6 ms·
Hopefully someone more knowledgable can weigh in, but as I understand the key stored on a 3G sim is more useful for authentication/identification rather than en
by thornjm 12y ago
Hopefully someone more knowledgable can weigh in, but as I understand the key stored on a 3G sim is more useful for authentication/identification rather than encryption.
3G/4G somehow uses random, short lived keys for encrypted communication, which change frequently enough to be a pain.
EDIT: It has been a while since I studied this, but I believe the shared key is used for trust - that this isn't a fake base station and the client is who they say they are. Then they use the equivalent of public key cryptography to establish short lived encryption keys. Stealing keys would probably enable a MitM only?
- scintill76 12y agoThat sounds plausible. One problem I still see is that if $agency gets the authentication key, they can impersonate the user and possibly hijack their traffic. Maybe not as bad as passive decryption in some ways.
- lucaspiller 12y agoI think that is actually worse. Say a person isn't liked by the current regime, but they haven't got any solid (i.e. legally useable in court) evidence to put them away. The agency could log onto the GSM network and impersonate that person performing an illegal act they know will be picked up by law enforcement.
- Spooky23 12y agoIt's a good thing that phone metadata is protected by the telephone carrier and requires a warrant to access. Oh, wait...
- mike_hearn 12y agoI've been trying to figure this out for days now, by reading the specs. I originally thought the same as you - the shared symmetric key is used only for authentication. But reading descriptions of the protocol closely I don't believe they are really using forward secrecy at all. The problem is that whilst, yes, unique and constantly rotating randomness is used to establish unique session keys, the session keys are derived from the random nonce that's an encryption of the network selected randomness. In other words if you have the SIM key, you can figure out what the session keys also were. Ultimately the standard SIMs don't seem to use asymmetric crypto anywhere, meaning a compromise of the SIM key still allows you to undo all the encryption. Ultimately everything is derived from these shared keys. And yes the problem of 2G downgrade attacks remain. There doesn't seem to be any good solution for those short of phasing out 2G entirely.
- bjornsing 12y agoI was also taken aback by this Perfect Forward Secrecy claim, and I hate how "anything goes" in this context because outright lies are hard to refute... It would be a huge service to humanity if you summarized your findings and published them, with references to the specs...
- nateguchi 12y agoPhasing out 2G isn't such a bad idea... Three in the UK have already done this with their 3G / 4G only network.
- chiph 12y agoThere's a lot of legacy hardware that still uses 2G, like alarm systems and ATMs. There's no doubt it'll have to be sunset at some point, but the cell & tower companies will need to see what percentage of their traffic it makes up before coming to a decision.
- rkangel 12y agoExcept that they haven't 'phased out' 2G, because that would be a nightmare for their customers when they're in poor reception. Instead, they've just subcontracted it to another company.
- nateguchi 12y agoThey phased out that partnership with orange a couple of years back, now it's 3G or nothing