Police Radio Encryption Vulnerabilities Exposed
Critical Infrastructure Radios still Vulnerable to eavesdropping Despite Security Fixes
Table of Contents
Two years ago, a troubling vulnerability was discovered in the encryption algorithms used in TETRA (Terrestrial Trunked Radio) systems – a standard powering radios used globally by critical infrastructure, law enforcement, intelligence agencies, and the military. Researchers found an intentional backdoor allowing eavesdropping on supposedly secure communications. While a fix was recommended, new research reveals that even the endorsed security solution contains a critical flaw, leaving sensitive communications at risk.
The Original TETRA Backdoor
The vulnerabilities were identified in 2023 by researchers at the Dutch security firm Midnight Blue - Carlo Major, Wooper Bock, and Jos Lawels. Their investigation focused on TETRA, a radio standard implemented in systems from manufacturers like motorola, Damm, and Sepura since the 1990s. For decades, the European Telecommunications Standards Institute (ETSI), the creator of the TETRA standard, restricted independent examination of the proprietary algorithms, keeping the flaws hidden.
The discovered backdoor allowed anyone with the right tools to decrypt communications secured by the TETRA algorithm. This posed a meaningful risk to sensitive data transmitted by emergency services, national security teams, and other organizations relying on secure radio dialog.
The Recommended Fix and Its Flaw
following the disclosure, ETSI advised users to implement end-to-end encryption on top of the flawed TETRA algorithm as a mitigation strategy. This was intended to add an extra layer of security, protecting communications even if the underlying TETRA encryption was compromised.
However,recent findings by the same Midnight Blue researchers reveal a critical weakness in at least one implementation of this recommended end-to-end encryption. The system utilizes a 128-bit encryption key, which is then compressed to just 56 bits before encrypting data. This reduction in key length drastically weakens the encryption, making it significantly easier to crack.
Who is Affected?
The vulnerable end-to-end encryption is primarily used in radios deployed by high-security organizations like law enforcement agencies, special forces, and covert military and intelligence teams.These groups require robust security for national security operations. ETSI’s initial endorsement of the solution following the 2023 backdoor discovery suggests its adoption might potentially be wider than initially anticipated.
Currently, it remains unclear which organizations are utilizing this specific implementation of the end-to-end encryption and whether they are aware of the vulnerability. The expensive nature of deploying such systems suggests a limited user base, but the potential consequences of compromised communications are severe.
Implications and Future Security
This discovery highlights the complexities of securing critical infrastructure and the importance of independent security audits. The initial concealment of the TETRA vulnerabilities by ETSI underscores the need for transparency in security standards.
The fact that a recommended fix also contains a significant flaw raises concerns about the thoroughness of security assessments and the potential for vulnerabilities to persist even after mitigation efforts. Organizations relying on TETRA radios, especially those utilizing end-to-end encryption, should urgently investigate whether their systems are affected and consider alternative, more secure communication methods.
