<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Less Radiation &#187; insecure</title>
	<atom:link href="http://www.lessradiation.co.uk/tag/insecure/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lessradiation.co.uk</link>
	<description>Love Electronics. Loathe Electrosmog.</description>
	<lastBuildDate>Wed, 01 Feb 2012 11:35:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>GSM Security Nearly Dead.</title>
		<link>http://www.lessradiation.co.uk/gsm-security-nearly-dead/</link>
		<comments>http://www.lessradiation.co.uk/gsm-security-nearly-dead/#comments</comments>
		<pubDate>Sun, 30 Aug 2009 21:17:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[3G]]></category>
		<category><![CDATA[a5/1]]></category>
		<category><![CDATA[breached]]></category>
		<category><![CDATA[cracked]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[eavesdropping]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[insecure]]></category>
		<category><![CDATA[listen in]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[mobile phone]]></category>
		<category><![CDATA[rainbow table]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spooks]]></category>

		<guid isPermaLink="false">http://www.lessradiation.co.uk/?p=256</guid>
		<description><![CDATA[A report at TheRegister.co.uk on 25th August suggests that basic GSM handset encryption will shortly be thwarted. For several years now, interested people have been doing ever more with GNU Radio and the USRP &#8216;software radio&#8217; hardware from Ettus Research. The USRP is a USB hardware device that can be made to act like any [...]]]></description>
			<content:encoded><![CDATA[<p>A report at TheRegister.co.uk on 25th August suggests that basic GSM handset encryption will shortly be thwarted.</p>
<p>For several years now, interested people have been doing ever more with <a href="http://gnuradio.org/trac">GNU Radio</a> and the USRP &#8216;software radio&#8217; hardware from <a href="http://www.ettus.com/">Ettus Research</a>. The USRP is a USB hardware device that can be made to act like any radio, using the GNU Radio software to alter its behaviour. Thus, the $1000 USRP can be made to act like a GSM phone, a WiFi Router, a regular FM radio or indeed a Tetra radio.</p>
<p>The <a href="http://openbts.sourceforge.net/">OpenBTS</a> project first showcased what was possible: a DIY GSM mast that allowed you to use a regular mobile phone to make calls without using the regular legitimate GSM carriers &#8211; using just a laptop &#038; USRP peripheral. Calls were routed through an Asterisk VOIP gateway. This project was actually tested for real at <a href="http://openbts.sourceforge.net/FieldTest/index.html">The Burning Man festival</a> &#038; also the 2009 <a href="https://wiki.har2009.org/page/GSM">Hackers At Random</a> conference .</p>
<p>Once the open-source GPL&#8217;d OpenBTS was out there regular coders could look and see how everything fitted together. Of course it was only a matter of time before other GSM applications followed.</p>
<p>The report at <a href="http://www.theregister.co.uk/2009/08/25/gsm_cracked/">The Register</a> states that the Chaos Computer Club (CCC) of Germany will be releasing tools in the next couple of months that will allow anyone with a laptop &#038; antenna (and presumably a USRP) to listen in on encrypted GSM calls. They plan to build a huge <a href="http://reflextor.com/trac/a51/">A5/1 Rainbow Table</a> of pre-computed encryption hashes (which is basically a lookup table of every possible answer for an encryption key) of some 2 terabytes in size. Presumably you&#8217;ll be able to post your key online and get a result from the rainbow table, in the same way you can with Windows Login passwords right now. Of course posting such a request to the table via the internet would probably get you a black mark down at Spooks HQ &#8211; and i&#8217;m quite sure they&#8217;ll be listening!</p>
<p>It&#8217;s amazing to think that this year will have seen both Dect and GSM hacked to bits. All this is possible because of the USRP hardware &#038; ever faster PCs. 3G phones however will be safe for some time to come, as it will be only the original implementations of GSM that can eventually be eavesdropped upon.</p>
<p><a href="http://www.theregister.co.uk/2009/08/28/mobile_phone_snooping_plan/">http://www.theregister.co.uk/2009/08/28/mobile_phone_snooping_plan/</a></p>
<p>Also, an <a href="http://uk.babelfish.yahoo.com/translate_url?doit=done&#038;tt=url&#038;intl=1&#038;fr=bf-home&#038;trurl=http%3A%2F%2Fwww.ftd.de%2Fit-medien%2Fit-telekommunikation%2F%3Agsm-netz-nicht-sicher-handys-bald-fuer-jedermann-abhoerbar%2F557540.html&#038;lp=de_en&#038;btnTrUrl=Translate">article</a> from the German Financial Times, translated to English.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lessradiation.co.uk/gsm-security-nearly-dead/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dect Monitoring Update</title>
		<link>http://www.lessradiation.co.uk/dect-monitoring-update/</link>
		<comments>http://www.lessradiation.co.uk/dect-monitoring-update/#comments</comments>
		<pubDate>Sat, 24 Jan 2009 12:08:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[DECT]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[com-on-air]]></category>
		<category><![CDATA[insecure]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.lessradiation.co.uk/?p=80</guid>
		<description><![CDATA[As you&#8217;ll see from our last post &#8211; Dect is now completely insecure. Over the last two weeks I&#8217;ve been doing some more research, and it seems like around 50% of Dect phones transmit without using the optional encryption. This means that someone with just a Laptop, Com-On-Air wireless Dect PCMCIA card &#38; Ubuntu Linux [...]]]></description>
			<content:encoded><![CDATA[<p>As you&#8217;ll see from our last post &#8211; Dect is now completely insecure. Over the last two weeks I&#8217;ve been doing some more research, and it seems like around 50% of Dect phones transmit without using the optional encryption.</p>
<p>This means that someone with just a Laptop, Com-On-Air wireless Dect PCMCIA card &amp; <a href="http://www.ubuntu.com/products/WhatIsUbuntu/desktopedition">Ubuntu Linux</a> can now monitor all those conversations you have. Imagine how much information you could be providing for identity thieves!</p>
<p>If you use telephone banking or use your credit card to pay for goods over the phone, then you really should go back to using a regular wired home phone for these calls at least (or just use your proper mobile, as these are still secure).</p>
<p>If you&#8217;re fortunate enough to own a DECT phone that does encrypt <a href="https://dedected.org/trac/wiki/ListOfPhones">(list)</a>, then you are still at some risk, the reason: the data-stream passing between your phone &amp; base-station can still be recorded &#8211; but at this moment it can&#8217;t be turned into  a conversation. Once more malicious hackers start to understand the current software, then eventually brute force hacks for the encrypted calls will appear &#8211; and when they do your old calls could be dusted-off &amp; decrypted.</p>
<p>Worryingly, it seems that Dect is used for <a href="http://www.ofcom.org.uk/consult/condocs/sfrip/sfip/responses/siemens_traffic">controlling traffic lights</a> &amp; some wireless credit card terminals. So these will likely become targets too.</p>
<p>This hack originated in Germany and their equivalent of the BBC&#8217;s Panorama have already done a piece on it. The equivalent of the UK&#8217;s OFCOM have already issued advice to Germans that they should stop telephone banking &amp; giving out credit card numbers over cordless Dect phones.</p>
<p>The equipment still takes a fair bit of computer <a href="http://www.ccc-mannheim.de/wiki/Dedected">knowledge</a> to get working, and the PCMCIA cards are only available in limited numbers &#8211; so it might not become an epidemic-level problem. The Dosch Amand Com-On-Air type II PCMCIA cards which were selling for €40 two weeks ago are now changing hands for €200+ on eBay!</p>
<p><a href="http://frontal21.zdf.de/ZDFde/inhalt/3/0,1872,7505859,00.html">Frontal21 (like BBC&#8217;s Panorama in the UK) website piece.</a></p>
<p><a href="http://media.benny.de/2009-01-20_-_ZDF_-_Frontal21_-_DECT.mpg ">Video of Frontal21 episode</a></p>
<p>If you want to experiment you can buy a DECT card for your PC from www.ebay.de (that&#8217;s the German eBay). Look for vendor arc-computer2 &amp; you could pickup a type III PCMCIA or PCI card for around €25 &#8211; you should pay €10 for UK carriage if in doubt.</p>
<p>Both the PCI card and type III PCMCIA card aren&#8217;t yet supported in the dect_cli software, but they soon will be. Once supported they&#8217;ll rocket in value like the type II cards already have &#8211; as these items are no longer manufactured &amp; stock of the product is limited.</p>
<p>Here&#8217;s a recent <a href="http://www.lessradiation.co.uk/ebay.gif" target="_blank">screengrab</a> from eBay.de &#8211; notice the joker selling a signed-by-the-hackers type II card for €2500.</p>
<p>Siemens Gigaset Dect Security &#8211; <a href="http://translate.google.co.uk/translate?prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=http%3A%2F%2Fgigaset.com%2Fshc%2F0%2C1935%2Cde_de_0_167508_rArNrNrNrN%2C00.html&amp;sl=de&amp;tl=en&amp;history_state0=">Read the press release</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lessradiation.co.uk/dect-monitoring-update/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://media.benny.de/2009-01-20_-_ZDF_-_Frontal21_-_DECT.mpg" length="449757615" type="video/mpeg" />
<enclosure url="http://media.benny.de/2009-01-20_-_ZDF_-_Frontal21_-_DECT.mpg" length="449757615" type="video/mpeg" />
<enclosure url="http://media.benny.de/2009-01-20_-_ZDF_-_Frontal21_-_DECT.mpg" length="449757615" type="video/mpeg" />
		</item>
		<item>
		<title>DECT Hacked &#8211; Eavesdropping Now Possible!</title>
		<link>http://www.lessradiation.co.uk/dect-hacked-eavesdropping-now-possible/</link>
		<comments>http://www.lessradiation.co.uk/dect-hacked-eavesdropping-now-possible/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 22:24:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[DECT]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[com-on-air]]></category>
		<category><![CDATA[compromised]]></category>
		<category><![CDATA[eavesdropping]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[insecure]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://www.lessradiation.co.uk/?p=60</guid>
		<description><![CDATA[Looking through the Security News on TheRegister.co.uk this evening I was surprised to see a report that DECT has now been hacked. If you didn&#8217;t know already, DECT is the technology used by the current generation of cordless home phones &#38; baby monitors. So now, not only is it probably bad for you, it&#8217;s also [...]]]></description>
			<content:encoded><![CDATA[<p>Looking through the Security News on <a href="http://www.theregister.co.uk/security">TheRegister.co.uk</a> this evening I was surprised to see a report that DECT has now been hacked.</p>
<p>If you didn&#8217;t know already, DECT is the technology used by the current generation of cordless home phones &amp; baby monitors. So now, not only is it probably bad for you, it&#8217;s also insecure!</p>
<p>The researchers reverse-engineered a standard Com-On-Air PCMCIA DECT card &#8211; which is normally used in a Windows laptop to bridge/ link DECT phones to Asterisk VOIP/SIP networks &#8211; and demonstrated their Linux-based sniffer at 25C3 hackers congress.</p>
<p>The PCMCIA Class II card costs just €40 from www.arc-computer.de (in Germany, you can buy one via their eBay shop). You will need a PC running Linux to do anything useful with it, and really it&#8217;s just a proof-of-concept tool right now. But watch this space.</p>
<p>Read more about it:</p>
<p><a href="http://events.ccc.de/congress/2008/Fahrplan/events/2937.en.html">http://events.ccc.de/congress/2008/Fahrplan/events/2937.en.html</a></p>
<p><a href="http://www.theregister.co.uk/2008/12/31/dect_hack/">http://www.theregister.co.uk/2008/12/31/dect_hack/</a></p>
<p><a href="https://dedected.org/cgi-bin/trac.cgi">https://dedected.org/cgi-bin/trac.cgi</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lessradiation.co.uk/dect-hacked-eavesdropping-now-possible/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

