Cryptanalysis of A5/1
There have been a lot of articles about the new attack against the GSM cell phone encryption algorithm, A5/1. In some ways, this isn’t real news; we’ve seen A5/1 cryptanalysis papers as far back as ten years ago.
What’s new about this attack is: 1) it’s completely passive, 2) its total hardware cost is around $1,000, and 3) the total time to break the key is about 30 minutes. That’s impressive.
The cryptanalysis of A5/1 demonstrates an important cryptographic maxim: attacks always get better; they never get worse. This is why we tend to abandon algorithms at the first sign of weakness; we know that with time, the weaknesses will be exploited more effectively to yield better and faster attacks.
Gerrit • February 22, 2008 7:07 AM
Here in South Africa I haven’t regarded cell phone calls as secure for quite some time. School kids figured out that if you dial the three-digit customer service number on your cell phone, and keep on waiting on the line a few minutes after the voice recording finishes, the following happens: It connects to (I presume) your local tower and you can hear the one side of random cell phone conversations. After a few minutes it switches over to another conversation. You can only hear one side of the conversation, but it proved quite entertaining for kids to listen in on conversations during school breaks (phoning customer service is a toll-free call). Luckily the cell phone company realized this and fixed the security hole after a few months.