutual authentication: the network checks if the phone is entitled to service but the phone never checks if it’s a legitimate base station. Telcos do not care about technical means of security. As long as the average person can’t eavesdrop it’s good enough. When it comes to protecting their economic interest (preventing free calls) they use smart cards and strong encryption. 800MHz scanners have been illegal for decades. Legacy support and reliability are very important (in the context of cellular service which still is inferior to fixed telecommunications). Customers will get angry if you tell them their phone is obsolete. Or encryption incompatibility causes failed calls. The FCC takes a dim view on 911 failures, so phones must have a fallback no enciphering mode to maximize 911 call success. Compatibility with roaming host networks must be maintained. AT&T shut down their GSM network Jan 1 2017 but UMTS has plenty of vulnerabilities too. The SS7 protocol underpinning the PSTN lacks authentication.