Chaos Computer Club registered association - press statement
Berlin, Friday 24,04,1998 23:61 o'clock chaos computer club
acknowledges serious GSM Sicherheitsloch - also German network carrier
concerned by a weak point in the technical standard logs of the GSM
network is possible it to copy smart cards of users unauthorized and
telephone at expense of notionless customers.  Some time ago the weak
point in the GSM network, become known by the American Smartcard
Developers Association, could be acknowledged now by the chaos
computer club for the first time in the practical attempt with
D2-Chipkarten.  " a majority of the world-wide GSM networks can apply
after this discovery as uncertain.  Also in GSM networks it is
possible, at expense of other customers to telephone ", said CC
SPEAKER franc Rieger.  The security of the GSM networks was based so
far on the fact that the underlying mathematical procedures were kept
secret.  Therefore these procedures could not be examined by the
drawer public on weak points.  Also the hearing security of the GSM
network was obviously limited on urge by security authorities and
secret services consciously.  After the algorithms A3 and A8 were
published by three American researchers, the serious weak points
contained in it could be discovered.  In the smart card of the user
and the data base of the network carrier stored secret codes can be
selected from the smart card quasi.  With PC and smart card reader in
experience secret codes brought can be used to simulate a GSM smart
card and to lead telephone calls at expense of the card owner.  A
household-usual PC is already oversized for this function.  Criminal
abuse of GSM cards is for example conceivable by unfaithful dealer,
who would be like that able to copy and with the codes concern the
data of GSM cards before the sales.  The normal customer can notice
the abuse only if he controls his calculation.  " the proof value of
connecting data, movement profiles and calculations sank so that a
reversal of the burden of proof appears meaningful, summarized " CC
SPEAKER Mueller Maguhn the problem.  Chaos reality service
http://www.ccc.de/CRD/CRD240498.html

William Knowles erehwon@dis.org
Translation by Altavista by Digital
Last updated 4.27.98 12:06pm C.S.T.