[00:00.900 --> 00:02.400] Shortly after they happen, actually. [00:02.500 --> 00:03.840] I think we're burning disks on site. [00:03.980 --> 00:05.480] So if you go check the merge tables, those are there. [00:05.600 --> 00:11.320] And that's a great way, once again, if you are an academic, to take things home to your students or to your parents or whoever else needs to hear things. [00:11.480 --> 00:15.860] Steve Rambam's talk is always great to scare people in the submission about privacy and things like that. [00:17.280 --> 00:17.600] Great. [00:18.180 --> 00:20.800] So, introducing Matt Blaze and Sandy Clark. [00:21.440 --> 00:23.960] And I forget your title, but it's going to be awesome. [00:24.080 --> 00:25.700] So everybody, give it up. [00:32.820 --> 00:33.560] That's all there? [00:33.640 --> 00:34.020] Yes, it is. [00:34.170 --> 00:34.280] Okay. [00:34.640 --> 00:34.860] Hi. [00:35.460 --> 00:37.560] So this is actually joint work. [00:38.900 --> 00:40.260] Sandy and I are here. [00:40.580 --> 00:42.120] Travis is God knows where. [00:42.840 --> 00:45.740] Perry Metzger might or might not be here. [00:46.340 --> 00:49.780] Zach Wasserman and Kevin Zhu are not here. [00:50.120 --> 00:52.820] So there are two of us here and two of us kind of metastable. [00:52.960 --> 00:53.920] So we'll see. [00:53.920 --> 01:13.880] So what I'm going to talk about is some work that we've been working on over the last three years, which we only first released last year, although I'm going to talk about a little more detail than we've talked about in the past, which is going to require me to put up. [01:13.880 --> 01:18.120] I hate disclaimers, but I have to put one up here. [01:18.290 --> 01:26.790] Partial support for this work was from the National Science Foundation, to whom we are very grateful for their enormous generosity. [01:27.000 --> 01:38.940] But they asked me to point out that any opinions, findings, and conclusions or recommendations expressed in this material are those of the author and do not necessarily reflect the views of the National Science Foundation or the United States Government. [01:38.940 --> 01:41.350] And that, it turns out, is absolutely true. [01:45.290 --> 01:48.980] So, yeah, I mean, the word necessarily is really unnecessary in this. [01:49.620 --> 01:50.240] Okay. [01:50.640 --> 01:51.120] Okay. [01:51.240 --> 01:59.500] So I'm going to talk about basically a security protocol that has nothing or very little to do with the Internet. [01:59.500 --> 02:06.320] We decided to do something a little bit different from the normal kind of Internet security model. [02:06.320 --> 02:14.380] And in particular, look at wireless security that also isn't 802.11, which is the wireless security that we usually look at. [02:14.520 --> 02:23.240] We decided to look at the security properties of two-way radio systems that are designed to be secure. [02:23.400 --> 02:27.980] And in particular, what we looked at is something called APCO Project 25. [02:28.480 --> 02:33.700] This implies that there were 24 before it, but I believe that the one before it was 16. [02:34.840 --> 02:37.740] So I'm not sure what's going on there with the numbering. [02:38.140 --> 02:41.140] APCO is the Association of Public Safety... [02:41.140 --> 02:42.220] Yeah, squares, right, exactly. [02:42.620 --> 02:45.440] Public Safety Communications Officers. [02:45.440 --> 03:06.440] It is basically the group that sets, along with the federal government and vendors, the protocols for various land-mobile two-way radio systems, such as they're used by the police and the federal government and others. [03:06.440 --> 03:12.840] APCO Project 25 is sort of the officially blessed U.S. [03:13.000 --> 03:21.300] government standard for narrow-band two-way radio that's intended to replace the analog FM systems that are currently being used. [03:21.700 --> 03:34.500] And so its main design property, its main design requirement has been that it be backwards compatible with the spectrum management that came before it for the FM systems. [03:34.720 --> 03:46.120] So it's not... you know, if you were designing two-way radio from scratch, you'd probably do all sorts of amazing things like spread spectrum and, you know, cognitive radio and frequency hopping and so on. [03:46.360 --> 04:03.000] They're using, you know, individual channelized radio, just like we were using in the analog days, in order to allow a transition and not require everybody to change everything at once and have to trash all the existing equipment. [04:03.600 --> 04:11.840] The idea is that this would be a standard in which one size fits, maybe not all, but as many as possible. [04:12.420 --> 04:25.860] So the users of this are intended to be, you know, local police two-way radio dispatch, but also things like the federal government, people performing surveillance. [04:25.860 --> 04:34.500] You know, there are... we're not going to talk about specific names of agencies, but you might imagine that there are bureaus of the federal government that perform investigations. [04:35.480 --> 04:37.800] You know, that they would use things like this. [04:37.900 --> 04:43.040] There are services that are somewhat secret that use things like this and so on. [04:43.220 --> 05:02.400] So while local two-way radio dispatch systems tend not to use the security features of this, they tend to be relatively open because interoperability is a big problem for local police two-way radio systems that have to deal with other agencies that are nearby. [05:02.740 --> 05:11.120] There are other users of this that care quite a bit about the confidentiality and resistance to denial of service and so on. [05:11.120 --> 05:27.240] So the same standard that's used for your local police and your local fire department and EMS is intended to also serve the needs of people whose primary problem is confidentiality and security in their communications. [05:27.240 --> 05:32.140] So there's... the standard dates back to the early 90s. [05:32.240 --> 05:39.940] Equipment started to come out on the market in earnest about 10 years ago, 12 years ago. [05:40.160 --> 05:46.940] There's now a fairly wide range of equipment that's being sold. [05:47.160 --> 05:47.820] There are several vendors. [05:47.980 --> 05:52.380] Motorola is probably the dominant vendor in the U.S. [05:52.560 --> 05:54.580] federal sector. [05:54.580 --> 06:00.080] But the intention is that the equipment is standardized and it doesn't really matter which vendor's equipment that you use. [06:00.220 --> 06:05.900] So there's a, you know, picture of a typical, you know, previous generation P25 radios. [06:06.080 --> 06:08.400] I have, you know, here's the current generation. [06:08.640 --> 06:10.560] The main difference is that it's more expensive. [06:14.760 --> 06:19.060] The user interfaces vary a little bit from piece of equipment to piece of equipment. [06:19.060 --> 06:27.820] But they're largely standardized and the standard has code bases associated with it that everybody tends to fork from. [06:28.060 --> 06:33.040] So there's not a lot of heterogeneity there. [06:33.880 --> 06:34.340] Okay. [06:34.860 --> 06:36.820] So I'll give you an example of some of the users. [06:36.920 --> 06:44.360] I went looking for photos of people using these radios to get a sense of who other than local law enforcement is. [06:44.360 --> 06:50.160] On the left is a picture from the New York Times about war fighters in Afghanistan. [06:50.340 --> 06:55.400] And we see a prominent picture of a Motorola XTS 5000 radio. [06:56.520 --> 07:10.300] There's a photo from an official White House photo of the security detail at the White House during the banquet that people crashed a few years ago. [07:10.300 --> 07:12.200] I think in 2009. [07:13.580 --> 07:16.360] That's a picture of the back of a Secret Service agent. [07:16.560 --> 07:20.260] And her evening dress is stuck awkwardly. [07:20.360 --> 07:24.060] A very heavy, large walkie-talkie. [07:24.640 --> 07:26.980] That's what's at the end of those little coiled earphones. [07:27.140 --> 07:29.580] But you can see under her arm the push-to-talk button. [07:29.800 --> 07:34.040] And also if you zoom in on the photo, you can also look, you can see the encryption switch. [07:34.040 --> 07:35.880] And it's actually in the clear position. [07:36.800 --> 07:39.840] Okay, so how does this, how does this work? [07:42.020 --> 07:48.100] The, it's intended to interoperate with, you know, the old analog FM system. [07:48.820 --> 07:54.800] So it uses a 12 and a half kilohertz wide channel on VHF or UHF or what have you. [07:54.800 --> 07:59.080] Using a C4 FM, which is just your simple quadrature modulation. [07:59.860 --> 08:05.100] Two bits per symbol at 4800 bits, symbols per second. [08:05.380 --> 08:09.100] So it's a 99.6 K channel. [08:09.460 --> 08:12.380] The main bearer service is voice. [08:12.380 --> 08:28.160] And there's a standard vocoder called IMBE that gives you pretty high intelligibility at that bit rate and tolerates errors in transmission over radio pretty well. [08:28.320 --> 08:34.880] So it's pretty heavily optimized for voice applications at this kind of a bandwidth. [08:35.160 --> 08:37.110] And the whole model is broadcast. [08:37.110 --> 08:52.140] So, you know, in spite of the fact that we think of this as two-way radio, it's actually one-way radio with a transmitter that makes all of the decisions and receivers that kind of, it's up to them to find how to demodulate the signal. [08:52.280 --> 08:56.140] You don't do any negotiation from the receiver back to the sender or whatever. [08:56.310 --> 08:57.040] Oh, is that Perry? [08:57.190 --> 08:57.350] Yeah. [08:57.350 --> 08:58.090] Oh, excellent. [08:58.210 --> 08:58.950] Come on over here. [08:59.170 --> 08:59.230] Come on. [08:59.230 --> 08:59.420] Okay. [09:01.810 --> 09:02.280] Okay. [09:02.540 --> 09:07.970] So on average, 50% of the people who might or might not have been here are here. [09:08.070 --> 09:08.470] Great. [09:10.030 --> 09:16.710] So it's essentially a one-way model of communication, which means there's no negotiation back and forth. [09:17.230 --> 09:18.790] There's no notion of a session. [09:18.790 --> 09:23.450] There are no acknowledgments and so on for the voice aspect of the protocol. [09:24.790 --> 09:39.140] So the security options, and again, these are options, are based on technology as it, all the technological assumptions that you might have wanted to make, you know, in the early 1990s when the project started. [09:39.720 --> 09:47.260] And the assumptions about how capable handsets and user equipment would be were all sort of set in stone 20 years ago. [09:47.260 --> 09:49.660] So it's all based on symmetric encryption. [09:49.850 --> 09:51.170] There's no public key involved. [09:51.400 --> 09:56.930] They allow for unclassified ciphers, DES, AES, and so on. [09:57.000 --> 09:59.920] There's a plug-in basically in the standard for it. [10:00.020 --> 10:02.330] They're currently standardized on AES and DES. [10:03.040 --> 10:09.430] Vendor-specific standards like 40-bit RC4 for export model radios. [10:10.120 --> 10:14.590] And it's possible to use it with classified algorithms as well. [10:15.580 --> 10:19.540] The traffic keys have to be loaded into the radios in advance. [10:19.880 --> 10:21.140] It's, again, all symmetric. [10:21.670 --> 10:23.790] And how do you do this? [10:24.020 --> 10:25.050] Well, there are two options. [10:25.290 --> 10:32.850] One is with an incredibly clunky device called a key loader in which you can squirt keys into the radio with a cable. [10:32.850 --> 10:36.690] And it's a little bit larger than one of the radios themselves. [10:37.550 --> 10:46.000] Or an over-the-air rekeying protocol in which you key radios in advance but can change keys over the air from a centralized base station. [10:46.140 --> 10:53.640] And the keys can be set to either expire or self-destruct or be erased at various intervals. [10:53.930 --> 10:56.180] So here's the communications model. [10:56.300 --> 10:58.280] This has to be one size fits all. [10:58.440 --> 11:02.230] So they made the following sets of decisions. [11:02.230 --> 11:04.110] First of all, it's the broadcast model. [11:04.320 --> 11:06.900] That's dictated by the nature of the channel. [11:07.080 --> 11:08.540] So there are no two-way sessions. [11:08.540 --> 11:10.380] There's no acknowledgment or negotiation. [11:11.490 --> 11:19.000] You will always play over the speaker if you receive clear text on your channel. [11:19.140 --> 11:24.760] And it's on the correct frequency with the correct network identifier. [11:24.850 --> 11:29.830] You will always play clear text that you receive over your local speaker if you're a radio. [11:30.990 --> 11:36.320] If cipher text comes in, you'll look and see if you have the correct key to decrypt it. [11:36.440 --> 11:44.060] And if you do, you will always try to decrypt it if you have key material to do so. [11:45.680 --> 11:50.970] If you don't, then your radio will remain silent when encrypted traffic comes in. [11:51.830 --> 11:54.680] And that happens regardless of the state of your radio. [11:54.830 --> 11:58.580] You'll always play clear text that comes in with the correct network code on the right frequency. [11:58.580 --> 12:06.590] And you'll always play cipher text that you have key material for that comes in on your frequency with the correct network code. [12:07.080 --> 12:12.040] On the sending side, you get to make all of the security decisions. [12:12.040 --> 12:18.140] Whether you are in the clear or encrypted mode on your outbound transmissions is up to the sender's radio entirely. [12:18.400 --> 12:22.110] There's no way for the sender and receiver to kind of say, hey, I've got this key. [12:22.320 --> 12:23.780] Why don't we use this key? [12:24.460 --> 12:33.420] Because of this completely one-way model, even though it's a one-way model in which the roles are changing back and forth quite frequently. [12:33.900 --> 12:41.680] And the standard configuration, there's a switch on the radio that can switch between clear mode and encrypted mode. [12:42.320 --> 12:42.710] Okay. [12:42.970 --> 12:47.230] So we decided to look at how secure this was. [12:48.420 --> 12:51.230] And we, you know, we wrote a paper on this. [12:51.330 --> 12:59.520] And the first thing that we discovered was that there were a whole bunch of obvious mistakes that you could make that we were kind of secretly hoping that they make so that we could write about it. [13:00.200 --> 13:08.210] And, you know, spend five minutes looking at the standard and discover, you know, that, oh, you know, if you XOR the first packet with the second packet, you get the key or something like that. [13:08.210 --> 13:14.540] And, you know, they don't do any of the crazily bad things that often happen. [13:15.220 --> 13:17.540] But there are some worrisome things. [13:18.160 --> 13:21.640] The design is apparently completely ad hoc. [13:22.200 --> 13:26.080] That is, there are no security requirements that are stated. [13:26.320 --> 13:32.180] We can't really measure how secure this is against any properties that it's supposed to happen. [13:32.180 --> 13:36.440] And we also found that there were some significant protocol weaknesses. [13:36.710 --> 13:38.540] And I'll talk about them very briefly. [13:38.540 --> 13:40.540] And then we'll highlight some of them. [13:40.680 --> 13:43.560] First is there's no authentication anywhere in the voice protocol. [13:43.960 --> 13:49.110] So it's possible to impersonate fairly straightforwardly. [13:49.710 --> 13:53.580] The second is that it's inherently susceptible to traffic analysis. [13:53.580 --> 14:00.940] Because radios have a unique identifiers that they send out in the clear, even if they're in encrypted mode. [14:01.230 --> 14:14.400] And then we found some very efficient denial of service attacks that allow an adversary to use 14 decibels less energy than the thing they're trying to jam. [14:14.400 --> 14:23.090] So it's actually more efficient to jam than to use legitimately, which is usually not a good property to have. [14:23.460 --> 14:30.090] We also found that in the equipment, there were some really serious usability weaknesses that we'll talk about in a second. [14:30.520 --> 14:34.140] Okay, so here are some examples of some practical attacks that we found. [14:34.260 --> 14:37.200] And we duplicated all of these in the lab. [14:37.350 --> 14:39.400] First is the no authentication problem. [14:39.400 --> 14:44.460] So voice traffic can be encrypted, but you don't get any assurance about where it came from. [14:44.580 --> 14:47.540] There's no indication of which user it came from. [14:47.610 --> 14:51.970] And there's no protection against replay or splicing attacks and so on. [14:54.110 --> 14:56.920] Also, clear text will always be received anyway. [14:57.060 --> 15:01.160] So even if you don't want to replay something, you can always just transmit out in the clear. [15:01.710 --> 15:06.060] The unit ID that's displayed is not authenticated in any way. [15:06.060 --> 15:19.560] And, you know, they included an AES GCM mode, which for those of you who are crypto types will recognize as an authenticated encryption mode that could fix this problem. [15:19.560 --> 15:22.440] But it actually isn't used in a way that does fix the problem. [15:23.080 --> 15:29.730] It's just used as a drop-in cipher with the same non-authenticating property that the existing ones had. [15:29.730 --> 15:36.230] So that's sort of a, you know, fundamental weakness in the design of the system. [15:36.420 --> 15:41.140] But maybe you could say that it's out of scope of what it's intended to do. [15:41.500 --> 15:49.180] And a little later, we'll talk about some of the amusing finger pointing that goes on when you describe problems like this in fielded systems. [15:50.300 --> 15:57.060] Second is that the system is incredibly vulnerable to traffic analysis, both passive and active. [15:57.060 --> 15:58.710] Let's talk about the simple one first. [16:00.520 --> 16:05.140] Every radio's unique identifier, and they're usually unique. [16:05.260 --> 16:07.590] They don't have to be, but they're typically unique. [16:08.460 --> 16:13.140] A 24-bit identifier is sent out with every transmission. [16:13.140 --> 16:27.210] Now, the standard says that if you're in encrypted mode, you should be encrypting the unit ID along with the rest of the traffic that you're encrypting. [16:27.380 --> 16:34.940] But we discovered, and as far as I know, we discovered it entirely just because we were the first people to look. [16:35.520 --> 16:39.440] Because we wanted to see, well, okay, what does the encrypted unit ID look like? [16:39.540 --> 16:40.660] Is there any traffic analysis? [16:40.880 --> 16:44.330] So it turns out the encryption seems to be something like XORing with all zeros. [16:46.900 --> 16:54.930] Because we found out that in encrypted transmissions, the unit ID is always sent out in the clear, even if the crypto is actually enabled. [16:55.900 --> 16:58.970] So that means that passive traffic analysis is really easy. [16:58.970 --> 17:03.090] You just record the identifiers that are supposed to be encrypted that aren't. [17:04.060 --> 17:08.640] But, so that's, you know, an unfortunate property. [17:08.780 --> 17:13.880] But we found that there's an active attack that's actually even more worrisome than this. [17:14.020 --> 17:27.060] Which is that radios that use the data service, which is any radio using the over-the-air re-keying protocol, will respond to particularly malformed packets that act as pings. [17:27.380 --> 17:38.700] And will essentially send back a negative acknowledgement that says, I didn't quite understand that the message was no good. [17:38.840 --> 17:47.380] So you can ping a radio even when it's not transmitting, if you're an active adversary, and get its unit identifier to come back and you could direction find it then. [17:48.860 --> 17:52.020] And that's invisible to the person wearing the radio. [17:52.280 --> 17:58.480] Unless you've got your finger stuck in the antenna so that you're actually feeling some heat, that power is going out of it, you don't know that your radio is responding. [17:58.720 --> 17:58.840] Right. [17:59.660 --> 18:01.660] And so it's completely invisible to you. [18:01.780 --> 18:06.560] So this enabled us, and I owe Margot Seltzer at Harvard the name. [18:06.660 --> 18:14.460] She said, oh, so you've built the Harry Potter Marauders map, where you can see where all of the watchers are automatically. [18:14.460 --> 18:33.540] So you can essentially ping a radio, set up two base stations with things like the new radios and a phased array antenna that will give you a rough sense of direction, and automatically get a real-time map of where everybody on a given channel is radio by radio. [18:34.580 --> 18:36.980] Now, is that a threat? [18:37.160 --> 18:55.160] Well, you know, in the law enforcement environment, arguably it's a threat against a serious adversary who's willing to invest in active attacks and willing to risk the possibility of being detected, because you have to actually actively transmit in order to do this. [18:55.600 --> 19:02.820] But, you know, it's also worth pointing out, if we go back to this picture, you know, the military is using these radios. [19:02.960 --> 19:10.040] You know, knowing where troops are is often considered to be somewhat of a tactical advantage in military operations. [19:11.300 --> 19:12.500] So, I'm told. [19:12.680 --> 19:13.880] I've never actually been in the military. [19:14.420 --> 19:14.540] Okay. [19:15.300 --> 19:17.760] So, let's look at denial of service. [19:18.920 --> 19:29.940] So, radio has this interesting property, which is that, in general, denial of service is a problem in radio, but it's a relatively evenly matched arms race. [19:29.940 --> 19:48.660] So, if I want to prevent your signal from being heard, what I need to do is put a little bit more energy, typically about three decibels more energy out on the frequency as received at the receiver, than the legitimate transmitter, and I could effectively block its signal. [19:49.400 --> 20:08.520] Now, there are spread spectrum systems that use either a secret spreading code or some fairly clever techniques that can actually tip the advantage to the defender and require the jammer to use significantly more energy than the defender, than the legitimate transmitter, [20:08.700 --> 20:09.880] to jam a signal. [20:10.740 --> 20:19.400] And, you know, the idea is that, you know, at some point, the power budget of the bad guy just gets exhausted. [20:19.400 --> 20:23.800] So, if you use a clever enough system, you can make yourself resistant to jamming. [20:23.960 --> 20:29.560] And, you know, a jammer also is at significant risk of being direction found. [20:29.860 --> 20:43.220] So, you know, in general, it's either an equal arms race in a typical narrow band system, or one that's very slightly... can tend to be tipped into the advantage of the defender, if you're using a spread spectrum system. [20:43.420 --> 20:48.480] But P25 manages to get that wrong in a really profoundly bad way. [20:48.480 --> 20:54.680] So, what P25 does is uses aggressive error correction codes, which is good. [20:55.200 --> 21:00.200] Aggressive error correction means I have to jam more of your signal in order to prevent it from being understood. [21:00.480 --> 21:02.920] And so that looks like a step in the right direction. [21:03.340 --> 21:09.880] But they don't error correct the entire frame over the same error correction code. [21:10.220 --> 21:14.840] They error correct each subfield of it separately. [21:14.840 --> 21:20.400] So, a voice frame, it turns out, is 1728 bits long. [21:20.780 --> 21:26.200] But it has a 64-bit subfield that's after error correction. [21:26.480 --> 21:30.980] A 64-bit subfield that says, this is a voice frame. [21:31.400 --> 21:35.960] And that, it turns out, you really need to receive that 64-bit subfield. [21:35.960 --> 21:42.960] Now, there are actually only about 12 important bits, but they're error corrected with a lot of extra redundancy, but it's very important. [21:43.480 --> 21:56.920] But if you jam only that 64-bit subfield, then you can prevent the entire other, you know, 1600 and some odd bits from being decoded, because we don't know what kind they are on the receiving side. [21:56.920 --> 22:02.820] So, essentially, you have to jam 32 symbols out of every 864 symbols that are being sent. [22:03.020 --> 22:08.960] One small thing that Matt might have thought of implicitly that some of you might be thinking of in the audience... [22:09.480 --> 22:10.740] Or I might not know myself. [22:10.840 --> 22:11.340] Well, no, you know. [22:11.980 --> 22:14.920] 64 bits, you know, might seem, oh, that's a tiny thing. [22:14.960 --> 22:17.820] But these are very, very, very slow signals. [22:18.100 --> 22:19.120] There's only... [22:19.120 --> 22:20.240] Well, 9600 bits. [22:20.340 --> 22:21.820] It's 9600 bits a second. [22:21.820 --> 22:26.040] So 64 symbols is actually a long time. [22:26.260 --> 22:28.660] Well, I mean, it's, you know, too long to do by hand. [22:29.020 --> 22:29.340] Or too quick to do by hand. [22:29.340 --> 22:30.580] But automatically, it's no problem. [22:30.720 --> 22:34.320] So, the question is, can you synchronize your... [22:34.800 --> 22:48.040] Can you synchronize to hit the 64 bits that you have to hit, if you're the jammer, accurately enough to allow you to get away with not transmitting for the rest of the time? [22:48.040 --> 22:55.640] Because if you could, that would give you, effectively, a 14-decibel advantage as the jammer over the legitimate receiver. [22:55.820 --> 22:59.840] Which, you know, let me just point out, this is phenomenally horrible, if that works. [23:00.940 --> 23:01.340] Okay. [23:01.480 --> 23:03.000] So, how hard is it to build one? [23:03.000 --> 23:12.060] So, thanks to Travis, he observed that there's this chip called the TICC1110. [23:12.120 --> 23:18.960] It's a family of single chip radio transceivers that use C4FM modulation. [23:19.640 --> 23:26.380] And, you know, different versions of the chip will work in all of the same frequency bands that P25 radios use. [23:26.380 --> 23:28.740] Now, it puts out about 100 milliwatts of energy. [23:28.900 --> 23:30.980] It's really not a particularly high-powered thing. [23:31.080 --> 23:35.120] But you can hook up a really dumb external amplifier after it to get more power than that. [23:35.460 --> 23:37.760] And you only have to pulse it for a little while. [23:37.960 --> 23:41.780] Now, the neat thing about this chip is it's an embedded microprocessor that you can program. [23:43.540 --> 23:46.000] And it has both a receiver and a transmitter. [23:46.240 --> 23:52.620] And it's programmable on the chip where you can have it receive and then control the behavior of the transmitter. [23:52.620 --> 23:56.080] Ooh, it turns out that's just what you need in order to do this. [23:56.220 --> 23:57.720] So, how do you get these chips? [23:57.960 --> 24:01.660] Well, you can buy them from TI, and they cost about 25 bucks each. [24:01.940 --> 24:07.140] Or, you can buy products that use them that, for some reason, are cheaper than buying the chips that are in them. [24:07.260 --> 24:10.980] The economics of consumer products are mysterious to me. [24:11.720 --> 24:15.060] So, we discovered that there's this device. [24:15.340 --> 24:16.340] Sandy, you have it there. [24:17.420 --> 24:18.940] It's marketed at girls. [24:18.940 --> 24:21.100] It's called a Girl Tech I Am Me. [24:21.260 --> 24:23.640] It's like the radio hacking dream device. [24:23.800 --> 24:26.740] They're basically about two for $30, because they come in pairs. [24:26.740 --> 24:27.900] You can text to each other. [24:28.020 --> 24:35.640] And if you are Travis, or you know Travis, you can get a programming kit to load your own firmware into the thing. [24:35.920 --> 24:42.960] And so, we found that it was possible to turn the I Am Me text messenger into the My First Jammer. [24:44.650 --> 24:51.620] And, you know, we programmed it to automatically sit on a frequency, wait for P25 signals to come in and automatically jam them. [24:51.740 --> 24:53.940] And, lo and behold, it turns out it actually worked. [24:55.540 --> 24:58.740] Now, we didn't actually jam real transmissions. [24:58.840 --> 25:00.880] We did this in our screen lab room. [25:01.020 --> 25:03.200] But, you hook up an external amplifier to it. [25:03.260 --> 25:08.860] This could easily, you know, work over an entire metropolitan area if it had an antenna situated in the right place. [25:09.360 --> 25:11.660] Okay, so what's the scenario on which you'd use? [25:11.660 --> 25:14.960] Well, one dumb scenario is to just jam everything. [25:15.140 --> 25:21.180] But that's not a really... that's not a very smart thing to do if you're under surveillance, because then you'll never find out what they're doing. [25:21.480 --> 25:30.340] Much better would be to convince the people who are putting you under surveillance that the encryption isn't working. [25:30.340 --> 25:33.700] So, only jam encrypted signals when you see them. [25:34.440 --> 25:42.240] And force the people that you're jamming to switch their radios into the clear mode. [25:42.460 --> 25:52.340] And it turns out that if you are... if people are conditioned to believe that the crypto is unreliable, they won't think anything... oh, you know, let's say, oh, the damn crypto isn't working again. [25:52.560 --> 25:55.420] Let's... we better switch to clear because that always works better. [25:56.160 --> 25:59.680] So, the downgrade attack is the interesting way to use this. [25:59.880 --> 26:05.600] That conditioning is very prevalent because analog radios used to be unreliable. [26:05.680 --> 26:05.780] Right. [26:06.140 --> 26:11.860] And so, they're used to losing reception... walking two feet in one direction and losing reception. [26:11.860 --> 26:14.880] So, they think, oh, damn, it's... [26:14.880 --> 26:15.080] Right. [26:15.400 --> 26:16.280] So, of course, these are digital. [26:16.780 --> 26:19.860] You know, the encryption has all the same radio propagation characteristics. [26:20.420 --> 26:22.000] The range is exactly the same. [26:22.100 --> 26:23.700] The voice quality is exactly the same. [26:23.900 --> 26:25.860] It's just encrypting the bits that are sent over. [26:26.120 --> 26:35.780] But the... there's a lot of belief that encryption degrades the quality, even though it's not actually true anymore with these current generation radios. [26:36.120 --> 26:39.180] Since the switch to go to clear is on each individual radio... [26:39.180 --> 26:39.840] Oh, yeah. [26:39.980 --> 26:40.720] Oh, you're way ahead of us. [26:40.720 --> 26:41.580] We'll get there. [26:42.000 --> 26:42.260] Yeah. [26:42.260 --> 26:43.380] You are just way ahead of us. [26:43.620 --> 26:43.920] Okay. [26:44.060 --> 26:45.180] So, usability and practice. [26:45.320 --> 26:47.820] So, how many people recognize this symbol? [26:48.880 --> 26:49.320] Yeah. [26:49.840 --> 26:50.360] It's the... [26:50.360 --> 26:51.020] Yeah, it's the... [26:51.020 --> 26:51.540] It's fee. [26:51.880 --> 26:52.620] It's the null set. [26:53.060 --> 26:54.620] So, we made up shirts with this. [26:54.920 --> 26:58.240] So, radios have a crypto switch and it has two positions. [26:59.080 --> 27:00.280] This is one of them. [27:01.920 --> 27:03.300] And there's another one. [27:03.820 --> 27:06.700] And one of them turns encryption on and the other turns it off. [27:07.120 --> 27:08.180] So, I'll leave you guessing... [27:08.180 --> 27:09.620] Does that symbol say encryption to you? [27:09.620 --> 27:09.900] Yeah. [27:10.380 --> 27:12.000] But it's also used in cars. [27:12.200 --> 27:15.980] This is the air conditioning is closed symbol on a lot of cars. [27:16.760 --> 27:18.760] And it's also, you know, don't touch. [27:19.000 --> 27:19.180] Yeah. [27:19.180 --> 27:19.600] Bad kitty. [27:19.820 --> 27:19.940] Yeah. [27:20.140 --> 27:25.920] So, there's very poor feedback in the radios in practice about the crypto state. [27:25.920 --> 27:32.040] So, transmit crypto is controlled by the switch, but it has no effect on received crypto. [27:32.240 --> 27:40.000] So, there's no way for you to tell what you've done by switching the switch because what you're receiving will work just as well no matter which position it's in. [27:40.000 --> 27:50.060] Similarly, if you are correctly keyed, you'll happily receive things even if you are in the clear mode. [27:50.540 --> 28:03.940] Now, exacerbating this problem is that there is a widespread belief printed in the manuals and mentioned in the standard that re-keying frequently is a really good idea for security. [28:03.940 --> 28:13.280] Because if your radios get captured while you're over enemy territory, you don't want somebody with a captured radio to be able to receive your signals. [28:13.860 --> 28:19.140] And, you know, as you know, federal agents are captured all the time by criminals. [28:20.980 --> 28:22.720] And, you know, lost radios are a problem. [28:22.820 --> 28:23.440] So, I actually checked. [28:23.540 --> 28:29.860] It turns out they lose their guns, which is like this career-ending mood, more often than they lose their radios. [28:29.980 --> 28:32.320] So, it's an almost non-existent problem. [28:32.480 --> 28:34.960] But there's this belief that they need to re-key frequently. [28:35.120 --> 28:36.640] Well, what happens when you re-key? [28:36.880 --> 28:39.440] Well, the radios have to be re-keyed one at a time. [28:39.580 --> 28:42.200] And when you install the new key, the old key goes away. [28:42.200 --> 28:55.640] So, if everybody you're working with doesn't have the same key, which happens, which is a situation that will happen more often, the more often you re-key, then you're going to be forced to go into clear mode more and more often. [28:56.300 --> 29:06.340] So, between the fact that you can't tell what the switch does and the fact that you might not be able to use the crypto, we thought maybe this is a usability problem that had some real potential. [29:06.340 --> 29:12.020] So, we weren't the first person to observe that crypto usability was important. [29:12.180 --> 29:31.840] Alma Witten and Doug Tygar wrote this famous paper in 1999 at USENIX Security called Why Johnny Can't Encrypt, where they analyzed the security of PGP and essentially observed that even geeks have trouble with it and non-geeks have no chance because there's no feedback about what's going on. [29:31.840 --> 29:38.980] So, essentially, it is almost as if the P25 designer said, well, what do we use as our usage model? [29:39.080 --> 29:44.500] Well, let's look at PGP and do it that way. [29:45.500 --> 29:55.960] So, almost line for line, you can look at Witten and Tygar's paper and the advice that they give and see how it wasn't followed in the design of the system. [29:56.460 --> 29:58.920] So, here's an example of the typical radio. [29:58.920 --> 30:01.180] Here's the radio in clear mode. [30:01.380 --> 30:03.280] Here's the radio in encrypted mode. [30:03.640 --> 30:04.860] Here's the radio in clear mode. [30:04.980 --> 30:05.760] Encrypted mode. [30:05.940 --> 30:06.360] Clear mode. [30:06.480 --> 30:07.140] Encrypted mode. [30:08.060 --> 30:09.260] Go back to the picture. [30:09.340 --> 30:09.440] Yeah. [30:09.880 --> 30:12.280] So, if you'll notice in... [30:12.280 --> 30:18.940] By the way, Matt, I'm embarrassed to say that I can't remember at the moment if slash through the circle was encrypted or not. [30:18.980 --> 30:21.240] And I've been working on this with you for years now. [30:21.340 --> 30:21.460] Yeah. [30:22.120 --> 30:22.640] Yeah. [30:22.640 --> 30:31.060] So, it turns out the little switch with the slash with the circle means the metaphor is it's supposed to mean closed as opposed to open. [30:31.900 --> 30:33.160] And clearly that's... [30:33.160 --> 30:33.900] So, that just says hi. [30:34.320 --> 30:36.220] So, that means that you're in encrypted. [30:36.580 --> 30:36.820] Yeah. [30:37.360 --> 30:37.680] Okay. [30:37.840 --> 30:39.900] So, there's also this cumbersome keying model. [30:40.020 --> 30:40.260] One thing. [30:40.380 --> 30:42.260] Remember the picture of the soldier. [30:42.480 --> 30:43.780] The radio's right here. [30:43.900 --> 30:44.020] Yeah. [30:44.160 --> 30:45.220] You can't actually see... [30:45.220 --> 30:45.960] The picture of the secret service agent. [30:46.080 --> 30:46.900] The radio's right here. [30:47.060 --> 30:47.180] Right. [30:47.180 --> 30:48.180] How the hell are you going to know... [30:48.180 --> 30:50.740] Well, actually, secret service agents have eyes in the back of their heads. [30:50.740 --> 30:51.140] Oh, that's right. [30:51.380 --> 30:51.500] Sorry. [30:52.090 --> 30:53.480] But not down here. [30:53.640 --> 30:53.760] Yeah. [30:55.300 --> 30:55.700] Okay. [30:55.900 --> 31:01.020] So, there's this problem of cumbersome keying. [31:01.340 --> 31:04.920] If you do lose the key, you can't actually enter a new key by hand. [31:05.020 --> 31:09.760] Even though, you'll notice the radio has a keypad on it, you can't actually enter keys through the keypad. [31:10.800 --> 31:15.680] You have to use either this key variable loader device or the over the RE keying protocol. [31:15.680 --> 31:20.360] The over the RE keying protocol for a variety of reasons fails fairly frequently. [31:20.640 --> 31:27.080] And there's this belief in the federal sector that frequent re-keying is a really good idea for security. [31:27.280 --> 31:32.180] And so, they rigorously enforce this either weekly or monthly depending on the agency. [31:32.800 --> 31:42.200] And so, what that means is that every time there's a re-key, there's this period of instability in which everybody is forced to use clear because that's more secure. [31:42.900 --> 31:45.840] And so, it takes about a week to stabilize. [31:46.400 --> 31:48.120] Some agencies do it weekly. [31:48.300 --> 31:53.800] So, that gives you an idea of how often they're forced to use the clear mode. [31:55.300 --> 31:58.060] Once you're in the field, you can't do it. [31:58.180 --> 32:01.200] So, this is an example of the previous generation key loader hardware. [32:01.420 --> 32:03.140] The current generation one is actually worse. [32:03.140 --> 32:07.040] It's based on a little secure PDA and has a touch screen and you can't turn it off. [32:07.160 --> 32:08.200] So, the battery is always dead. [32:10.940 --> 32:17.320] And the policy generally involves keeping this in a safe at headquarters and not allowing it out into the field. [32:17.500 --> 32:17.980] So, if somebody... [32:17.980 --> 32:18.260] But it's really expensive. [32:18.260 --> 32:25.520] If at the beginning of an operation we discover that, oh, Bob doesn't have the key in his radio, everybody has to switch to the clear mode. [32:26.300 --> 32:26.700] So... [32:26.700 --> 32:26.860] Yeah. [32:27.020 --> 32:30.940] Well, the key loaders are really expensive and a group will only usually have one. [32:31.080 --> 32:31.180] Right. [32:31.500 --> 32:37.480] So, there isn't like they're carrying one around in the field and if there's 20 people in the middle of an operation that they can re-key. [32:37.800 --> 32:41.200] This is done back at base on all the radios at once. [32:41.200 --> 32:46.480] It's just such a shame that you could never write software to let you enter a key in on the keypad. [32:47.440 --> 32:49.620] It's 64 punches and if you miss... [32:49.620 --> 32:51.640] Turing proved that's impossible, right? [32:52.200 --> 32:52.360] Yeah. [32:52.360 --> 33:20.000] So, anyway, Bob Morris, who was a chief scientist at NSA for a while and prior to that at Bell Labs and notorious hacker, gave a talk while he was at NSA at Crypto 95 and we were all eagerly going there because he promised to reveal the NSA's secrets of cryptanalysis. [33:20.860 --> 33:29.300] Basically, his talk consisted largely of repeating rule one of cryptanalysis at the NSA, which was, first, look for clear text. [33:29.300 --> 33:33.560] And, you know, everybody was a little disappointed when Bob said that. [33:34.120 --> 33:37.400] But it occurred to us that maybe we should see if that works. [33:38.000 --> 33:42.020] So, we decided to build our own little low-budget NSA. [33:43.180 --> 33:54.440] And, you know, we found that, well, we don't want to do any active attacks to the federal government to find out how they react to things like jamming and so on. [33:54.580 --> 33:55.480] That would be unfriendly. [33:55.480 --> 34:00.340] But passive attacks, according to our lawyers, were perfectly fine to do. [34:02.260 --> 34:11.420] So, we built a little intercept system to find out how much unintended sensitive clear text is out there. [34:12.270 --> 34:21.130] And so, we got started with this because we accidentally configured one of the radios we were playing with and, you know, got the frequency wrong by like 10 megahertz. [34:21.130 --> 34:26.110] And, suddenly, we're hearing this reference to some surveillance operation going on in our neighborhood. [34:26.420 --> 34:27.750] And, yeah, be careful. [34:28.020 --> 34:29.440] We have a confidential informant here. [34:29.630 --> 34:33.400] But, so-and-so seems to have a gun and blah, blah, blah. [34:33.570 --> 34:36.550] And, ooh, this is like having our own private version of the wire. [34:36.750 --> 34:37.590] This is really interesting. [34:39.150 --> 34:42.210] And so, we were wondering, gee, how often does this happen? [34:42.210 --> 34:45.000] So, we decided to collect some statistics. [34:45.290 --> 34:54.210] And, what we did was we first found all of the frequencies in the bands used by the federal government specifically. [34:54.210 --> 34:58.550] We got rid of state and local agencies that have encrypted traffic on them. [34:58.630 --> 35:01.480] That are mostly consisting of encrypted traffic. [35:02.110 --> 35:13.090] And, then, we built an infrastructure to collect all the clear traffic that comes in on those frequencies, along with time stamps and all the metadata that we could collect. [35:13.320 --> 35:16.900] And, we used only commercial off-the-shelf equipment. [35:17.150 --> 35:18.630] You know, we had a low budget. [35:18.790 --> 35:22.290] And, part of the point was that you don't really need special equipment to do this. [35:22.290 --> 35:31.690] So, we found a software-controlled receiver called the Icom R2500 that has a P25 decoder in it for a variety of reasons. [35:31.820 --> 35:36.540] We were going to use GNU radio, but, for a variety of reasons, found that the performance of these is better. [35:36.710 --> 35:39.750] And, also, the difficulty of using them was lower. [35:39.920 --> 35:44.840] We wanted something that was within the realm of possibility of an actual adversary. [35:45.420 --> 35:55.170] Because, we wanted to see, well, you know, what would an actual criminal use today to do these, a passive attack, to find out who is putting you under surveillance. [35:55.500 --> 35:57.770] So, there are about 2,000 discrete frequencies. [35:57.980 --> 35:58.790] They're shared. [35:59.020 --> 36:02.190] So, in one place, the park service might use a frequency. [36:02.360 --> 36:04.360] Then, in another place, the FBI is using. [36:05.070 --> 36:10.420] So, we looked specifically for those frequencies that had mostly encrypted traffic on them. [36:11.170 --> 36:14.940] And, we basically installed this in a few cities. [36:15.070 --> 36:20.090] I can't tell you what cities they are, but you can use your imagination. [36:20.630 --> 36:24.730] And, I can't tell you what agencies we intercepted, except to say it's all of them. [36:27.150 --> 36:29.860] And, we let it run for a couple of years. [36:30.570 --> 36:30.820] So... [36:30.820 --> 36:31.650] Go on three years. [36:31.880 --> 36:32.110] Yeah. [36:32.250 --> 36:34.880] There was one weird exception, wasn't there? [36:34.960 --> 36:36.880] There is a weird exception, but I can't say they are. [36:37.040 --> 36:37.190] Yeah. [36:38.000 --> 36:42.340] But, yeah, there's an agency that you wouldn't think of that turns out to be really good at ComSec. [36:43.650 --> 36:44.230] And, yeah. [36:44.790 --> 36:44.860] Yeah. [36:44.860 --> 36:45.320] You want me to... [36:45.320 --> 36:45.750] Okay, yeah. [36:46.020 --> 36:46.190] So... [36:46.190 --> 36:48.520] Yeah, why don't you talk about what we found? [36:48.690 --> 36:51.460] So, mind you, we weren't looking at crypto at all. [36:51.550 --> 36:52.590] Can you see me over the microphone? [36:55.130 --> 36:55.500] Thanks. [36:56.040 --> 37:04.790] As far as we know, if they're using the AES crypto module, which is an option you can purchase, you can also purchase DES, or you can use the Motorola's proprietary crypto. [37:04.790 --> 37:06.940] And DES and proprietary crypto are broken. [37:07.400 --> 37:11.270] There was a paper at RuxCon in Australia where they did a nice example of breaking DES. [37:11.690 --> 37:15.820] But as long as they're using AES, the crypto's working, and so we didn't bother. [37:16.040 --> 37:21.520] We didn't have to, because they're not using the crypto correctly. [37:23.250 --> 37:29.880] And to find the frequencies that we wanted to listen on, you just scan and you look for crypto. [37:30.070 --> 37:33.650] And if you can't understand it, that's a channel that uses crypto, so monitor it. [37:35.460 --> 37:37.710] These are 2,500 radios. [37:38.070 --> 37:39.570] I think they were selling for, what, about 1,500? [37:39.570 --> 37:40.440] It's about a thousand bucks. [37:40.520 --> 37:40.650] Yeah. [37:41.070 --> 37:42.610] And they're a lot cheaper now. [37:44.960 --> 37:48.840] The programmable radios are getting to the point where they can do this quite well. [37:49.000 --> 37:52.380] But they weren't, for our needs, they weren't at the, two or three years ago. [37:52.630 --> 37:56.110] They didn't decrypt fast enough for us to use them. [37:57.020 --> 38:00.590] There was also a problem with the codec decoding the... [38:00.590 --> 38:04.000] Which I think is fixed now, because there's some really good work on that. [38:04.000 --> 38:06.000] So it's not exactly how you'd do it if you were going to do it today. [38:06.000 --> 38:06.460] Today, right. [38:06.630 --> 38:08.230] You can do it for cheaper than we did. [38:08.460 --> 38:08.920] That's what I'm saying. [38:08.960 --> 38:09.630] It's easier now. [38:10.790 --> 38:12.440] And what we're doing is live monitoring. [38:12.440 --> 38:20.730] So, we were picking up around 20 minutes a day from each of our listening posts of unintended clear text. [38:20.840 --> 38:24.400] And what I mean by unintended, I'll get to, but it essentially falls into three categories. [38:24.860 --> 38:28.960] And most of the time, in the first two categories, they think they're encrypted when they're not. [38:31.310 --> 38:39.150] After we published our paper at USENIX, and we went and we talked to a bunch of different agencies, and they said, yes, this is a real problem. [38:39.230 --> 38:40.170] Yes, we've got to deal with it. [38:40.210 --> 38:41.250] And they were really, really good. [38:41.440 --> 38:43.690] We started getting 30 minutes of clear text. [38:43.840 --> 38:45.320] So we're not sure what's going on. [38:47.650 --> 38:53.070] And by unintentional clear text, this is pretty sensitive information. [38:53.070 --> 38:55.230] And how sensitive information? [38:56.070 --> 38:57.460] Use your imaginations. [38:58.320 --> 39:08.610] Anything that goes on in any sort of investigation, any sort of operation, that you need to use encryption because you need to keep it confidential. [39:09.880 --> 39:11.290] That's the stuff that we're hearing. [39:12.170 --> 39:15.320] So, names, targets, addresses. [39:15.730 --> 39:22.130] And it's worth, you know, in the old days when everyone knew radio was insecure, they were much more circumspect about what they would say. [39:22.130 --> 39:28.150] But if you believe the radio is a secure channel, then you are much more free in what you say over it. [39:28.610 --> 39:28.730] Yeah. [39:29.050 --> 39:30.090] We know locations. [39:30.210 --> 39:31.460] We know directions they're moving in. [39:31.500 --> 39:32.420] We know what they're wearing. [39:32.540 --> 39:33.590] We know what the targets are wearing. [39:33.710 --> 39:36.050] We know whether or not they're wearing other devices. [39:36.270 --> 39:38.250] Whether or not there's a helicopter involved, et cetera. [39:38.500 --> 39:39.540] Pretty much anything. [39:42.520 --> 39:44.250] And this is kind of scary. [39:45.590 --> 39:48.440] So, we didn't know at first whether or not we should say anything about it. [39:49.130 --> 39:51.050] But our lawyers took care of that for us. [39:52.500 --> 39:57.900] And this is most of the stuff that we were picking up and listening to were criminal investigations. [39:58.650 --> 40:01.940] But there was some interesting national stuff too. [40:02.070 --> 40:04.790] And some counterintelligence stuff. [40:08.540 --> 40:11.670] As we listened to it, and mind you, this was... [40:11.670 --> 40:17.040] But when we wrote the paper, it was about two, almost two and a half years of monitoring this. [40:17.360 --> 40:23.150] We started building a taxonomy of it because we wanted to figure out what was going wrong and why and whose fault it was. [40:23.150 --> 40:28.550] And it turns out that the problems fall in one of three categories. [40:29.020 --> 40:33.170] Either one person is not encrypted and everybody else is. [40:34.610 --> 40:36.790] Everybody's not encrypted but they think they're encrypted. [40:37.650 --> 40:40.400] Or they can't get the encryption to work. [40:40.880 --> 40:47.940] And we could categorize this quite easily because if one person was not encrypted and everybody else was, you only heard one side of the conversation. [40:48.210 --> 40:53.360] You'd hear them responding to somebody and you wouldn't hear the rest because we didn't have the keys so we couldn't decode it. [40:54.850 --> 40:59.440] If everybody's in the clear, we were hearing things like, here's how you do the encryption. [40:59.590 --> 41:01.550] Turn your switch to the O. [41:02.630 --> 41:04.020] Or we'd hear people... [41:04.020 --> 41:06.710] Which is wrong, by the way, for anybody using one of these radios. [41:07.250 --> 41:10.750] We'd hear people give instructions on how to do over-the-air re-keying. [41:11.440 --> 41:14.980] And now they'd say, okay, everybody got the new keys, great, now we're encrypted. [41:15.750 --> 41:16.610] So, and... [41:19.250 --> 41:26.210] And of our, you know, 20 to 30 minutes a day, we were hearing about 10 minutes of the first and 10 minutes of the second. [41:26.500 --> 41:34.290] And the last, the key failure, this particularly happened in those regularly scheduled over-the-air re-keying. [41:34.290 --> 41:38.770] And then what you would hear is, and this is a direct quote, f*ck the radios go in the clear. [41:41.500 --> 41:43.500] So, and it was pretty evenly split. [41:44.460 --> 41:48.090] Now, I want to say, these people are professionals. [41:48.480 --> 41:50.380] They are really good at their jobs. [41:50.540 --> 41:55.690] And all of the things that I listened to, I developed an incredible respect for them and the work that they're doing. [41:56.170 --> 41:58.250] But they can't get these tools to work. [41:59.050 --> 42:01.340] Now, I drive a car every day. [42:01.550 --> 42:03.730] I have to use it as part of my job. [42:03.730 --> 42:08.020] I'm not a professional mechanic, but I can drive a car safely. [42:08.270 --> 42:15.050] You shouldn't have to be a Motorola radio developer in order to be able to operate these radios properly. [42:18.700 --> 42:23.230] So, the radios are used all over. [42:23.840 --> 42:32.230] Every three-letter and spooky agency, police departments, the park service, everybody uses these. [42:32.230 --> 42:48.480] They were, the development of them and the adoption of them was sped up specifically after 9-11 in order to get agencies to be able to communicate with each other quickly, easily, and as they need it. [42:48.540 --> 42:49.690] The Red Cross uses these. [42:51.520 --> 42:53.150] But they can't use them effectively. [42:56.420 --> 42:58.590] We shouldn't be hearing the things that we're hearing. [42:58.880 --> 43:02.730] We shouldn't be hearing them no matter where we are in the country. [43:03.650 --> 43:05.050] And we are hearing them. [43:06.940 --> 43:14.210] And of the two causes, one of them is unfixable, really. [43:14.360 --> 43:17.020] The keying failure is not a usability problem. [43:17.110 --> 43:18.130] It's not a user issue. [43:24.770 --> 43:30.590] Those are things that we're going to have to go back to the system and redesign from scratch in order to fix. [43:30.980 --> 43:37.320] The accidental clear text is part user, part usability. [43:38.590 --> 43:44.440] The design of the radios is such, as Perry said, you know, it's hard to remember what this does if you don't use it frequently. [43:44.440 --> 43:48.400] The radios, every single button and switch on this is programmable. [43:48.980 --> 43:50.430] Most of the buttons and switches are overloaded. [43:51.200 --> 43:55.680] There are little flashing lights, for example, that will tell you maybe you're encrypted, maybe you're not. [43:55.770 --> 43:57.520] But the flashing light also means something else. [43:57.750 --> 44:00.340] There's a little beep that will tell you maybe you're encrypted, maybe you're not. [44:00.420 --> 44:01.680] But that also has another use. [44:02.000 --> 44:11.540] And so they're incredibly complicated that it's almost impossible to use correctly at the right time. [44:11.540 --> 44:13.580] And I argue that that's not a user problem. [44:13.580 --> 44:19.200] And even if it were a user problem, I'd argue that we can't fix the users, so you have to fix the usability. [44:21.980 --> 44:23.270] Anyway, I'm going to hand this back to Matt. [44:23.620 --> 44:26.700] So, I just want to spend a second using this. [44:29.140 --> 44:36.770] Before we published this, we wanted to help the users of this, you know, fix the problems. [44:36.940 --> 44:40.820] We worried that, you know, as a result of publishing, which we have to do. [44:41.000 --> 44:42.730] We're academics, we publish findings. [44:42.730 --> 44:45.100] We're required by our funding agencies to do that. [44:45.200 --> 44:49.080] But we didn't actually want to, you know, cause harm. [44:49.230 --> 45:00.580] And one of the things we were worried about was that, you know, in pointing out this problem, we'd be encouraging actual criminals, you know, real bad people that, you know, do belong locked up to, you know, do better counter surveillance. [45:01.360 --> 45:12.520] And so we, you know, well in advance of publication, very politely approached the federal government and, you know, pointed out some of the problems. [45:12.640 --> 45:17.200] And we were a little bit worried that they would decide that we were the problem rather than the radios. [45:17.320 --> 45:20.320] But it turns out that they, that it was extremely well received. [45:20.460 --> 45:26.640] The people in the federal agencies responsible for security, it turns out, are just like us. [45:26.860 --> 45:31.400] They understand that, you know, discovering a problem is not the same as causing a problem. [45:31.710 --> 45:41.660] And so, you know, initially we were, we were quite encouraged by the fact that we were talking to people who really wanted to work with us to develop mitigations. [45:42.100 --> 45:51.270] And, you know, we made a bunch of suggestions, which we don't really have time to go in to hear of short term things you can do to mitigate the passive attacks. [45:51.420 --> 46:01.920] The active attacks will require a protocol redesign, but the passive attacks, which are the real immediate threat, you know, we, there are some things that you can do. [46:02.140 --> 46:08.340] So the, the first thing is that, you know, they didn't, you know, try to arrest us or anything crazy like that. [46:09.060 --> 46:13.730] But we kept our statistics gathering about how much clear text is going on. [46:14.400 --> 46:25.600] And what we found was that for about a week after we talked to any given agency in the cities that we were monitoring, the amount of accidental clear text would go down. [46:25.770 --> 46:31.620] And in fact, we capture audio of things like everybody, you got to pay more attention and switch to the encrypted mode. [46:32.380 --> 46:35.020] You know, and so we're thinking, okay, great. [46:35.160 --> 46:35.770] Maybe they're getting us. [46:35.900 --> 46:37.640] But then it would ramp back up. [46:38.000 --> 46:40.060] And then it would exceed where it was before. [46:40.200 --> 46:47.730] So we went from about 20 minutes of sensitive clear text to about 30 minutes within about a month after talking to any given agency. [46:47.880 --> 46:52.120] So it seems that the act of paying attention to the problem makes it worse. [46:53.020 --> 46:54.620] And we don't, we don't know why. [46:54.750 --> 46:56.770] I mean, I can conjecture why that might be. [46:56.880 --> 47:03.840] One reason that it might be is that, you know, you realize that you have to do something, but you don't remember what it is after a while. [47:04.020 --> 47:07.900] And you fiddle with the switch more often or something along those lines. [47:08.040 --> 47:14.400] But there's some very interesting usability and user experience phenomenon going on that's worth exploring. [47:15.360 --> 47:28.270] We also talked to the standards and vendor community, which was not nearly as, as well behaved as the federal government. [47:28.440 --> 47:40.960] It turns out if you, if you're going to poke your finger in the eye and you have a choice of doing it to like federal law enforcement agencies or standards bodies, the federal law enforcement agencies will be much more respect, receptive to you. [47:41.420 --> 47:57.980] So back when I did the voting machine research, which I, we talked about at HOPE, I made up a security excuse bingo for the responses from different vendors, you know, with responses like, oh, you're just talking theoretical mumbo jumbo, and we already knew about it, [47:58.000 --> 48:06.540] or you're just academics, you don't understand real security, or, you know, hey, our proprietary encryption algorithms prevent this sort of thing from happening. [48:06.840 --> 48:12.560] And we take security very seriously, which actually means we don't take security very seriously. [48:13.250 --> 48:17.560] And this is on my website, you can just click on it, you get a new board each time. [48:17.730 --> 48:24.820] So it turns out that the vendors of the P25 radio seem to use this as their script generator for responses. [48:26.420 --> 48:30.940] We got things like, well, you guys aren't radio engineers, you don't understand decibels. [48:31.770 --> 48:41.200] And the frequent problem response, I think you got a response from a vendor we won't name, because we're polite people. [48:42.660 --> 48:49.340] But where they said to you, well, this isn't a problem with the radios, it's a problem with our users. [48:49.660 --> 48:52.960] So, yeah, it's a problem with our users. [48:53.140 --> 48:58.700] So, you know, and that makes me wonder, so you're actually saying that your users are too stupid to use your products? [48:59.270 --> 49:00.770] That's an interesting... [49:01.270 --> 49:02.560] It's a good marketing strategy. [49:02.560 --> 49:03.840] It's a good marketing strategy, yes. [49:07.120 --> 49:16.480] So, you know, this appears to be, you know, fixing the standard appears to be a much more difficult and long-term process. [49:16.660 --> 49:20.360] So, in the meantime, we have some mitigations that we've suggested. [49:21.250 --> 49:24.120] You know, we don't have time to go over them here. [49:24.620 --> 49:28.340] But there are, you know, things like don't re-key more frequently. [49:29.320 --> 49:30.270] Configure the radios. [49:30.270 --> 49:48.040] There are ways to force the radios to be configured in a kind of nonstandard way that prevents Clear from interoperating with encryption in the way that they normally do that leads to these usability failures and gives you a little bit better feedback. [49:48.340 --> 49:51.920] But it's not obvious how to do it, so we've got some suggestions about how to do it. [49:52.080 --> 49:57.710] So, if any of you have P25 systems, I'd encourage you to go to www.crypto.com slash P25. [49:57.710 --> 50:02.270] You can get some of our mitigation strategies there. [50:02.420 --> 50:06.770] And I think with that, we have maybe four and a half minutes for questions left. [50:07.960 --> 50:09.100] And go to the microphone. [50:09.250 --> 50:10.140] Not this microphone. [50:10.140 --> 50:14.770] So, one of the problems with the mitigations, though, is that it requires that you do it on each individual radio. [50:15.000 --> 50:26.980] And this can't be done en masse, which means that for some groups, like one particular one we talked to that had 15,000 radios on one area, they're going to have to do it to every single radio. [50:28.200 --> 50:28.460] Okay. [50:28.580 --> 50:29.520] So, I can't see anyone. [50:29.660 --> 50:30.920] So, if there's someone at the microphone... [50:30.920 --> 50:31.320] There is. [50:31.500 --> 50:31.790] Feel free to... [50:31.790 --> 50:32.560] We're at the mic. [50:32.580 --> 50:33.230] We're at the mic. [50:34.550 --> 50:38.620] So, you mentioned, so, you've developed all this cool software to do all this traffic analysis. [50:39.600 --> 50:41.730] Are there software releases of this? [50:41.880 --> 50:44.900] Can we use our new radios and the $35 dongles? [50:45.730 --> 50:53.680] Well, again, we're using software-controlled radios, not the SDR platforms, because when we started developing, that was what would work. [50:54.360 --> 51:02.320] We've not yet released our version of the software to control the icons, but we are absolutely planning on doing it. [51:02.380 --> 51:05.600] We're not releasing it yet, because we're too embarrassed to release it right now. [51:06.270 --> 51:06.290] Yes. [51:06.290 --> 51:07.880] It's my code, and it's crappy. [51:08.020 --> 51:08.060] Yeah. [51:08.580 --> 51:09.580] So, blame Carrie. [51:09.960 --> 51:13.540] But we are planning on sharing that. [51:13.660 --> 51:21.860] What we're not going to share, and actually our IRB requirements prevent us from sharing, and it puts us in an odd situation, is any of the data we've actually collected. [51:22.400 --> 51:23.400] And, you know, it's weird. [51:23.560 --> 51:41.700] We can't... If we find out that somebody is going out in the clear, we're actually prohibited by our university IRB rules from telling that agency about a specific agent who's making a mistake, because they might be punished, and we're not allowed to do things that might harm an end user. [51:41.700 --> 51:45.840] So, it's a real... We're in kind of a very difficult situation with data. [51:45.980 --> 51:47.540] And we also won't give you the frequencies. [51:48.340 --> 51:48.750] That's fine. [51:48.920 --> 51:49.040] Right. [51:49.120 --> 51:49.710] But you can find them. [51:52.940 --> 51:58.080] I'm new to this, but you said that there's no concept of a session with these radios. [51:58.210 --> 52:02.840] But then you also said that you could ping a radio controller and it would respond back. [52:02.980 --> 52:03.770] So, is that... [52:03.770 --> 52:03.770] Right. [52:03.960 --> 52:09.160] So, yeah, I should say, there are no sessions with the voice service, but there's a data service that does have sessions. [52:09.160 --> 52:10.660] And is that like a one-to-one thing? [52:10.840 --> 52:11.060] Yeah. [52:11.140 --> 52:12.540] The data service is a one-to-one. [52:12.540 --> 52:13.230] If you... [52:13.230 --> 52:21.960] The data service has interesting features like it will reply requesting retransmits of malformed packets in certain circumstances. [52:22.230 --> 52:22.820] There's actually... [52:22.820 --> 52:27.880] I think there's a bit you set saying whether or not the data is supposed to be reliably transmitted. [52:28.320 --> 52:28.540] Okay. [52:29.710 --> 52:32.640] It's not interesting unless you really want to dive into it. [52:32.730 --> 52:33.880] But suffice it to say, it's straightforward. [52:34.270 --> 52:34.840] Thank you. [52:34.840 --> 52:38.000] Can you talk to us sometime about one-way crypto protocols versus two-way? [52:38.180 --> 52:40.600] Because it's an interesting problem and we don't sure it's solved. [52:40.730 --> 52:41.160] Next time. [52:41.440 --> 52:41.620] Yeah. [52:42.420 --> 52:43.160] So, quick question. [52:43.880 --> 52:44.940] Two minutes, I'll make it quick. [52:45.100 --> 52:45.640] We're number two. [52:45.840 --> 52:45.920] Yes. [52:46.320 --> 52:46.420] Okay. [52:47.860 --> 52:50.320] Mouse, do you know Narfi in local city? [52:50.730 --> 52:51.440] No, I don't think so. [52:51.440 --> 52:52.100] Can you introduce me? [52:52.230 --> 52:53.290] Yeah, I'll introduce you. [52:53.500 --> 52:55.790] He has talked to me about P25 radios. [52:55.900 --> 53:01.620] He apparently has an algorithm on EC2 built on Amazon that he pulls the key in and decrypts it in about three hours. [53:01.790 --> 53:01.900] Right. [53:01.900 --> 53:03.860] Yeah, that's for the DES keys. [53:04.210 --> 53:06.290] No, I think he said it wasn't just the DES keys. [53:06.520 --> 53:07.500] Yeah, I... [53:07.500 --> 53:08.880] So, I'll talk to you about it. [53:09.230 --> 53:11.600] But I don't remember exactly which ones he said. [53:11.840 --> 53:14.320] But he said he has the DES and he has the other ones as well. [53:14.520 --> 53:17.840] Yeah, if he's breaking AES, then he gets a Nobel Prize in photography. [53:17.920 --> 53:20.360] He said it wasn't AES that he was breaking. [53:20.360 --> 53:24.730] There was a flaw in the adaptation of it for the P25 radios. [53:25.480 --> 53:26.600] Why am I not surprised? [53:27.120 --> 53:27.700] Yeah, we've got to talk. [53:28.160 --> 53:29.160] Just two quick comments. [53:29.160 --> 53:33.320] First of all, the IMMEs are getting exceedingly rare on eBay and Amazon. [53:34.160 --> 53:36.140] So, if you want one of those, jump on it now. [53:36.860 --> 53:41.230] And we're going to need to find a new CC1110 platform to play with. [53:41.380 --> 53:50.440] And second thing, if any of you want a good FET but don't want to do all the surface mount soldering, I personally sell the good FETs pre-assembled for you. [53:50.440 --> 53:53.400] I am Kenneth Finnegan at thelifeofkenneth.com. [53:53.640 --> 53:54.790] So, just search for the life of Kenneth. [53:54.790 --> 53:56.660] And then all you need is the TI chip. [53:56.940 --> 53:57.820] And you've got what you need. [53:58.100 --> 54:03.230] And actually, you're better off, if you're really serious, get the development kit for the CC11. [54:03.230 --> 54:04.230] Right, it's much easier. [54:04.380 --> 54:04.730] Yeah. [54:04.880 --> 54:06.620] How secure is the over the air rekeying? [54:07.680 --> 54:10.770] So, we're doing some stuff with that now. [54:11.480 --> 54:14.020] I mean, you know, the short answer is take a guess. [54:14.500 --> 54:15.100] Okay, then. [54:15.160 --> 54:17.790] So, I have two questions on that, kind of to break it out. [54:18.460 --> 54:21.420] Can you intercept it and grab their keys when they rekey? [54:21.600 --> 54:21.820] No. [54:21.820 --> 54:23.440] No, but it's... [54:23.440 --> 54:26.580] Well, you can hear the over the air traffic. [54:27.080 --> 54:27.250] Yeah. [54:27.500 --> 54:29.810] What you can do with that is an interesting question. [54:30.540 --> 54:30.680] Yeah. [54:31.200 --> 54:32.360] Expect another paper. [54:32.420 --> 54:33.750] Can you force rekeying? [54:33.860 --> 54:34.120] Yes. [54:37.410 --> 54:37.750] Yes. [54:37.750 --> 54:37.880] Yeah. [54:38.020 --> 54:38.360] Yeah. [54:38.900 --> 54:39.770] Yes, it's broken. [54:40.160 --> 54:40.500] Yeah. [54:41.210 --> 54:41.480] Okay. [54:41.820 --> 54:42.710] Stop and thanks. [54:42.710 --> 54:43.360] Sorry, we're out of time. [54:43.440 --> 54:43.500] Thank you.