/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers: encryption algorithm GEA-1, used in GPRS data in 2G networks, was deliberately weakened by its designers; ETSI blames export regulations

A new paper shows that two old encryption algorithms still used in mobile networks can be exploited to spy on phones' internet traffic.

VICE Lorenzo Franceschi-Bicchierai

Discussion

  • @matthew_d_green Matthew Green on x
    This is an amazing paper. It implies (with strong statistical evidence) that the design of a major mobile-data encryption algorithm — used in GPRS data — was deliberately backdoored by its designer. https://eprint.iacr.org/...
  • @k8em0 Katie Moussouris on x
    Effects of overly restrictive export controls on encryption: forced weak implementations that weaken security for all for decades. “researchers tested several modern phones to see if they would still support the vulnerable algorithms, “surprisingly” found that they still do.” htt…
  • @privacydigest @privacydigest on x
    Bombshell Report Finds Phone Network Encryption Was Deliberately Weakened A new paper shows that two old encryption algorithms still used in mobile networks can be exploited to spy on phones' internet traffic https://www.vice.com/...
  • @vice @vice on x
    The paper has sent shockwaves through the encryption community because it implies that a weakness was intentionally put into the algorithm to allow hackers to spy. https://www.vice.com/...
  • @campuscodi Catalin Cimpanu on x
    Do not discount this discovery just because it's 2G and not 5G. 2G is still used for controlling loads of IoT devices. You might be surprised by how many “smart cars” use 2G modems nowadays. https://twitter.com/...
  • @sickcodes Sick.Codes on x
    GPRS (2G) is allegedly weak by design: “...cryptanalytic attacks on the GEA-1 and GEA-2 algorithms... the initial state of GEA-1 can be recovered from as little as 65 bits of known keystream... and 44.5GB of memory” https://eprint.iacr.org/... https://www.vice.com/... 👍 @lorenzof…
  • @matthew_d_green Matthew Green on x
    Fortunately for everyone involved, these ciphers have been mostly deprecated. They're only even included in some older phone basebands. But that's not cause for celebration. https://twitter.com/...
  • @motherboard @motherboard on x
    A weakness in the algorithm used to encrypt cellphone data in the 1990s and 2000s allowed hackers to spy on some internet traffic, according to a new research paper. https://www.vice.com/...
  • @ekoivune Erka Koivunen on x
    Ah, the telecomms industry and their lip service to security. https://twitter.com/...
  • @dcuthbert Daniel Cuthbert on x
    Finally got a chance to turn off all distractions and read this thread and oh boy, it's a belter. Thanks to Matthew for explaining it so well. https://twitter.com/...
  • @naomibrockwell Naomi Brockwell on x
    So has our standard encryption been backdoored? Turns out it was for years. It's incredible they got away with it for so long. What about current encryption standards? We'll find out soon, no doubt people are now looking very closely to find out. https://twitter.com/...
  • @ildannymoore Daniel Moore on x
    If this was intentional backdooring it's impressive. It took a long time to discover and maintains a level of minimal deniability even after. https://twitter.com/...
  • @jason_koebler Jason Koebler on x
    This paper is bonkers, essentially found that encryption on a cell network used for data for a decade was intentionally weakened ... by using math https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Researchers revealed in new paper that a cellphone encryption algorithm from the late 1990s—still in use today—was deliberately designed to be weak. The weakness allows attackers to spy on phone's internet traffic. https://www.vice.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    Turns out ETSI, the organization that designed the GEA-1 algorithm, had to make it weak because of export controls. https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    New: researchers believe probability of a particular weakness being introduced accidentally into phone network crypto is extremely low. Think it was put into the algorithm on purpose. Now group that designed the algorithm confirmed to us this was the case https://www.vice.com/...
  • @stshank Stephen Shankland on x
    From the paper: “This implies that the weakness in GEA-1 is unlikely to occur by chance, indicating that the security level of 40 bits is due to export regulations.” https://twitter.com/...
  • @granick @granick on x
    Fascinating thread. Come for the cryptanalysis, stay for the Big Brother state. https://twitter.com/...