ZDNet News ZDNet Sites:  Reviews | Downloads | Tech Update | Prices 

 
Page OneHardwareSoftwareNetworkingE-CommerceCommentary


Computing

Cell phone flaw opens security hole

By Sara Robinson
Interactive Week
September 18, 2000 4:01 AM PT
Your cell phone may be multilingual -- and that could be detrimental to your privacy. Computer security researchers said a design flaw in the protocol used in global system for mobile communication cell phones could allow eavesdropping. The trick: Just make the cell phone think it's somewhere else.

Only 6.5 million people in North America use global system for mobile communications cell phones -- through providers such as Pacific Bell Wireless and VoiceStream Wireless -- but worldwide, it's the most widely used standard, accounting for 65 percent of the total wireless digital market. GSM phones are increasingly popular in the United States because they allow roaming in Asia and Europe upon insertion of the appropriate smart card.


Since Western Europe can't export encryption products to certain countries, such as targets of United Nations sanctions, the default version of the GSM protocol does not use encryption. This in itself isn't necessarily a problem, said David Wagner, a professor of computer science at the University of California-Berkeley, but GSM also does not authenticate its base stations, the hardware that communicates with the handsets -- and that is potentially troublesome.

Experts said it is possible to build a phony base station that jams the signal from the real base station and forces the cell phone to connect to it. The base station then tells the cell phone, in essence, "You're in Iraq, don't use encryption," and the call proceeds unprotected with the false base station relaying information between the real base station and the handset.

A handful of researchers have been aware of the loophole for several years now, but it's been "a well-kept secret," Wagner said.

Security experts call this a "man-in-the-middle" attack because the phony base station sits between the handset and the real base station, intercepting their communications, but neither the real base station nor the handset knows it's there.

"We know about it as a technical issue, but we haven't seen it demonstrated," said James Moran, fraud and security director at the GSM Association. He added that building an interception device would require considerable technical skill. Moran said the next GSM standard would address the problem.

Other cell phone standards probably don't authenticate base stations either, Wagner said, perhaps because their designers were more concerned with preventing handset cloning, which allows someone to bill his or her calls to someone else's number. But the phony-base-station trick is a particular problem for GSM because different strengths of encryption are used in different places.

"Whenever you have to support both weak and strong cryptography, one very real risk is that you end up with 'least common denominator' security," Wagner said.

Cracking different pieces of the cryptography that protects GSM cell phones from eavesdropping has long been a favorite pastime for computer security researchers. Just last December, two Israeli researchers announced that they had found a fast method of cracking the A5/1 algorithm, the strong encryption used to protect GSM phone calls in Europe and the United States. But the phony-base-station strategy obviates the need for any encryption busting.


E-mail this story!
Printer Friendly

 Related Links:
> Can cell phones really kill you?
> Cell phone makers vie for global market
> Radiation warning labels coming to cell phones
> Telecom Resource Center
> ZDNet Wireless Guide


Also on ZDNet
  FREE! One-of-a-kind Windows downloads when you join ZDNet.
  AvantGo lets you put ZDNet on your PDA.
  ZDNet's Price Guarantee: Get the best price or get cash back!
  Get the info you need to succeed in today's marketplaces.
  Laid off? Jumpstart your career with over 90,000 job listings.



This story originally appeared in Interactive Week.


 

search for



 


Tech Update


Workers get recycled


Wireless security gets a jumpstart


XP dawns; More Windows ahead

News in Brief


FCC proposes $100,000 fine against SBC 02:04p

Loch Ness monster swims into the Net 11:33a

Sega venture to sell games via ISPs 11:14a

Cable rate hikes at AT&T Broadband 09:52a

Homestore.com posts third-quarter loss 07:54a

More...

Commentary


DVORAK DVORAK
Microsoft, please fix your software! More...


SCHONFELD SCHONFELD
Must-see merger: EchoStar & DirecTV. More...




GARTNER: Linux's future is still murky

SOMOGYI: The Great OS X 10.1 Experiment

BAILEY: Prepare for Microsoft to inflate XP success

More Commentary...

TalkBack Central


TalkBack Central Commentaries dedicated entirely to you and your views! Got a column for 'Your Turn'? Submit it here.



Gates unveils Windows XP

Microsoft braces for browser battles

MSN lockout fuels antitrust cry

MSN.com won't play nice with others

Ashcroft to speed Net search for terrorists



News Tools

  News Archives

  News in Brief

  News for your PDA

  Contact us

  Corrections


Newsletters
ZDNet News brings you a summary of top headlines each business day.
ZDNet News
Tech Update Today



More newsletters


 

 Sponsored Links
Download  Free Macromedia JRun Download
Great Buy!  NEC AccuSync 70 CRT monitor
Omnis.com  Web Hosting as low as $3.75/month! 50% Off Domains!
Genuity  Discover Genuity's Black Rocket eBusiness network platform.
Books  Free Shipping at Barnes & Noble.com!
Shop Smart  Everyday Great Prices at J&R Music and Computer World

 Everything Intel    Find Out More
FREE!   Ground shipping with select Dell! - Dell Small Business Center
Shop Now!   Gateway Home Computing Center - TOSHIBA
Shop Now!   Gateway Business Center

 Featured Links
Best Buys  Shop Smart for scanners, digital cameras, monitors & more!
FREE $5  Buy it New or Used at eBay's Half.com.
FREE!  Tech Advice and 100's of Downloads for IT Pros!

 Magazine Offers
2 FREE CDs  CLICK HERE For Your FREE TRIAL of Computer Shopper

ZDNet Free Membership | Newsletters | Tech Update | Tech InfoBase | Careers

Support | Privacy | Terms of Use | Advertise | About Us


Copyright © 2001 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc. Content originally published in Ziff Davis Media publications is the copyrighted property of Ziff Davis Media. Copyright © 2001 Ziff Davis Media. All rights reserved. Titles of Ziff Davis Media publications are trademarks of Ziff Davis Publishing Holdings Inc.