Sci-tech

Business Maverick, Politics, Sci-Tech

Now everybody can listen to your (cell) phone calls

Now everybody can listen to your (cell) phone calls

It used to be limited to just your cellphone provider, the SA government and its various branches and bureaucracies, any foreign government, any other organisation with sufficient motivation and resources, or anybody with the skills to find and bribe a couple of easily-bribed network provider employees. But as of this week, anyone with a couple of grand for equipment and two hours to spare can listen in on your cellphone calls.

If you thought your cellphone conversations were secure before, then you were, well, a damn fool. But at least your retired neighbour couldn’t listen in on your calls for casual amusement, and your business rivals would have had to hire a crooked private investigator (and wait a couple of days) to get that kind of intelligence. Now, however, they’ll just need some off-the-shelf hardware and the ability to use a search engine.

Or so we hear. Note that actually doing so would be illegal in South Africa and that we would never, ever, engage in such activity. Nor would we encourage you to do so. Cross our hearts.

The encryption standard used in normal GSM operation, A5/1, has been known to be vulnerable for many years, but those who cracked it kept their methods to themselves. This week the Chaos Computer Club, a German group with a history of neat hacks, published a solution, and a couple of hours later it was all over the interweb.

To use it will require a laptop or two, proximity to the cellphone you want to tap (a couple of hundred meters will be close enough), a couple of GSM modems to which you have low-level access, and a modicum of technical ability. Or the ability to find and follow detailed instructions.

The GSM Association, which is responsible for the encryption standard, says the hack is illegal (which is true, in some countries), that it is technically infeasible (which is downright false) and that phone calls are protected because there are so very many of them going on at any one time that picking out the right one is like finding a needle in a haystack. That last argument is by far the best, but is (a) cold comfort when you’re supposed to have proper protection and (b) not an obstacle that is particularly hard to overcome.

A5/1 is two decades old, which is why a more secure alternative, A5/3, was finalised two years ago. It is far more robust and has no currently known vulnerabilities. It is also in use by virtually nobody anywhere in the world, because network operators haven’t been willing to spend the money required for its implementation.

Our advice: go back to the landlines when the call really matters. At least only the government (and its various arms), Telkom and its employees and anybody who can lever open the local exchange box down the street and clip on a couple of wires can listen to those.

By Phillip de Wet

Read more: Guardian, Daily Tech

Photo: Reuters

Gallery

Please peer review 3 community comments before your comment can be posted

X

This article is free to read.

Sign up for free or sign in to continue reading.

Unlike our competitors, we don’t force you to pay to read the news but we do need your email address to make your experience better.


Nearly there! Create a password to finish signing up with us:

Please enter your password or get a sign in link if you’ve forgotten

Open Sesame! Thanks for signing up.

We would like our readers to start paying for Daily Maverick...

…but we are not going to force you to. Over 10 million users come to us each month for the news. We have not put it behind a paywall because the truth should not be a luxury.

Instead we ask our readers who can afford to contribute, even a small amount each month, to do so.

If you appreciate it and want to see us keep going then please consider contributing whatever you can.

Support Daily Maverick→
Payment options

Daily Maverick Elections Toolbox

Feeling powerless in politics?

Equip yourself with the tools you need for an informed decision this election. Get the Elections Toolbox with shareable party manifesto guide.