That didn't take long

2021-05-07

The GSMA is having a tough time keeping encrypted things encrypted. Just over a couple of weeks ago the GSM encryption was broken, now the 3G encryption it seems is no longer secure. The transition to 3G networks and their more secure encryption algorithm was one of the ways some downplayed the importance of breaking the GSM encryption.

The original algorithm intended for UMTS is called MISTY1, but was too computationally intensive, so it was replaced by a revised version called KASUMI (Japanese for "mist"). The new algorithm was supposed to be easier on the hardware, but not any less secure.

It turns out that"s not the case. An attack on the algorithm takes just several hours on a regular computer to break the encryption. So, it doesn"t enable real-time eavesdropping (at least not using a single computer), but the researches that broke the code say their implementation wasn"t optimized, so there"s probably room for improvement.

This attack however doesn"t work on the original MISTY1 encryption. Still, unless it"s possible to switch to it from the current algorithm that doesn"t help the situation much.

Source