29 ms·
Encryption made for police and military radios may be easily cracked
https://archive.ph/5GMa5 https://archive.ph/5GMa5
- deleted 1y ago[deleted]
- tptacek 1y agoThe funny thing about this is that my municipality just recently started encrypting their radios at all. And it was controversial! Residents liked being able to listen in to the scanners.
- ronsor 1y agoAnd now they're going to be unencrypted again, but not by choice!
- tptacek 1y agoNo, this story is about TETRA radios, which are used in Europe; I'm in Chicago, on Motorola's STARCOM (P25), which is ostensibly AES (it wouldn't be shocking to find vulnerabilities; in fact shocking not to, but it won't be as crazy as TETRA, which freelanced its entire encryption stack).
- colmmacc 1y agoI listened to your great podcast and the remark along the lines of "unencrypted police comms let the robbers know when the police are getting close" made me wonder if anyone has built a simple signal intensity detector for the encrypted radios. You don't need to hear the contents to know that the radios are closing in on you. I can't imagine police forces practice RF silence like special forces do. It really would be better to hide in the noise of 5G.
- buildbot 1y agoI’ve long wanted to do this with an SDR and maybe some simple ML, build a dataset by driving by cars/things with frequencies of interest. Now I wonder if you can fingerprint antennas…
- dumah 1y agoYou can fingerprint transmitters. Antennas would be much more difficult and likely moot. https://arxiv.org/html/2402.06250v1 https://arxiv.org/html/2402.06250v1
- mindcrime 1y agoSome transmitters have such a distinct sound that you can identify them with just your unassisted human hearing. Back in my firefighting days, I remember that certain trucks or stations had transmitters where you could identify them from the half second or so of "hum" between the time somebody keyed up the mic and the time they started talking. Using ML / signal processing stuff on a computer, yeah, you can probably get pretty fine grained at discriminating these things.
- mystraline 1y agoI have a BT scanner app for my phone. "BLE Radar". I have a detection on there for the MAC address "00:25:DF:*". That's the MAC OUI prefix for Taser International. I keep it on while driving, because the badgecams and hardware in cop cars spurts this out regularly. So even unmarked cars show themselves.
- Forbo 1y agoA.K.A. Axon Enterprises. Some OUI databases have the new name, some have the old.
- jasonjayr 1y agohttps://www.krakenrf.com/ https://www.krakenrf.com/ For about $700, you can get some pre-made kit to use SDR to do Radio direction finding. IIRC this device uses the same chips as a RTL-SDR, but it uses 4-5 of them, all synchronized and has a signal emitter for calibration, and a nice web ui to report the data. (I have not used it, but I've been learning about all sorts of neat radio products as I'm dabling and learning about SDR)
- raggi 1y ago"which is ostensibly AES" in the 5% or less of deployments that turn that on Both of the systems are crap, when we were evaluating them for nationwide purchase we chose TETRA because of systemic safety features (like local DMO handover modes for public safety use in noisy environments), but when I read their crypto choices I made screwy faces constantly, I wasn't in the slightest bit surprised when this research came out. I remember at the time some ex signals military folks trying to tell me that the encryption barely matters as the channel selection rate is so high you'd need multi-site intercepts to even make heads of tails of it, sadly they didn't really seem to understand how far SDR and compute has come. The whole experience to this day flavors a lot how I think about military and telco thinking around the whole space, everything touching that boundary feels infected with oldthink.
- fc417fc802 1y ago> everything touching that boundary feels infected with oldthink. I'd guess that's due to the expense of the equipment and all the regulations coupled with the lack of immediate usefulness to a casual hobbyist. Without the sort of vibrant wild west ecosystem that FOSS provides innovation happens much more slowly and most of the participants will be entrenched.
- nonameiguess 1y agoI'll never forget 8 years ago someone managed to set off every tornado siren in Dallas for an entire Friday night, apparently because they're controlled by radio and the control signal was not encrypted, so the "hacker" just recorded it during a real alert and then played it back to attack the system.
- andrewflnr 1y agoThat might still work even with encryption, if they don't specifically prevent replay attacks.
- bilegeek 1y agoThe majority of EAS equipment responds this way. That's why the tones are so strictly regulated on broadcasts. https://docs.fcc.gov/public/attachments/DA-19-758A1.pdf https://docs.fcc.gov/public/attachments/DA-19-758A1.pdf
- lazide 1y agoPreviously you could hear what was going on in town - a degree of transparency around police. Now you can’t. For better or worse, eh?
- tptacek 1y agoYeah, it's complicated! Europe goes the other way on this, apparently, so much so that it's headline news when someone comes up with cryptographic attacks on their police radios. Here, on the other hand, people committing crimes can (or could, a few months ago) just listen on their iPhones to see if anybody is on to them. The City of Chicago makes decrypted audio available, just on a 30 minute delay. That's a sane compromise, I think.
- stevage 1y agoThat's a great compromise.
- jMyles 1y agoAt some point, this needs to turn a corner into real-time resistance, and massive community presence to assist regular people in asserting their rights. A 30-minute delay crushes that.
- deleted 1y ago[deleted]
- tptacek 1y agoMost communities are far more victimized by property crime than they are by the police. Anti-police activists tend to premise their arguments on the idea that everybody opposes police intervention, but read transcripts of neighborhood meetings in Black neighborhoods: the more common complaint is that the police aren't responding and aren't taking their complaints seriously.
- mulmen 1y agoDoes a 30 minute delay assist the police in preventing or responding to property crime?
- cptskippy 1y agoSan Diego?
- LeoPanthera 1y ago> Residents liked being able to listen in to the scanners. They're a public service funded by taxpayer dollars. Knowing what they're doing seems reasonable.
- tptacek 1y agohttps://news.ycombinator.com/item?id=44830592 https://news.ycombinator.com/item?id=44830592
- boston_clone 1y agoDo you think that the US police force culture mirrors that of Europe? Could there be a need for more oversight, accountability, and transparency for American cops? Please also remember that law enforcement effectively steals billions of dollars from citizens each year - https://ij.org/press-release/new-report-finds-civil-forfeiture-rakes-in-billions-each-year-does-not-fight-crime-2/ https://ij.org/press-release/new-report-finds-civil-forfeitu...
- hypercube33 1y agoMany many years ago a buddy of mine loved listening to the scanners. One evening we are on AIM chatting and he explains what is going on: noise complaint at a house down the block (kids partying) He looks the address up and calls them to warn them and sits back to see if they do anything. sounds like they managed to bail before anyone showed up to the address.
- baby_souffle 1y agoNot all heros wear capes. Some of them keep their ears glued to the scanners...
- zdragnar 1y agoNow replace "kids" with gangs and other organized crime, and it makes a little more sense why they'd want to encrypt it.
- throwawayoldie 1y agoBoston?
- HexPhantom 1y agoAnd yeah, the scanner culture thing is real
- dist-epoch 1y agoIs it still illegal in Europe to buy radios with 128 bit encryption?
- GauntletWizard 1y agoIt's still illegal to point out that the emperor has no clothes
- mystraline 1y agoIts also illegal to report hospitals that post PHI (protected health information) over POCSAG or FLEX - pager networks. Of course, theres no encryption or anything. The encoding is plain text. Yes, it is also illegal to post PHI over pagers, due to HIPAA addendum in 2016. But 1986 ECPA law forbids decoding pager messages unless they were intended for you.
- sidewndr46 1y agoWell it's a good thing they made it illegal! otherwise criminals would use that to get your data!
- cluckindan 1y agoAs in TETRA? Probably not, as SDRs are widely available anyway, as are scanners capable of decrypting TETRA traffic. You do need authorization to buy a transmitter though, at least where I live.
- dist-epoch 1y agoI meant like hand-held walkie talkies. But with 128 bit encryption. Weird it's regulated, given you can use mobile phones like that (sure, you need coverage).
- kevin_thibedeau 1y agoMobile phones are backdoored and trackable by default.
- drewnick 1y agoNote this affects TETRA which is not used in North America. Most US systems use P25 which is not mentioned in the article.
- kotaKat 1y agoNot like there’s not enough problems with P25… until the day they can deploy LLE (link-layer encryption) across all P25 systems, there will always be a way to gather some kind of intelligence about the system and its radio traffic. (And the fact that it’s taking so long to implement link layer authorization, barely a scratch in the security dent…)
- LeoPanthera 1y agoNorthern California services use P25 but with encryption turned off. They also have analogue repeaters. Presumably because that way they can still use old radios and don't have to worry about key rotation. The audio quality on the analogue signal is a lot better than the P25 version, which is often harder to understand.
- sjsdaiuasgdia 1y agoThe P25 audio is digital, so it degrades worse than analog audio when signal quality is bad. You more quickly get to a point where it's not understandable at all, particularly if it's the signal coming from a handheld radio that's some distance away from the receiver. The analog repeater is likely getting a high quality feed from the digital system, and then that's being broadcast at decent power from a tall antenna. It's starting with the best audio the system has to offer, has advantages in how it's broadcast, and degrades more gracefully. I capture a lot of the P25 traffic in my area and there are times I can understand the dispatcher side of a conversation fine but the other end is too far away / too weak a signal and is unintelligible. The dispatcher's signal is coming from a fixed tower transmitting at higher power than a portable radio can manage.
- eitland 1y ago> You’ve read your last free article. Haven't read a Wired article in months :-| And thanks to poster for adding archive link.
- robterrell 1y agoWired is killing it with great reporting this year. Worth subscribing and supporting.
- kstrauser 1y agoI've done that. It seemed like Wired got lost on the road for a while, but lately they're back with a vengeance, which I'm delighted to see (and to support).
- drumhead 1y agoI mean, in this day and age is it such a bad thing that police and military radio is crackable?
- tonetegeatinst 1y agoI believe TETRA was already vulnerable to being broken based of some research that a group did into the protocol. They showed a proof video but didn't release any technical info or poc due to security fear.
- tiagod 1y agoTFA literally starts by saying that.
- theturtle 1y agoCool! Maybe all the apps and sites intended to let you keep track of what your local kopz are doing will work again!
- HexPhantom 1y agoRight? All it took was some deeply flawed encryption and a couple researchers pulling the thread
- anfractuosity 1y agoVery interesting, curious how long it would take to brute force the 56 bit key, with something like a GPU/FPGA. It looks like hashcat supports DES, which is also 56 bit.
- ethan_smith 1y agoModern GPU clusters can break 56-bit DES in under a day - AWS instances could do it for a few hundred dollars, making this vulnerability practically exploitable by motivated attackers with modest resources.
- anfractuosity 1y agoInteresting thanks, that's faster than I thought it'd be.
- genocidicbunny 1y agoHuh, I was catching up on DEFCON videos recently, and just earlier this morning watched the talk about Tetra. How serendipitous. https://www.youtube.com/watch?v=iGINoIYQwak https://www.youtube.com/watch?v=iGINoIYQwak
- dokyun 1y ago> The flaws remained unknown publicly until their disclosure, because ETSI refused for decades to let anyone examine the proprietary algorithms. Got what they asked for.
- mindcrime 1y agoFor anyone who's curious, the closest equivalent in the US is P25[1] or "Project 25". And if you're wondering, yes, P25 systems have been known to have their own share of vulnerabilities of various sorts. My favorite one[2] is the one that lets an attacker force a P25 radio to broadcast tokens "on demand" allow you to (theoretically, with the right receiving setup and software) track the location of P25 radios more or less in real-time. And on a related note, for anyone who is interested in listening in on any local P25 transmissions, you can do so in a fairly inexpensive manner, using an RTL-SDR dongle and the Open Source op25[3] software package. No listening to encrypted traffic, but IME, many (maybe most) public safety agencies keep most of their traffic in the clear. More so for fire/ems traffic. Law enforcement is more likely to be encrypted, but even then, I find that many jurisdictions only encrypt a small number of channels, like maybe a dedicated vice/narc squad channel, SWAT team channel, etc. General LE dispatch and tac channels are still in the clear in many areas. [1]: https://en.wikipedia.org/wiki/Project_25 https://en.wikipedia.org/wiki/Project_25 [2]: https://www.reddit.com/r/tacticalgear/comments/1f4d5dr/psa_p25_packet_data_security_vulnerability/ https://www.reddit.com/r/tacticalgear/comments/1f4d5dr/psa_p... [3]: https://github.com/boatbod/op25 https://github.com/boatbod/op25
- theoreticalmal 1y agoI wonder if it would be illegal to employ this method. Tracking law enforcement isn’t explicitly illegal, right?
- privatelypublic 1y agoTransmitting on spectrum you don't have a license for- especially when the government WILL cast it as "interfering with emergency services" or just Big-T- very much is.
- eru 1y agoWhat's 'Big-T'?
- 1y ago
- tamimio 1y agohttp://archive.today/5GMa5 http://archive.today/5GMa5
- WrongOnInternet 1y agoKevin Mitnick figured out how to get around police radio encryption in the 90's. From 'Ghost in the Wires': "Whenever I heard any hiss of communication, I’d hold down my Transmit button. That would send out a radio signal on the same exact frequency, which would jam the signal. Then the second agent wouldn’t be able to hear the first agent’s transmission. After two or three tries back and forth, the agents would get frustrated with the radio. I could imagine one of them saying something like, “Something’s wrong with the radio. Let’s go in the clear.” They’d throw a switch on their radios to take them out of encryption mode, and I’d be able to hear both sides of the conversation! Even today I’m amused to remember how easy it was to work around that encryption without even cracking the code."
- tptacek 1y agoIt's an odd story, since until pretty recently most North American police radio was plaintext to begin with.
- user3939382 1y agoNot IA
- eru 1y agoWhat's IA?
- loeg 1y agoInternal Affairs? But I'm not sure why that's relevant to encryption or Mitnick.
- user3939382 1y agoI have heard of them having stricter radio protocols which strikes me as sensible
- WrongOnInternet 1y ago
- gloyoyo 1y agoThe local PD in my area has/had the laptops in their vehicles set to ad-hoc mode, and each broadcast static MAC addresses in the open, and could simply be looked up on the Wigle database. At about 100-yards, you could pick up the broadcast on any phone, and it would be trivial for someone to deduce that you could setup an active monitor w/ alerts for when these specific MAC addresses were present in a designated area, let alone what a distributed monitoring/alert effort would be capable of...
- mindcrime 1y agoa distributed monitoring/alert effort would be capable of... Thinking out loud... an RTL-SDR dongle costs like $35.00 or so (well maybe more now due to tariffs, I haven't bought one in a while), plenty of relevant software is open source (GNURadio etc.), drones are cheap, small solar panels are fairly inexpensive. Hmm... I almost think a motivated individual (or small group of individuals) could piece together a rather capable "distributed monitoring/alert" system. Not that I'm encouraging anyone to do such a thing, of course.
- BobaFloutist 1y agoI don't even know that it's explicitly illegal. Google maps is allowed to warn you about speed traps.
- mindcrime 1y agoI agree, it probably isn't really explicitly illegal. But if one put together such a thing, depending on how they decided to use it, I have a hunch that the State would find something to charge them with. I'll resist the temptation to say more, to avoid going too overtly political here.
- gloyoyo 1y agoI'm pretty sure it's not outside of the range of ANYONE to whip up in a fortnight, and have distributed near instantaneously. If anything, it's the most basic of "wireless site survey" applications.
- deleted 1y ago[deleted]
- fortran77 1y agoGood. I used to listen to police calls in the US. I don’t like the fact that my police is now the “secret police” with encrypted digits radios.
- HexPhantom 1y agoThis is what happens when security is treated like a checklist item instead of a core requirement
- LeGrosDadai 1y agoRelated: https://www.usenix.org/conference/usenixsecurity23/presentation/meijer https://www.usenix.org/conference/usenixsecurity23/presentat... and https://tosc.iacr.org/index.php/ToSC/article/view/12077 https://tosc.iacr.org/index.php/ToSC/article/view/12077 Why EU saw fit to buy very expensive proprietary software encryption, when there are open source standards, some of them designed in the EU itself is beyond me. Of course, you still someone to build the hardware and so on.
- jedisct1 1y ago"military grade" encryption.
- gonzo41 1y agoSo what's really important with military radio's is the concept of tactically perishable information. If i give battle directions duing a fight, that information only needs to be secure for a few days, after that, I'm somewhere else.
- throwaway48476 1y agoAnother Crypto AG
- __alexander 1y ago> 128-bit key, but this gets compressed to 56 bits before it encrypts traffic A5/1 had a similar issue in which the weakness was deliberately added. I have some notes and references on it. Super interesting https://github.com/alexander-hanel/asm-examples/tree/master/A51#background-aka-the-tmz-of-a51 https://github.com/alexander-hanel/asm-examples/tree/master/...