Jump to content

Recommended Posts

Posted

Looking at a new two-way radio solution and the options for encryption. It is inevitable that even if we say "don't transmit any identifiable information on the radios", it will happen. There will be some emergency, or someone forgets, or it gets decided that actually, they'd very much like to be able to say names and PID over the radio. So I've been asked to look into encryption for this new suite of radios.

 

Currently looking at Motorola R2's and R5's. They offer 8-bit (XOR), 40-bit (RC4) and for an extra unknown amount of money (around £200~) the R5's will do AES-256.

 

Ruling out the 8-bit "encryption" straight away... RC4 has been considered "broken" for well over 10 years now.

 

Am I right in thinking that schools are therefore required to have AES-256 encrypted radios if they should ever want to utter the name of a student?

Posted
1 hour ago, psynegy said:

Looking at a new two-way radio solution and the options for encryption.

 

If this is for your school building / area, if you have decent WiFi coverage throughout could you use a push-to-talk-over-WiFi solution? That should take care of your network security / encryption, and should give you network-manageable devices.

  • Like 1
Posted (edited)
1 hour ago, psynegy said:

Am I right in thinking that schools are therefore required to have AES-256 encrypted radios if they should ever want to utter the name of a student?

Depends what other mitigations might already be in place and where it falls on your risk assessment as to how much the school feels neccassary to invest in additonal security.

 

Yes, to be as safe as possible, you would need full AES encrypted radios (or no radios - that's the "most secure" option), and I'm sure other people will be quick enough to go into detail about that.

 

But risk matrix it:  If it happens it's hight impact for sure, so the question for you is, realisitcally  what are the chances of someone scanning/using the same frequency as you within about 10 miles of the school? and what are the chances that that person has the techcnial knowhow and desire to break XOR or RC4 ecryption? 

Unless there's something specific in your circomstances, I'd say it's a pretty low likelyhood, which makes it overall a lowe/meduim risk category event. In which case, it might not warrrant the extra expenditure of ful AES ecrypted radios.


or just do what @dhicks says.

Edited by Rob_D
Posted
1 hour ago, Rob_D said:

But risk matrix it:  If it happens it's hight impact for sure, so the question for you is, realisitcally  what are the chances of someone scanning/using the same frequency as you within about 10 miles of the school? and what are the chances that that person has the techcnial knowhow and desire to break XOR or RC4 ecryption? 


That's security through obscurity though, which probably isn't the best route. 🫣

Posted

We bought ear-pieces for all the staff who use radios. Not encryption, but it stops (or at least greatly reduces) the amount of names/PID which is overheard. Yes, if you had the right tech you'd be able to connect in and listen, but our concern was about students overhearing stuff.

Posted
1 minute ago, paulkerton said:

That's security through obscurity though, which probably isn't the best route. 🫣

No it's not. It's risk management. Impact vs likelyhood matrix is the basis every risk assessment I've ever done. High impact, low chance = low to medium risk. I'm not advocating for doing nothing, I'm saying make the response preportional to the risk. Do you need to spend a bunch extra on a maximum security solution for a medium level risk or is it better to manage the risk and put that etxra money to mitigating a high risk category issue? 

 

I know the general oppinion on here is to aim for maximum security in all thigns at all times, and Ideally yes do all the things. But realisitcally, we have to look at where to best target limited budgets.

  • Like 2
Posted (edited)
15 minutes ago, Rob_D said:

No it's not.

1 hour ago, Rob_D said:

realisitcally  what are the chances of someone scanning/using the same frequency as you within about 10 miles of the school? and what are the chances that that person has the techcnial knowhow and desire to break XOR or RC4 ecryption? 


Yes it is. Almost the textbook definition of it. You're undertaking a risk management exercise but you're relying on:

1. The attacker would need to be within a 10 mile radius of the school
2. They'd have to be scanning the same frequencies you're using
3. They'd have to have the technical ability to break XOR or RC4.

That is literally security through obscurity. You're suggesting weaker encryption is fine, based on the likelihood it'll be found. Plus, using known broken encryption to transmit PII would absolutely not be considered as an appropriate technical measure under the DPA. Low likelihood is not a security control. If someone wanted to do it, a RPi and an SDR aerial would have them listening in minutes. Once encryption is broken, there is no "technical knowhow" needed at that point. Theres like 100,000 amateur radio operators licensed in the UK. That's plenty of people who are bored, can't listen to the police radios anymore, and could be looking around for conversations.

My answer would be to go with AES-256. If you can't do it properly, you don't do it at all.

Edited by paulkerton
Posted
5 minutes ago, paulkerton said:



That is literally security through obscurity.

No that's not security through obscurity, that's publicly broadcasting on open frequencies. there's no obscurity involved. 

  • Like 3
Posted
4 minutes ago, paulkerton said:

You're undertaking a risk management exercise but you're relying on:

1. The attacker would need to be within a 10 mile radius of the school
2. They'd have to be scanning the same frequencies you're using
3. They'd have to have the technical ability to break XOR or RC4

How would you risk assess it without assessing how likelty it is to happen then? I've mostly used the risk V likeleyhood matrix for assessing threats.

Posted
Just now, Rob_D said:

How would you risk assess it without assessing how likelty it is to happen then? I've mostly used the risk V likeleyhood matrix for assessing threats.


I wouldn't assess the likelihood of it happening first. I'd start with the likelihood of success if an attempt were made.
 

The success rate is basically 100% because RC4 is broken and SDR hardware is cheap. They wouldn't even need to be within 10 miles since high-gain aerials can capture radio traffic from way further away. That instantly rules out RC4 and XOR. I wouldn't even bother with the rest of the assessment as it fails at the first hurdle.

My insurer isn't going to cover me if I leave my front door unlocked because I thought the likelihood of someone trying the handle was low. Or if they find out I kept a key under the mat.

  • Like 1
Posted
1 hour ago, paulkerton said:


1. The attacker would need to be within a 10 mile radius of the school
2. They'd have to be scanning the same frequencies you're using
3. They'd have to have the technical ability to break XOR or RC4.
 

I'm not a radio ham by any stretch, but I've often sat with an SDR on my PC scanning for interesting things. 

In any builtup area there will be people doing 2, it's quite a big hobby, there's loads of info around it.

I guess you'd have to capture a lot of data and break it for 3. never tried. 

  • Like 1
Posted

I'm pleased to see that I'm not just overthinking this. I think I realised I wasn't getting great advice from this two-way radio sales person when they told me that instead of AES-256, we should instead get a private frequency from Ofcom, because, you know, that's more private... Impenetrable I tell you!

 

They even went so far as to tell me that "plenty of schools that use these radios are more than meet their privacy requirements"...

 

Speaking of which... anyone know any good radio suppliers..? 👀

 

WiFi devices sound great in theory, but our site makes it... impractical... see my thread asking about solar powered WiFi AP's 🙃

Posted

If you're talking about standard low-power two-way radios (like PMR 446) without a repeater, they're unlikely to be heard by eavesdroppers 5 miles away, let alone 10 miles.

 

I'm more inclined to agree with Rob_D in that the measures need to be appropriate to the risk. Methods used to lower the risk are to advise staff not to transmit personal info over the radios, and to use some form of encryption (some is better than none at all).

Posted
10 hours ago, webman said:

I'm more inclined to agree with Rob_D in that the measures need to be appropriate to the risk. Methods used to lower the risk are to advise staff not to transmit personal info over the radios, and to use some form of encryption (some is better than none at all).


But we know how successful that will be (They will transmit personal info, let's be honest) so for the cost, you may as well get an encryption standard that isn't already popped wide open, surely?

Posted

We use Entel DX485 radios and get them pre-configured by our supplier Radiocoms.

 

  • Staff are told not to say any sensitive information over the radio and to instead pick up a phone
  • All staff with radios are given earpieces
  • Only behaviour use the radios day to day, the other uses are when a fire alarm goes off
  • Facilities have their own radios and channel
  • We have a private frequency range we pay for via Ofcom
  • We have a signal repeater for full site coverage, there were too many instances of the concrete and metal work between the floors blocking the signal

I honestly couldn't tell you whether they're encrypted or not, it's not a thought that crossed my mind until I read this thread.

Posted
2 hours ago, drutt said:

We use Entel DX485 radios and get them pre-configured by our supplier Radiocoms.

They're very cute looking! Looks like a base unit is around £200 and the only price I can find for the AES-256 licence is €177. Nearly doubles the price! Still cheaper than Motorola...

 

2 hours ago, drutt said:

I honestly couldn't tell you whether they're encrypted or not, it's not a thought that crossed my mind until I read this thread.

Sorry...

 

3 hours ago, paulkerton said:

But we know how successful that will be

No comment.

  • Haha 1
Posted

Ours are basic as hell CRT 7WP models. No encryption, we do have our own frequencies but also a strict policy on their use. Breaking that policy is taken seriously and if it results in an active breach then that's effectively gross misconduct. 

Rock and a hard place here, wifi reception is good but not good enough thanks to the building type to rely on it for safeguarding purposes, and phone reception is akin to a faraday cage in all but a couple of tiny places. And to top it off, the financial reserves of a hobo means that spending on fancy systems is out of the question.

So risk management ftw - you break the rules, we break your..... employment? :)

Posted
1 minute ago, synaesthesia said:

 

Rock and a hard place here, wifi reception is good but not good enough thanks to the building type to rely on it for safeguarding purposes, and phone reception is akin to a faraday cage in all but a couple of tiny places. And to top it off, the financial reserves of a hobo means that spending on fancy systems is out of the question.

I didn't know you worked here...

 

1 minute ago, synaesthesia said:

you break the rules, we break your..... employment? :)

Putting that straight in the policy - verbatim.

  • Haha 1
Posted (edited)

These are £70 each depending on where you buy. They support AES256 out of the box and get really good reviews.

I'm not sure of the UK licensing wrt encryption on walkie talkie frequencies. 

 

 

Edit: to answer my own Question wrt encryption: It's illegal on amateur radio, you will need a business license for £75 for 5 yrs: https://www.ofcom.org.uk/spectrum/radio-equipment/business-radio-licensing

Edited by dmj
Posted
16 hours ago, dmj said:

These are £70 each depending on where you buy. They support AES256 out of the box and get really good reviews.

I'm not sure of the UK licensing wrt encryption on walkie talkie frequencies. 

 

 

Edit: to answer my own Question wrt encryption: It's illegal on amateur radio, you will need a business license for £75 for 5 yrs: https://www.ofcom.org.uk/spectrum/radio-equipment/business-radio-licensing

 

Happily, we are already licenced as required!

 

Those radios are indeed a tempting proposition compared to a similarly spec'd R7 at less than 1/10th the price! (R7 FKP Premium: £540 + Charger £40 + AES256 £200 = £780)

 

However, whilst it looks like there haven't been any more recent "discoveries", the not so distant past is worrisome.

Posted

I had money on someone commenting about chinese backdoors, even though you're uploading you own certificate.

Posted
2 hours ago, dmj said:

I had money on someone commenting about chinese backdoors, even though you're uploading you own certificate.

It doesn’t matter what certificate you use if the encryption is prevented from being implemented properly…

 

Have a read of the thread; it’s quite interesting. Goes above my head somewhat, but my understanding is that without the initialisation vector being randomised, any repeating patterns make it surprisingly easy to decrypt without the key. But this particular issue was magically fixed in a later firmware version.

 

I’m also not saying this is just a China problem, I’m sure there are plenty of accidental (or not so accidental) flaws in many systems we rely on.

 

I’m very aware that some CCTV manufacturers can generate password reset codes for their devices as they please… So we take precautions and firewall them off. Not so easy when it comes to a device that can receive a radio signal from miles away..!

  • Like 1
Posted
2 hours ago, psynegy said:

It doesn’t matter what certificate you use if the encryption is prevented from being implemented properly…

 

My point is the exhausting double standard. If a Chinese company like Huawei or Baofeng patches a standard vulnerability, the internet instantly screams 'Chinese State backdoor!' But when Microsoft patches a massive Exchange Server flaw, or Apple fixes a zero-click exploit in iOS, everyone just shrugs and calls it a normal software bug. It’s like everyone completely forgot about Edward Snowden. The NSA literally intercepted American-made Cisco routers in transit to plant surveillance tools in them,  they even owned Crypto AG  and sold it on yet we pretend only the Chinese government exploits tech. You know after Snowdon there's even a US Law that explicitly allows the US government access to data held on any US owned companies servers anywhere in the world (because Snowdown pointed out they were illegally dragnet sweeping up this data anyway). It's why lots of EU schools ban Google/MS infra. AWS had to start an entirely EU owned company to restore trust, and It's why the EU is scrambling around trying to build it's own infra. I think a patched finmware is the least of the problems TBH. 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...