ZDNet News ZDNet Sites:  Reviews | Downloads | Tech Update | Prices 

 
Page OneHardwareSoftwareNetworkingE-CommerceCommentary


Computing

Cell phone flaw opens security hole

By Sara Robinson
Interactive Week
September 18, 2000 4:01 AM PT
Your cell phone may be multilingual -- and that could be detrimental to your privacy. Computer security researchers said a design flaw in the protocol used in global system for mobile communication cell phones could allow eavesdropping. The trick: Just make the cell phone think it's somewhere else.

Only 6.5 million people in North America use global system for mobile communications cell phones -- through providers such as Pacific Bell Wireless and VoiceStream Wireless -- but worldwide, it's the most widely used standard, accounting for 65 percent of the total wireless digital market. GSM phones are increasingly popular in the United States because they allow roaming in Asia and Europe upon insertion of the appropriate smart card.


Since Western Europe can't export encryption products to certain countries, such as targets of United Nations sanctions, the default version of the GSM protocol does not use encryption. This in itself isn't necessarily a problem, said David Wagner, a professor of computer science at the University of California-Berkeley, but GSM also does not authenticate its base stations, the hardware that communicates with the handsets -- and that is potentially troublesome.

Experts said it is possible to build a phony base station that jams the signal from the real base station and forces the cell phone to connect to it. The base station then tells the cell phone, in essence, "You're in Iraq, don't use encryption," and the call proceeds unprotected with the false base station relaying information between the real base station and the handset.

A handful of researchers have been aware of the loophole for several years now, but it's been "a well-kept secret," Wagner said.

Security experts call this a "man-in-the-middle" attack because the phony base station sits between the handset and the real base station, intercepting their communications, but neither the real base station nor the handset knows it's there.

"We know about it as a technical issue, but we haven't seen it demonstrated," said James Moran, fraud and security director at the GSM Association. He added that building an interception device would require considerable technical skill. Moran said the next GSM standard would address the problem.

Other cell phone standards probably don't authenticate base stations either, Wagner said, perhaps because their designers were more concerned with preventing handset cloning, which allows someone to bill his or her calls to someone else's number. But the phony-base-station trick is a particular problem for GSM because different strengths of encryption are used in different places.

"Whenever you have to support both weak and strong cryptography, one very real risk is that you end up with 'least common denominator' security," Wagner said.

Cracking different pieces of the cryptography that protects GSM cell phones from eavesdropping has long been a favorite pastime for computer security researchers. Just last December, two Israeli researchers announced that they had found a fast method of cracking the A5/1 algorithm, the strong encryption used to protect GSM phone calls in Europe and the United States. But the phony-base-station strategy obviates the need for any encryption busting.


E-mail this story!
Printer Friendly

 Related Links:
> Can cell phones really kill you?
> Cell phone makers vie for global market
> Radiation warning labels coming to cell phones
> Telecom Resource Center
> ZDNet Wireless Guide


Also on ZDNet
  Get the best bang for your buck in our Holiday Gift Guide.
  Make the customer connection with cutting-edge CRM info.
  Check out ZDNet Editors' Top 5 for the best products money can buy!
  Last-minute tips to get your site through the holiday season.
  When times are down keep customer service up.



This story originally appeared in Interactive Week.


 

search for



 


Tech Update


Special report: Standardizing C#


Holy handheld, Batman! They put Java where?!


XP and beyond

News in Brief


Canada's baking TV-over-Net bill 04:33p

Face-lift for GFS storage software 03:08p

MP3.com, CD Baby sign distribution deal 12:58p

Distributed computing gets new tool 12:05p

NetApp plays role in 'Lord of the Rings' 11:16a

More...

Commentary


PFEIFFER PFEIFFER
Operating systems: Expect the unexpected. More...


COURSEY COURSEY
XP may be ready for wireless, but it looks like wireless isn't ready for XP. More...




PETERSEN: DVD downloads: Thumbs down

SOMOGYI: Which new game console is best?

GARTNER: Why Big Blue is like comfort food

More Commentary...

TalkBack Central


TalkBack Central Important notice: ZDNet News is pleased to announce that we are undergoing a complete overhaul of our TalkBack publishing system. Click here for more details.

Plus: We'd still like to feature you as a guest columnist! Got a column for 'Your Turn'? Submit it here.




News Tools

  News Archives

  News in Brief

  News for your PDA

  Contact us

  Corrections


Newsletters
ZDNet News brings you a summary of top headlines each business day.
ZDNet News
Tech Update Today



More newsletters


 

 Sponsored Links
UltimateTV  Get $100 off the power of Digital Video Recording.
Great Buy!  NEC AccuSync 70 CRT monitor
CDW.com:  Computing Solutions Built for Business.
Download  Free Macromedia ColdFusion Download
Books  Free Shipping at Barnes & Noble.com!
Shop Smart  Everyday Great Prices at J&R Music and Computer World

 Everything Intel    Find Out More
Great Deal   Buy a Dell™ for the perfect gift! - Dell Small Business Center
Shop Now!   Gateway Home Computing Center - TOSHIBA
Shop Now!   Gateway Business Center

 Featured Links
Best Buys  Shop Smart for scanners, digital cameras, monitors & more!
FREE $5  Buy it New or Used at eBay's Half.com.
FREE!  Tech Advice and 100's of Downloads for IT Pros!

 Magazine Offers
HolidayDeal  Try Computer Shopper FREE ($3.99 value) & Get 2 FREE CDs

ZDNet Free Membership | Newsletters | Tech Update | Tech InfoBase | Careers

Support | Privacy | Terms of Use | How to Advertise | About Us


Copyright © 2001 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc. Content originally published in Ziff Davis Media publications is the copyrighted property of Ziff Davis Media. Copyright © 2001 Ziff Davis Media. All rights reserved. Titles of Ziff Davis Media publications are trademarks of Ziff Davis Publishing Holdings Inc.