Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain
- Reference: 1699948809
- News link: https://www.theregister.co.uk/2023/11/14/tetra_encryption_algorithms_open_sourced/
- Source link:
The algorithms are used by TETRA – short for the Terrestrial Trunked Radio protocol – and they are operated by governments, law enforcement, military and emergency services organizations in Europe, the UK, and other countries.
In mid-2023, Netherlands-based security firm Midnight Blue [1]disclosed five vulnerabilities affecting all TETRA radio networks that could allow criminals to decrypt and intercept communications in real time.
[2]
The bugs — and the secrecy of the algos themselves — [3]sparked outrage in the security community, which pointed out that proprietary encryption algorithms mean third-party researchers couldn’t test code, making it harder to detect bugs and defend networks.
[4]
[5]
The technical committee in charge of the TETRA standard met in October to discuss making the secret algorithms public. They then voted unanimously to open source all TETRA Air Interface cryptographic algorithms.
"The meeting was very well attended and had a wide spread of the TETRA community including operators, users, manufacturers and governments," ETSI committee chairman Brian Murgatroyd is quoted as saying in a statement. "Following publication of the algorithms, we are open to academic research for independent reviews."
[6]
The standards org hasn’t set a date for making the algorithms accessible, ETSI spokesperson Claire Boyer told The Register .
[7]Europe mulls open sourcing TETRA emergency services' encryption algorithms
[8]TETRA radio comms used by emergency heroes easily cracked, say experts
[9]Inside Denmark's hell week as critical infrastructure orgs faced cyberattacks
[10]Royal Mail cybersecurity still a bit of a mess, infosec bods claim
TETRA includes an original set of Air Interface cryptographic algorithms: TEA 1, 2, 3, and 4. Some of these were disclosed by the Midnight Blue research team, which found the five vulnerabilities and released technical details of the flaws at the annual Black Hat and DEF CON security conferences in August 2023.
The researchers said they waited a year and a half to disclose details — instead of the standard six-month wait — due to the sensitive nature of the networks and the complexity of fixes for the flaws, which were named [11]TETRA:BURST .
In 2022 ETSI [12]added three new and supposedly quantum-proof algorithms to the TETRA family, dubbed TEA 5, 6, and 7. The algos are intended to address the threat that, in the worryingly near future, quantum computers will be able to break existing encryption schemes, thus rendering data and comms protected by legacy encryption insecure.
According to ETSI, this entire set of new and old algorithms will enter the public domain, along with TAA1 (the original authentication and key management specification) and TAA2 (the new authentication and key management specification). ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2023/07/24/tetra_radio_security_flaws/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVNTVN171DXryty8EmF9VAAAAJc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2023/10/12/etsi_tetra_open_source/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVNTVN171DXryty8EmF9VAAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVNTVN171DXryty8EmF9VAAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVNTVN171DXryty8EmF9VAAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/10/12/etsi_tetra_open_source/
[8] https://www.theregister.com/2023/07/24/tetra_radio_security_flaws/
[9] https://www.theregister.com/2023/11/13/inside_denmarks_hell_week_as/
[10] https://www.theregister.com/2023/11/13/royal_mail_cybersecurity_still_a/
[11] https://tetraburst.com/
[12] https://www.etsi.org/newsroom/press-releases/2140-2022-11-etsi-secures-critical-infrastructures-against-cyber-quantum-attacks-with-new-tetra-algorithms
[13] https://whitepapers.theregister.com/
In fact most are patchable.
Obsolete within a year, maybe - but still be in daily use
TETRA is used extensively and it won't be an easy upgrade if it can't be patched to cope seamlessly with both old and new standards. By way of example, in the UK, each regional Police force has its own budget. In order to swap their radio kit to a new standard, all forces would have to align their strategies and buying cycles. If not, they'd be pretty much obliged to stick to the old standard until their neighbouring forces had also upgraded. At a time when budgets are under huge pressure, I can't see this being a quick change for them.
Granted, some users (higher security users like government spooks and other very specialist sub-groups) might get new kit sooner - but the existing hardware is in the hands of so many 'normal' users it could take a while to effect a changeover unless in-field patching is possible.
Most of these units run on a mobile OS, like Symbian, WinCE/Mobile/Embedded, VxWorks, etc, with updateable software on top. You'd have to go *way* back to find bare-hardware systems. Firmware updates are a fact of life for the departments that use them -- newer ones even do OTA!
In fact, the release of the vulnerability coincided with availability of new firmware across most in-service models and confirmation that major customers had applied them. (There are really only a few big makers, for that matter.)
I have no idea where you guys are getting the idea that these are some black box that once put out into the world, just exists in stasis forever, and can only be fixed by a total upgrade cycle.
Well, let's see what kind of rubbish is in that, I'm guessing at this point it'll be obsoleted within a year (because presumably most TETRA radios are pretty much unpatchable, despite it being 2023) and replaced with something else because of what's found when this happens.