[00:18.960 --> 00:20.280] Oh, there it is. [00:23.200 --> 00:24.440] It keeps moving. [00:38.040 --> 00:39.040] That's what we can do. [00:39.260 --> 00:41.820] No, we can't stand up. [00:42.080 --> 00:42.840] We can't stand up. [00:43.820 --> 00:45.100] We can't stand up. [01:02.030 --> 01:03.470] We stand up a little bit. [01:12.760 --> 01:13.760] We're actually... [01:15.480 --> 01:17.620] Actually, we can just describe it from here. [01:18.000 --> 01:19.400] It pretty much matches what's up there. [01:19.760 --> 01:19.980] Yeah. [01:20.940 --> 01:21.500] Okay, cool. [01:21.700 --> 01:22.760] With minor variation. [01:23.460 --> 01:25.280] Maybe you can just look at it until this. [01:26.060 --> 01:27.200] Oh, but you can just look at this. [01:27.340 --> 01:29.540] It's all the same acronyms and it's connected to what? [01:29.780 --> 01:31.140] I can just describe it off here. [01:31.420 --> 01:32.400] What software do you have? [01:32.800 --> 01:33.160] Which? [01:34.180 --> 01:35.300] What's the place in software? [01:36.200 --> 01:36.920] On switches? [01:37.280 --> 01:37.380] Yeah. [01:37.860 --> 01:38.820] There's two main ones there. [01:39.620 --> 01:44.840] You start Nortel, DMS, and Ericsson, AXE. [01:45.920 --> 01:50.800] Okay, we have Nortel, DMS. [01:50.900 --> 01:52.340] Yeah, they used the Nortel as a lot. [01:58.270 --> 01:59.810] They had three MSCs. [02:00.030 --> 02:01.310] Two Nortels and one Ericsson. [02:01.730 --> 02:02.630] And one HLR. [02:16.420 --> 02:20.520] Well, if somebody gave me a cell I could write on, it wouldn't be a problem. [02:30.710 --> 02:31.790] That's clear enough. [02:37.310 --> 02:38.190] Hey! [02:40.620 --> 02:41.500] Unbelievable. [02:49.250 --> 02:50.350] We ready? [02:51.330 --> 02:52.390] We're going. [02:53.270 --> 02:53.650] Okay. [02:54.050 --> 02:56.430] This is the GSM panel. [02:56.790 --> 02:57.690] I'm Phiber. [02:57.910 --> 02:58.470] This is Tom. [02:59.910 --> 03:00.790] Hi. [03:04.920 --> 03:12.200] And tonight we'll be talking about the new global system for mobile communications. [03:12.820 --> 03:13.300] Yes. [03:14.340 --> 03:14.820] Exactly. [03:18.040 --> 03:25.320] Anyway, how many of you have actually read my article on the latest issue with 2600 already? [03:26.140 --> 03:26.620] Yes. [03:27.580 --> 03:29.060] Okay, you can go now. [03:32.930 --> 03:45.190] What I'm going to do, or what me and Tom are going to do, is go over some of the basic stuff, little background information, recap some of the stuff I mentioned in the article, then we'll take it from there. [03:46.230 --> 03:50.590] Provide more detail for any particular thing that anybody might be interested in. [03:51.270 --> 03:52.950] We'll take some questions. [03:53.390 --> 04:02.330] We'll probably start taking questions early on because I know I hate listening to myself talk for too long a period of time without somebody else saying something. [04:03.070 --> 04:05.330] So why don't we start off? [04:05.550 --> 04:05.950] Okay. [04:07.470 --> 04:10.030] We threw this diagram up there. [04:10.250 --> 04:14.750] It's similar to the diagram that we have in 2600. [04:14.910 --> 04:16.110] I simplified it a bit. [04:26.670 --> 04:27.270] GSM. [04:27.490 --> 04:27.650] Yep. [04:27.850 --> 04:28.490] That's it. [04:28.690 --> 04:33.250] This is basically the network diagram of GSM. [04:34.010 --> 04:39.710] And what I'll do is we'll start from the left and work our way over to the right. [04:40.930 --> 04:47.970] Now, starting from the left, we have the mobile equipment, which is a handset. [04:48.590 --> 04:54.350] And inside the mobile equipment is a subscriber identity module. [04:54.990 --> 04:56.130] And I'll show that to you. [04:59.270 --> 05:00.650] It's a little smart card. [05:01.310 --> 05:06.390] Some of them are this little plug-in size and some of them are a full credit card size. [05:07.470 --> 05:12.910] For the phones that take the full credit card size, you can insert the smaller one into a plug-in adapter. [05:13.430 --> 05:13.950] Anyway. [05:15.510 --> 05:16.490] Hey, what happened? [05:24.650 --> 05:25.370] Oh, okay. [05:32.550 --> 05:33.610] Hey, there we go. [05:34.050 --> 05:34.230] Okay. [05:34.990 --> 05:35.870] Here's my SIM. [05:36.090 --> 05:37.030] Here's Tom's SIM. [05:37.210 --> 05:38.530] See, they're pretty much the same. [05:39.010 --> 05:40.150] They're both made. [05:40.270 --> 05:44.330] Well, actually, they're not both made by the same company, but they're SIMs. [05:44.610 --> 05:45.050] Just the same. [05:48.110 --> 06:01.930] Now, when you make a call with your handset, your mobile equipment, you go over the airwaves to the nearest cell site, which in the GSM nomenclature is known as a base transceiver station. [06:02.230 --> 06:02.970] And that's your BTS. [06:03.610 --> 06:10.050] Now, BTSs are normally located in apartment buildings, usually on the roofs of apartment buildings. [06:10.350 --> 06:21.950] And the BTSs are connected over lease lines, T1s, for example, to the nearest base station controller, the BSC. [06:22.830 --> 06:36.290] BSC is basically a means of doing diagnostics, making sure all the cells in a particular area are functioning properly, and all these tests can be done remotely. [06:36.610 --> 06:46.090] Now, the BSCs connect to the mobile switching center, the MSC, which, you know, better known as the switch. [06:46.910 --> 06:58.330] And the way it basically all ties together is that the MSC, the mobile switching center, accesses two really important databases. [06:59.250 --> 07:09.110] The first being the HLR, which is the home location register, the HLR is more or less a switch in its own right. [07:09.590 --> 07:16.870] It actually contains all the information about all the subscribers that are valid for that particular network. [07:17.350 --> 07:23.930] For example, whether it be Omnipoint or Sprint Spectrum or Pacific Bell Mobile and so on and so forth. [07:24.310 --> 07:28.890] All the subscribers information is stored in the HLR. [07:29.150 --> 07:35.210] And by information, I mean the secret information that is also stored on the SIM cards. [07:35.870 --> 07:40.850] There are two pieces of information that uniquely identify a subscriber. [07:41.790 --> 07:49.030] One of them is the International Mobile Subscriber Identifier, better known as the IMSI. [07:49.430 --> 07:59.690] And also stored on the SIM and in the HLR is the KI or the K sub I, which is a unique randomly generated number. [08:00.510 --> 08:09.310] And these two things together uniquely identify the subscriber to the GSM network and also play a major role in authenticating that person. [08:09.930 --> 08:23.570] And if we wanted to make a comparison briefly, just to digress a little bit, let's track mobile communications throughout the past few couple of decades in the United States. [08:24.130 --> 08:29.030] Originally, we started out with the mobile telephone system, MTS. [08:29.630 --> 08:33.490] And one of the companies that pioneered that technology was Motorola. [08:35.270 --> 08:38.130] After MTS came IMTS. [08:38.650 --> 08:42.170] And IMTS is the improved mobile telephone system. [08:43.330 --> 08:48.350] After that, they came out with AMPS, the advanced mobile phone system. [08:48.870 --> 08:50.830] So it's getting kind of redundant. [08:51.250 --> 09:03.790] But anyway, AMPS is the one that everyone's used to as being the relatively shitty analog cellular network that's extremely easy to clone and eavesdrop and so on and so forth. [09:04.990 --> 09:09.910] After AMPS came D-AMPS, which is digital AMPS. [09:10.070 --> 09:14.210] And there are actually two flavors of digital AMPS, which I'll get into shortly. [09:15.770 --> 09:23.470] And after that came the two dueling standards, CDMA and GSM. [09:25.550 --> 09:35.310] Now, why don't I familiarize you with PCS, since that's really the buzzword that has a lot to do with GSM and CDMA. [09:35.490 --> 09:39.110] And no doubt you're seeing it on television commercials all the time. [09:39.370 --> 09:48.310] So you're probably wondering, and I'm sure you've also heard us talk about it on the radio show, those of you who have heard the PCS-related shows that me and Emmanuel have done. [09:51.290 --> 09:57.450] A lot of the mobile phone manufacturers are trying to confuse you. [09:57.970 --> 10:00.710] Because nobody really knows what PCS is. [10:01.270 --> 10:09.010] At least the general populace, the guy who's sitting at home on his couch, sipping a beer and watching a football game. [10:09.270 --> 10:16.350] So you see commercials from AT&T PCS and, you know, and Sprint PCS and so on and so forth. [10:17.370 --> 10:23.510] The fact of the matter is, PCS, as far as the FCC is concerned, is a very specific thing. [10:24.350 --> 10:31.390] PCS in North America is the 1900 megahertz band or 1.9 gigahertz. [10:33.630 --> 10:36.110] Which you can see by the blue screen. [10:36.650 --> 10:42.770] But anyway, PCS stands for personal communication services. [10:44.050 --> 11:02.530] And one of the main features of PCS are things like these neat-o-keen little handsets and personal digital assistants and things like that that are supposed to connect to a wireless network, a digital wireless network, relatively securely. [11:04.730 --> 11:29.700] Anyway, getting back to PCS and what it's supposed to do, the best way to illustrate all the different protocols that people are touting as PCS is we can reflect on what you've been seeing on television. [11:30.540 --> 11:33.060] Let's take as a prime example, Sprint PCS. [11:33.340 --> 11:34.380] Now, what does that mean? [11:35.220 --> 11:42.360] Well, Sprint PCS, contrary to popular belief, is not GSM. [11:42.500 --> 11:44.200] It has absolutely nothing to do with GSM. [11:44.840 --> 11:50.840] It does use the 1900 megahertz band, but it doesn't have to. [11:52.020 --> 11:57.140] In fact, Sprint is calling all of their new cellular service PCS. [11:57.520 --> 11:58.020] Why? [11:58.240 --> 11:59.060] Because they're stupid. [11:59.380 --> 12:01.340] That's the best reason I could come up with. [12:04.840 --> 12:10.900] The part of Sprint PCS that actually is PCS is twofold. [12:12.720 --> 12:28.640] Two algorithms that they are using are CDMA, which is code division multiple access, which is an algorithm that has been used by the military for decades and was adapted for use by consumers. [12:29.400 --> 12:44.900] And the other is TDMA, or rather what's known as IS 136, which IS stands for interim standards, something that's not actually a standard yet, but kind of is a standard. [12:45.060 --> 12:50.840] It's kind of like on the internet when you say request for comments, when you say refer to RFC, whatever. [12:51.500 --> 12:57.920] It's like request for comments, but, you know, the comments are over and done with because the RFC is 20 years old. [12:58.220 --> 13:00.160] I don't think anybody is really commenting on it anymore. [13:00.700 --> 13:14.460] Anyway, TDMA, or the newer version of digital amps is one of the other protocols that Sprint PCS uses in the absence of the availability of CDMA. [13:15.200 --> 13:21.600] CDMA is an available in all too many places throughout the country, whereas digital amps is. [13:22.480 --> 13:41.260] In the case of GSM, which is relatively new in North America, all the GSM providers, Sprint Spectrum, which has nothing to do with Sprint PCS, Omnipoint, Pacific Bell Mobile, West Cell, and a myriad of other companies. [13:42.180 --> 13:49.820] These companies have banded together into a consortium, the North American GSM consortium. [13:50.320 --> 13:59.800] They basically decided that they're not going to step on other people's feet and that if Omnipoint is going to provide GSM service in New York City, so be it. [14:00.060 --> 14:02.000] Sprint Spectrum is not going to give them a hard time. [14:02.380 --> 14:07.320] Sprint Spectrum is going to stay in the Virginia and Baltimore and D.C. [14:07.540 --> 14:10.340] area and they're going to do their own thing. [14:10.760 --> 14:20.700] So in a way, the GSM companies have inadvertently created a monopoly on the areas that they cover, which is both good and bad. [14:21.480 --> 14:30.000] The good part, obviously, is that you know that all the GSM companies in North America have roaming agreements with each other. [14:30.440 --> 14:38.240] If I want to use my Omnipoint phone in Baltimore, I know it's going to work because Omnipoint and Sprint Spectrum have an agreement. [14:39.600 --> 14:42.740] However, the obvious downside to that is pricing. [14:43.440 --> 14:57.100] Since there are no other GSM companies in this area, then Omnipoint is kind of free to set their rates to whatever they want to, subject to however they want to compete with the other existing companies and protocols and so on. [14:57.700 --> 15:00.120] Tom, you can feel free to just bust in at any time. [15:00.840 --> 15:00.940] Okay. [15:03.060 --> 15:05.000] Things run slightly different in the UK. [15:05.940 --> 15:09.240] Our GSM networks completely run on 900 megahertz. [15:09.760 --> 15:14.960] The old tax network, which is the analog in the UK, running on 800, much the same as over here. [15:15.580 --> 15:26.060] But we have a system called PCN, which is personal communications network, which is our equivalent to PCS, which is running at 1800 megahertz. [15:26.980 --> 15:27.500] So... [15:46.340 --> 15:50.160] The obvious... Obviously this was due to the forward looking of the FCC. [15:51.560 --> 15:55.260] Why not make it 1800 megahertz like it is in Europe? [15:55.500 --> 15:57.480] I don't know, because we're going to make it 90,000. [15:57.480 --> 15:57.840] You're going to make it 900. [15:58.500 --> 16:01.780] So basically our handsets are totally incompatible. [16:02.260 --> 16:05.820] Currently there are no GSM handsets that work in both the U.S. [16:06.240 --> 16:10.320] and Europe and the rest of the world because of that fact. [16:10.560 --> 16:10.660] Motorola. [16:10.660 --> 16:13.320] Yeah, Motorola seem to be working on that fact at the moment. [16:13.700 --> 16:20.660] They're hoping to release something in the next few weeks, they're telling me, but I can't see that happening in the near future. [16:24.120 --> 16:30.560] With the old analog systems in the UK, they've actually found a way of defeating the cloning now. [16:30.920 --> 16:45.160] With Vodafone they've brought out a new thing called tax authentic verification, which is a form of a 10-digit code which is sent out when a call... when a cell talks to a cell site. [16:45.760 --> 16:47.780] And that code changes every time. [16:48.040 --> 16:57.180] And if the code is not the correct with the ESN and min transmitted, then it will actually bar the phone from the network until you've contacted your service provider. [16:58.280 --> 17:00.520] Cellnet haven't actually come up with anything yet. [17:01.220 --> 17:07.520] And we're looking at knocking out the analog system in the year 2004 in the UK. [17:08.440 --> 17:10.980] So they don't see much point in doing that. [17:11.740 --> 17:14.480] It's really considered petty crime in the UK. [17:14.760 --> 17:16.320] It's not a big market. [17:16.640 --> 17:23.060] It was a few years back, but they seem to detect cloning within a day or two now. [17:23.320 --> 17:24.460] So it's really stupid. [17:26.600 --> 17:30.900] With the GSM, they're bringing out new stuff now. [17:31.680 --> 17:37.340] The PCN network 1 to 1 and Orange, which are the two main PCN provided in the UK. [17:37.940 --> 17:45.860] 1 to 1 have just released the new Motorola 88,000 International, which can roam between GSM and PCN. [17:46.220 --> 17:52.060] So you can take your phone, your PCN phone to most of the countries in Europe and the surrounding areas. [17:54.100 --> 18:03.800] Orange haven't actually released that yet, but they have quite a few roaming agreements with foreign GSM countries and connections across the world. [18:06.740 --> 18:09.140] Who do Omnipoint roam with in the UK? [18:10.180 --> 18:14.120] Omnipoint, I believe, is roaming with Vodafone, if I'm not mistaken. [18:14.820 --> 18:21.600] And when we say roaming, you're probably wondering, well, I thought you just said that you can't take your handset there and vice versa. [18:21.760 --> 18:22.360] Well, you're right. [18:23.100 --> 18:33.260] The cool thing about it is that since all your subscriber information is stored on the little SIM card, you could take your SIM card with you and stick it in a phone in Europe and it'll work. [18:33.840 --> 18:49.080] What you could also do if your local provider supports it, which Omnipoint does as an example, you can rent a foreign phone from them and stick your card in it and bring it with you to Europe so you don't have to worry about getting a handset when you're there, [18:49.460 --> 18:50.680] which is a great idea. [18:51.040 --> 19:01.000] Until one of the major companies like Nokia or Ericsson comes out with a dual mode handset that does both the European and the American GSM. [19:02.340 --> 19:09.160] In the UK, if we want to buy a roaming phone to use over here, the best people to go to at the moment are CellNet. [19:09.440 --> 19:26.040] If we approach CellNet with that, what they actually do is they sell you an old analog phone which is compatible in the US and they sell you a GSM phone which is compatible in the UK and you have to buy both handsets and it's stupidly, ridiculously priced. [19:27.260 --> 19:42.680] I don't actually have any pricing but just the GSM model in its own is about 250 pounds for the Ericsson G8 388 and you get, I'm not actually certain, what analog Ericssons do you have over here? [19:43.720 --> 19:49.120] Oh, the, I think, I'm pretty sure they have the 318 I think is an analog Ericsson. [19:50.200 --> 19:51.780] I don't remember off the top of my head. [19:51.980 --> 19:53.480] Yeah, well they sell you one of those as well. [19:54.260 --> 20:00.660] And then you use the, you have to inform them 28 days before you come into the States and then they activate your analog. [20:01.720 --> 20:12.600] But they charge, I think it was roughly 2.45 for incoming calls on the, that's UK pounds for incoming calls on the analog. [20:14.160 --> 20:16.780] I don't know, can you actually hire phones over here? [20:17.760 --> 20:36.920] The funny thing that I've noticed is that while GSM's been around a lot longer in Europe, especially in England, there's, there's a lot more accessories and doodads and things available that in general the equipment is a hell of a lot more expensive. [20:37.320 --> 20:39.120] And I can't really figure out why. [20:39.340 --> 20:42.360] You can get these GSM Ericsson phones now for 50 bucks. [20:43.060 --> 20:45.860] And in England, these are probably the equivalent of what? [20:45.960 --> 20:46.860] A couple of hundred dollars? [20:47.160 --> 20:47.720] Yeah. [20:48.200 --> 20:49.060] Which is crazy. [20:49.380 --> 20:53.520] So I don't really understand what, what pricing scheme they have in mind. [20:53.900 --> 21:07.200] But the other ironic thing in comparison with the United States is that they've had GSM for so long in Europe that they actually have the old GSM network and the new one. [21:07.380 --> 21:12.100] The new one being PCN, as Tom described, the personal communications network. [21:12.400 --> 21:21.120] The older one being just called GSM, which is actually in the 900 megahertz band as opposed to their PCN, which is at 1800. [21:21.980 --> 21:29.540] And if anybody is aware, 900 was used in the United States for digital cordless phones. [21:30.260 --> 21:34.500] So again, we're kind of gearing ourselves up to be totally incompatible with the rest of the world. [21:44.040 --> 21:46.940] You want to talk about the authentication and encryption stuff? [21:47.940 --> 21:49.220] Let's talk about that. [21:50.240 --> 21:57.220] Since the questions that I get the most have to do with, well, how secure is this thing? [21:57.340 --> 21:57.980] Can it be broken? [21:58.560 --> 22:10.230] Well, relatively speaking, we already know analog cellular does absolutely nothing to protect either your privacy or your identity. [22:11.710 --> 22:17.770] Analog cellular phones are extremely easy to eavesdrop on and they're also extremely easy to clone. [22:18.890 --> 22:25.470] And supposedly this costs the... hey, what's so funny over there? [22:34.440 --> 22:40.200] Anyway, digital cellular isn't really much better. [22:41.440 --> 22:52.760] The initial version of digital amps was actually an overlay onto the currently existing... currently existing 800 megahertz analog cellular band. [22:53.000 --> 22:56.440] And the only part of it that's digital is basically your voice. [22:57.640 --> 23:05.860] The ESN and min, the electronic serial number and mobile identification number that are used by analog cellular phones, are still transmitted in the clear. [23:06.400 --> 23:09.420] The only difference is that your voice is digitized. [23:09.660 --> 23:11.920] And it's exclusive ORD. [23:12.120 --> 23:14.760] And that's basically to protect your privacy. [23:15.000 --> 23:16.680] And you can imagine how effective that is. [23:18.520 --> 23:21.880] So, so much for the older digital amps. [23:24.260 --> 23:25.660] Hey, I know those guys. [23:27.420 --> 23:33.500] The newer digital amps actually works in the PCS 1900 megahertz band. [23:33.740 --> 23:41.300] And the newer digital amps, the amps, what I mentioned before, IS-136 is digital and digital. [23:41.640 --> 23:51.160] It actually does the network authentication digitally and it also digitizes your voice, which is obviously digital. [23:53.120 --> 23:59.840] As far as encryption goes, it's not really much better than the analog counterpart. [24:00.060 --> 24:04.960] They basically take the same information, the ESN and min that used to be analog. [24:05.220 --> 24:05.900] And now it's digital. [24:06.160 --> 24:07.100] But nothing's changed. [24:07.320 --> 24:08.680] So, no big deal there. [24:10.060 --> 24:11.940] So, then along comes CDMA. [24:13.620 --> 24:37.620] With CDMA, code division multiple access, the way that basically works is, and just to paraphrase, recently, as in a couple of months ago, Bruce Schneier, who spoke earlier, published a white paper, along with a couple of other guys, concerning the security of CDMA phones. [24:38.280 --> 24:42.460] And as he showed, it's obviously not very secure. [24:42.860 --> 24:50.660] If you're going to speak relatively, it's, you know, it's relatively more secure than both D amps and obviously more secure than analog cellular. [24:51.180 --> 24:56.380] But overall, it's not really very secure at all. [24:58.060 --> 25:00.640] The specifications were published. [25:01.560 --> 25:15.460] Bruce Schneier basically worked with a paper that was written by someone that I suspect was an employee of some CDMA provider somewhere and didn't want to go on the record saying that it was weak. [25:15.960 --> 25:20.280] So, they took this guy's paper, they did a review, they did a crypt analysis of the whole thing. [25:20.500 --> 25:26.980] Bruce published the paper, along with a couple of other guys, and showed that basically, you know, CDMA was crap. [25:27.760 --> 25:32.780] So, while it is stronger, that doesn't necessarily make it better. [25:33.680 --> 25:39.160] In comparison with GSM, now we get into some more cloak and dagger kind of stuff. [25:39.440 --> 25:51.460] Because the algorithms that are used for authentication and encryption in GSM were actually devised by the spook organizations in France and England, to name a couple. [25:53.660 --> 25:56.520] And by spook, I mean secret agent types. [26:03.460 --> 26:06.040] Originally, some stupid French acronym. [26:06.340 --> 26:07.080] Let me just look it up. [26:07.200 --> 26:10.800] I hate French acronyms that are spelled differently than what they really are. [26:11.020 --> 26:14.700] The European Conference of Post and Telecommunication Administrators. [26:14.920 --> 26:15.560] CEPT. [26:16.200 --> 26:28.220] They originally proposed... Why it's not, you know, why it isn't ECPTA and CEPT is because it's French. [26:28.900 --> 26:30.860] So, you know, go figure. [26:31.060 --> 26:36.520] It was first proposed in the early 80s by the CEPT. [26:37.300 --> 26:48.460] And it was later picked up by the ETSI, which is another stupid French acronym, but luckily it spells out the same way. [26:48.620 --> 26:51.080] It's the European Telecommunication Standards Institute. [26:51.720 --> 26:59.300] And what they did was they organized something known as the Memorandum of Understanding, or MOU. [26:59.900 --> 27:04.520] And I guess this is the way European people do things. [27:04.680 --> 27:10.520] No offense to Tom, but, you know, all these agencies and acronyms that don't spell the same thing. [27:10.940 --> 27:12.340] It's really aggravating. [27:12.920 --> 27:13.260] But... [27:15.740 --> 27:22.860] But the Memorandum of Understanding is more of an organization than it is a piece of paper. [27:23.080 --> 27:25.640] Or actually stack of papers. [27:26.020 --> 27:33.980] What it is, is... Say, for example, you or anybody in the audience wants to set up a GSM network. [27:34.600 --> 27:41.640] What you do is you'd have to apply with the Memorandum of Understanding in Europe in care of the ETSI. [27:42.120 --> 27:48.940] And they would license to you the encryption technology that's used in GSM, which is top, top, top secret. [27:49.740 --> 28:09.140] And the interesting thing concerning these so-called secret encryption algorithms is a couple of years ago, the encryption algorithm that's supposed to protect subscribers against eavesdropping was given to a university to review. [28:10.040 --> 28:17.420] And unfortunately, this university saw fit that to... that some of this information was leaked out. [28:17.980 --> 28:25.880] So people have a good general working knowledge of the encryption algorithm that's used to protect against eavesdropping. [28:26.040 --> 28:28.540] We actually had a problem with that in the UK as well. [28:29.360 --> 28:46.920] With the Orange Network, with the SMS transfer protocol, transmitting the short messages services, a major government body, do you see the GCHQ, which is a... they need to know everything that goes on really. [28:47.280 --> 28:51.620] The GCHQ in England is basically the equivalent of the NSA in the United States. [28:52.260 --> 28:56.160] And they weren't happy with the encryption method being used on these phones. [28:56.600 --> 29:14.840] And so they called a restate and we had to go through quite a long session without being able to use SMS on the Orange Network while they reinstated a new version of the encryption system, which I believe has now been broken again in the UK. [29:16.480 --> 29:30.220] We're getting around to new things in the UK, like not actually cloning of the cell phones, but ghosting of them, which is much the same as cloning, but we can't actually grab any of the information from the transmissions. [29:30.800 --> 29:45.920] So we need to grab hold of a SIM card to be able to ghost a phone, which obviously isn't as easy as the old analog system where you can just grab the SN and then you now have to walk up to someone and take their SIM card and put it in a reader and copy it. [29:47.360 --> 30:04.720] Yeah, basically, as far as the whole cloning and eavesdropping threat goes, the only way you're going to clone somebody's service is you're going to either break into a GSM switch or you're going to find a way to defeat the security on the SIM cards. [30:05.620 --> 30:15.740] As far as pulling information, network information, from over the airwaves, it's a lot difficult than any other protocol that's come along so far. [30:16.000 --> 30:20.380] It doesn't mean it's impossible, but so far it's the strongest thing we've got. [30:20.900 --> 30:29.120] And it's kind of like the way the old saying goes that, you know, our president might be an asshole, but he's our president. [30:29.920 --> 30:31.600] And you know, and you can't make fun of him. [30:31.720 --> 30:43.520] Well, basically, GSM security might not be as good as it can possibly be, but it's the best thing that's come along so far and it's the one that we've agreed to use. [30:44.680 --> 30:55.680] And we've gone through, you know, all the paper, you know, these companies have gone through all the paperwork and signed the memorandum of understanding and they've gotten this proprietary encryption protocol mumbo jumbo. [30:55.680 --> 31:00.840] Basically, there's three algorithms that are relevant to GSM that you should know about. [31:01.820 --> 31:06.320] And they have equally snobby names. [31:06.560 --> 31:10.100] They're called A3, A5, and A8. [31:11.340 --> 31:12.760] Why they're called that? [31:13.040 --> 31:20.160] I don't know, because they didn't use any of the numbers in between and A doesn't really stand for anything other than probably algorithm. [31:21.120 --> 31:25.900] But A3 and A8 are actually performed on your SIM card. [31:26.380 --> 31:30.180] And A5 is performed by your phone, by the actual handset. [31:31.380 --> 31:38.480] A5 is the algorithm that's actually used to encrypt the conversation between your handset and the cell site. [31:39.020 --> 31:59.320] Now, bear in mind that if you were ever so fortunate as to bust into a building, an apartment building typically, because GSM phones are much lower powered than other cellular phones, they have to be a lot more cell sites and they have to be a lot more closely spaced together. [31:59.620 --> 32:06.320] Because of this fact, what the companies do is get the permission of the landlords of various apartment buildings in whatever town it is. [32:06.460 --> 32:09.660] And they put the cell sites on the roof typically are on the front of the building. [32:10.220 --> 32:14.100] And some of them are disguised with the color of brick and all kinds of neat things. [32:15.060 --> 32:20.340] And they would go back to the actual hardware which would be on the roof, the antenna would be on the side of the building. [32:21.680 --> 32:42.520] Now, the thing is that if you would be so lucky as to get into one of these apartment buildings or maybe you live in one that has a GSM cell site in it, all the traffic, including all the voice traffic, which has been digitized, is not encrypted from... well, [32:42.600 --> 33:00.420] the diagram ain't up there anymore, but between the BTS, the base transceiver station, which in essence is a cell site, in between that and the base station controller and ultimately the switch, none of the traffic in between that is encrypted. [33:00.960 --> 33:20.980] It is that if you were to get... I'm not going to tell you what you can get, but if you were to get the appropriate test equipment that you could use to demultiplex the traffic on the T1 leased lines that were going between the BTS, the cell sites, and the BSCs and ultimately the switches, [33:21.380 --> 33:27.800] then you'd be able to demultiplex the traffic going over these lines in the clear, including the voice traffic. [33:28.380 --> 33:31.260] So that kind of assumes a lot. [33:31.380 --> 33:37.220] It is that you have access to the premises and that you spent thousands of dollars on the equipment to get the job done. [33:37.460 --> 33:43.980] Otherwise, it's a lot more difficult to pick up conversations over the airwaves. [33:44.220 --> 34:01.140] Simply because even though the A5 algorithm is relatively simplistic, it's sufficient to make it inconvenient for somebody, even somebody to go through a lot of trouble, to be able to eavesdrop easily. [34:01.760 --> 34:05.280] It's not to say that it can't be done, but it can't be done easily. [34:05.640 --> 34:16.440] Again, it would be a lot easier, relatively speaking, to break into a switch or to crack the security on a SIM card if you were going to gauge... or if you were going to be a lazy bastard and sit at home. [34:17.260 --> 34:21.340] Basically, you know, you could sit at home and crack a SIM card or you could sit at home and break into a switch. [34:21.620 --> 34:28.620] Or you could run around outside with some weird doohickey with an antenna trying to pick up GSM signals in the airwaves. [34:28.840 --> 34:30.040] So you take your pick. [34:34.590 --> 34:47.670] Anyway, the authentication algorithms that are on the SIM card, A3 and A8, are used to basically say to the switch that you have permission to use the network. [34:48.130 --> 34:55.030] Just because you have a phone and you can turn it on and you know how to dial, it doesn't mean you have permission to use the network. [34:56.130 --> 35:02.510] Basically, the way it works is a random number is generated by the GSM switch. [35:02.730 --> 35:04.590] A 128-bit random number. [35:05.050 --> 35:13.330] And this random number is transmitted in the clear over the airwaves to the handset that's requesting use of the network. [35:14.790 --> 35:21.990] Now, what happens is this 128-bit number, this supposedly pseudo-random random number. [35:23.390 --> 35:24.750] Two things are done. [35:26.610 --> 35:33.990] It's subjected to the A3 algorithm and the A3 algorithm is used to generate a digital signature. [35:35.050 --> 35:45.290] The inputs to the A3 algorithm are this same random number and your KI, your secret key, which is only known to your SIM card and the switch. [35:45.610 --> 35:47.290] Your phone doesn't know what it is. [35:47.430 --> 35:48.410] You don't know what it is. [35:48.550 --> 35:53.190] You can't even ordinarily read it off the SIM card if you have the necessary equipment. [35:53.590 --> 35:56.330] So this information is extremely difficult to come by. [35:57.030 --> 35:59.490] It's, if you will, it's a shared secret. [35:59.730 --> 36:01.790] The SIM card knows it and the switch knows it. [36:02.850 --> 36:10.470] Anyway, this random number and your secret key are fed through the A3 hashing algorithm and a digital signature is generated. [36:10.870 --> 36:13.750] At the same time, the switch does the same thing. [36:14.110 --> 36:16.110] It takes the same random number. [36:16.330 --> 36:20.650] It takes your K sub I, your secret key, which it knows from the HLR. [36:21.150 --> 36:28.710] It does the same computation with the same A3 algorithm and it generates what should be the same digital signature. [36:29.770 --> 36:32.230] Now it's going to compare the digital signatures. [36:32.490 --> 36:36.690] And if they match, then so far so good. [36:36.930 --> 36:45.730] Now the next thing that's going to happen is it's going to use your phone and the switch are going to use the very same random number for this particular session. [36:46.230 --> 36:49.130] And it's going to feed it through the A8 algorithm. [36:49.410 --> 36:55.490] And the A8 algorithm is going to generate a key that's used to initialize A5. [36:56.550 --> 37:09.770] And basically the switch and your SIM card are feeding the random number and your K sub I, same deal, through the A8 algorithm to generate what's known as K sub C. [37:10.110 --> 37:12.530] K sub C is the ciphering key. [37:12.530 --> 37:20.390] But like I said, it's fed into the A5 engine in your handset to initialize the A5 algorithm. [37:20.590 --> 37:26.870] At the same time, when the switch does this, it sends the K sub C to the cell site. [37:27.330 --> 37:37.490] And the cell site uses it, provided that the switch tells it to even use encryption, to then say, okay, this guy is authenticated to use the network. [37:38.110 --> 37:41.470] Now, from this point onwards, encrypt everything using A5. [37:41.710 --> 37:43.070] And it proceeds that way. [37:44.390 --> 37:45.130] Tom? [37:51.050 --> 37:52.270] Any questions? [37:56.430 --> 37:58.410] Does anybody have a question? [37:59.950 --> 38:03.890] We have a question... [38:09.580 --> 38:12.500] No, it sends a random number over the airwaves. [38:14.700 --> 38:15.440] What's that? [38:17.140 --> 38:21.460] He said, does it send the encryption key over the airwaves in the clear? [38:21.800 --> 38:23.100] The answer is no. [38:23.280 --> 38:30.760] The only thing that ever goes in the clear over the network, in the initial negotiation, is the 128 bit random number. [38:31.520 --> 38:35.200] Your secret key is never, ever sent over the air. [38:35.380 --> 38:35.740] Ever. [38:35.920 --> 38:36.900] It's a shared secret. [38:37.120 --> 38:39.640] It's stored on the SIM card and at the switch. [38:40.000 --> 38:45.060] That's why your phone and the switch generate a digital signature. [38:45.320 --> 38:49.040] The digital signature is compared at the switch. [38:49.620 --> 38:56.820] Basically, my handset, by way of the SIM card, generates a digital signature, sends it back to the switch. [38:57.020 --> 39:00.360] The switch compares it with the one it just generated. [39:00.540 --> 39:03.480] And if they match, that means that I'm a valid subscriber. [39:03.820 --> 39:05.160] It's relatively straightforward. [39:05.680 --> 39:07.580] It's not rocket science. [39:09.040 --> 39:10.060] Next question. [39:15.580 --> 39:19.720] Is the handset encrypting when it sends the digital signature back to the cell? [39:29.410 --> 39:33.970] You're saying that once we've already been authenticated and we're talking on the phone? [39:34.490 --> 39:35.810] Yeah, most definitely. [39:40.290 --> 39:40.930] Everything. [39:41.310 --> 39:49.670] The only thing on the GSM network that's encrypted to prevent eavesdropping is what goes over the airwaves. [39:49.810 --> 39:55.250] In between the mobile handset and the cell site, that's the only thing that's encrypted. [39:55.590 --> 40:03.910] Between the cell site and the base station controller and between the base station controller and the switch, the MSC, nothing is encrypted. [40:04.170 --> 40:07.350] At that point, though, nothing is going over the airwaves. [40:07.510 --> 40:19.430] So the only place that encryption is implemented for the purposes of protecting your conversation against eavesdropping is the part of the network that goes over the airwaves. [40:20.330 --> 40:22.270] There is a question, Mike. [40:22.490 --> 40:25.950] The cell site actually has the A5 encryption engine in it. [40:26.130 --> 40:28.850] Every cell site has A5 encryption hardware. [40:29.130 --> 40:29.270] Yes. [40:31.110 --> 40:32.070] Next question. [40:32.610 --> 40:34.570] Use the microphone in the middle. [40:34.790 --> 40:36.270] Use the microphone in the middle. [40:36.650 --> 40:38.930] It took us quite a while to set this up. [40:39.150 --> 40:39.670] So use it! [40:41.890 --> 40:42.610] Thank you. [40:44.630 --> 40:47.670] I'm wondering about the problems with building this infrastructure. [40:47.670 --> 40:48.290] Talk louder. [40:48.590 --> 40:49.030] Can't hear you. [40:49.110 --> 40:50.010] I'll bring the mic closer. [40:50.310 --> 40:50.910] There you go. [40:51.130 --> 40:51.250] Okay. [40:51.410 --> 40:53.810] I'm wondering about the problems we're developing here. [40:54.010 --> 40:58.850] We're setting up infrastructure in different parts of the world that are incompatible. [40:59.050 --> 41:00.110] I still can't hear you. [41:00.350 --> 41:00.550] Okay. [41:00.930 --> 41:03.470] We're spending a lot of money building this infrastructure. [41:03.690 --> 41:03.790] Right. [41:04.430 --> 41:06.030] And they're all incompatible. [41:06.910 --> 41:08.950] Or maybe we have problems here. [41:09.070 --> 41:10.750] We're spending a lot of money setting this thing up. [41:10.850 --> 41:13.810] A lot of global money that could be used for other purposes. [41:14.090 --> 41:15.030] It's being wasted. [41:15.030 --> 41:18.030] Well, it all boils down to who's incompatible with who. [41:19.350 --> 41:23.170] GSM has been the standard throughout the world since the early 80s. [41:23.770 --> 41:25.390] It was a proposed standard. [41:25.390 --> 41:26.790] It became a standard. [41:27.010 --> 41:28.770] And we're only just getting it now. [41:28.970 --> 41:30.970] So who needs the CDMA crap? [41:31.410 --> 41:35.930] As far as I'm concerned, if it totally disappeared off the face of the planet, I wouldn't miss it. [41:36.310 --> 41:37.670] The military can keep it. [41:38.110 --> 41:40.810] It's not as secure as GSM is. [41:40.990 --> 41:43.870] It's only creating a headache for all the GSM providers. [41:44.710 --> 41:46.770] And it's only clouding the issue. [41:47.470 --> 41:54.330] The average person who owns a mobile phone has no clue what the hell PCS is. [41:54.650 --> 41:56.570] They think it's a small phone. [41:56.950 --> 41:59.170] They have no idea what the hell it means. [41:59.430 --> 42:09.150] Because the actual, the companies and the industry would have you believe that PCS is one and only one thing. [42:09.390 --> 42:15.370] When it's actually a myriad of different protocols that are directly competing with each other. [42:15.770 --> 42:17.570] One saying they're better than the other. [42:18.250 --> 42:20.350] And what does the consumer believe? [42:21.630 --> 42:26.870] So if it was up to me, if you wanted my personal opinion, I'd say that we should stick with GSM. [42:27.170 --> 42:40.970] Despite the fact that the frequency is different than the one it is in Europe, you know eventually the smart Swedes at Ericsson and the smart Finns at Nokia are going to come out with a phone that can do both frequencies because it's the same exact protocols. [42:41.410 --> 42:43.150] All it is is a different frequency. [42:43.650 --> 42:51.750] If you're going to compare that with a totally incompatible protocol at a totally different frequency, what's the lesser of two evils? [42:52.030 --> 42:53.250] I'd choose GSM. [42:53.590 --> 42:57.510] As it stands right now, I can take my SIM card and go to Europe and use it. [42:57.690 --> 43:01.030] You can't do that with CDMA because there ain't no such thing as a SIM card. [43:01.470 --> 43:05.430] The entire identity of the subscriber is still stored in the handset. [43:06.230 --> 43:11.850] If I take the SIM card out of my phone, think of the SIM card as the soul of the phone. [43:12.430 --> 43:15.590] If I remove my SIM card, you basically have a dead running carcass. [43:16.230 --> 43:19.250] It in no way, shape or form reflects the identity of the user. [43:20.470 --> 43:21.330] Next question. [43:23.250 --> 43:32.990] You said that you could roam within the United States even though they have... even though the different... because the different companies have some kind of a deal? [43:33.530 --> 43:35.070] You can't actually roam. [43:35.390 --> 43:40.210] You can use your SIM card in hybrid phones in the UK from the US. [43:40.670 --> 43:40.870] Okay. [43:41.050 --> 43:44.990] You said that the switch knows the secret key? [43:45.770 --> 43:46.030] Right. [43:46.210 --> 43:51.130] How would a switch with another company know the secret key or in the UK know the... Okay. [43:51.330 --> 43:55.570] The way things are set up right now are a little different than the way they should be. [43:57.470 --> 44:17.190] Right now, the way things are with most of the GSM providers, in fact, all the GSM providers, they are batching, they're basically running off a tape and mailing a tape to whoever they have a roaming agreement with containing a list of all the valid IMSIs, [44:17.870 --> 44:23.330] K-sub-Is, and MSISDNs, which are the actual phone numbers that you dial to reach somebody. [44:24.310 --> 44:37.090] In the ideal scenario and the way that it's defined by the Memorandum of Understanding is that all GSM providers are supposed to be able to reach each other over the SS7 network. [44:37.970 --> 44:41.470] And obviously that's not always possible. [44:41.890 --> 44:47.190] It will be possible probably fairly shortly, since most of the U.S. is SS7 capable. [44:49.670 --> 45:03.850] And GSM has really only been implemented in major cities in the United States that more than likely already have SS7, signaling system 7, in the public switch telephone network. [45:04.150 --> 45:18.490] So ultimately what would happen is that every GSM provider would have something on its network called the Visitor Location Register, which is the opposite of the Home Location Register, which contains all the information about local subscribers. [45:19.770 --> 45:38.730] What would happen is that the mobile switch, the MSC, on receiving a request to use the network from a foreign handset with a foreign SIM, what it would do is that it would go to the HLR, the Home Location Register, and it wouldn't find the person identifying themselves by their SIM. [45:38.850 --> 45:40.270] It wouldn't find them in the HLR. [45:40.630 --> 45:44.490] So the MSC would assume that this person is from another network. [45:44.770 --> 45:49.890] So what it's going to do is go to its nearest VLR, its Visitor Location Register. [45:50.170 --> 45:56.710] And its VLR is going to contact the foreign GSM network over the SS7 network. [45:56.930 --> 45:59.430] And it's going to say, who the hell is this guy? [46:00.190 --> 46:07.150] And the foreign GSM network is basically going to say, this guy's okay, this guy's not okay. [46:07.350 --> 46:13.250] And it's going to send that information back to the local GSM network's VLR. [46:13.490 --> 46:18.370] And then it's going to in turn tell the mobile switch, the MSC, let this guy make a call. [46:19.210 --> 46:35.850] The way it stands right now is that no one's using VLRs because the infrastructure has not yet been set up that allows all the cooperating GSM companies in North America to directly talk to each other over the public switch telephone network using SS7. [46:36.330 --> 46:45.590] So what they're doing is that they're shipping each other giant lists, dumps, of valid IMSIs, K-sub-Is, and MSISDNs. [46:45.730 --> 46:49.830] They're entering this long list into their home location register. [46:50.050 --> 46:54.350] And basically, you're going to take your phone, you're going to try to use the network. [46:54.690 --> 46:56.790] It's going to contact the mobile switch. [46:57.030 --> 46:59.290] The mobile switch is going to look in the HLR. [46:59.650 --> 47:02.370] And the HLR is either going to find you or not. [47:02.650 --> 47:04.650] And if it doesn't, you can't use the network. [47:04.790 --> 47:05.710] And it's as simple as that. [47:07.310 --> 47:08.210] Next question. [47:09.770 --> 47:10.830] Hi, Phiber. [47:11.270 --> 47:16.070] I've been a big fan of your radio show for a long time. [47:16.850 --> 47:20.930] And I also read the article that you had in 2600. [47:22.670 --> 47:25.990] My question is, that's not a picture of me. [47:27.410 --> 47:34.850] My question is, you were referring to the pair of the A3 and the A8 as Comp 128? [47:35.330 --> 47:36.230] In the article, yes. [47:36.410 --> 47:36.950] In the article, yes. [47:37.230 --> 47:39.270] Can you explain how this got its name? [47:40.710 --> 47:52.570] Well, the way it got its name is in the Memorandum of Understanding, they refer to A3 and A8 together as a single algorithm known as Comp 128. [47:53.430 --> 47:56.750] And this is actually spelled out. [47:56.990 --> 48:07.350] It's a simple hashing algorithm that takes... well, the way it got its name, first of all, is it's computation 128 bit. [48:07.890 --> 48:25.090] What it does is it's a single hashing algorithm that takes 128 bit random number as one input, takes the K sub I, the secret key of the subscriber, as a second input, and allows to select between as two modes. [48:25.330 --> 48:29.870] Whether you want a 64 bit output or whether you want a 32 bit output. [48:30.510 --> 48:34.350] If you select the 64 bit output, that's the A3 mode. [48:34.690 --> 48:38.190] Because the 64 bits is the digital signature. [48:38.990 --> 48:45.730] If you want the cipher and key generator... or maybe I have that backwards. [48:45.930 --> 48:46.610] Hold on a second. [48:47.570 --> 48:50.350] I don't want to tell you something wrong because then I'll feel stupid later. [48:51.990 --> 48:53.850] Yeah, I did it slightly backwards. [48:54.090 --> 48:54.210] Okay. [48:55.250 --> 48:59.530] The 32 bit is the digital signature, which is A3. [49:00.770 --> 49:10.650] The comp 128, if the algorithm is told to generate a 32 bit output from the very same 128 bit and the K sub I. [49:10.850 --> 49:14.290] And I should mention that the K sub I isn't a secret. [49:14.570 --> 49:24.010] You know, it might be... anybody who has done any research into GSM, they might have found it difficult to find information on exactly, you know, the nature of K sub I. [49:24.550 --> 49:32.650] I did find one really good site on GSM in Italy, which you kind of have to read Italian to be able to understand. [49:33.250 --> 49:41.850] But the K sub I is actually eight groups of four hex digits each. [49:42.170 --> 49:45.770] So if you do your math, that comes out to be... [49:49.890 --> 49:51.570] Oh, you people are stupid. [49:51.790 --> 49:52.210] Come on. [49:52.690 --> 49:55.070] How many bits are in a single hex digit? [49:55.530 --> 49:56.130] Four. [49:56.530 --> 49:56.950] Okay. [49:57.770 --> 50:00.130] How many digits is eight times four? [50:00.410 --> 50:00.970] 32. [50:01.750 --> 50:03.730] What's 32 times four? [50:12.260 --> 50:18.800] 32 times four is... 128. [50:19.320 --> 50:19.540] Thank you. [50:19.640 --> 50:20.160] Who said that? [50:20.660 --> 50:21.800] You're so smart. [50:21.940 --> 50:22.320] Stand up. [50:22.420 --> 50:22.860] Be recognized. [50:27.640 --> 50:28.360] Okay. [50:28.980 --> 50:32.100] The other reason why comp 128 got its name. [50:32.240 --> 50:37.040] It takes two 128 bit inputs, the random number, and the secret key. [50:37.360 --> 50:47.520] And like I was saying, it can be selected whether you want the A3 output, which is 32 bits, or whether you want the A8 output, which is 64 bits. [50:48.560 --> 50:51.320] Is that a sufficient answer, Mr. How did it get its name? [50:51.820 --> 50:52.240] Yes. [50:52.480 --> 50:52.920] Thank you. [50:53.180 --> 50:53.600] Okay. [50:53.880 --> 50:54.720] Next question. [50:57.200 --> 50:58.120] Not you. [51:01.840 --> 51:02.400] Hi. [51:02.740 --> 51:08.280] First of all, in your article, you say that you want to know if people want more information printed about this. [51:08.520 --> 51:09.660] Yes, I do. [51:09.920 --> 51:10.800] Nobody else does. [51:11.960 --> 51:19.400] My first question, I'd like to compile some sort of a web page concerning Nokia 2190 information. [51:19.400 --> 51:25.180] If anybody has any information on the Nokia 2190 phone, I'm sitting up there, just come see me. [51:25.280 --> 51:30.860] I'd like to compile some information because it seems that there's a lot of information available for the Ericsson phone. [51:34.660 --> 51:35.100] Okay. [51:52.590 --> 52:01.470] My next thing is something that's very interesting that I learned about looking for information on the net is how to hook these phones up to your PC. [52:01.950 --> 52:03.650] Something we haven't really discussed yet. [52:03.650 --> 52:10.570] Could you talk a little bit about how these phones get hooked up to your PC and how to use these phones as a modem? [52:11.210 --> 52:11.490] Okay. [52:11.810 --> 52:18.750] In the UK, over the GSM network, we can only reach 9600 BPS. [52:19.730 --> 52:24.090] Over the PCN network, you can actually get 14.4 connects using the Orange. [52:24.310 --> 52:26.650] They support the Nokia data card. [52:28.750 --> 52:33.030] Unbelievably, under the analog network, you can actually reach a lot higher board rates. [52:33.350 --> 52:38.430] The tolerance can be a lot higher on some of the bigger phones, the 4800X. [52:39.590 --> 52:50.030] But with the new modern phones, the GSM, mainly the Nokia and stuff, you can only reach 9600 over 14.4 if you're lucky, but it won't be a stable connection. [52:52.170 --> 52:52.990] Let's see. [52:53.170 --> 52:54.610] Last question... [52:54.610 --> 52:59.310] Just to add to that, in the United States, it's the same. [53:00.030 --> 53:06.570] You're limited basically by the available bandwidth that's available to the GSM protocol, which is 13 kilobits. [53:06.910 --> 53:12.210] But you're more restricted by the speed of the hardware in the handset itself. [53:12.850 --> 53:17.750] So we're restricted to 9600 bits per second in the US as well. [53:17.990 --> 53:39.190] Some of the newer phones that are coming out that are faster, such as the Ericsson 388, as well as there's a newer Ericsson, a really small flip phone that looks similar to the Motorola StarTAC, which is the Ericsson 788, can actually achieve higher data rates beyond the 19200. [53:41.310 --> 53:48.650] Just to add to that, on most phones there's two cool things that you can do. [53:49.250 --> 54:07.290] Specifically on the Ericsson phones, on this particular model, as an example, if you have the pinout to the little bus connector on the bottom, what the bus connector is for is for various things like recharging the phone, and connecting a little earphone, [54:07.410 --> 54:10.670] microphone jack deal, so you can do hands-free. [54:11.590 --> 54:16.030] Well, two cool things that you can do is build a serial cable for the phone. [54:16.790 --> 54:26.210] And if you manage to get your hands on the plans for a serial cable, and you have a GSM phone, I highly suggest you play around with it because it's pretty neat. [54:26.450 --> 54:46.110] What you can do is if on one particular setting, and I'm not going to give away all the tricks and secrets, but if you hook up your handset to the serial port of a PC in ProCom or something like that, at the proper speed, and make a call on your handset, [54:46.250 --> 54:52.390] you'll get various information dumped to your PC about the status of the cell site that you're connected to. [54:52.610 --> 54:53.710] And it's pretty cool. [54:54.190 --> 55:10.790] The other thing that you can do is if you turn off your phone, connect it to a PC at the different proper speed, turn it on, and enter in the proper response on your PC's keyboard back to the phone, you'll enter into the phone's ROM debugger. [55:11.170 --> 55:21.010] And you'll be able to dump the firmware of the handset and play around with the EEPROM settings inside the phone itself, which is also fun to play with. [55:21.910 --> 55:34.550] And yet another thing that I read about while doing this sort of stuff, there's actually some sort of a weird AT command set that you can use where you can actually set up the phone to use it as a modem for your PDA or whatever. [55:35.130 --> 55:40.690] And I think that the network that you're on has to be set up in order to use that. [55:40.910 --> 55:43.150] But it is something which is built into these phones. [55:43.910 --> 55:45.410] Actually, I've never heard that. [55:45.590 --> 56:00.330] I heard that it was built in... if you wanted to use your GSM phone to connect, say, at 9600 bits per second and make a call and connect to a modem, you'd basically, you'd plug in a little module on the bottom that connects to a PCMCIA card that you plug into your laptop. [56:01.050 --> 56:05.950] And to my knowledge, it's the PCMCIA card that understands the AT command set. [56:05.950 --> 56:06.670] Okay. [56:06.790 --> 56:08.210] And the last question. [56:08.470 --> 56:16.230] How difficult would it be, do you think, to buy a cell site and set it up for your own personal use? [56:16.510 --> 56:17.070] Thanks. [56:18.010 --> 56:23.910] How difficult would it be to buy your own cell site and set it up for your own use? [56:26.190 --> 56:27.450] Pretty damn hard. [56:28.570 --> 56:32.070] Considering that, number one, you'd have to have a buttload of money. [56:32.070 --> 56:36.310] And let's say, for example, that you have lots of money already. [56:38.870 --> 56:40.710] You think that's kind of funny, don't you? [56:44.470 --> 56:48.750] Well, considering that you... let's say, for example, you have sufficient funding. [56:49.850 --> 57:10.670] The companies that sell this hardware, for example, Ericsson and Nortel, Northern Telecom, being the two prevalent companies, they're not going to sell you any kind of GSM hardware other than handsets, unless you can show that you're a licensed bona fide member of the MOU, [57:10.890 --> 57:13.150] the Memorandum of Understanding with the ETSI. [57:13.330 --> 57:14.810] Otherwise, all bets are off. [57:16.030 --> 57:17.030] Next question. [57:17.030 --> 57:21.870] It's to answer some of the previous questions. [57:22.150 --> 57:31.590] On the AT command set, there was some work done, mainly by Nokia and Ericsson, which were offered to the TIA, not the AT, but the TIA, which was standardized by the TIA. [57:31.990 --> 57:33.090] We can't hear you. [57:33.670 --> 57:34.150] Sorry? [57:34.410 --> 57:35.530] We can't hear you. [57:35.810 --> 57:45.870] On the AT command set for GSM phones, there was some work done by, mainly Nokia and Ericsson, which were standardized by the TIA. [57:46.770 --> 57:51.710] And the draft, at least, of the standard was available on Nokia's site. [57:51.850 --> 57:53.010] I don't know if it's still there or not. [57:53.970 --> 58:09.790] And on the speed, I mean data speed, data transfer speed, Nokia has demonstrated, and I think Ericsson has also done some demonstration, of transmission at 48 kilobits per second, and video, especially on GSM, by multiplying data channels. [58:13.090 --> 58:18.430] So, it's possible to go faster than AT 600, but it's not an option available on networks today. [58:18.890 --> 58:21.450] But several demonstrations have been done at 48 kilobits per second. [58:30.390 --> 58:39.350] Well, something that we should add, as far as bandwidth goes concerning these things, is they were designed with ISDN in mind. [58:39.470 --> 58:54.810] They were hoping that ultimately they would gateway all the GSM companies to the terrestrial ISDN network, which ultimately goes over SS7, with the local phone companies, the wired phone companies. [58:54.810 --> 59:10.410] The only problem is that there really isn't enough infrastructure, or much less switching equipment, that can handle X number of people. [59:10.670 --> 59:26.310] If everybody who has an Omnipoint phone in New York City suddenly decided that they wanted to dial up somewhere using ISDN at 64 kilobits, there would be madness, insanity. [59:26.850 --> 59:28.570] There just isn't enough man-width. [59:29.410 --> 59:35.190] If everybody in New York City decided that they were going to connect at 9600 bits per second, it probably wouldn't work either. [59:37.350 --> 59:41.490] Luckily, since this is so new, there isn't a very high demand for that yet. [59:41.910 --> 59:47.950] So as far as bandwidth concerns go, it remains to be seen. [59:48.230 --> 59:53.350] It'll be really neat once they connect GSM gateway to ISDN. [59:53.930 --> 01:00:00.770] I'm sure there'll be a lot of fun to be had there if you could actually achieve ISDN speeds over wireless. [01:00:01.570 --> 01:00:03.690] But anyway, I digress. [01:00:03.990 --> 01:00:04.830] Next question. [01:00:08.190 --> 01:00:08.710] Hello. [01:00:09.570 --> 01:00:09.890] Okay. [01:00:10.070 --> 01:00:10.290] Hi. [01:00:10.830 --> 01:00:11.230] Hi. [01:00:13.670 --> 01:00:14.190] Okay. [01:00:14.390 --> 01:00:22.010] Well, first of all, I'm a Sprint Spectrum customer from the Baltimore area and everything, and I'm paying excessive amounts of money using my phone up here. [01:00:22.150 --> 01:00:26.070] But, you know, contributing to the good of development and all, I guess. [01:00:28.630 --> 01:00:33.090] Sprint Spectrum is supposed to implement spread spectrum technology. [01:00:34.110 --> 01:00:35.170] I'm wondering... Wait. [01:00:35.170 --> 01:00:35.850] Sprint Spectrum? [01:00:36.010 --> 01:00:36.730] Spread Spectrum? [01:00:36.930 --> 01:00:37.570] No. [01:00:37.790 --> 01:00:37.930] Seriously. [01:00:38.730 --> 01:00:39.530] I mean, no. [01:00:40.090 --> 01:00:40.730] Okay. [01:00:41.010 --> 01:00:42.350] Say that three times fast. [01:00:43.570 --> 01:00:44.210] No. [01:00:44.970 --> 01:00:45.310] Okay. [01:00:45.530 --> 01:00:48.690] Anyway, do they implement this? [01:00:48.810 --> 01:00:49.890] Do they implement it properly? [01:00:50.290 --> 01:00:56.830] And from what I understand about spread spectrum, it was developed by the military to use in a hostile environment. [01:00:58.050 --> 01:01:03.750] Possibly to... Well, as... Yeah, Nicaragua. [01:01:04.730 --> 01:01:10.330] As kind of an anti-jamming type device and possibly anti-ease dropping. [01:01:10.530 --> 01:01:16.250] Does this... I understand that it is possible to use drop with the digital stuff. [01:01:16.410 --> 01:01:17.550] You just have to deal with the encryption. [01:01:17.550 --> 01:01:19.410] But does the spread spectrum get in the way? [01:01:20.370 --> 01:01:26.770] Well, GSM uses something similar to spread spectrum. [01:01:27.850 --> 01:01:36.650] It also implements a method of frequency hopping, which isn't so much meant to deter people from eavesdropping. [01:01:36.770 --> 01:01:38.610] They've really left that up to the encryption element. [01:01:38.810 --> 01:01:38.990] Right. [01:01:39.110 --> 01:01:39.170] Right. [01:01:39.230 --> 01:01:45.310] The frequency hopping is meant to make better use of the available frequencies and the available bandwidth. [01:01:45.750 --> 01:01:45.850] Right. [01:01:45.850 --> 01:01:52.930] So, as far as sprint spectrum implementing things properly, they're all using the same switches. [01:01:53.690 --> 01:02:01.490] And the two most popular switches that are in use for GSM are Nortel's and Northern Telecom's and Ericsson's. [01:02:02.030 --> 01:02:04.450] And they do things pretty much the same way. [01:02:05.970 --> 01:02:06.510] Okay. [01:02:07.470 --> 01:02:08.050] Thanks. [01:02:11.500 --> 01:02:13.680] You were mentioning the smart cards. [01:02:13.920 --> 01:02:14.240] Hey, wait. [01:02:14.380 --> 01:02:14.860] I know you. [01:02:15.000 --> 01:02:15.700] Aren't you the rebel? [01:02:19.460 --> 01:02:21.240] You were mentioning the smart cards. [01:02:21.400 --> 01:02:23.520] And you say if you take them out, the phone's useless. [01:02:24.000 --> 01:02:26.400] I heard that somebody else has an Omnipoint phone. [01:02:26.600 --> 01:02:29.900] They say that without the smart card, the only number you can dial is 911. [01:02:30.200 --> 01:02:30.640] Is that true? [01:02:31.420 --> 01:02:33.560] In the general case, yes. [01:02:35.160 --> 01:02:41.360] I can't promise you that if you take your phone somewhere else, to some other GSM network, that you're going to be able to dial 911. [01:02:41.860 --> 01:02:43.680] Especially if it's in a foreign country. [01:02:44.040 --> 01:02:46.180] Because, number one, your phone wouldn't work. [01:02:46.600 --> 01:02:48.860] And number two, even if it did, they don't use 911. [01:02:49.140 --> 01:02:49.820] They use something else. [01:02:50.460 --> 01:02:50.520] Right. [01:02:50.840 --> 01:02:50.920] But, yeah. [01:02:51.060 --> 01:02:56.340] There's no way you can possibly make a phone call, free or otherwise, without a SIM card in the phone. [01:02:56.340 --> 01:02:57.240] All right. [01:02:57.580 --> 01:03:00.040] Now, you're talking about the encryption thing. [01:03:01.000 --> 01:03:05.600] Tell us about the features like voicemail and email that you get and fax. [01:03:06.060 --> 01:03:08.300] Do you want to hear about some of the really cool features? [01:03:08.300 --> 01:03:09.160] Yeah. [01:03:09.260 --> 01:03:14.280] Did that get encrypted, too, as well as the voice and the other things that you were mentioning? [01:03:14.620 --> 01:03:18.380] Everything is encrypted once you've been authenticated to the network. [01:03:18.740 --> 01:03:21.160] Everything is encrypted using the A5 algorithm. [01:03:21.940 --> 01:03:26.140] Including short messages, which can be sent between handsets. [01:03:26.680 --> 01:03:27.780] Including beeps. [01:03:28.100 --> 01:03:30.240] You can page somebody on their phone. [01:03:30.240 --> 01:03:33.440] And all the myriad of other features. [01:03:33.720 --> 01:03:36.740] Basically, each phone has a little menu on it. [01:03:36.880 --> 01:03:40.080] That you usually scroll through with the left and right arrow keys. [01:03:40.420 --> 01:03:42.460] Some phones have up, down, left and right. [01:03:42.860 --> 01:03:44.100] Like the Nokias do. [01:03:45.780 --> 01:03:50.940] Basically, the features usually consist of call waiting. [01:03:50.940 --> 01:03:53.880] Sometimes conference calling or three-way. [01:03:55.000 --> 01:03:58.200] Call forwarding of various different types. [01:03:58.380 --> 01:04:00.800] Whether you're unreachable, call forward if you're busy. [01:04:01.400 --> 01:04:07.840] Call forward if... Basically, call forward for anything you can imagine. [01:04:08.060 --> 01:04:10.300] If you don't answer the phone and so on and so forth. [01:04:10.480 --> 01:04:13.260] And you can set the number that you forward to whatever you want. [01:04:13.760 --> 01:04:13.940] All right. [01:04:14.180 --> 01:04:21.840] Now, all these steps that you're going through with the flow chart, this happens the instant that you turn on the phone and want to make a phone call, right? [01:04:22.780 --> 01:04:23.360] What's this? [01:04:23.680 --> 01:04:25.620] It goes through all those steps that you've mentioned. [01:04:26.060 --> 01:04:27.440] The instant that you turn on the phone? [01:04:27.640 --> 01:04:28.840] In a split second. [01:04:29.540 --> 01:04:31.220] Actually, it goes through all those things. [01:04:31.380 --> 01:04:37.600] Depending on the company, it's definable how many times... [01:04:38.260 --> 01:04:42.080] Or how often, rather, it regenerates this cryptographic information. [01:04:42.580 --> 01:04:50.420] Namely, how often it regenerates the digital signature and the K sub C, the ciphering key. [01:04:50.420 --> 01:04:53.620] That's used... that's fed into the A5 algorithm. [01:04:54.960 --> 01:04:58.780] On some networks, it's done every single call. [01:04:59.160 --> 01:05:06.320] On some networks, it's done every single call or within a fixed period of time, whichever one comes first. [01:05:07.140 --> 01:05:13.260] And on yet other networks that are really stupid, they might not ever change it unless you turn your phone off. [01:05:17.340 --> 01:05:17.780] Okay. [01:05:17.780 --> 01:05:19.700] He has nothing to say in response to that. [01:05:19.920 --> 01:05:25.900] Just quickly, on the conference call, with Orange in the UK, you can now get five-way calling, which is quite impressive, I thought. [01:05:26.280 --> 01:05:31.160] But the real question was to Tom, and how many PCN phone numbers have you had? [01:05:33.140 --> 01:05:37.000] I've had six PCN phones now. [01:05:37.540 --> 01:05:39.440] And how many of those have been disconnected? [01:05:40.920 --> 01:05:41.520] Five. [01:05:41.840 --> 01:05:42.480] Thank you. [01:05:44.580 --> 01:05:45.180] Hi. [01:05:45.600 --> 01:05:49.240] I wanted to ask about the feasibility of breaking the encryption algorithm in real time. [01:05:49.660 --> 01:05:55.540] Would it be possible to brute force the encryption algorithm in a reasonable length of time to listen to the conversation? [01:05:55.540 --> 01:06:18.140] Well, the problem with that is the amount of time that it would take you to crack the encryption is ridiculously longer than the amount of time that a particular piece of traffic that you're going to grab is valid with the same key. [01:06:18.140 --> 01:06:29.440] There are various different inputs to the A5 encryption algorithm, including the voice samples of both the transmit and receive channels. [01:06:29.920 --> 01:06:50.700] So you have to figure that all these different things are being fed into the A5 algorithm, including the ciphering key, which initializes A5, K sub C, the 114-bit frame for both the transmit and receive channels are fed in. [01:06:51.500 --> 01:06:58.080] And if you think about that for a moment, every split second, that's going to be different. [01:06:58.960 --> 01:07:07.200] Because your voice, you know, unless you sit there and you just, you know, make the same tone for, you know, some period of time. [01:07:07.400 --> 01:07:09.620] But even then, I mean, those samples are going to vary greatly. [01:07:09.620 --> 01:07:17.780] If you convert something from analog to digital, you're going to be presented with a wide variety of digital representations of that analog speech. [01:07:18.280 --> 01:07:20.440] That's fed into the encryption algorithm. [01:07:20.740 --> 01:07:25.580] And the output of that is only valid for that one split second. [01:07:26.100 --> 01:07:35.980] So the actual key, if you will, or one of the inputs that decides what the output of the encryption algorithm is, is constantly changing. [01:07:37.200 --> 01:07:41.820] So it would be incredibly difficult to brute force the algorithm. [01:07:42.000 --> 01:07:47.280] The only real way that you'd be able to take advantage of it is if you were able to crack it outright. [01:07:47.840 --> 01:07:51.820] And again, A5 is not a particularly complicated algorithm. [01:07:52.160 --> 01:07:57.060] It really just consists of three linear feedback shift registers. [01:07:57.540 --> 01:07:59.460] That's basically the core of A5. [01:08:00.400 --> 01:08:06.580] And I give a lot more specifics about the makeup of A5 in my article, so you might want to check that out. [01:08:07.180 --> 01:08:13.480] And if you find any other information about it, then you didn't get it from me. [01:08:15.760 --> 01:08:17.660] So does that answer your question at all? [01:08:22.410 --> 01:08:24.030] I just had a real quick question. [01:08:24.150 --> 01:08:26.730] Maybe I missed it while I was putting the Kiss Me hat on that guy over there. [01:08:27.090 --> 01:08:33.390] But when the tower and the phone generate their digital signal key, how do they check it? [01:08:33.650 --> 01:08:37.850] And if they check it over sending it back and forth, is it encrypted? [01:08:38.490 --> 01:08:39.050] No. [01:08:39.290 --> 01:08:45.850] The digital signature is generated using the A3 algorithm, which is a one-way hash. [01:08:46.410 --> 01:08:50.970] When the switch sends you the 128-bit random number, that's sent in the clear. [01:08:51.610 --> 01:09:00.690] If you had some way of predicting what that 128-bit random number was going to be, then even then you'd still only have half the equation. [01:09:00.810 --> 01:09:07.290] If you didn't know what the subscriber's secret key was, then that's never sent over the air, ever. [01:09:07.290 --> 01:09:10.730] So you're still left with quite a problem to solve. [01:09:11.190 --> 01:09:22.130] As far as the generation of the 32-bit digital signature, this digital signature, once it's generated by your phone, it is sent back in the clear. [01:09:22.590 --> 01:09:29.130] Back to the switch, and the switch compares it with the one that it just generated using the exact same criterion. [01:09:29.850 --> 01:09:34.050] Now the reason why that's not really a problem is because it's a one-way hash. [01:09:34.050 --> 01:09:36.870] There's really no way to reverse this one-way hash. [01:09:37.250 --> 01:09:43.230] Well, cryptographically speaking, if it's a secure one-way hash, then there's no way to reverse it. [01:09:43.370 --> 01:09:48.790] And there's also... there shouldn't be any other two inputs that should yield the same output. [01:09:49.610 --> 01:09:54.690] So granting that, there's no problem with sending the digital signature back in the clear. [01:09:55.310 --> 01:10:06.470] It's no different than, say for example, using PGP, which in essence is using RSA to do a digital signature that you're tagging onto the end of a message. [01:10:07.110 --> 01:10:09.550] That digital signature you're sending in the clear. [01:10:09.890 --> 01:10:18.950] I mean, the digital signature in and of itself doesn't contain any information that you can use to derive the secrets that were used to generate it. [01:10:18.950 --> 01:10:20.850] Which are only really one thing. [01:10:21.030 --> 01:10:23.930] There's only one secret, which is the subscriber's secret key. [01:10:24.350 --> 01:10:27.930] The 128-bit random number that's sent over the network in the clear. [01:10:28.110 --> 01:10:29.590] Who cares if you get that? [01:10:29.790 --> 01:10:30.690] It really doesn't matter. [01:10:31.450 --> 01:10:36.070] The subscriber's secret key is really at the core of GSM security. [01:10:36.070 --> 01:10:49.170] If you could somehow either break into a GSM switch or gain access to the subscriber's secret key on the SIM card, then you're in essence, you've compromised the security of GSM. [01:10:49.390 --> 01:10:51.790] Because that in and of itself is at the heart. [01:10:57.770 --> 01:11:04.810] You mentioned the communications between the, what is it, BSC and MSC are not encrypted. [01:11:05.130 --> 01:11:07.630] Or the BTS and the BSC are encrypted either. [01:11:07.630 --> 01:11:12.350] Yeah, and that runs over landlines to between like the apartment complex and wherever else it's going. [01:11:12.550 --> 01:11:18.190] Yeah, they go over lease lines, T1 lines, that are leased from whoever the local phone company is. [01:11:18.470 --> 01:11:25.670] Given that the rooftop areas on apartment buildings are notoriously easy to break into, I suspect that they'll start encrypting those fairly soon. [01:11:26.010 --> 01:11:27.910] And it's similar to ATM networks. [01:11:27.910 --> 01:11:38.630] Actually, they probably won't anytime soon because no such equipment exists and no such specification exists in the GSM standard to do such a thing. [01:11:39.030 --> 01:11:45.910] It's specifically spelled out that the encryption only exists between the cell site, the BTS, and the handset. [01:11:48.790 --> 01:11:51.390] So, I mean, you know, it is what it is. [01:11:51.550 --> 01:12:05.850] I guess if you're going to go through the trouble of getting the proper equipment, the demultiplex GSM traffic in the clear between the cell site and the rest of the network over the wired network, and I guess you deserve to listen to it. [01:12:05.850 --> 01:12:08.370] The implication was the T1 channel bank, right? [01:12:08.990 --> 01:12:10.350] Or is it different from that? [01:12:10.490 --> 01:12:19.530] They're T1s, yes, but the actual stuff, the data that's going over the T1s, is not the same as your typical channel bank. [01:12:20.490 --> 01:12:21.730] Okay, I actually did have a question. [01:12:21.970 --> 01:12:30.350] The subscriber secret key and associated other thing on the chip, does that relate back to one single subscriber in the billing database? [01:12:30.810 --> 01:12:32.990] In other words, how's the privacy of that handled? [01:12:32.990 --> 01:12:37.090] The subscriber secret key is unique to the subscriber. [01:12:37.290 --> 01:12:39.150] No two subscribers have the same key. [01:12:40.150 --> 01:12:46.850] The actual database, whatever they use for billing, the billing database does not contain the secret keys either. [01:12:48.330 --> 01:13:01.510] To identify the subscriber in the billing database, it would use either the mobile subscriber's ISDN number, their phone number, or their IMSI, or both. [01:13:01.730 --> 01:13:08.930] The IMSI is the equivalent of the serial number of the subscriber, which is stored on the SIM card. [01:13:09.950 --> 01:13:14.590] And the billing database would use those criteria to identify the subscriber. [01:13:15.010 --> 01:13:30.810] As far as the HLR goes, the home location register, the secret keys are either stored in the clear on the switch, or there's an option in later revisions of the switching software to store the secret keys in encrypted format once they're input. [01:13:32.910 --> 01:13:46.050] And again, the security and secrecy of these secret keys, which are unique to a subscriber, is really at the heart of GSM security, as far as cloning is concerned. [01:13:52.270 --> 01:13:57.410] Okay, so you got me curious about the ID chip on the phone end. [01:13:57.990 --> 01:14:01.390] And I'm wondering, what do we know about that? [01:14:01.570 --> 01:14:02.910] Is it secured hardware? [01:14:05.290 --> 01:14:07.130] Are they easy to duplicate? [01:14:07.490 --> 01:14:09.390] What's the situation with the ID chips? [01:14:10.370 --> 01:14:12.270] Hold on, people are too busy leaving. [01:14:13.130 --> 01:14:13.890] Say again? [01:14:13.890 --> 01:14:15.890] People are too busy leaving. [01:14:16.090 --> 01:14:17.730] Why don't you repeat your question? [01:14:19.090 --> 01:14:20.370] I didn't hear that. [01:14:20.530 --> 01:14:20.710] I'm sorry. [01:14:22.570 --> 01:14:24.290] People are walking out. [01:14:24.430 --> 01:14:25.710] Why don't you repeat your question? [01:14:26.090 --> 01:14:30.530] The question is, the ID chip on the phone seems like a rather interesting device. [01:14:31.250 --> 01:14:31.430] Right. [01:14:31.770 --> 01:14:32.850] It's got the memory. [01:14:33.690 --> 01:14:39.630] My question is, can they be duplicated that we know about? [01:14:39.630 --> 01:14:46.410] Are they secured hardware in the form of, you know, chips that are difficult to trace and analyze? [01:14:47.150 --> 01:14:49.270] What's the situation with the ID chips? [01:14:49.850 --> 01:14:54.030] Well, the first thing is, who exactly do you mean by we? [01:14:54.790 --> 01:14:55.630] Who's we? [01:14:56.890 --> 01:14:57.490] Us. [01:14:57.830 --> 01:14:58.430] Us? [01:14:58.570 --> 01:14:59.670] Us all together? [01:14:59.930 --> 01:15:00.670] Can we break it? [01:15:00.950 --> 01:15:03.110] The general we of the hacker community. [01:15:03.110 --> 01:15:04.870] Not you too in particular. [01:15:04.870 --> 01:15:04.970] Not you too in particular. [01:15:05.150 --> 01:15:05.790] We the people. [01:15:07.150 --> 01:15:11.910] Well, unfortunately, I'm not at liberty to say whether or not the security can be defeated. [01:15:13.270 --> 01:15:17.610] What I am at liberty to say is how it's implemented. [01:15:18.950 --> 01:15:31.410] Basically, to take as an example, two of the major manufacturers of SIM cards in the United States are Gemplus and Orga. [01:15:34.590 --> 01:15:49.250] And when Gemplus and Orga implement their SIM cards and the way the SIM cards are communicated with according to the latest GSM specifications as laid out by the ETSI. [01:15:49.430 --> 01:15:53.110] The latest being GSM version 11.11. [01:15:54.150 --> 01:16:12.850] And the SIM cards, taking for, as an example, Orga SIM cards, the information that's stored on them that's really considered secret, is the IMSI and the K-sub-I. [01:16:14.170 --> 01:16:17.190] The IMSI can be read. [01:16:17.490 --> 01:16:19.970] The K-sub-I can never be read. [01:16:20.190 --> 01:16:23.710] In the case of Gemplus, the same thing holds true. [01:16:24.370 --> 01:16:32.970] The difference being, the difference between the two is how the K-sub-I is written to the card. [01:16:33.590 --> 01:16:41.010] In either case, they claim that the K-sub-I is actually programmed into the card and can never be changed. [01:16:41.710 --> 01:17:07.210] Well, the thing that isn't in the GSM spec that the manufacturers of SIM cards leave up to their own interpretation are access codes that are often undocumented, where if you know the proper sequence of byte-coded commands to send to the SIM card, you can get it to relinquish certain pieces of information, [01:17:07.470 --> 01:17:12.830] known as file identifiers, stored on the SIM card. [01:17:13.410 --> 01:17:20.850] And these particular pin codes are typically known as, for example, ADM1 or ADM4. [01:17:21.930 --> 01:17:40.730] And knowledge of these pin codes would allow you to access certain parts of the SIM card that are normally only allowed for by the manufacturer for the company that's using the SIM cards. [01:17:41.010 --> 01:17:53.450] And the subscriber is never aware of what these pin codes are, because they really have nothing to do with the day-to-day operation of the phone itself, nor would they ever be used from the actual handset. [01:17:54.210 --> 01:17:59.850] So, as far as the security of the SIM cards go, they are fairly secure. [01:18:02.790 --> 01:18:07.890] Of course, as time goes by and more and more people start playing with the things, we'll see what happens. [01:18:12.530 --> 01:18:18.150] The last question was very close to what I was going to bring up. [01:18:18.150 --> 01:18:23.170] It sounds like through the air is the most difficult thing to break. [01:18:23.510 --> 01:18:24.030] Right. [01:18:24.430 --> 01:18:27.890] At the switch, it would be the second most difficult thing to break. [01:18:29.450 --> 01:18:39.730] And from a... let's say I'm trying to protect my CIO, my CEO, and his cell phone traffic. [01:18:40.070 --> 01:18:40.650] Right. [01:18:41.050 --> 01:19:04.250] It seems like the thing that I would be most afraid of is that someone would swipe his phone phone for 35 minutes, an hour or two, put a serial cable into the butt end of it, and be able to draw down enough information to identify his case of I. [01:19:04.570 --> 01:19:05.690] See, that's just it. [01:19:05.810 --> 01:19:15.190] None of that information is accessible by the handset itself or by connecting up any kind of crazy serial cable. [01:19:15.690 --> 01:19:20.110] The case of I, the secret key, is never sent over the network. [01:19:20.410 --> 01:19:24.210] The handset doesn't even know what it is when it's talking to the SIM card. [01:19:25.050 --> 01:19:28.130] The SIM card never relinquishes this information. [01:19:29.010 --> 01:19:31.350] Okay, let me rephrase that then. [01:19:32.230 --> 01:19:45.410] He loses his phone for 30 minutes, 45 minutes, and someone has figured out some manufacturer codes to reprogram the case of I to a known quantity. [01:19:46.330 --> 01:19:50.430] Well, that's not going to jive with the case of I stored in the switch. [01:19:50.850 --> 01:19:51.310] That's right, that's right. [01:19:51.310 --> 01:19:51.310] Okay. [01:19:51.350 --> 01:19:52.610] So you know better off. [01:19:52.910 --> 01:20:02.650] The only thing you'd have to worry about is somebody borrowing his phone, pulling out a SIM card, and finding a way to copy the contents of his SIM card onto another SIM card. [01:20:02.650 --> 01:20:04.970] Then they've effectively cloned his phone. [01:20:05.230 --> 01:20:07.810] If they've figured out a way to do that, then he's fucked. [01:20:08.450 --> 01:20:10.390] And it's as simple as that. [01:20:10.630 --> 01:20:17.530] But that would involve more than just putting up a funny serial cable. [01:20:17.710 --> 01:20:21.590] You'd have to construct an interface for the SIM card itself. [01:20:21.950 --> 01:20:31.810] Yeah, you'd have to have a SIM card programmer, which is actually a unit that you'd connect to a PC for the purposes of programming or initializing SIM cards. [01:20:31.970 --> 01:20:33.770] It has nothing to do with the handset. [01:20:33.950 --> 01:20:41.950] The handset in no way, shape, or form is capable of directly accessing any of the file identifiers stored on the SIM card. [01:20:42.170 --> 01:20:49.930] It uses a really crude bytecode language to communicate with the SIM card and get responses from it. [01:20:50.550 --> 01:21:01.210] It can't directly affect the information stored on the SIM card except that information that the subscribers allowed to modify through his handset. [01:21:01.370 --> 01:21:06.930] For example, if he wants to save a message that he received from somebody, he could save it on a SIM card. [01:21:07.470 --> 01:21:13.950] Or if he has a list of speed dial numbers of frequently called people, he could save that on a SIM card. [01:21:14.150 --> 01:21:19.710] Those would be saved on the SIM card or in the switch and then confirmed by the SIM card? [01:21:19.950 --> 01:21:21.230] No, never stored on the switch. [01:21:21.390 --> 01:21:26.290] The switch knows nothing about stored messages or speed dial numbers. [01:21:26.310 --> 01:21:28.710] All that is done by the handset and the SIM card. [01:21:29.690 --> 01:21:30.470] Thanks, Phiber. [01:21:34.020 --> 01:21:34.540] Handoffs? [01:21:34.900 --> 01:21:35.660] Hold on. [01:21:35.820 --> 01:21:36.980] I'll get the handoffs. [01:21:38.320 --> 01:21:43.340] I wanted to ask... I just wanted to go into a little more detail about the SIM card itself. [01:21:45.060 --> 01:22:03.980] I might probably sound ignorant, which I am, of this, but would you say that these SIM cards are more akin to the smart cards that were tested at the Olympics last year and is being tested in New York City this year for debit? [01:22:04.220 --> 01:22:11.820] Or is it more like the dumb cards, so to speak, that are used on prepaid calling cards in Europe? [01:22:11.820 --> 01:22:19.700] And would a smart card programmer be able to read or write to a SIM card? [01:22:19.700 --> 01:22:26.980] I know you said that the K-sub-I cannot be changed on a SIM card that already had a K-sub-I value written to it. [01:22:27.140 --> 01:22:27.400] Right. [01:22:27.500 --> 01:22:40.500] But if you were able to get a blank SIM card, would you be able to read another SIM card's K-sub-I and copy it to it with relatively little or difficult ease? [01:22:40.720 --> 01:23:01.600] And also I was wondering whether or not you were aware of the white paper that came out by Belcor last year about them having cracked smart cards in general, being able to relinquish the secret key by actually damaging it either through heat or radiation, [01:23:01.600 --> 01:23:07.400] if I remember correctly, and whether or not that could be applied in attacking a SIM card. [01:23:07.980 --> 01:23:12.440] Yeah, actually I am familiar with Belcor's white paper. [01:23:12.660 --> 01:23:19.260] The only problem with that is that they are talking about SIM cards that use a known algorithm to leak information. [01:23:19.660 --> 01:23:33.920] If the smart card is using RSA or DES, by damaging the smart card or causing faults in the actual computation, they would be able to track where these faults turn up in the response based on a known input. [01:23:34.200 --> 01:23:39.720] Well, the problem with that is that the nature of the A3 and A8, a.k.a. [01:23:39.840 --> 01:23:42.640] the comp 128 algorithm is not generally known. [01:23:42.940 --> 01:23:45.020] So you can't really attack it from that direction. [01:23:45.300 --> 01:23:47.460] You could if you knew the nature of the algorithm. [01:23:48.480 --> 01:23:51.360] As far as, what were your other questions? [01:23:52.420 --> 01:24:09.380] Whether or not since it's perceived generally at this point that the K-sub-I cannot be changed on a SIM card that already has that value stored, if you were to get a blank, would you be able to... would a smart card reader, first of all, be able to read a SIM card, [01:24:09.440 --> 01:24:11.660] as you're calling it, or is it very general? [01:24:11.900 --> 01:24:12.360] No. [01:24:12.360 --> 01:24:12.900] Is it similar? [01:24:13.320 --> 01:24:13.540] No. [01:24:13.720 --> 01:24:15.020] Smart cards and SIM... [01:24:15.020 --> 01:24:22.000] A SIM card is a type of smart card simply because it has a microcontroller on it that makes it a smart card. [01:24:22.000 --> 01:24:30.040] It is not a smart card like, you know, a bank card with a little chip on it might be. [01:24:30.240 --> 01:24:34.360] Or a calling card on an overseas phone card might be. [01:24:34.580 --> 01:24:35.580] That's totally different. [01:24:36.280 --> 01:24:40.780] A SIM card actually adheres to the GSM standard. [01:24:41.160 --> 01:24:54.700] There's actually a standard for the byte codes that a handset uses to communicate with the SIM card and vice versa, which has in no way, shape, or form have anything to do with the way smart cards work. [01:24:55.340 --> 01:24:58.000] SIM card is a specific type of smart card. [01:24:58.280 --> 01:25:07.740] There is no, like, one unifying smart card protocol that a hardware uses to... that hardware and software would use to talk to a particular SIM card. [01:25:07.980 --> 01:25:09.360] Well, you said there are two, right? [01:25:09.560 --> 01:25:11.500] I mean, it's not like there's 10 or something. [01:25:11.740 --> 01:25:15.480] There's either the ones made by Gemplus or... No. [01:25:15.740 --> 01:25:18.720] There's a number of different companies that make SIM cards. [01:25:19.000 --> 01:25:26.340] And there are a couple of different types of SIM cards depending on the GSM network in question. [01:25:26.660 --> 01:25:30.240] Not all GSM network SIM cards are interoperable. [01:25:31.120 --> 01:25:37.080] In North America, the two most prevalent companies are Gemplus and Orga. [01:25:38.140 --> 01:25:41.160] Overseas, there are other companies that are used. [01:25:41.280 --> 01:25:47.580] There's one such company in addition to Gemplus and Orga known as Sol Aic, S-O-L-A-I-C. [01:25:47.860 --> 01:25:50.040] They make a lot of SIM cards overseas. [01:25:50.980 --> 01:25:58.360] And some of the pinouts of the SIM cards are slightly different than other SIM cards are. [01:25:59.140 --> 01:26:06.000] Most definitely, some pinouts of smart cards in general can differ from SIM cards. [01:26:06.500 --> 01:26:17.980] However, if a SIM card manufacturer is going to claim to be compatible with the GSM spec, then their pinout and the bytecode that they use is going to have to be the same. [01:26:19.260 --> 01:26:36.840] But as far as getting access to the K-sub-I to read it and copy it onto a blank SIM or a test SIM, you're assuming that you can read the K-sub-I once you've gotten your hands on a SIM programmer. [01:26:37.080 --> 01:26:38.180] The answer is no. [01:26:39.000 --> 01:26:48.720] You can access... if you had a SIM card reader-writer right now, you could read all the public information stored on the SIM. [01:26:48.940 --> 01:26:55.960] You could not read the K-sub-I because simply it's not a readable field. [01:26:56.240 --> 01:26:58.080] It's a write-only field. [01:26:58.360 --> 01:27:00.880] And even then, only if you have permission to write to it. [01:27:01.000 --> 01:27:03.520] After you've authenticated yourself to the smart card. [01:27:03.720 --> 01:27:04.860] To the SIM card, rather. [01:27:06.120 --> 01:27:32.460] So, in essence, the only way you could really clone a phone in the absence of knowing some crazy way of defeating the physical security on a SIM card would be if you had access to a switch or through some other means you had access to the subscriber's secret key and you programmed it onto your own SIM card, [01:27:32.640 --> 01:27:36.280] then there's the possibility of cloning. [01:27:36.680 --> 01:27:37.560] But then and only then. [01:27:37.880 --> 01:27:45.220] It's extremely difficult to access that information on a real subscriber's active SIM card. [01:27:45.440 --> 01:27:49.440] And are PCS phones in this way similar to GSM? [01:27:50.240 --> 01:27:53.040] Well, a GSM phone is a PCS phone. [01:27:53.500 --> 01:27:54.980] Is it the other way around, though? [01:27:55.840 --> 01:27:56.120] No. [01:27:56.820 --> 01:28:02.120] GSM is one of the competing protocols that are being used in the PCS band. [01:28:02.380 --> 01:28:03.440] 1900 megahertz. [01:28:04.180 --> 01:28:06.480] GSM is the only one that uses SIM cards. [01:28:06.920 --> 01:28:09.940] And the only one that uses these particular algorithms. [01:28:10.940 --> 01:28:16.040] CDMA is really the direct competitor to GSM, but they do not use SIM cards. [01:28:16.240 --> 01:28:20.260] And the identity of the subscriber is stored in the handset. [01:28:20.460 --> 01:28:25.900] So it's really the same as all the other cellular phone networks are. [01:28:26.780 --> 01:28:32.020] With the exception of the fact that CDMA is that much more secure than the older networks. [01:28:34.140 --> 01:28:35.240] Hi, Phiber. [01:28:35.540 --> 01:28:43.020] In the UK, the two GSM 1800 operators have taken the practice of locking the phones to the networks. [01:28:43.980 --> 01:28:46.980] And then ask an extension of the amount of money to release the phones. [01:28:47.280 --> 01:28:49.560] Is it the same with the PCS operators in the States? [01:28:51.700 --> 01:28:53.080] Can you understand them? [01:28:53.740 --> 01:28:55.820] I couldn't understand what you said. [01:28:56.320 --> 01:28:56.520] Okay. [01:28:56.780 --> 01:29:02.900] In the UK, the two GSM 1800 operators are locking the phone to their own networks. [01:29:03.200 --> 01:29:08.920] If you buy an orange phone, you cannot use it on one-to-one and the reverse. [01:29:09.940 --> 01:29:13.120] You can actually use an orange phone on a one-to-one service. [01:29:13.320 --> 01:29:15.400] You can get the phone unblocked. [01:29:15.680 --> 01:29:19.720] Yeah, you can get it unblocked, but not when you get it at the origin. [01:29:20.700 --> 01:29:22.960] Which is not the case with GSM 900. [01:29:23.960 --> 01:29:27.460] And what is the situation in the States with GSM 1900? [01:29:27.840 --> 01:29:30.280] Are they locked initially or unlocked? [01:29:31.660 --> 01:29:40.720] Well, in the United States, all there is is GSM... there's only one GSM, PCS, which uses 1900 megahertz. [01:29:41.100 --> 01:29:50.200] So there isn't really a question of whether or not your phone is going to work on, you know, the older or the newer network, because there's only one anyway. [01:29:50.680 --> 01:30:00.960] As far as the question of roaming goes, it depends on if you're concerned about whether you're using the 900 megahertz GSM network in Europe? [01:30:01.300 --> 01:30:01.700] No, no, no. [01:30:02.020 --> 01:30:05.320] There are at least three operators in the States now. [01:30:06.540 --> 01:30:11.040] There are three PCS 1900 operators in the States, you mentioned. [01:30:12.040 --> 01:30:14.980] You mentioned OmniTel and two others, I think. [01:30:15.140 --> 01:30:18.800] There are three PCS operators in the States. [01:30:19.940 --> 01:30:21.080] There are three PCS. [01:30:21.080 --> 01:30:21.440] There's more. [01:30:21.540 --> 01:30:22.420] There's a lot more than three. [01:30:22.680 --> 01:30:24.480] Okay, there are several operators. [01:30:24.760 --> 01:30:34.840] So if you get a phone with one operator, let's say OmniTel, for instance, then you move to another part of the States. [01:30:36.020 --> 01:30:41.720] And can you use the same phone with a SIM from the other operator on the same phone? [01:30:42.120 --> 01:30:42.580] Would that work? [01:30:43.080 --> 01:30:43.340] Yeah. [01:30:43.600 --> 01:30:45.600] You don't have to bring the SIM alone. [01:30:45.760 --> 01:30:46.720] You can bring the whole handset. [01:30:47.700 --> 01:30:55.980] All the GSM operators in North America are banded together under the North American GSM consortium. [01:30:55.980 --> 01:31:08.520] And they're all under the agreement that any subscriber of any other GSM network within the United States can freely roam on any other GSM network within the United States. [01:31:08.760 --> 01:31:10.040] I'm not talking about SIM roaming. [01:31:10.340 --> 01:31:12.180] I'm talking about sort of phone roaming. [01:31:12.440 --> 01:31:15.840] That you put a SIM from another operator in your phone. [01:31:17.020 --> 01:31:19.060] That was impossible in the UK. [01:31:19.820 --> 01:31:22.580] You're talking about if I was to bring my SIM card overseas? [01:31:22.580 --> 01:31:23.220] No. [01:31:24.260 --> 01:31:28.660] You bring your phone from one part of the States to another part of the States. [01:31:28.800 --> 01:31:28.840] Oh, oh. [01:31:32.080 --> 01:31:32.480] Okay. [01:31:33.300 --> 01:31:35.000] You're talking about the... Wait. [01:31:35.640 --> 01:31:36.080] Which one? [01:31:36.700 --> 01:31:39.300] Unlocking your SIM card for use with other service providers. [01:31:39.500 --> 01:31:40.420] Is that what you're talking about? [01:31:40.980 --> 01:31:42.540] I'm asking if the phones are locked. [01:31:42.640 --> 01:31:43.700] Are sold locked or not? [01:31:45.700 --> 01:31:52.240] To my knowledge, in North America, anyway, they're not locking any of the phones for use with any other service providers. [01:31:52.240 --> 01:31:54.080] Everyone's in cooperation with each other. [01:31:54.280 --> 01:31:59.160] I've only actually ever heard of that on the UK PCN system between Orange and One to One. [01:32:00.260 --> 01:32:04.040] And another comment on the emergency numbers. [01:32:04.460 --> 01:32:14.180] What happened is that the manufacturers accept... I mean, build the phones for the different markets with an emergency number 9-11 in the States. [01:32:15.580 --> 01:32:17.580] Well, that was better except for the mic. [01:32:19.240 --> 01:32:27.320] When this number is dialed, with or without the SIM, it accesses an emergency channel. [01:32:27.600 --> 01:32:33.600] I mean, it frees the channel even if all the channels of the cells are busy for the emergency call. [01:32:33.600 --> 01:32:37.960] But then it is up to the network whether to accept or not the call. [01:32:38.680 --> 01:32:46.400] And in the UK, I know that at least both Orange and One to One refuse seamless emergency calls. [01:32:46.640 --> 01:32:48.240] But it's up to the network. [01:32:49.440 --> 01:32:51.380] They refuse emergency calls. [01:32:52.600 --> 01:32:57.040] You're saying in One to One in the UK, you can't make emergency calls without a SIM? [01:32:57.260 --> 01:32:57.940] That's correct. [01:32:58.140 --> 01:32:59.000] Yes, you can. [01:32:59.740 --> 01:33:04.100] The phone generates the emergency call, even dumps the channel if necessary. [01:33:04.780 --> 01:33:07.360] But then the network refuses the emergency call. [01:33:08.080 --> 01:33:08.340] Really? [01:33:08.340 --> 01:33:20.580] If you try and make a 9-1-1 or 9-9-9 call from a UK one-to-one PCN telephone, without a SIM card, you will be transferred to a one-to-one operator who puts you through to the emergency services. [01:33:20.960 --> 01:33:22.240] If you get a SIM. [01:33:22.960 --> 01:33:24.740] Without a SIM, the network refuses the SIMs. [01:33:24.740 --> 01:33:32.760] With or without the SIM, you will still be transferred to a one-to-one customer service operator who will transfer you to the emergency services whether you have a SIM card or not. [01:33:33.420 --> 01:33:34.560] It's the same with Orange. [01:33:35.100 --> 01:33:39.080] No, the call is initiated, but the network refuses it. [01:33:39.480 --> 01:33:41.500] It has been discussed quite a lot on the arrangement list. [01:33:41.780 --> 01:33:44.260] I don't know if you looked at it, and it's refused. [01:33:44.400 --> 01:33:45.180] This is saying that the network refuses it. [01:33:48.840 --> 01:33:50.600] I've actually used that facility. [01:33:50.880 --> 01:33:54.760] You can make a 999 call without a SIM card in your one-to-one telephone. [01:33:55.040 --> 01:33:56.820] I have a one-to-one, that's what I use. [01:33:57.060 --> 01:34:00.440] And I've actually made an emergency telephone call without a SIM card. [01:34:01.740 --> 01:34:11.220] The spec specifies that the phone has to make the emergency call on a high-party channel, but it doesn't specify that the network has to accept it or not. [01:34:11.920 --> 01:34:15.680] The network doesn't have to accept it, but one-to-one choose to accept it. [01:34:16.460 --> 01:34:23.500] And according to a recent discussion on the arrangement list, it was refused by both networks. [01:34:24.980 --> 01:34:29.600] So they said that it wasn't necessary to be able to make an emergency call without a SIM card? [01:34:30.320 --> 01:34:31.960] It's not that it's necessary or not. [01:34:32.200 --> 01:34:46.020] It's that, I mean, some networks, and according to recent discussion on the orange ringing list, it was mentioned, at least for orange and one-to-one, that both networks were refusing SIM-less emergency calls. [01:34:46.300 --> 01:34:51.880] That, in the GSM standard, there is no obligation for the network to accept the emergency call. [01:34:52.080 --> 01:35:01.760] There is an obligation for the mobile equipment to generate the call even without a SIM and with a high priority call. [01:35:02.060 --> 01:35:04.460] So, possibly dumping active channels. [01:35:04.800 --> 01:35:09.840] But there is no requirement for the network to actually accept the call. [01:35:10.020 --> 01:35:11.460] It's up to the network operator. [01:35:12.740 --> 01:35:13.320] Yeah. [01:35:14.580 --> 01:35:26.380] Well, I guess what it all boils down to is, are you going to get into an emergency situation with somebody else's GSM phone without a SIM card? [01:35:27.080 --> 01:35:34.220] I don't know how often that would happen, but at least in New York City, you could always run through a pay phone and dial 9-1-1. [01:35:35.180 --> 01:35:38.000] But, yeah, if the phone isn't vandalized. [01:35:42.790 --> 01:35:43.230] Handoffs. [01:35:43.990 --> 01:35:46.290] Wait, let's take this other question. [01:35:48.190 --> 01:35:59.890] As far as pricing is concerned, with GSM, does it work within the, like, standard area codes, like, for one thing? [01:36:00.110 --> 01:36:04.030] Or is there, like, a special area code for GSM subscribers? [01:36:04.390 --> 01:36:08.810] Now, as far as, well, why don't you tell them about the rate structure in the UK first? [01:36:08.830 --> 01:36:13.670] In the UK, you don't actually pay for incoming calls, which is one of the things that they get charged for over here. [01:36:15.610 --> 01:36:22.590] In the UK, it's, the cheapest service provider is either one-to-one or orange, which offer much the same service now. [01:36:23.650 --> 01:36:29.510] You pay a standard airtime monthly contract of about 17 pounds, 50 pence. [01:36:30.810 --> 01:36:40.330] And then you can have added extras, like 100 minutes, 200 minutes, 400 minutes, 600 minutes extra on top of your bill, which is free. [01:36:41.170 --> 01:36:53.910] You're free to make those calls to any other number except for another cellular phone, unless it's the same type of cell, same make of cellular phone anywhere in the UK at any time, night or day. [01:36:55.130 --> 01:37:03.150] Apart from that, the calls are about 25p during the day, peak time, until 7pm, 6pm with some service providers. [01:37:03.730 --> 01:37:07.290] After that, either 5 or 10 pence, depending on which service provider. [01:37:07.550 --> 01:37:08.790] That's with PCN. [01:37:08.930 --> 01:37:12.870] With GSM, they're actually a lot higher rates. [01:37:13.050 --> 01:37:15.770] During the day, it can be up to 78 pence per minute. [01:37:16.750 --> 01:37:20.690] And during the evening, about 35 pence per minute. [01:37:21.350 --> 01:37:23.410] I don't know, what are the rates in the US? [01:37:23.650 --> 01:37:31.530] In the US, to take Omnipoint as an example, the real value is in the feature package that you choose. [01:37:32.170 --> 01:37:35.850] As far as long distance goes, either it's long distance or it's not. [01:37:36.190 --> 01:37:43.110] The way they break it down is off peak, peak, and long distance. [01:37:44.490 --> 01:37:52.090] Off peak is anything after, I believe, about 5 or 6 o'clock. [01:37:52.850 --> 01:37:57.770] And peak would be during the day. [01:37:58.530 --> 01:38:14.110] As far as long distance goes, I believe the way it breaks down, if I'm not mistaken, it's typically 25 cents a minute for off peak, local. [01:38:15.430 --> 01:38:21.170] And again, 25 cents a minute for off peak, local isn't particularly great. [01:38:21.430 --> 01:38:28.570] But just as an example, the feature package that I have, I pay 79.99 a month. [01:38:28.810 --> 01:38:34.430] And I get 300 free minutes, which is both peak and off peak. [01:38:34.430 --> 01:38:48.630] I get 100 free emails, 100 free pages, and a myriad of other things, including weather reports, news headlines, and so on. [01:38:48.970 --> 01:38:59.670] So you really need to contact the provider of your choice and find out what package deals they have, because that's where you really rack up the mileage in free minutes. [01:38:59.670 --> 01:39:06.750] If you're going to gauge somebody by how much they charge by the minute, it's not really the complete picture. [01:39:07.070 --> 01:39:13.570] It's really, you should see how many free minutes you get for the buck and really judge it by that. [01:39:15.750 --> 01:39:24.450] You said that, did you say that each GSM local provider has a monopoly in the area, or what was the deal there? [01:39:25.830 --> 01:39:31.130] Yeah, inadvertently, I mean, it wasn't really done that way on purpose. [01:39:34.310 --> 01:39:49.390] Among some of the first companies to set up in the particular place that they got licensed by the FCC to operate in, since they got such an early start, there was really no reason for any other of the companies that came along to try to compete with them. [01:39:49.590 --> 01:40:02.030] So rather than doing that, they stuck to their home area that they were the first to set up in, and they organized a consortium with all the other companies that set up in their respective geocentric areas. [01:40:02.250 --> 01:40:04.590] And it's more of a cooperative kind of thing. [01:40:05.130 --> 01:40:18.630] But since the SIM card can be, it works for any phone like in the country, what's to prevent someone from like buying a phone in Los Angeles and then using it all the time in New York? [01:40:18.870 --> 01:40:22.510] Can they just not get a local New York number like from Los Angeles? [01:40:22.790 --> 01:40:23.770] Does it have to be... [01:40:23.770 --> 01:40:33.370] No, see, the thing is that the thing that the North American GSM consortium is in agreement over is what the roaming charge is for the call time per minute. [01:40:34.210 --> 01:40:40.090] And that's independent of what the cost of the call is on the local network for long distance. [01:40:40.870 --> 01:40:46.450] If, for example, I'm using my phone in San Francisco, I'd be using Pacific Bell Mobile. [01:40:46.970 --> 01:40:58.970] And I believe the current rate for the per minute roaming charge off peak is... Last time I checked, I think it was about 69 cents a minute. [01:40:59.330 --> 01:41:09.870] And on top of that would be the cost of wherever it was that you called, which would be relative to whatever company that you were roaming on. [01:41:10.210 --> 01:41:13.770] But the roaming charge per minute is always there and that's a constant. [01:41:14.310 --> 01:41:19.170] So they're at least guaranteed that, no matter where you bought your phone and where you're currently using it. [01:41:19.390 --> 01:41:35.010] But would it be more... Would it be more inexpensive if someone were to buy one phone in Los Angeles and one in New York and whenever he wanted to call his friends in Los Angeles uses Los Angeles SIM chip in New York? [01:41:35.350 --> 01:41:38.250] Would that save money or would it be about the same? [01:41:38.810 --> 01:41:41.410] I don't really follow what you're driving at. [01:41:43.130 --> 01:41:50.150] If you bought a phone locally in Los Angeles, took it to New York and you had another phone that you bought in New York. [01:41:50.570 --> 01:42:00.050] Now, since it's only the SIM chip that matters, you can just carry one phone around and two SIM chips and transplant your Los Angeles phone chip into your New York phone. [01:42:00.390 --> 01:42:08.770] Would that save you money on long distance charges if you wanted to call your friends in Los Angeles from New York having a Los Angeles phone? [01:42:10.250 --> 01:42:21.690] Well, technically, no, because you're still paying a roaming charge and the fact that you're making the call on the local network, it doesn't matter where your phone number is. [01:42:21.830 --> 01:42:27.150] The fact that I have... Say I have a 917 phone number and I'm in San Francisco. [01:42:28.270 --> 01:42:32.750] If I call somebody in New York, it's not as if I'm in New York. [01:42:32.970 --> 01:42:36.490] I'm making a call from San Francisco to New York. [01:42:36.670 --> 01:42:42.030] So I'm billed a roaming charge plus a long distance charge from Pacific Bell Mobile. [01:42:43.330 --> 01:42:53.390] It goes back to whatever company you're home to, or rather whoever you're home to at that particular moment, not who your home company is. [01:42:53.570 --> 01:42:55.410] My home company is Omnipoint. [01:42:55.730 --> 01:43:07.610] If I go to Los Angeles or San Francisco, and I make a call from there to somebody back in New York, it's a long distance call from Pacific Bell Mobile to New York, to somebody living in New York. [01:43:07.830 --> 01:43:10.150] And I'm going to be billed as a long distance call. [01:43:10.450 --> 01:43:15.050] It's not going to be as if I'm making a call from a 917 number to somebody else in New York. [01:43:15.050 --> 01:43:16.030] It's not how it works. [01:43:19.330 --> 01:43:19.910] Question. [01:43:24.100 --> 01:43:25.300] Now I can talk to you. [01:43:25.780 --> 01:43:30.400] One last question, probably total esoterica, but I'll ask it anyway. [01:43:31.720 --> 01:43:33.100] I wear hearing aids. [01:43:33.400 --> 01:43:38.760] GSM phones run with this radio pulse of about 170 hertz. [01:43:38.880 --> 01:43:40.360] I forget what the number is exactly. [01:43:40.760 --> 01:43:42.780] This screws up hearing aids really badly. [01:43:43.680 --> 01:43:51.440] So the question I have, questions I have, are one, what's the interference? [01:43:51.660 --> 01:44:01.620] Is it direct EMF from the magnetics in the phone or indirect induced into the hearing aid from the antenna? [01:44:02.140 --> 01:44:04.860] And two, what are people doing about this? [01:44:04.920 --> 01:44:07.700] I know there's some noise in the industry about it. [01:44:09.280 --> 01:44:15.340] Well, as far as, if you're concerned about health hazards of using GSM phones? [01:44:15.340 --> 01:44:15.500] No, no. [01:44:15.700 --> 01:44:16.560] Not health at all. [01:44:16.780 --> 01:44:17.760] I wear hearing aids. [01:44:18.240 --> 01:44:18.720] Right. [01:44:18.900 --> 01:44:21.300] They pick up induced EMF from things. [01:44:21.440 --> 01:44:21.660] Right. [01:44:22.000 --> 01:44:25.140] Especially, oh, maybe in the microwave region. [01:44:25.400 --> 01:44:25.780] Right. [01:44:26.200 --> 01:44:29.360] And so they pick this up from GSM phones. [01:44:31.300 --> 01:44:35.760] And the question, you know, it's not a very good hack toy if I can't hear them. [01:44:38.020 --> 01:44:46.740] Well, as far as what they're doing about something like that, I know this is probably a funny question, but have you tried using the other ear? [01:44:52.300 --> 01:44:53.080] Yeah, right. [01:44:56.080 --> 01:44:56.520] Right. [01:44:56.740 --> 01:44:57.660] No, I understand that. [01:44:59.040 --> 01:45:08.500] As far as being able to do something about that to prevent that, I mean, right now there really is no way to prevent you picking up harmonics from the phone inside your hearing aid. [01:45:08.960 --> 01:45:13.020] I mean, I guess you could complain to the FCC. [01:45:13.080 --> 01:45:14.900] I don't know how far that's going to get you. [01:45:15.500 --> 01:45:19.000] But I don't really know what to tell you. [01:45:22.860 --> 01:45:25.060] Have you tried using a hands-free kit? [01:45:29.780 --> 01:45:31.840] One of the Ericsson hands-free kits? [01:45:32.380 --> 01:45:33.620] Does that help at all? [01:45:33.840 --> 01:45:34.620] Does anyone have any experience? [01:45:34.620 --> 01:45:35.400] Say again, did you catch that? [01:45:36.480 --> 01:45:43.040] I've used the hands-free kit myself, which is basically the little earphone and the microphone that you could clip on your collar. [01:45:43.380 --> 01:45:47.040] No, I haven't tried GSM phones much because they live up in Boston. [01:45:47.640 --> 01:45:52.140] Because I do get interference when using a personal stereo, when your cellular rings. [01:45:52.900 --> 01:45:53.080] Really? [01:45:53.400 --> 01:45:56.640] And if you have a hands-free kit, that doesn't seem to affect it. [01:45:56.960 --> 01:45:58.980] Yeah, that's something I do intend to check out. [01:45:59.620 --> 01:46:01.340] Yeah, you should definitely look into that. [01:46:01.460 --> 01:46:02.340] They're not that expensive. [01:46:11.830 --> 01:46:14.810] Here, why don't you come up and use this mic? [01:46:18.890 --> 01:46:19.710] It's not on? [01:46:19.710 --> 01:46:20.290] Here. [01:46:22.250 --> 01:46:29.490] Apparently, there's something going on between Sprint PCS and the GSM companies. [01:46:30.190 --> 01:46:41.270] Sprint PCS, which uses CDMA, is trying to get the FCC to mandate hearing aid compatibility on all these handsets. [01:46:42.210 --> 01:46:47.790] Because the GSM phones, for some reason, and I don't know why, maybe fiber can answer this question. [01:46:48.390 --> 01:46:56.330] The GSM phones do not, are not hearing aid compatible, yet the phones that utilize the CDMA technology are. [01:46:56.530 --> 01:46:57.410] I don't know why that is. [01:46:57.530 --> 01:46:58.330] Do you know why that fiber is? [01:46:58.430 --> 01:47:12.910] But apparently, Sprint PCS is trying to make an end run and knock out the competition by lobbying the FCC to require this hearing aid compatibility when it's easy for them to, their phones are apparently compatible with it. [01:47:12.970 --> 01:47:17.930] And that's something about the CDMA versus ESM technology that makes one hearing aid compatible with the other. [01:47:18.110 --> 01:47:19.030] I don't know why. [01:47:19.230 --> 01:47:20.430] Do you know anything about that? [01:47:23.930 --> 01:47:29.190] This is the first I'm hearing about all these problems with hearing aids. [01:47:35.850 --> 01:47:36.370] Yeah. [01:47:37.130 --> 01:47:45.770] Well, I mean, I would just assume that anybody that has a hearing aid or a pacemaker is going to have a problem with anything up in the microwave range. [01:47:48.250 --> 01:47:51.050] The CDMA phones don't have this problem. [01:47:59.850 --> 01:48:00.410] Right. [01:48:26.800 --> 01:48:40.240] Well, I'm at a loss because I'm not really clear on which component of GSM is actually causing the interference and which component is lacking in CDMA, which doesn't cause the problem. [01:48:40.720 --> 01:48:45.740] If anybody has any foresight into this, I'd love to hear about it afterwards. [01:48:48.940 --> 01:49:00.340] I'm fine, but we've established that as far as the eavesdropping goes, GSM or anything using SIM card technology is kind of secure unless you're on the apartment rooftop with a lot of expensive equipment. [01:49:00.800 --> 01:49:10.500] If a call is made on the same network, does the call actually break out onto the PSTN or does it stay within the mobile switching unit? [01:49:10.940 --> 01:49:15.820] You mean, for example, if I used my GSM phone and called somebody on a landline? [01:49:15.900 --> 01:49:16.740] On the same network. [01:49:17.000 --> 01:49:18.440] If you call someone on the same network. [01:49:18.700 --> 01:49:23.200] Oh, if I call somebody on the same network, it stays on the GSM network. [01:49:23.380 --> 01:49:28.220] So it's secure right the way through either being encrypted over the airwaves or on a lease line, yeah? [01:49:28.560 --> 01:49:33.400] Yeah, it's actually it's different than the way it works, for example, in the UK. [01:49:33.820 --> 01:49:53.820] In the UK, since one company might span the entire country, you'll make a phone call from a handset to another handset on the same network and the mobile switch might actually assign that call a temporary mobile station roaming number. [01:49:53.980 --> 01:50:01.220] And that mobile station roaming number will map out to a non-existent phone number on the public switch telephone network. [01:50:01.440 --> 01:50:10.720] And that will get sent along with the point code of the SS7 node on the public switch telephone network's SS7 enabled switch. [01:50:11.480 --> 01:50:29.840] And that will be sent over the SS7 network of the PSTN to the nearest PSTN or whether or not it's the same PSTN, to the nearest switch on that PSTN, And finally to the nearest mobile switch at the other end that belongs to the same company. [01:50:30.160 --> 01:50:49.620] In the US, since each individual GSM provider covers a relatively smaller area than a single provider does in Europe, they don't actually bridge the gap over the public switch telephone network. [01:50:49.740 --> 01:50:51.140] It stays on their own network. [01:50:51.140 --> 01:51:00.780] So if I make a call from one Omnipoint subscriber, say myself, to another Omnipoint subscriber, it never leaves Omnipoint. [01:51:00.940 --> 01:51:02.260] So that's pretty secure then. [01:51:02.620 --> 01:51:02.880] Yeah. [01:51:03.180 --> 01:51:13.420] And if someone did manage to duplicate the SIM card, effectively cloning the phone, that would only enable them to make calls on your bill rather than eavesdrop in any way, right? [01:51:14.200 --> 01:51:15.120] Definitely, yeah. [01:51:15.120 --> 01:51:31.800] If somebody was able to duplicate my SIM card and they began using their SIM card in a handset and I didn't happen to be using my phone at the moment, then they would be able to make calls and as far as the switch was concerned, it was me making them. [01:51:32.040 --> 01:51:32.140] Uh-huh. [01:51:33.000 --> 01:51:33.420] Okay, great. [01:51:33.580 --> 01:51:33.720] Thanks. [01:51:34.480 --> 01:51:35.620] Can I just snag that for a second? [01:51:36.640 --> 01:51:38.880] Can we just pause while I change tapes, please? [01:51:39.220 --> 01:51:39.820] 2 a.m. [01:51:40.100 --> 01:51:42.300] We should probably make this the final question. [01:51:42.460 --> 01:51:43.960] It's already 2 a.m. [01:51:43.960 --> 01:51:47.980] Considering most of everyone has left already and I'm sure everyone's tired. [01:51:48.900 --> 01:51:54.700] I'm waiting to see which is better for me to go with, which is Sprint PCS or Omnipoint. [01:51:54.900 --> 01:51:56.600] And I understand the security issues. [01:51:57.760 --> 01:52:03.920] Sprint PCS offers much better deals right now, financially, packages, than Omnipoint does. [01:52:04.080 --> 01:52:13.060] And I'd like your comments on that and also on poor building penetration that both providers have, prospects for improvement in that. [01:52:13.060 --> 01:52:20.000] And also, can you be tracked, can your location be tracked when you're using GSM or Sprint PCS? [01:52:20.600 --> 01:52:20.920] Okay. [01:52:21.080 --> 01:52:33.840] Well, to start, as far as Sprint PCS having better rates, it's... if you're talking about the CDMA end of a Sprint PCS, try bringing your phone to Europe. [01:52:34.340 --> 01:52:35.240] You can't. [01:52:35.400 --> 01:52:36.320] It's not going to work. [01:52:36.600 --> 01:52:42.140] I mean, there are certain things that you're getting where you're really getting what you pay for. [01:52:42.140 --> 01:52:58.020] I mean, by being an Omnipoint subscriber, Omnipoint has roaming agreements with dozens of countries around the world where you could simply rent a handset and take your SIM card with you and go and use your phone overseas. [01:52:59.040 --> 01:53:04.900] No other countries overseas have accepted CDMA as a standard of any kind. [01:53:05.920 --> 01:53:12.280] If you want to compare the rates of Omnipoint and Sprint Spectrum, you're really talking about one and the same thing. [01:53:12.540 --> 01:53:16.280] I mean, their local rates might differ slightly. [01:53:16.980 --> 01:53:23.560] But again, their rates per minute as far as roaming goes are the same. [01:53:23.560 --> 01:53:24.760] They're in agreement on that. [01:53:26.300 --> 01:53:43.360] The other question that you had concerning whether or not someone can tell where you are, they can tell which mobile switch you're home to if they can access the switch. [01:53:46.080 --> 01:54:02.180] If they had... see, it's... if they were able to decrypt the actual traffic going over the airwaves, then they would be able to get a pretty good idea of where you were. [01:54:02.480 --> 01:54:08.000] The most direct approach would be to gain access to a cell site. [01:54:08.400 --> 01:54:29.100] And if you could somehow physically interface with that cell site and be able to determine which phones are actually homed to that cell site, and in essence home to which mobile switch, then you'd be able to get a pretty good idea of where somebody is. [01:54:29.300 --> 01:54:32.400] But this isn't something that's easy to do. [01:54:32.840 --> 01:54:35.020] How about from a law enforcement perspective? [01:54:35.300 --> 01:54:45.700] From a law enforcement perspective, there's actually provisions made in the design of the GSM switch with law enforcement in mind. [01:54:45.700 --> 01:54:57.620] There's actually... there are... there is a table in the switch that allows calls to be rerouted to a law enforcement listening station. [01:54:58.660 --> 01:55:16.980] It's really inconvenient for law enforcement to use this because basically the switch manufacturers left the headache up to the law enforcement agency to make sure that the call was rerouted back to where it was supposed to go. [01:55:17.340 --> 01:55:38.800] In the example of the Northern Telecom switch, Northern Telecom's DMS MSC, Mobile Switching Center, there's a table in the DMS MSC that... where you would specify the IP address of the... [01:55:38.800 --> 01:55:50.020] where the law enforcement agency had a computer set up on the internet, which hopefully would be on an intranet, where the call-related data would be... would be relayed. [01:55:50.460 --> 01:55:55.960] And then there... you would provide a phone number through which the call would be rerouted. [01:55:56.620 --> 01:56:08.220] So let's say, for example, I'm gonna make a phone call to some guy and this particular guy's phone calls are being... [01:56:08.220 --> 01:56:11.080] eavesdropped on by law enforcement. [01:56:12.420 --> 01:56:15.180] So what's gonna happen is... [01:56:18.900 --> 01:56:28.320] To use a better example, let's say that I'm making a mobile phone call and law enforcement is eavesdropping on my mobile phone. [01:56:29.540 --> 01:56:30.140] What? [01:56:32.140 --> 01:56:33.520] How would they do that? [01:56:34.360 --> 01:56:36.100] Oh, why would they do that? [01:56:36.300 --> 01:56:37.040] Oh, I don't know. [01:56:38.880 --> 01:56:47.920] Anyway, if they were to do such a thing, what they would do is that, with a court order hopefully, they would contact the GSM provider. [01:56:48.360 --> 01:57:03.120] The GSM provider would stick the IP address of the law enforcement agency's computer that they wanted to receive all the call data, for example, who I was calling, the phone number of the person I was calling, so on and so forth. [01:57:03.640 --> 01:57:11.860] As soon as I dialed the number, that information would be relayed by the mobile switch to law enforcement using the IP protocol. [01:57:12.960 --> 01:57:22.360] Then the switch would reroute my phone call, regardless of what number I dialed, to the law enforcement listening post. [01:57:22.640 --> 01:57:23.120] Okay? [01:57:23.540 --> 01:57:41.060] Now, it's up to law enforcement to have the proper recording equipment set up to record... start recording the call, and at the same time reroute the call out on another line to the destination that it was provided by the switch over the IP protocol. [01:57:42.680 --> 01:58:05.660] So, this might sound kind of ridiculous, and I think it was really the switch manufacturer's way of saying, we think this new law, this new digital telephony law is really stupid, so we're just going to put something in there to satisfy the law, but not make it any easier for you to do this thing. [01:58:07.380 --> 01:58:13.600] But, the concept is there, and if they did want to set something like that up, it is possible. [01:58:13.960 --> 01:58:15.380] So, that's how it would be done. [01:58:18.120 --> 01:58:24.520] I think we should probably wrap this up, because I'm kind of falling asleep here, and I think everybody in the audience is... Oh wait, we have a question! [01:58:24.760 --> 01:58:27.660] Yeah, I have a quick question for Tom. [01:58:28.440 --> 01:58:31.220] Can you grab Mark and take him off stage with you now? [01:58:33.040 --> 01:58:35.640] He wants us to leave... He wants us to leave the stage. [01:58:35.980 --> 01:58:38.200] Wait, who's the guy that brought up... You want I should whack him? [01:58:38.380 --> 01:58:41.220] Who brought up the mock-up of the Nokia Communicator? [01:58:43.140 --> 01:58:49.840] On the location of a phone, Orange had a phone stolen before the launch of the network. [01:58:51.820 --> 01:58:55.760] And with the cooperation of the police, they managed to find the person that stole the phone. [01:58:56.080 --> 01:58:58.440] Wait, hold on, wait, we didn't know somebody was talking here. [01:58:58.700 --> 01:58:59.580] Could you repeat that? [01:58:59.580 --> 01:59:06.120] Yeah, on the location of a phone, Orange had a phone stolen before the launch of the network. [01:59:06.940 --> 01:59:09.320] And with the cooperation of the police, they managed to find it. [01:59:09.460 --> 01:59:15.220] And they claimed that they are able to locate a phone in 150 meter error range. [01:59:15.720 --> 01:59:17.040] I'll tell you what... [01:59:17.040 --> 01:59:21.140] Yeah, they can use that using triangulation methods between three cell sites. [01:59:23.460 --> 01:59:31.560] Basically, when you transmit between the cell sites, they measure the strength of the frequency, the strength of the transmission between the three cell sites. [01:59:31.720 --> 01:59:34.420] And then using a triangulation method, they can point you down. [01:59:36.220 --> 01:59:36.740] Cool. [01:59:37.380 --> 01:59:41.280] Well, for whoever is still awake, it's after 2 a.m. [01:59:41.400 --> 01:59:44.820] And I think whatever questions remain, you should just ask us personally. [01:59:45.120 --> 01:59:46.220] And we want to wrap this up. [01:59:46.540 --> 01:59:47.260] Are we done yet? [01:59:47.440 --> 01:59:48.520] Are we going to the rave or what? [01:59:48.520 --> 01:59:51.280] Well, I think we're going to finish this off. [01:59:51.440 --> 01:59:53.900] And whoever's left, thanks for coming. [01:59:55.520 --> 02:00:01.300] And whoever chickened out and left because they were too tired, you could tell them that I personally said that they suck. [02:00:01.800 --> 02:00:03.900] But anyway, thanks for coming. [02:00:04.640 --> 02:00:06.480] This has been the GSM panel. [02:00:06.800 --> 02:00:07.500] Thank you.