Why (Special Agent) Johnny (Still) Can't Encrypt: A Security Analysis of the APCO Project 25 Two-Way Radio System

نویسندگان

  • Sandy Clark
  • Travis Goodspeed
  • Perry Metzger
  • Zachary Wasserman
  • Kevin Xu
  • Matt Blaze
چکیده

APCO Project 25 (“P25”) is a suite of wireless communications protocols used in the US and elsewhere for public safety two-way (voice) radio systems. The protocols include security options in which voice and data traffic can be cryptographically protected from eavesdropping. This paper analyzes the security of P25 systems against both passive and active adversaries. We found a number of protocol, implementation, and user interface weaknesses that routinely leak information to a passive eavesdropper or that permit highly efficient and difficult to detect active attacks. We introduce new selective subframe jamming attacks against P25, in which an active attacker with very modest resources can prevent specific kinds of traffic (such as encrypted messages) from being received, while emitting only a small fraction of the aggregate power of the legitimate transmitter. We also found that even the passive attacks represent a serious practical threat. In a study we conducted over a two year period in several US metropolitan areas, we found that a significant fraction of the “encrypted” P25 tactical radio traffic sent by federal law enforcement surveillance operatives is actually sent in the clear, in spite of their users’ belief that they are encrypted, and often reveals such sensitive data as the names of informants in criminal investigations.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Why Johnny Still, Still Can't Encrypt: Evaluating the Usability of a Modern PGP Client

This paper presents the results of a laboratory study involving Mailvelope, a modern PGP client that integrates tightly with existing webmail providers. In our study, we brought in pairs of participants and had them attempt to use Mailvelope to communicate with each other. Our results shown that more than a decade and a half after Why Johnny Can’t Encrypt, modern PGP tools are still unusable fo...

متن کامل

One-Way Cryptography

In a forthcoming paper[2], we examine the security of the APCO Project 25 (“P25”)[3] two-way digital voice radio system. P25 is a suite of digital protocols and standards designed for use in narrowband shortrange (VHF and UHF) land-mobile wireless two-way communications systems. The system is used by law enforcement, national security, public safety, and other government users in the United Sta...

متن کامل

Why Johnny Can't Encrypt: A Usability Evaluation of PGP 5.0

User errors cause or contribute to most computer security failures, yet user interfaces for security still tend to be clumsy, confusing, or near-nonexistent. Is this simply due to a failure to apply standard user interface design techniques to security? We argue that, on the contrary, effective security requires a different usability standard, and that it will not be achieved through the user i...

متن کامل

A Handheld Software Radio Based on the Ipaq Pda: Software

Vanu, Inc. has demonstrated analog FM two way radio and digital APCO Project 25 waveforms on an iPAQ-based handheld software radio. The iPAQ contains a low-power 206 MHz StrongARM processor that is used for all signal processing. This paper explains the software approaches used and lessons learned from implementing the waveforms on this platform. Commercial and public safety applications of the...

متن کامل

The Johnny 2 Standardized Secure Messaging Scenario

We present a scenario for user testing secure messaging tools and anti-phishing technology. The scenario, Johnny 2, is loosely based on the scenario that Whitten and Tygar presented in their acclaimed paper “Why Johnny Can’t Encrypt,”[14], but provided with significantly refined detail and automation. We recently used this scenario successfully in a user test with 43-subjects. We hope that by d...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011