The most widely used mobile-phone technology — Global System for Mobile Communication (GSM) — has been cracked. The more than 20-year-old encryption, which protects mobile-phone calls and texts from being intercepted, was cracked by a computer hacking group called the Chaos Computer Club.
The encryption based on the A5/1 and A5/2 algorithm offers over-the-air privacy by scrambling the communications link between a handset and a radio base station. Serious weaknesses were discovered in both algorithms.
In February 2008, Pico Computing announced plans to commercialize devices that allow A5/1 to be broken. In 2007 a hacking group claimed to be building an attack on A5/1 by constructing a large look-up table of approximately two terabytes — equivalent to the data contained in a 20-kilometer-high pile of books. Another group announced similar plans this year.
Before a practical attack can be attempted, the GSM call has to be identified and recorded from the radio interface, according to Claire Cranton, a spokesperson for the GSM Association. The association, which has a security group that looks at all issues regarding security, said the matter is not something it is taking lightly.
“We have a new security algorithm that is being phased, as the protection and privacy of customer communications is at the forefront of [wireless] operators’ concerns,” Cranton said. “So far, this aspect of the methodology has not been explained in any detail and we strongly suspect that the teams attempting to develop an intercept capability have underestimated its practical complexity.”
A hacker would need a radio receiver system and the signal-processing software to process raw radio data, Cranton added. The complex knowledge required to develop such software is subject to intellectual-property rights, making it difficult to develop a commercial product.
“All in all, we consider this research, which appears to be motivated in part by…