Researchers: encryption algorithm GEA-1, used in GPRS data in 2G networks, was deliberately weakened by its designers; ETSI blames export regulations
A new paper shows that two old encryption algorithms still used in mobile networks can be exploited to spy on phones' internet traffic.
VICE Lorenzo Franceschi-Bicchierai
Related Coverage
- GPRS-era mobile data encryption algorithm GEA/1 was ‘weak by design’, still lingers in today's phones The Register · Iain Thomson
- New report finds early cell phone encryption algorithm was intentionally weakened by design TechSpot · Shawn Knight
- Cryptology ePrint Archive: Report 2021/819 Cryptology ePrint Archive
- Report Finds Phone Network Encryption Was Deliberately Weakened Slashdot · Msmash
- Report insinuates that early mobile data networks were deliberately backdoored XDA Developers · Adam Conway
- Intentional Flaw in GPRS Encryption Algorithm GEA-1 Schneier on Security · Bruce Schneier
Discussion
-
@matthew_d_green
Matthew Green
on x
This is an amazing paper. It implies (with strong statistical evidence) that the design of a major mobile-data encryption algorithm — used in GPRS data — was deliberately backdoored by its designer. https://eprint.iacr.org/...
-
@k8em0
Katie Moussouris
on x
Effects of overly restrictive export controls on encryption: forced weak implementations that weaken security for all for decades. “researchers tested several modern phones to see if they would still support the vulnerable algorithms, “surprisingly” found that they still do.” htt…
-
@privacydigest
@privacydigest
on x
Bombshell Report Finds Phone Network Encryption Was Deliberately Weakened A new paper shows that two old encryption algorithms still used in mobile networks can be exploited to spy on phones' internet traffic https://www.vice.com/...
-
@vice
@vice
on x
The paper has sent shockwaves through the encryption community because it implies that a weakness was intentionally put into the algorithm to allow hackers to spy. https://www.vice.com/...
-
@campuscodi
Catalin Cimpanu
on x
Do not discount this discovery just because it's 2G and not 5G. 2G is still used for controlling loads of IoT devices. You might be surprised by how many “smart cars” use 2G modems nowadays. https://twitter.com/...
-
@sickcodes
Sick.Codes
on x
GPRS (2G) is allegedly weak by design: “...cryptanalytic attacks on the GEA-1 and GEA-2 algorithms... the initial state of GEA-1 can be recovered from as little as 65 bits of known keystream... and 44.5GB of memory” https://eprint.iacr.org/... https://www.vice.com/... 👍 @lorenzof…
-
@matthew_d_green
Matthew Green
on x
Fortunately for everyone involved, these ciphers have been mostly deprecated. They're only even included in some older phone basebands. But that's not cause for celebration. https://twitter.com/...
-
@motherboard
@motherboard
on x
A weakness in the algorithm used to encrypt cellphone data in the 1990s and 2000s allowed hackers to spy on some internet traffic, according to a new research paper. https://www.vice.com/...
-
@ekoivune
Erka Koivunen
on x
Ah, the telecomms industry and their lip service to security. https://twitter.com/...
-
@dcuthbert
Daniel Cuthbert
on x
Finally got a chance to turn off all distractions and read this thread and oh boy, it's a belter. Thanks to Matthew for explaining it so well. https://twitter.com/...
-
@naomibrockwell
Naomi Brockwell
on x
So has our standard encryption been backdoored? Turns out it was for years. It's incredible they got away with it for so long. What about current encryption standards? We'll find out soon, no doubt people are now looking very closely to find out. https://twitter.com/...
-
@ildannymoore
Daniel Moore
on x
If this was intentional backdooring it's impressive. It took a long time to discover and maintains a level of minimal deniability even after. https://twitter.com/...
-
@jason_koebler
Jason Koebler
on x
This paper is bonkers, essentially found that encryption on a cell network used for data for a decade was intentionally weakened ... by using math https://www.vice.com/...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
NEW: Researchers revealed in new paper that a cellphone encryption algorithm from the late 1990s—still in use today—was deliberately designed to be weak. The weakness allows attackers to spy on phone's internet traffic. https://www.vice.com/...
-
@lorenzofb
Lorenzo Franceschi-Bicchierai
on x
Turns out ETSI, the organization that designed the GEA-1 algorithm, had to make it weak because of export controls. https://www.vice.com/... https://twitter.com/...
-
@josephfcox
Joseph Cox
on x
New: researchers believe probability of a particular weakness being introduced accidentally into phone network crypto is extremely low. Think it was put into the algorithm on purpose. Now group that designed the algorithm confirmed to us this was the case https://www.vice.com/...
-
@stshank
Stephen Shankland
on x
From the paper: “This implies that the weakness in GEA-1 is unlikely to occur by chance, indicating that the security level of 40 bits is due to export regulations.” https://twitter.com/...
-
@granick
@granick
on x
Fascinating thread. Come for the cryptanalysis, stay for the Big Brother state. https://twitter.com/...