Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
18 minutes ago by NGTsummit_ASIA on twitterZDNet is available in the following editions:
update Users should be warned when encryption is turned off or alerted of "other suspicious activity" at base stations, says security expert at Symbian Foundation.
update A security expert is calling for the creation of a mobile app to alert users when their communications security has been compromised.
Craig Heath, chief security technologist at the Symbian Foundation, threw up the idea in a blog post Monday, noting that the security tool would serve up a warning dialog when encryption is turned off, or when "other suspicious activity" originating from base stations is detected.
Mobile phones, he said, currently are able to identify what encryption algorithm is being used between the base station and the device. For example, the Sony Ericsson P1i displays a triangle icon as warning when the base station switches to A5/0, which according to the GSM Security Web site, utilizes no encryption. GSM Security is a service provided by U.S.-based Network System Architects.
At press time, Sony Ericsson was unable to confirm Heath's remarks about P1i or whether its other phones were capable of displaying the security alert.
Heath's blog post was in response to German computer engineer Karsten Nohl's revelation last week that he had cracked the GSM (Global System for Mobile communications) algorithm, which encrypts 80 percent of the world's mobile calls.
Statistics from the GSM Association (GSMA) indicate that, as of the second quarter of 2009, there were over 4.3 billion mobile connections globally. GSM connections accounted for 3.5 billion connections.
Nohl, in his presentation at the Chaos Communication Congress in Berlin last week, detailed the efforts that went into decrypting the A5/1 algorithm. The 28-year-old concluded that GSM security "must be overhauled" with a mandatory security patch to upgrade the GSM encryption function.
Noting that Nohl's point was "a very valid one", U.K.-based Heath said cryptographic protocols ought to be designed such that different algorithms could be tapped should the need arises.
"Happily, this is the case for the GSM protocols and all that is needed is for the phone manufacturers and network operators to deploy the stronger A5/3 algorithm, and we can all go about our business," he said in his blog post.
However, Nohl noted in his presentation that replacing A5/1 with A5/3 algorithm might not be adequate for two reasons: the A5/3 cipher Kasumi is academically broken, and the same keys are used in A5/1 and A5/3.
Industry slow to react
According to Graham Titterington, principal analyst at Ovum, this is not the first time the A5/1 encryption has been cracked. He told ZDNet Asia in an e-mail that Nohl's technique is unlikely to be widely used, but said this development would spur the industry to eventually adopt stronger encryption.
"The mobile phone network has never been secure as there is no standard requiring encryption of traffic on the wired section of the network, between the carrier and the base transmitter. [There's a standard requirement] only on the wireless leg of the journey," Titterington said, adding that tapping traffic over the wired network was physically more difficult but still possible.
"The reality is that most mobile traffic isn't worth intercepting," he said. "People with sensitive data should overlay their own encryption on the transfer.
"I expect that the industry will eventually move to a stronger encryption algorithm, but it is hard to change when there is such a large investment in existing technology. The industry has been aware of the potential problem for at least 11 years, so don't expect rapid action."
A spokesperson from Singapore mobile operator, StarHub, said in an e-mail response to ZDNet Asia it was aware of reports that the GSM encryption has been cracked.
"As a GSMA member, we will of course be guided by what the GSMA recommends, and review and change our security protocols accordingly," he said.
Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG
18 minutes ago by NGTsummit_ASIA on twitter@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech
18 minutes ago by mcjimmm on twitterMalaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP
33 minutes ago by zdnetasia on twitterRT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
33 minutes ago by nickstersss on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news
33 minutes ago by Nathiet on twitter#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity
48 minutes ago by SecMash on twitterhttp://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security
48 minutes ago by CYSEC_COM on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN
48 minutes ago by Cloud_Fail on twitterPacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0
48 minutes ago by zdnetasia on twitterMalaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir
48 minutes ago by V_RaV on twitterhttp://t.co/VNaUVSe1 Malaysia organizations don't realize severity of cyberattacks: Cyberatt... http://t.co/TA5zWvUI http://t.co/wiqTBKkj
48 minutes ago by RavtachSolution on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/x1BJ0qSK
48 minutes ago by p_maju on twitterMalaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/3Yaa40JE
1 hour ago by InfoSecurityVid on twitterMalaysia organizations don't realize severity of cyberattacks, country's minister of sci, tech, innovation says http://t.co/KGEHLi18 #in
1 hour ago by EllyZDNetAsia on twitterMalaysia offers some manufacturing benefits over China http://t.co/mH23Uumr
1 hour ago by daryllau on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
4 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.