BERLIN — A German computer engineer said Monday that he had deciphered and published the secret code used to encrypt most of the world’s digital mobile phone calls, saying it was his attempt to expose weaknesses in the security of global wireless systems.
And with that, the encryption key for all GSM handsets will find its way into open source repositories around the world. It's funny, reading the New York Times article, because it's almost as if the GSM Association is taunting hackers.
“This is theoretically possible but practically unlikely,” said Claire Cranton, an association spokeswoman. She said no one else had broken the code since its adoption.
As with every other major security crack ever (CSS, Fairplay, AACS, etc.), whenever you start taunting the audience that is trying to teach you something, they respond with tools that put exploiting security cracks in the hands of even more people. Streisand effect, anyone?
It's just a matter of time now before a Kismet-style application is developed that lets you listen in other people's conversations. And a few months after that someone else will release a version with a user-friendly GUI.