[2496] in cryptography@c2.net mail archive
Re: TIME Magazine on GSM cell phone crack
daemon@ATHENA.MIT.EDU (Phil Karn)
Mon Apr 13 21:52:58 1998
Date: Mon, 13 Apr 1998 17:55:49 -0700 (PDT)
From: Phil Karn <karn@qualcomm.com>
To: marc@cygnus.com
CC: declan@well.com, marc@scard.org, cryptography@c2.net
In-reply-to: <t53btu59rgi.fsf@rover.cygnus.com> (message from Marc Horowitz on
13 Apr 1998 20:28:45 -0400)
>> The SDA cautions that no practical over-the-air attack is known yet
>> but that one should not be ruled out.
>Ok, so which is it?
The latter. I am not intimately familiar with the details of GSM
over-the-air authentication, but I suspect it is indeed possible to
conduct this attack over the air. The bottleneck is apparently the SIM
card, so it wouldn't take much longer to do it over the air. But I'll
defer to the experts who actually worked on the problem.
Phil