10 ms·
Vulnerabilities in TETRA radio networks
- denysvitali 3y agoTL;DR: The only newsworthy vulnerability is the breaking TEA1 - which is anyways the least secure of them all and only intended for commercial use (that is, no emergency services). https://www.tetraburst.com/ https://www.tetraburst.com/
- pixl97 3y agoThe question is, did things like emergency services actually use the higher levels, or did they just use TEA1? It's kind of like saying... Vendor: "We support up to 1 zillion bit encryption!" User: "What's the default out of the box?" Vendor: "10 bit"
- riversflow 3y agoHogwash, I think it's worth noting that this European system was intentionally backdoored. Everybody plays the espionage game, Europe really is no exception, they just like to use the US to keep their hands (mostly) clean.
- deleted 3y ago[deleted]
- riedel 3y ago> TL;DR: The only newsworthy vulnerability is the breaking TEA1 This is IMHO a very unfair TLDR; . The news is that the researchers claim that there is deliberate backdoor, which ETSI denies. If it is true, there cannot be any further trust in other proprietary parts as well.
- matthewdgreen 3y agoIt appears to be used for infrastructure, including things like power and transportation signals here in the US.
- crotchfire 3y agoAre you sure? TETRA uses frequency-hopping spread spectrum, which requires a much wider contiguous bandwidth allocation for this modulation and use. That allocation doesn't exist in the US. The lack of any large allocation for this kind of radio is a big part of why US first responders are stuck with P.25, which is narrowband FM. If there were a wide-enough band in which it could be used, a lot of first responders would have bought TETRA radios a long time ago. P.25 is easy to jam by brute-force power output, and trivial if you directly attack the error correction bits. TETRA and FHSS have a much much larger ratio of attacker transmit power to victim transmit power. https://en.wikipedia.org/wiki/Project_25#Jamming_vulnerability https://en.wikipedia.org/wiki/Project_25#Jamming_vulnerabili... (FWIW, P.25 is an even worse dumpster-fire than TETRA...)
- matthewdgreen 3y agoGoogling “MTA Tetra” turns up a pile of articles about the deployment of TETRA trunked radio for communications in the NYC bus fleet and Staten Island Railroad. And in those articles there’s some controversy about the spectrum and interference issues. I don’t know where else they use TETRA, just that they were cited in some of the original articles about the vulnerabilities.
- crotchfire 3y agoAh, looks like they created a much lower-power TETRA in a different band for North American use (search for "low power tetra"): https://www.powertrunk.com/pressroom/tetra-in-north-america/ https://www.powertrunk.com/pressroom/tetra-in-north-america/ That's cool, but it's going to be a niche use at those power levels. One of the things that make TETRA and P.25 so attractive is that you can put a huge, high-power repeater on a hill or tall building and cover a big chunk of a city using (fairly) small low-power handsets. Then multiple agencies (police, fire, spooks, clowns) can all use that repeater and share the cost burden. The power-limited version looks like it'll always be a fairly niche single-agency-in-single-jurisdiction use. So the threat, while technically not zero, is not at the five-alarm-fire level that it is in Europe. Edit: also looks like MTA bought their own spectrum license just for this one use: MTA owns licenses in 700 MHz and 800 MHz
- opless 3y agoSome installations have additional cryptography. Which alone implies that the Tetra crypto security theatre is well known in that industry, and isn't a surprise to vendors in the slightest.
- freeopinion 3y ago> The vulnerabilities were discovered during the course of 2020, and were reported to the NCSC in the Netherlands in December of that year. It was decided to hold off public disclosure until July 2023, to give emergency services and equipment suppliers the ability to patch the equipment. Interesting discussion about responsible disclosure. It seems a strange belief that you can tell all the radio operators about the vulnerability without also telling exploiters. Aren't they often one and the same? What's a reasonable approach here?
- deleted 3y ago[deleted]
- tptacek 3y agoImmediate public disclosure.
- freeopinion 3y agoI'm inclined to agree. I'm not comfortable with the way this unfolded. > The Dutch NCSC (NCSC-NL) was informed in December 2021, after which meetings were held with the law enforcement and intelligence communities, as well as with ETSI and the vendors. Shortly afterwards, on 2 February 2022, preliminary advice was distributed to the various stakeholders and CERTs. The remainder of 2022 and the first half of 2023 were used for coordination and advisory sessions with stakeholders, allowing manufacturers to come up with firmware patches, updates or workarounds. This reads to me as if malicious parties were notified some 18 months before users were notified.
- actionfromafar 3y agoDepends on who the stakeholders were.
- freeopinion 3y agoDoes it? Intelligence agencies were among the first informed. Those are the bad guys. I know "bad guys" is a harsh phrasing, but when it comes to encrypted communication, they are literally the definition of the adversary. Anybody in intelligence that doesn't play for my team is a "bad guy". And since everybody belongs to multiple conflicting teams, even a person who plays on one of my teams is a "bad guy" from the perspective of my other teams. If the first place you go with a disclosure is to the intelligence community, you are hurting users.
- LocalH 3y agoSounds like they took the "roll your own and don't tell anyone how it works" approach. Security by obscurity is never security. History has shown that the open encryption standards are the most secure.
- denysvitali 3y agoYou can't easily put backdoors in cryptographic algorithms that can be audited
- anonym29 3y ago^ this post brought to you by RSA, ANSI, ISO, NIST, the NSA, and the authors of DUAL_EC_DRBG /s
- gpderetta 3y ago... Which iirc was immediately identified as suspicious during auditing.
- a1369209993 3y agoAnd yet became a official standard anyway, and was occasionally actually used, despite the fact that is was obviously backdoored to anyone who knew anything about (elliptic-curve) cryptography. (It's literally a textbook-exercise leaky RNG, of the sort that you would find under "Exercise: create a elliptic-curve-based RNG that leaks seed bits within N bytes of random data." in a actual cryptography textbook.)
- tptacek 3y agoYou don't really need to understand elliptic curves to understand Dual EC. It's a public key RNG. The vulnerability is that there's a matching private key.
- 3y ago
- k8svet 3y agoWhat exactly were TETRA radios used for? I assume they were government/infra related, but then I don't understand why they'd need to backdoor the keying
- tptacek 3y agoThey don't so much backdoor the keying as that they have 4 different cipher profiles, and the one approved for global rather than European use (TEA1) compresses the key from 80 to 32 bits. It's essentially a surreptitious version of what the US did in the 1990s with "export ciphers".
- wyck 3y agoThe newsworthy item here is that this is an intentional backdoor. The wikipedia pages list the specific uses per country and department. https://en.wikipedia.org/wiki/Terrestrial_Trunked_Radio#Usage https://en.wikipedia.org/wiki/Terrestrial_Trunked_Radio#Usag...
- H8crilA 3y agoDo you remember when cryptography export was controlled? It was implemented by limiting key size to certain number of (effective) bits (of security). This suite is just a victim of that law, as it is a 1990s design.
- tptacek 3y agoIt's not "just" a victim of that law unless they disclosed that the export cryptography protocol was trivially breakable. Export cryptography in the 1990s US was documented.
- jeroenhd 3y agoTo quote https://www.cryptomuseum.com/crypto/algo/tea/1.htm https://www.cryptomuseum.com/crypto/algo/tea/1.htm: > The algorithm was developed in 1996/97 at Philips Crypto BV in Eindhoven (Netherlands) as a consultancy job for ETSI-SAGE. As the algorithm is secret, it has never been submitted for peer-review or in-depth security analysis. Instead it was evaluated by other ETSI-SAGE members before being submitted as a formal ETSI standard. All members of the TEA family, use an 80-bit key, but in the case of TEA1 it is effectively reduced to 32 bits, which makes it vulnerable to a brute-force attack. According to one of the developers, this was mandatory to get the algorithm approved for export. It was part of the ETSI specification and was clearly visible in the code [3].
- wkat4242 3y agoAnd when people were saying it was a stupid thing? This is one of the many examples that prove it.
- creato 3y ago
- marcus0x62 3y agoThe interview that is linked[0] in the footnotes of the article with the person from ETSI is absolutely wild... Some excerpts: > kz (interviewer): How did it go about meeting those requirements, because that's the one they're saying has a backdoor in it. Was that the condition for export? > BM (ETSI): Backdoor can mean a couple of things I think. Something like you'd stop the random number generator being random, for instance. [But] what I think was revealed [by the researchers] was that TEA1 has reduced key-entropy. So is that a backdoor? I don't know. I'm not sure it's what I would describe as a backdoor, nor would the TETRA community I think. ... > KZ: People ... believe they're getting an 80-bit key and they're not. > BM: Well it is an 80-bit long key. [But] if it had 80 bits of entropy, it wouldn't be exportable. ... > kz: You're saying 25 years ago 32 bit would have been secure? > BM: I think so. I can only assume. Because the people who designed this algorithm didn't confer with what was then EP-TETRA [ETSI Project-TETRA is the name of the working group that oversaw the development of the TETRA standard]. We were just given those algorithms. And the algorithms were designed with some assistance from some government authorities, let me put it that way. ... > bm: That's what we now know yeah - that it did have a reduced key length. > KZ: What do you mean we now know? SAGE created this algorithm but the Project-TETRA people did not know it had a reduced key? > BM: That's correct. Not before it was delivered. Once the software had been delivered to them under the confidential understanding, that's the time at which they [would have known]. ... You've really got to wonder who at ETSI gave the thumbs up on doing this interview. 0 - https://www.zetter-zeroday.com/p/interview-with-the-etsi-standards https://www.zetter-zeroday.com/p/interview-with-the-etsi-sta...
- deleted 3y ago[deleted]
- sillysaurusx 3y agoThe researchers added a footnote explicitly refuting the claim that 32 bit keys were secure 25 years ago, too. > The Midnight Blue researchers have since demonstrated real-life exploitations of some of the vulnerabilities, for example at the 2023 Blackhat Conference in Las Vegas (USA). They have shown that TETRA communications secured with the TEA1 encryption algorithm can be broken in one minute on a regular commercial laptop and in 12 hours on a classic laptop from 1998 [III].
- YinSpray 3y agoSome time ago there was a github repo online that has all teaX and hurdle algorithms code, and also ta61 identity encryption algorithm mentioned by Midnightblue. https://web.archive.org/web/20230213001503/https://github.com/frits-greuter/ampx/blame/5ee95317a2c05a751e64a909b630f51d6d08b643/projects/tetra/source/ai/mm/security/algorithm_tea1.cpp https://web.archive.org/web/20230213001503/https://github.co... https://web.archive.org/web/20230213001335/https://github.com/frits-greuter/ampx/archive/refs/heads/master.zip https://web.archive.org/web/20230213001335/https://github.co...
- neilv 3y ago> Two of the vulnerabilities are deemed critical. One of them appears to be an intentional backdoor [...] Reading the contents of a firmware upgrade is not trivial though, as it is heavily encrypted and relies on a Trusted Execution Environment (TEE), embedded in the core processor of the radio.* I don't know whether the backdoor allegation is correct, but unfortunately we should treat opaque ostensible security with skepticism. By their nature, such things often can be used for our protection at the same time they are secretly used against us.
- jordanmoconnor 3y ago[flagged]
- lostlogin 3y agoThat’s your interpretation? I read it as ‘show source, distrust the opaque and while this might be unintentional, don’t assume it is.’
- generalizations 3y agoThe last paragraph is probably what they were referring to.
- creer 3y agoIsn't the time for the generous qualifiers long past? Such, often, can, our protection, unfortunately, skepticism... There is a good track record by now. Something like: "under the guise of protecting trade secrets and swear words in the code, the code encryption actually protects crappy code stuffed with vulnerabilities (i.e. future entry points available to the right friends and foes) and backdoors (some forgotten and some very much not)". And in this case "future" was a while ago.
- deleted 3y ago[deleted]
- ajsnigrutin 3y agoI heard about this some time ago... the timeline shows the sources should be available from august this year, but nothing yet on github ( https://github.com/MidnightBlueLabs/TETRA_burst https://github.com/MidnightBlueLabs/TETRA_burst )
- deleted 3y ago[deleted]
- notfed 3y agoIn 2023 you're telling me that some emergency vehicles are happily rocking encryption protocols with 80-bit, wait actually, 32-bit keys? These are all cases of systemic procrastination. We're talking about emergency vehicles here though, so: neglect. Nobody is surprised these protocols have been broken, it should not be a surprise, and having some kind of panic reaction should be considered either a charade or a case of abysmal management.
- Roark66 3y agoThe fact many armies use this (including my own country's) is mind boggling. Didn't they request the technical details of the encryption and the source code and have it vetted properly before awarding the tender for these devices? /sarcasm