Europe mulls open sourcing TETRA emergency services' encryption algorithms
- Reference: 1697138710
- News link: https://www.theregister.co.uk/2023/10/12/etsi_tetra_open_source/
- Source link:
"The ETSI Technical Committee in charge of TETRA algorithms is discussing whether to make them public," Claire Boyer, a spokesperson for the European standards body, told The Register .
The committee will discuss the issue at its next meeting on October 26, she said, adding: "If the consensus is not reached, it will go to a vote."
[1]
TETRA is the Terrestrial Trunked Radio protocol, which is used in Europe, the UK, and other countries to secure radio communications used by government agencies, law enforcement, military and emergency services organizations.
[2]
[3]
In July, a Netherlands security biz [4]uncovered five vulnerabilities in TETRA, two deemed critical, that could allow criminals to decrypt communications, including in real-time, to inject messages, deanonymize users, or set the session key to zero for uplink interception.
The Midnight Blue researchers dubbed the bugs, which affected all TETRA networks, [5]TETRA:BURST . The team waited one and a half years, as opposed to the usual six-month disclosure period, to make the flaws public because of the sensitive nature of emergency comms, and the complexity of fixing the issues.
[6]
At the time ETSI downplayed the flaws, which it said had been fixed last October, and noted that "it's not aware of any active exploitation of operational networks."
It did, however, face criticism from the security community over its response to the vulnerabilities — and the proprietary nature of the encryption algorithms, which makes it more difficult for proper pentesting of the emergency network system..
Security author Kim Zetter [7]broke the story that ETSI was discussing making the TETRA algorithms public. She also quoted Matthew Green, a Johns Hopkins University cryptographer and professor, who said keeping algorithms secret is a dated idea that makes problems worse.
[8]
"This whole idea of secret encryption algorithms is crazy, old-fashioned stuff. It's very 1960s and 1970s and quaint," he said. "If you're not publishing [intentionally] weak algorithms, I don't know why you would keep the algorithms secret."
[9]TETRA radio comms used by emergency heroes easily cracked, say experts
[10]curl vulnerabilities ironed out with patches after week-long tease
[11]Cat accused of wiping US Veteran Affairs server info after jumping on keyboard
[12]European telco body looks into terahertz for future 6G comms
Zetter indicated that ETSI's recent security failures may have changed some members' minds about removing the cloak of secrecy around the technology. ETSI [13]disclosed that intruders had exploited a vulnerability to breach its members-only portal and steal a database containing personal information.
It didn't provide any additional information about the flaw used to break into the portal, but noted "ETSI has fixed the vulnerability."
The disclosure also included a statement from ETSI Director-General Luis Jorge Romero, who said: "Transparency is at the root of ETSI, in our governance and technical work."
It looks like the real test of this will come later this month when the TETRA algorithms go to a vote. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZShsgprIIFjwtG3H24n0aQAAAIM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZShsgprIIFjwtG3H24n0aQAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZShsgprIIFjwtG3H24n0aQAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2023/07/24/tetra_radio_security_flaws/
[5] https://tetraburst.com/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZShsgprIIFjwtG3H24n0aQAAAIM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.zetter-zeroday.com/p/standards-body-considers-uncloaking?
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZShsgprIIFjwtG3H24n0aQAAAIM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/07/24/tetra_radio_security_flaws/
[10] https://www.theregister.com/2023/10/11/vulnerabilities_in_curl_receive_patches/
[11] https://www.theregister.com/2023/10/05/hospital_cat_incident/
[12] https://www.theregister.com/2022/12/15/european_telco_body_6g/
[13] https://www.etsi.org/newsroom/news/2267-etsi-faced-a-cyberattack
[14] https://whitepapers.theregister.com/
Re: Problem?
They would always have preferred it be impossible for the public to listen in, but they didn't have a choice before. Beyond the nefarious reasons that I'm sure could be listed, it makes it easier for criminals e.g. robbing a bank if they know that the cops have been called and are on their way. Someone holding hostages would benefit from listening in the police and know what they are planning, etc.
Re: Problem?
Probably the no1 reason was that "news" reporters would just follow police and ambulance around...
In any case, all this stuff is recorded for use in court, so they should probably encrypt properly. At least for the privacy of the public whose addresses and alleged crimes get read out.
Re: Problem?
Being able to listen in makes it too easy for criminals to plan work and then listen out for the police getting on to them to make their getaway. Drug dealers would suddenly all be kitted out with the ability to listen in to evade being caught in the act.
Re: Problem?
As others have said, it made it too easy for the boys in striped vests and domino masks.
There are numerous period pieces being shown on, eg, Talking Pictures TV (Freeview) where the getaway driver is shown listening to the police on a portable trannie, two flashes means tools down, keep quiet until the patrol goes past...
Bag
Is it about encryption or whether tax payers paid for a pile of rubbish and they want to cover up?
If they think security by obscurity is the way to go, why are they not sacked already?
Problem?
I can understand the paranoia in some quarters about listening to encrypted emergency services comms. But what's the problem?
Until tetra in the late 90's, all but a few emergency services transmissions were broadcast in clear analogue radio channels.
The fire brigade used frequencies in the FM broadcast band for years (1960-80's), and any FM radio could pick them up.
The police used channels in mid VHF (around 150Mhz) which were not hard to pick up for anyone suitably interested.
Off the shelf radio scanners have been around since the mid 70's. Before that general coverage VHF receivers had been around since WW2.
Why, all of a sudden, are they paranoid about being listened to?