Kevin Karhan :verified: · @kkarhan
1292 followers · 87467 posts · Server mstdn.social

@manawyrm @q let me guess: Those were used for / devs that tended to use as testing grounds for their Software...

Sadly the bands have been allocated and AFAIK all regular multi-band bands have veen allocated and the only Sub - 700MHz bands unused are extremely uncommon (GSM-400 for example) and @BNetzA won't issue even experimental useage licenses for events in said bands...

#gsm #chaoscommunicationcongress #opengsm #osmocom

Last updated 1 year ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space

Circuit Switched Data (CSD) in GSM (osmodevcall)

about this event: c3voc.de
media.ccc.de/v/osmodevcall-202 #2023 #31

#ccc #OsmoDevCall #osmocom #berlin

Last updated 1 year ago

Open Source Mobile Comms · @osmocom
198 followers · 27 posts · Server fosstodon.org

Our next on March 15, 20:00 CET will feature a presentation about Circuit Switched Data (CSD). See osmocom.org/news/210 for details. Attendance free/open to any interested party.

#osmocom #OsmoDevCall #gsm #retronetworking

Last updated 1 year ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space

Long-range Telecommunications in HF band (osmodevcall)

about this event: c3voc.de
media.ccc.de/v/osmodevcall-202 #2023 #30

#ccc #OsmoDevCall #osmocom #berlin

Last updated 1 year ago

Renaud Lifchitz :verified: · @nono2357
258 followers · 1433 posts · Server infosec.exchange

RT @LaF0rge
I've last played with XOR-2G (test GSM auth algorithm ) in 2008-2010 timeframe. In we've had COMP128v1/2/3, MILENAGE and XOR-3G support, but somehow never bothered to implement XOR-2G. Changing that in gerrit.osmocom.org/c/libosmoco

#osmocom

Last updated 1 year ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space

iCE40-usbtrace: Full-Speed USB tracer (osmodevcall)

about this event: c3voc.de
media.ccc.de/v/osmodevcall-202 #2023 #29

#ccc #OsmoDevCall #osmocom #berlin

Last updated 2 years ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space
philpem · @philpem
394 followers · 975 posts · Server digipres.club

Practically speaking, you get a 2x8-bit additive checksum of the answer, which is 48 bits compressed into 16. So there are 2^32 RESULT values which would give the same SRES.

I'll leave it as an exercise to someone with better cryptography and maths skills than me to figure out how many challenge/response pairs you'd have to grab off the air to break the SAK.
And after that, you have to derive the number dialling key (K4,K5,K6).

#osmocom #NMT450

Last updated 2 years ago

philpem · @philpem
394 followers · 974 posts · Server digipres.club

Answer is ... yes, if we knew the value of RESULT for a given AUTH challenge. But RESULT isn't transmitted over the air. The mobile transmits the value SRES instead:
SR1 = (R1+R2+R3) mod 256
SR2 = (R4+R5+R6) mod 256
SRES = (R1 || R2)

So the problem boils down to: you have to brute-force a 96-bit key with 3 known bits. On a GPU, this might be feasible, each operation is a pair of big-integer exponentiations and a modulo.

#osmocom #NMT450

Last updated 2 years ago

philpem · @philpem
394 followers · 973 posts · Server digipres.club

This is useful because the algorithm imposes some constraints:
- MSBit of K1, K2 and K3 must be set (reduces keyspace to 16+32+48 - 3 = 93 bits (down from 96)
- K4, K5 and K6 are used to encrypt the dialled number (not authentication)
- K3 must be greater than or equal to RESULT

So we can break NMT SIS really easily, right?

#osmocom #NMT450

Last updated 2 years ago

philpem · @philpem
394 followers · 972 posts · Server digipres.club

Well then, that's a good find. Been staring at Analog and the code, did a deep dive... and found what may be the NMT SIS authentication algorithm: groups.google.com/g/fido7.ru.p

Looks like the "120 bit" SAK (subscriber auth key) is really six subkeys: K1 (16 bits). K2 (32 bits). K3 (48 bits). K4,5,6 (8 bits each).

The BS generates a random number RAND, which consists of two parts: RD1 (16 bits), RD2 (12 bits).

RESULT = ((RD1**K1) + (K2**RD2)) mod K3

#NMT450 #osmocom

Last updated 2 years ago

philpem · @philpem
382 followers · 888 posts · Server digipres.club

oh dear I've bought yet another silly thing. a Benefon TDP40/Delta phone, with charger. Hopefully it'll work with NMT. Either way, the service pod (Localbox) turns out to be a programmed 24LC16 EEPROM soldered into a charge/handsfree/car-kit connector, so programming the IDs and frequencies should be possible. web.archive.org/web/2004061117

#osmocom #NMT450

Last updated 2 years ago

Thorsten Alteholz · @debian
43 followers · 6 posts · Server alteholz.social

My Debian Activities in November 2022
FTP master
This month I accepted 292 and rejected 43 packages. The overall number of packages that got accepted was 295.
Debian LTS
This was my hundred-first month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian. 

This month my all in all workload has been 1
blog.alteholz.eu/2022/12/my-de

#Uncategorized #debian #ELTS #en #ftpmaster #LTS #osmocom #package #planetdebian

Last updated 2 years ago

media.ccc.de 🤖 · @mediacccde
584 followers · 2075 posts · Server botsin.space

MS/BS Power Control in OsmoBSC and OsmoBTS (osmodevcall)

about this event: c3voc.de
media.ccc.de/v/osmodevcall-202 #2022 #27

#ccc #OsmoDevCall #osmocom #berlin

Last updated 2 years ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space

MS/BS Power Control in OsmoBSC and OsmoBTS (osmodevcall)

about this event: c3voc.de
media.ccc.de/v/osmodevcall-202 #2022 #27

#ccc #OsmoDevCall #osmocom #berlin

Last updated 2 years ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space

Osmocom SIMtrace2 Tutorial - SIM protocol tracing: how & why (osmodevcall)

about this event: c3voc.de
media.ccc.de/v/osmodevcall-202 #2022 #26

#ccc #OsmoDevCall #osmocom #berlin

Last updated 2 years ago

Open Source Mobile Comms · @osmocom
160 followers · 18 posts · Server fosstodon.org

It just went public: @OpenTechFund has awarded us funding for the improvement of mainly in areas related to better integration of 2G+4G networks, including supporting @rhizomatica in Mexico. opentech.fund/results/supporte

#osmocom

Last updated 2 years ago

Thorsten Alteholz · @debian
43 followers · 6 posts · Server alteholz.social

My Debian Activities in October 2022
FTP master
This month I accepted 484 and rejected 55 packages. The overall number of packages that got accepted was 492.
Debian LTS
This was my hundredth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.  Woohoo, There is a party. (yes I am o
blog.alteholz.eu/2022/11/my-de
-astro

#Uncategorized #debian #ELTS #en #ftpmaster #LTS #osmocom #package #planetdebian

Last updated 2 years ago

Sebastian Lasse · @sl007
1092 followers · 2603 posts · Server digitalcourage.social

Well, apart from that both seem to use the same kind of 1 cable as attack vector, I'm watching

“GSM-R and how it differs from GSM”
media.ccc.de/v/osmodevcall-202

#osmocom #berlin #OsmoDevCall #gsm #gsmr

Last updated 2 years ago

media.ccc.de 🤖 · @mediacccde
982 followers · 2705 posts · Server botsin.space

media.ccc.de/v/osmodevcall-202 Osmocom Community TDMoIP (OCTOI) (osmodevcall): about this event: c3voc.de #2022 #25

#ccc #OsmoDevCall #osmocom #berlin

Last updated 2 years ago