I'm Michael Moore, the director of Canadian Bacon and the producer-host of TV Nation. But we all know this is a radio nation. So listen to 99.5 FM WBAI, New York. And you're listening to radio station WBAI. Time is 8 o'clock. Time for Off the Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself off shaving, now I can't make a call. It couldn't be yet much worse, but if they could, they would. I'm Billy Bump, but I best expect the worst. I hope that's understood. I'm Billy Bump! We'll be right back. You little wonder, little wonder you. Well, the thing that we've been talking about for the last couple of years on this radio show actually seems to have taken place. I don't know how many of you read the newspapers. Actually, I think quite a few of you do. And if you did, if you listen to some other radio programs, maybe even see it on the TV news, you may have heard this story about the Smart Card Developer Association known as the SDA. And two UC Berkeley researchers who jointly announced yesterday that digital GSM phones are susceptible to cloning. The thing that we've been talking about for years, about how it's not possible. You know, well, we didn't really say it wasn't possible. We had people on the show saying it wasn't possible, that we actually were secure if we used these GSM phones. GSM being companies like Omnipoint, Sprint Spectrum, other companies around the nation, around the world actually. Because GSM is the standard that the rest of the world has already adopted. And we're kind of lagging behind. Well, maybe it's a good thing we're lagging behind because, according to these people, they were able to clone GSM phones. Most widely used cell phone standard in the world, more than 79 million GSM phones in use worldwide. In contrast, there are about 58 million U.S. cell phone users of all kinds, both analog and digital, including some GSM. We'll get into some more of the details as to exactly what these guys did. First, let's take a brief look at the New York Times article of today. On page D1, written by none other than our friend John Markoff. Researchers crack code in cell phones. Weakened encryption raises security concern. Now, that's the interesting part. The weakened encryption. In successfully cracking a widely used encryption method designed to prevent the cloning of digital cellular phones, a group of University of California computer researchers believe they have stumbled across evidence that the system was deliberately weakened to permit government surveillance. Fascinating, isn't it? I mean, this is the kind of stuff that you dream about, but it seems to have actually taken place. Very, very strange. We have on the phone with us Mark Brisseno, I believe. Is I pronouncing your name correctly? Mark Brisseno. Mark Brisseno. And you're the director of the SBA, is that correct? That's correct. So, you're part of this whole thing. I mean, first of all, how long have you been attempting this kind of crack? Let me first say it's an honor to be on your show. I've been a 2600 magazine reader for a good number of years. Well, thanks. It's good to know that our readers are inspired to do just this kind of thing that will drive everybody else crazy. Well, it had to be done. Absolutely. It had to be done. At any rate, the SmartCard Developer Association actually started out as an association trying to help developers, software developers, wanting to integrate smart cards with their application in that process, since it is very difficult to get useful information from smart card vendors. The toolkits are all highly proprietary and so forth. So, we actually developed some universal smart card software that allows you to talk to any smart card, really. One of the smart cards we decided to support were GSM SIMs. In the process, and this was in late December of last year, late December of 1997, we realized that there was preciously little known about the inner workings of the security features in a GSM SIM. At least very little public knowledge. Of course, we discovered that from the specifications that the SIM performs both authentication of the device as well as generation of the on-the-air voice privacy encryption key, which is then used by an algorithm inside the handset itself to encrypt the communication and retain the voice privacy. Looking at this, in earnest, began about late January, early February, when our association started piecing together information that was actually publicly available, the key component being a leaked document that has been circulating in the academic community for a number of years now that describes the basic structure and then some other pieces and hints that we found in the literature. The remaining component then was reverse-engineered from using a Pacific Bell GSM SIM manufactured by Schlumberger. What kind of leaked document was this? The document says GSM security study. It's from the late 80s. It is the document that was also used by Ross Anderson and Bruce Schneier to write their implementation of A5, the actual on-the-air encryption algorithm. The implementation, by the way, that has been written is not completely correct. But it's the same document. But while they only looked at the on-the-air encryption algorithm, we decided to look at the authentication and key generation side of things. Now, the paper is by no means sufficient to implement this algorithm, but it gave us an outline into which area we should focus our investigations. Now, I have a quote here in the New York Times from George Schmidt, president of Omnipoint, which is our local GSM company. He says, My hat goes off to these guys. They did some great work. I'll give them credit, but we're not at any risk of fraud. Is that an accurate statement? Well, I would say that statement would be inaccurate. I think the GSM providers are very much at risk of fraud. First of all, while it is true that we, for our research, extracted the secret information from the SIM by inserting the SIM into a smart card reader and asking the SIM to identify itself, it is collecting the corresponding responses and from that deducting the internal key. It is also true that this is a normal process that's taking place every time a GSM phone roams into a new area. The base station will ask the SIM to identify itself, and the SIM will respond to the challenge with a response. If a base station, a legitimate base station, can perform this over the air, then it stands to reason that it may be possible that attackers that do not operate legitimate base stations might also be able to perform this over the air, and in which case they might be capable of extracting the keys from the SIM. Now, from all the SIMs, or I should say from all the GSM phones, and it's in the environment of the Rogue base station, the GSM providers claim to defend against clones on the network, but we have seen no evidence of this. We have received now reports from individuals in Europe, Asia, Australia, and the U.S., all of which indicate that the GSM providers, in fact, do not defend against clones on the network. The reports we've seen so far, and we did not do these studies ourselves, given the questionable legality of them, to actually put a clone in operation on the network. All the responses we received was that, yes, the networks did not defend against clones, and if you were to call the cloned number, then one out of the cloned phones will ring. Just one, not both? Just one, just one, and it apparently occurs at random. That's something. This is not an easy process, though, is it? The process is actually fairly straightforward. What we do is to, once, certainly discovering it was not an easy process, but at the state we're at now, it would be as simple as running our software. It's taking a SIM, inserting it into a smart card reader, and run our software, which would extract the internal key from the SIM within about eight hours. That's something. When did you realize that you were really close to breaking this? We've realized this when, and here now I need to tell a little bit more about the history of this break. Once the SmartCode Developer Association, in this case, apparently myself, had reverse-engineered Comp128. We approached Ian Goldberg and David Wagner at UC Berkeley, two cryptographers that have a long history of finding flaws in widely fielded systems. David Wagner last year discovered a flaw together with, I believe, Bruce Schneier on the privacy features of, I believe it was CDMA, touch-tone encryption. And the two together found a fatal flaw in Netscape's random number generator a few years back that made national headlines. So once I had the algorithm, and the algorithm at this point had been kept secret by the GSM consortium for many, many years. It was provided to employees at base station manufacturers and same manufacturers on a need-to-know basis, meaning the algorithm had never seen public review. So I provided David Wagner and Ian Goldberg with the algorithm, which then, within two hours, had discovered the fatal flaw that would allow them to create the software that would extract the internal key right out of the SIM. Now, I believe you said that if it wasn't so proprietary, if it wasn't so hidden, they actually would be more secure. Oh, absolutely. It would be wrong to look at what happened here to GSM as the failure of a particular algorithm. It was a failure of the design process. It's shown so many times in the past, a design process conducted in secret and without public review will invariably lead to an insecure system. And here we just have another example of how security by obscurity is no security at all. Had the design process been open and public as opposed to closed and secret, the flaws in Comp128 would have been discovered long before Comp128 would have been fielded. It's certainly long before it would have been discovered before it would have even been fielded, and not at a point when it had been installed in, as we now just found out today, well over 80 million devices. And what's going to have to happen now for them to fix this? Well, at a minimum, well, for a true fix, at a minimum, new SIMs would have to be issued to all subscribers worldwide. Wow. But we don't rule out a need for software upgrade on the base stations. There is something that can be done, certainly in the meantime, GSM providers can make sure that, or can start implementing software that would detect clones in the network. This really shows just how arrogant these designers really were. They thought that the cryptography could never be broken and didn't even bother to put in defenses into the system in case the cryptography would be broken. Amazing. I mean, you'd think people would learn from, you know, things of the past. You would. You would. But, again, GSM was designed a long time ago. I don't know exactly when the design phase was, but we're looking here at something that was designed quite a few years ago by a European consortium in secret. In a way, the U.S. GSM providers now are inheriting the results of design flaws that were performed, committed many years ago. We certainly hope that now that Comp128, which will have to be replaced and removed from the system, replaced with a more secure algorithm, we certainly hope that this algorithm and, in fact, the entire security infrastructure of GSM will see public review as soon as possible. I'd like to just look at something that came over today from the Netly News, basically reaction to all of this. And there has been quite a bit of reaction, obviously. So I'd like your comments on this. Basically, they say, our report yesterday that GSM cell phones can be cloned has some affected companies crying foul. Terry Phillips, Public Affairs Director for Omnipoint, calls the crack interesting but not significant. It's not news. Phillips claimed that digital ID sniffing cannot be done over the air, which, of course, contradicts what eminent cryptographers and security experts say. Phillips did correctly point out, however, that we said there are 80 million GSM phones nationwide when we meant worldwide. Phillips also sniped at the motivations of the merry band of cypherpunks who cracked the proprietary encryption code. He suggested that they're acting on behalf of and being paid by the competition. They've been working on this for years. They're aiming for a million-dollar prize. They never actually broke the algorithm. What do you have to say to that? Quite amazing. Let's address this one by one. First issue was, I believe, the feasibility of an over-the-air attack. Now, I am not a radio engineer. I would defer this to radio engineers that would be able to determine just how difficult it would be to either generate a rogue base station from scratch or turn a GSM phone into a rogue base station requesting challenges from its environment. Certainly, all the radio electronics, I would think, are there. So, as far as the feasibility of an over-the-air attack is concerned, I really defer this question to somebody more qualified, perhaps, than I am. It doesn't look that difficult to me. Regarding the motivation of attacking the system that we're being paid for with suitcases full of cash by Qualcomm or whoever else GSM's competition may be, I would assume it's primarily the CDMA providers, is that there's absolutely no truth to this whatsoever. To anybody who feels that we should be paid for this effort, my mailing address is up on our webpage, www.scard.org. We do accept checks. We do accept anonymous suitcases of cash. We did not receive a dime from anybody. In fact, the reverse engineering of the algorithm was performed by myself with a little help from a large number of parties in the course of about two months, literally in my evenings and weekends, on a budget well below $100. Below $100? Well below $100. Does that include food? Well, my food expenses remain constant during the time. It's not that I spent only $100 during this time, but the cost associated with the project was well below $100. Well, that's great. I mean, what kind of response have you gotten, though, in the last 24 hours? You must be flooded with mail. I'm surprised you're able to answer us. Well, actually, yesterday's response was quite amazing. Within a matter of hours, the news started calling, but today it even increased due to the New York Times article. Due to the New York Times article. But as I told you at the beginning of the show, it's an honor to be on 2600. On a 2600-based radio show. Did you, by chance, catch the headline in yesterday's Wall Street Journal? Now, that was something. They basically drew attention to this, but the headline read, Hackers can make free calls. It always boils down to hackers making free calls. That's the biggest worry that they have. That apparently is the biggest worry they have. We found, which is, in a way, why this break is so significant, because had we just attacked the voice privacy features, while this is of great interest to the consumer and of some interest, as opposed to the providers, and of definitely negative interest to the government, it's not as significant as a breach in the authentication system. That will hit the providers where it hurts, which is the pocketbook. Let's talk about what I consider to be the most worrisome issue of all this, and that's the intentionally weakened encryption. What's that all about? Yes. As we finished the analysis and realized how Comp128, the cipher, or I should say the hash function that I discovered, relate to both the authentication and the key generation. I have to get a little bit technical here. When a GSM cell phone receives a challenge from the base station, it runs this through an algorithm called RunGSM algorithm, which is performed on the SIM, the output of which contains two components. One is a response to the challenge, which the phone sends back to the base station, and if the response is correct, then the phone is allowed to make calls. And at the same time, an encryption key that is then handed on to the handset, to the mobile phone, which then uses it to encrypt the voice traffic over the air. The cipher used inside the phone is using a 64-bit key. Typically, a cipher, a well-designed cipher, tends to be stronger the larger the key used is. This is A5, the encryption cipher, is using a 64-bit key, which by today's standards would not be adequate. Industry experts advise to use symmetric keys of at least 90 bits. But we discovered that the key generation algorithm actually does not generate a 64-bit key to be used by A5. Well, I shouldn't say that. It does generate a 64-bit key, but then erases the last 10 bits of the key with zeros, just overwrites it with zeros, so that only 54 bits of the key are actually unknown. You have 54 bits of key, of effective true key. You have 10 bits of zeros, which are essentially just padding, and that is handed on to a cipher that's expecting a 64-bit key. Now, there are two reasons, perhaps one might argue, why this could have been done. The first reason, one might argue, and in fact, a representative of a SIM manufacturer did argue so at our Saturday press conference, the first reason was that it would help to speed up operations, assuming that typically ciphers with longer keys have lower throughput at times than ciphers with shorter keys, which is, of course, complete nonsense in this case. Because the cipher used, that uses the deliberately weakened encryption key, is still a 64-bit cipher. It just merely receives 54 bits of real key and 10 bits of zeros, but it still receives a total of 64 bits. So it does not speed up operations at all. The second reason, perhaps, is because the original output of comp 128, which is then split up into two components, one, the challenge, the response to the challenge, and one, the cipher key, perhaps may not be long enough to allow for both the challenge and the full 64 bits of the cipher key. We found this to be not the case. In fact, there are extra bits left over from this output that are just simply thrown away. We discovered that the first four bytes of the output of comp 128 is used as a response to the challenge and the last 54 bits are the first 54 bits of the key used by A5 later on. The rest is then padded with zeros. Meanwhile, there are a whole bunch of bits between the beginning of the output and the end of the output which are completely ignored and just thrown away. Is this true domestically or worldwide? This is, so far we've gotten, this is the best of our knowledge to worldwide. Okay. And this has been going on from the outset of GSM? From the outset of GSM and you can test this, you can verify this at home if you have a GSM SIM and a smart card reader simply by... Sure, a lot of our listeners have those components. Well, if someone has a GSM SIM and a smart card reader they can verify it themselves simply by downloading the free software we have on our webpage that allows you to talk to a number of smart cards including a GSM SIM and send the GSM SIM a challenge and watch the output of the algorithm, you will find that the last 10 bits have been set to zero and you can repeat that experiment as many times as it takes for you to convince yourself that this is not due to chance because they will always be set to zero. We're speaking with Mark Brissino. I pronounced it right this time, right? That's correct. Director of the SDA and one of the people who claims to have cracked GSM. Now, I think what people would really be impressed by would be if you could show them, you know, take a regular GSM phone, have somebody talking on it and show them how you can eavesdrop. Is that possible? Do you think that's something that you'll be able to do pretty soon? Eavesdropping is a possibility. We've discussed this and, in fact, I think this will be where our research will be directed next. What's the possibility of this? In order to eavesdrop on someone else's conversation, you obviously would need to know the internal key, which, of course, we have shown can be extracted. It also would require some, presumably would require, I say presumably because I don't know what funny diagnostic modes are possible with some of the GSM phones. Presumably would require some hardware modifications or perhaps some firmware upgrades. Since many GSM phones offer flashable phone firmware, there is much room for experimentation. Mm-hmm. So you think this is something that is imminent? Not imminent, but this is certainly something that a great number of people will work on and I would not be at all surprised if we saw some results within the next six months. Now, do you think there are a lot of people worldwide who have been trying to do just what you've done? I'm surprised people haven't done this years ago. That's true. It's required. I'm sure there were some people out there that have tried this. Certainly, I would assume some researchers would have tried this. GSM is a pretty fat target. It stands to reason it has been tried. I don't know why they did not succeed and we did. Could it be that they did succeed but they just didn't tell anybody? Oh, it is absolutely I'm not saying in fact, I misspoke here. I'm not saying that this has never been done. It may have been done by parties that decided to keep the knowledge secret and exploit it for financial gain. Certainly, the knowledge of the hypothetical knowledge of being able to snarf GSM identities out of GSM keys out of the SIMs nestled inside the phones in people's pockets allows itself for commercial exploit. If you were until Friday before a press release, if you were to approach a GSM provider with the claim that the following charges on your bill could not have been made by you and someone must have cloned your SIM, the provider would not only at least in Europe would ignore the complaint but most likely tell you that you better stop making this claim or they will file charges of intended fraud against you because of course the SIMs can't be cloned therefore if you claim it had been cloned you must be attempting to defraud the provider. Interesting. Now let's delve into that and we'll be taking phone calls 212-279-3400 if you have any questions for what could be one of the most interesting cracks in the last decade I think. What kind of legal things are we talking about here? I know there's some concern that all these crazy laws that are being passed right now you may have broken a lot of them by doing this and you could be facing all kinds of penalties. Are you worried about that? I'm certainly not an attorney though I'm finding out more and more about laws that are out there that I know very little about. I followed the case of Bernie S. who I understand was just essentially arrested and convicted on mere possession. Possession of items that could be used to defraud the phone company if assembled in the proper way yes. Yes, yes. In fact it hadn't even been assembled yet. That was my understanding so certainly given that we are concerned and I have retained counsel that's looking into the issues. we do not believe that we have violated any law. In fact we do not believe that we have violated any law but just because we have not violated any law doesn't mean there won't be an investigation and we're prepared to deal with that if it should happen. And by making all the findings available on the website even if something does happen to you the information is out and I can't stop that. Yeah, the information is out certainly Comp128 is useful to download from our homepage which by the way I'd like to add is located outside on a server outside of the United States. That's very smart. Yes, given that there are in this particular case Comp128 is only authentication so it should not fall under the U.S. export controls and cryptography anyway but just to be on the safe side it was exported from the U.S. in paper form and then retyped outside the U.S. and the servers outside the U.S. so our international audience really can get access to this information. The actual software the actual software that allows you to extract an internal key from the SIM is not available yet. I know some of you probably would like nothing more than download it this very minute. It's not available yet. It simply isn't ready for wider distribution where we're making improvements to it on an almost daily basis. And before that certainly would be made available in wider we definitely would have to spend some more time talking with counsel. Uh-huh. I see. And what was that homepage again for people that... The homepage for the Smartcard Developer Association is www.scard.org smartcard.org Okay. Now, do you have any... One more question before we go to the phones. Do you have any thoughts on CDMA phones? Are they less secure? As secure? Given... You know, CDMA, we know... We know, and I've talked with this... I've talked about this with Philip Harnoff, Qualcomm, who certainly is intimately familiar with the CDMA standard process. The CDMA committees have been pressured by the National Security Agency and others to also dumb down their system. So, I would not make the claim that CDMA is necessarily more secure. However, what I would like to point out is that after last year's breach of the touchstone privacy system used in CDMA, the North American cell phone or CDMA providers, whoever is setting the standard, I keep forgetting their exact name, have vowed to, from hands on, make the standard process public and allow public review of the design criteria and the results of the design, which would make a break such as the one we have performed impossible. Really? Okay. What was this thing you mentioned that happened last year, compromising? David Wagner, one of the members of our group, last year discovered, together with, I believe, Bruce Schneier, that the algorithm used to encrypt the touchstones that are being sent, I believe it was by CDMA phones over the air, broke this particular algorithm. Apparently, there are two algorithms, one for voice, one for the touchtone information. So if somebody, I assume, was to call their bank and dial their, do IVR phone banking, one might be able to intercept this. Interesting. So virtually all the phones out there right now, the portable phones, seem to be not as secure as we've been led to believe. That's correct, and I do believe we have national intelligence agencies to thank for this fact. That is something, and no comment from them, I suppose. No comment from them. I'm sure they're meeting in a dark room someplace talking about this right now. All right, we're talking with Mark Prasino, director of the SDA. Tell us quickly something about the group, and then we'll take some phone calls. Yeah, the SDA was founded last year, actually, as in response to the need of software developers to get vendor independent, operating system independent, and card independent tools that would allow them to make use of smart cards in their applications. We're small organizations. We have some 35 members at the moment. We're completely member funded and are an all-volunteer organization. Is it international? Yes, it's international. We have members in Europe, Australia, New Zealand, Japan. Okay. Let's go to our first phone call, 212-279-3400. Good evening. You're on the air. Hi. What's on your mind? Well, I live in Pepper Pike, Ohio, and a kid in another school put up a web page about a band director. About a band director? Yeah, and obviously he said some bad things about him. What is a band director? A guy who directs marching band. Oh, okay, okay. And he got suspended from school. For putting this up now, was this on his school site, or was this something... This was totally independent. Totally independent. You know, we've heard about this quite a few times, where people do things on the net outside of school, and they get disciplined for it inside school, which, if you draw parallels to other forms of discipline, it doesn't really make sense. But because it's the net, somehow they can do whatever they want. So this person was, what happened to them? They were suspended? They were suspended, and then they went to the school council, and they got appealed. And now he's back in school, and I believe he took them to court or something. I know he won some amount of money. Oh, really? Yeah. He took them to court. Well, we'd certainly like to know about that, because that's what's known as a precedent. Somebody's actually able to take them to court and win money. Boy, that's something that other people need to know about, and when they see that, maybe they won't be so quick to do the same kind of thing to kids in other parts of the country as well. Uh-huh. And also, I went to Radio Shack, and I bought the new tone dialer, and I opened it up, and I found the crystal was synthesized onto the board. Really? Yeah. So it couldn't be modified. So it could not be modified anymore. That's a sobering fact, isn't it, for all those red boxers out there? Well, that's something. But what did you expect? You know, it's been like, what, 15 years since this was uncovered, and everybody's been, you know, making all kinds of mischief with these things. But, you know, it's really, you know, if you want to make free phone calls, it's ridiculously simple, but, you know, it's also somewhat risky. I mean, all it is is tones. You don't need a tone dialer. You need, you know, a tape recorder that plays tones five times. It's not hard. And, you know, the fact that they don't fix this makes it seem to me like they don't really care that much. It must not be costing them that much. I just want to say that I love listening to your show. I listen to every chance I can. Well, thanks. And I want to say I do the Mad Scientist and Nighthawk. Okay. Thanks for calling. Okay. Okay. Greetings from Ohio there. Okay, let's try to stay on the topic, though. We're talking about GSM cracking and encryption and the evil NSA plotting to make our lives open to scrutiny. Good evening. You're on the air. Hi, Emmanuel. I'm calling from my Qualcomm CDMA cellular phone. Well, now, that's, is this a smart move on the caller's part? It's hard to tell at the moment. I can tell you it probably isn't, but that's because I have further knowledge. I see. Well, I am talking on a Qualcomm cell. It's not a PCS phone. I thought it was, but I guess I mean, I got this thing Monday. Well, what service are you using? I'm using Bell Atlantic, which is a good service because they give you free nights and weekends. Well, you know, you can't really judge a service by free nights and weekends. You have to judge it by its technical capabilities. I agree to that. Yeah, let me ask Mark, have you heard of Bell Atlantic's service? No, I have not heard of the quality of Bell Atlantic's service, to be perfectly honest, since I live out on the West Coast. I'm based in San Francisco. So I really don't have an opinion on Bell Atlantic's service. I know that We have an opinion over here. You have an opinion over here. Well, it's probably the same opinion. We have a Pacific Bell over here. Well, they give you not only free nights and weekends, but the first incoming minute is free. Okay, that's great, but the thing is, you know, it's a concern to some people if that first incoming minute and all the other minutes are able to be listened to by everybody under the sun. Well, that's true, but it's digital. It's digital, so in order to listen, you'd have to, you know, from what I hear, modify the digital signal. Well, then you're not listening, are you? Well, no, I am listening. I know what you're talking about, but I'm saying, you know, I know what you're talking about, about the encryption and everything, but, you know, I mean, people have to really be high tech to do that. I mean, I'm not really concerned about people listening. You know, people change with the times. Oh, that's true. Yeah, there's always going to be a way around something. Certainly, all the required radio equipment, the demultiplexes and so forth, all of this, yes, it is very difficult, and yes, it's highly technical, but yes, it also is in each and every single cell phone out there that subscribes to the same type of service. So, the added complexity of the digital world over the analog world, I don't think really holds since, since all the equipment you need is already in every single cell phone. It just requires one smart person to figure out how to put it into the right diagnostic mode or to snip the right bridge or to add this one or two transistors or whatever the eventual break may be before you'll be able to intercept digital calls just as easily as analog calls. And then stocks will plummet worldwide. Has that happened, by the way? Have you heard anything about this, GSM companies? No, I haven't. In fact, I meant to take a look today. Someone else brought this up. I meant to take a look at the GSM provider stocks and the Qualcomm stock. You know, I have a GSM phone right here and I have the ability to look up a stock, but I don't know how to do it. Does anybody know how to do it? Almi Point has a certain code, but I don't know what it is off the top of my head. I'm sitting right in front of a computer with a web browser, but I suppose I could look it up. Turn on one of those business channels and find out what's going on out there. Any other questions from the phone? Let me just mention something about... Real quick now, real quick. Real quick. About co-cuts, I remember I was on a co-cut. You had three seconds. All right. I went to a co-cut and dialed zero because I wanted the operator. You know, it dials another operator, but then when I dial 10698 for New York Telephone or Bell Atlantic, it dials, guess what? AT&T. Remember that? Yeah, I do. Thanks for the call. Oh, boy. It's like going back in time, you know? I could have sworn we had this call three years ago. 10698. That's 10NYT. New York Telephone hasn't existed since 1994. And carrier access codes are seven digits now, not five. Good evening. You're on Off the Hook. Oh, hi. Hi. What's on your mind? I admire the spirit of your guest very much. Can I ask your nationality, sir? Actually, I'm a U.S. citizen. I was born in San Diego despite the accent. You sound Swiss. I was raised in Europe. Okay. The thing I would like to say is, you mentioned the possible legality, illegality of what you've just done. I would make the quote from Franz Kafka that the law is the sawdust that's been chewed by a thousand mouths, and there's maybe a lawyer somewhere re-chewing the sawdust to maybe, you know, like right now you may be fine, but if the right lawyer re-chews the sawdust in the right context, then maybe it isn't fine. And I think this is a very important problem here, because I think someone said once that the big secret that the government doesn't ever want anyone to know is that there are no secrets, and I think that is really the best way to look at everything. Well, then they should be happy with what we found out today. Well, that's what I'm saying, is that since that you can't, you know, that's why encryption is kind of a, the genie's already out of the bottle, so that the encryption is almost a moot point, really, in the future. Well, somebody certainly successfully managed to deliberately weaken the encryption in the world's most widely used digital cellular telephony system, with over 80 million units fielded. So, yes, the genie's out of the bottle, but there are certainly quite a few systems out there deployed that have been deliberately compromised. Yeah, but see, what I'm trying to say is that in every case, there's always, you know, all you need is one person who's already five years or ten years ahead of the current technique, and then all of a sudden everything's obsolete, which I think is a great, a great lesson in human nature, you know. That's why they banned time travel. Well, that remains to be seen. I'm going to hang up and give someone else a choice. Okay, thanks for calling. 212-279-3400, and we're speaking with someone, I think you're going to be on the covers of many magazines because of what you've done here. Actually, how many of you were really at the core of this crack? I'm sorry, Sagan? How many of you actually, I understand you have at least one partner that worked on this, too. this was very much a team effort. The Smart Developer Association reverse-engineered Compone 28, and the ISAC Research Group, meaning Ian Goldberg and David Wagner, crypto-analyzed it. It took the SDA about two months to reverse-engineer the algorithm, and it took David and Ian, which are some of the best there are, just a tad over two hours to find the cryptographic flaw. Wow. Credits definitely, definitely goes very much to David and Ian for having found it so quickly and writing and coming up with the exploit literally within a few hours. Hopefully you guys have inspired hundreds of other people to pursue this as well, because I think a lot of people thought this would never happen, this is impossible. They say it's encrypted so well that no one's ever going to be able to crack this. Yeah, and really, the big problem for the GSM providers and equipment vendors at this point is that they started believing their own marketing department and failed to put in the defenses and failed to subject their design to the required outside review. And yes, it helped keeping the internals of GSM security secret. served, and I discussed this with one of the SIM vendors, his answer was, well, by keeping it secret, you can at least delay the time until an attack. And that is true, I wholeheartedly agree. The SIM manufacturers and the entire GSM consortium managed to delay this flaw from being found before the system had been fielded until 80 million units had been fielded. Tell us something about this GSM consortium, though, because we've talked about this in the past. Basically, they agree not to compete ever? To be honest, I don't know much about the business side of the GSM consortium on the inside. I know it's called the GSM MOU, my mind of understanding. Their website is www.gsmworld.com. So I can't tell you much about the business workings. I didn't look at it. Okay. Now, have you heard response from other GSM companies? You've heard Omnipoint already. Has anyone else gotten back to you or been quoted in the paper or anything like that? Not that I'm aware of. I know one person had been talking with somebody at Pacific Bell, which then in turn turned around to send a SIM manufacturer to our press conference. So no official response that I'm aware of. I believe that there currently is a lot of internal finger pointing going on at the GSM providers. I'll just bet there is. It's not a pleasant environment in there. No, no. Despite what the gentleman from Omnipoint may have said, that he slept like a baby after hearing about this break, I suspect that if in fact he did, he's one of the very, very few GSM providers that showed this reaction. I'm speaking with Mark Persino, director of the Smart Card Developer Association. And you're out there in Berkeley, is it? David Wagner and Ian Goldberg are actually located at UC Berkeley. I'm physically in a, I live in a suburb of San Francisco, 10, 15 minutes away from Berkeley. California, in that area, because we're over here in New York, so it's all the same to us. It's all the same. San Francisco and Berkeley. 212-279-3400. Good evening. You're on off the hook. Yes, you're off the hook? Yes, speak up, please. Okay. I just recently got a cell phone service, and I was wondering why it is, I mean, whether or not you can have this cloned. Well, what kind of service do you have? I don't know. It's just a regular cell phone. Who do you write the checks to? What company? Oh, AT&T, yeah. Is it AT&T PCS? Is it PCS, Phil? Oh, no, that's the digital. Oh, yes, it is. PCS, yes, right. Okay, well, that's a CDMA service, I believe. And as we've, it's not? I think it is. TDMA? I don't know. Okay, well, AT&T PCS is CDMA. It's not. Okay, there's all kinds of debate here. But I think basically the answer to your question is, yes, you're not as secure as you might think you are. Yeah, but what I wanted to know is that I have, I pay the, I could, I would have use for another phone with the same number. You know, a cloned phone. Oh, you want, you want to be able to clone a phone legitimately for your own use? Yeah. Well, now, they, they always make it so that that's either impossible or illegal. Mark, you know anything about the, the capabilities of this? Well, I wanted to, I do not know how to clone a CDMA phone. Okay, I'm sorry, try that again? I'm sorry, I do not know how to clone a CDMA phone. We, we really specifically looked at GSM and, uh, we had our work cut out for ourselves, so, uh, we didn't have, we did not have a chance to do a similar analysis of other, of other systems. Okay, well, what I was trying to ask is that I have, uh, magazines here, you know, uh, nuts and bolts and various other electronics, uh, magazines, and I have seen ads that say they'll clone a phone, it's not illegal, and so on, and I've called them, uh, out of state or in, uh, Mississippi and other places, and, uh, they say, yes, it's perfectly legal, we'll send you a form you fill out, and so on. And I wondered, what's the issue here? I mean, if I'm willing to pay for the service? Well, this is one of the things Bernie S. went to prison for, for having the capability of, of cloning a phone, cloning his own phone. Uh, it's very, it's very easy to twist this around and make it seem like you're doing something fraudulent by, by copying a phone, you know, and, and, and, you know, using a phone that you're not supposed to be using. Same thing used to happen back in the 60s. The phone company wouldn't let you have an extension without paying. Oh, yeah, I remember. And today, the cable companies want you to have a cable outlet without paying extra for that. It's, it's, it's nonsense, but, uh, what the, what the cellular companies today pretty much have successfully done is prevent people from, from legally cloning their own phones, and I believe there is legislation that, that prohibits that. Uh, there are companies that will do this for you, and, uh, you know, obviously it's a little bit risky dealing with companies that, uh, are technically doing something that you could get in trouble for. Yeah. But a lot of people are doing this. It's a legitimate use for a cellular phone, in my opinion, and a lot of other people's opinions, to have the same number, you know, in a car and in your house. I just don't know what the issue is with the telephone company. I mean, they're, I'm willing to pay whatever bills, and as a matter of fact, I may even have more calls so that they'd make more money, it would seem to me. Well, I believe they would be, by, by doing this, they're admitting that it's possible to do it fraudulently as well, and that they might be opening themselves up to all kinds of, of, uh, you know, non-authorized use by allowing this kind of service. Okay, well, and what do you think of these people who are offering this service? I mean, is it, is it really very risky? I mean, I would, I've, I've, because I've listened to Bernie, he didn't sound happy in jail. Well, no, he certainly wasn't happy in jail, but you have to understand, Bernie was targeted by the Secret Service for various reasons, and any one of us could wind up in prison for anything, because, you know, we, we break the law on a daily basis, I'm convinced, you know, whether it's traffic rules or, you know, thought crime of various sorts, there's always something they can get you on. I know what you mean. There's always something they can get you on, so I don't think what Bernie was accused of in itself is a serious thing. I think what a serious thing is, is that, you know, federal agencies go around acting vindictive and imprisoning people because they want to. So that's, you know, that's the real issue. I don't think it's really dangerous to deal with these companies or to do something that you want to do technically with your own equipment. Okay, thank you. All right, thanks for calling. Just don't call on anyone else's phone. Simple, simple rule. All right, 212-279-3400. Good evening, you're on the air. Okay, you were on the air. See, the thing is, you got to speak up within five seconds, otherwise we lose patience. Good evening, you're on the air. Yeah, um, hi, I have a question. I was just wondering where fiber is these days. Uh, I don't know. Oh, you don't know? No. Can I try a little experiment? Uh, okay. Uh, I don't know. Oh, you don't know? No. Can I try a little experiment? Uh, okay. I thought I said time travel is illegal. No, don't do it. Good evening, you're on the air. Yes. Go ahead, please. Hello. Why does everybody have to drop the phone when they pick up here? Okay, yeah, what's on your mind? Yes, uh, I, um, well, first thing I'd like to say is, you know, free Kevin. Okay, thank you. You know, by the way, there's been a surplus of free Kevin bumper stickers all around the place. I don't know if people have seen this. Oh, uh, I haven't seen any, but, uh, I tell you, I've been following you guys, your show is great. Thank you. And my question, um, for the professor is, um, is it possible, I mean, patting with, patting the encryption with all these zeros, is it possible to correct all this after it gets out, how the whole thing was kind of like, uh, orchestrated by the government to make it weak? Is it possible to, to, to correct the situation? Well, um, it certainly would be possible to, uh, correct the weak generated, the weak key generation up to the maximum of the 64 bits, the A4, A5 cypher, cypher support, um, if one were to issue, if one, if one were to choose a new authentication and key generation algorithm and issue new SIMs based on that, the SIMs could, uh, given the current, uh, GSM specifications, um, it would then, could be, uh, constructed to return the full 64, uh, the full 64 bit key. The question at this point then remains, um, first of all, is 64 bit enough, even if you have the full 64 bit? And the second question becomes, uh, is the on the air voice privacy encryption algorithm itself strong enough? Now, um, as, as I said earlier, a, a, uh, group of astute cryptographers released, released a report, and, on minimum key length, and their recommendation is for anything that you want to, to be secret and remain secret for, um, as long as you might possibly care about this, would require 90 bits. Um, it's not 64 bits. Um, all of that... We have to throw the phones away, I guess. Also, also, yeah, they, also, there have been indications that A5 itself has been weakened. Now, you may know that there are really two different versions of A5. There's A5-1, the so-called strong A5, and then there is A5-2, which was shipped to countries that the GSM consortium thought were not appropriate to receive the, quote-unquote, strong cryptography of A5-1. Um, very little is known about A5-2. What is known about A5-1, the stronger version, is that it probably is in itself rather weak. Um, I've heard suggestions that it has never been fully cryptanalyzed, and, in fact, this is, this is a project that I, currently, a number of groups are working on, and our group just might get involved in as well, uh, now that we've compromised the key generation and authentication of GSM. Mark, I have to warn you, we're out of time, so, uh, you have one minute to sum this whole thing up. I want to thank the caller for calling. Thank you very much. You have, uh, one minute to sum up this whole thing. You there? Yes, I'm here. Okay, go ahead. You have 50 seconds now. Oh, I have 50, I, I, I, I apologize. Um, so what I would like, what I would like, uh, the listeners to, to really walk away with here is, this was not so much a failure of a particular cipher or authentication system, though it, it failed utterly. It was primarily a failure of a design process. The closed secret room, uh, back room, um, influenced by intelligence agencies design process, um, that was used to design GSM would, um, could invariably only lead to an insecure system. Um, what we're looking at here, um, is really nothing but the chicken coming home to roost. Um, I would strongly urge the, the GSM consortium to, for the next revision of GSM, uh, use an open design process with public participation. There must be no secrets. Well, Mark, I want to thank you. Thank you very much for, uh, for pointing all this out to us and for demonstrating this. I think you're performing a very valuable service and I hope, uh, lots of other people follow, uh, in this. Uh, one more time, do you want to give out, uh, contact information? Yeah, uh, the contact information is www.scard, as in smartcard.org. Um, you can email me, mark with a C, M-A-R-C, at scard.org. We'll be happy to help, though it may take, uh, a little while for us to get back to you, given the rush we're under. Okay, we're speaking with Mark Prusino, director of the Smartcard Developer Association, and, uh, thank you very much for being with us. We'll be in touch in the future. We'll keep people updated as to just where this is going. Thanks for being on the show. Take care. And that will do us, uh, do it for this week on Off the Hook. We'll be back again with, uh, I guess another breaking story of one sort or another next week on Off the Hook. Till then, it's Emmanuel Goldstein. Have a good night. The telephone keeps ringing So I ripped it off the wall I cut myself while shaving Now I can't make a cough We couldn't get much worse But if they could, they would Bumbin' LeBomb for the best Expect the worst I hope that's understood Bumbin' LeBomb Can't you wait last week? Whether it's solidified Let's doи Verb Gluck Check your chenon a and Don't I can't do it Don't Habs Don't misfortune Don't Spin Rob Turn cape Ex We'll be right back. We'll be right back. April 28th from 7 to 11 p.m. April 28th from 7 to 11 p.m. Tickets must be purchased in advance, so call 212-533-6515. That's 212-533-6515 for your ticket. And the party is hosted by Ken Nash and Mimi Rosenberg. This is WBAI 99.5 FM in New York. Coming up next, our voice, Crescent Rising. Stay tuned. Stay tuned. We'll be right back.