
Encryption Made for Police and Military Radios May Be Easily Cracked
When the researchers publicly disclosed the issue in 2023, the European Telecommunications Standards Institute (ETSI), which developed the algorithm, advised anyone using it for sensitive communication to deploy an end-to-end encryption solution on top of the flawed algorithm to bolster the security of their communications.
But now the same researchers have found that at least one implementation of the end-to-end encryption solution endorsed by ETSI has a similar issue that makes it equally vulnerable to eavesdropping. The encryption algorithm used for the device they examined starts with a 128-bit key, but this gets compressed to 56 bits before it encrypts traffic, making it easier to crack. It's not clear who is using this implementation of the end-to-end encryption algorithm, nor if anyone using devices with the end-to-end encryption is aware of the security vulnerability in them.
The end-to-end encryption the researchers examined, which is expensive to deploy, is most commonly used in radios for law enforcement agencies, special forces, and covert military and intelligence teams that are involved in national security work and therefore need an extra layer of security. But ETSI's endorsement of the algorithm two years ago to mitigate flaws found in its lower-level encryption algorithm suggests it may be used more widely now than at the time.
In 2023, Carlo Meijer, Wouter Bokslag, and Jos Wetzels of security firm Midnight Blue, based in the Netherlands, discovered vulnerabilities in encryption algorithms that are part of a European radio standard created by ETSI called TETRA (Terrestrial Trunked Radio), which has been baked into radio systems made by Motorola, Damm, Sepura, and others since the '90s. The flaws remained unknown publicly until their disclosure, because ETSI refused for decades to let anyone examine the proprietary algorithms. The end-to-end encryption the researchers examined recently is designed to run on top of TETRA encryption algorithms.
The researchers found the issue with the end-to-end encryption (E2EE) only after extracting and reverse-engineering the E2EE algorithm used in a radio made by Sepura. The researchers plan to present their findings today at the BlackHat security conference in Las Vegas.
ETSI, when contacted about the issue, noted that the end-to-end encryption used with TETRA-based radios is not part of the ETSI standard, nor was it created by the organization. Instead it was produced by The Critical Communications Association's (TCCA) security and fraud prevention group (SFPG). But ETSI and TCCA work closely with one another, and the two organizations include many of the same people. Brian Murgatroyd, former chair of the technical body at ETSI responsible for the TETRA standard as well as the TCCA group that developed the E2EE solution, wrote in an email on behalf of ETSI and the TCCA that end-to-end encryption was not included in the ETSI standard 'because at the time it was considered that E2EE would only be used by government groups where national security concerns were involved, and these groups often have special security needs.
For this reason, Murgatroyd noted that purchasers of TETRA-based radios are free to deploy other solutions for end-to-end encryption on their radios, but he acknowledges that the one produced by the TCCA and endorsed by ETSI 'is widely used as far as we can tell.'
Although TETRA-based radio devices are not used by police and military in the US, the majority of police forces around the world do use them. These include police forces in Belgium and Scandinavian countries, as well as East European countries like Serbia, Moldova, Bulgaria, and Macedonia, and in the Middle East in Iran, Iraq, Lebanon, and Syria. The Ministries of Defense in Bulgaria, Kazakhstan, and Syria also use them, as do the Polish military counterintelligence agency, the Finnish defense forces, and Lebanon and Saudi Arabia's intelligence services. It's not clear, however, how many of these also deploy end-to-end decryption with their radios.
The TETRA standard includes four encryption algorithms—TEA1, TEA2, TEA3 and TEA4—that can be used by radio manufacturers in different products, depending on the intended customer and usage. The algorithms have different levels of security based on whether the radios will be sold in or outside Europe. TEA2, for example, is restricted for use in radios used by police, emergency services, military, and intelligence agencies in Europe. TEA3 is available for police and emergency services radios used outside Europe but only in countries deemed 'friendly' to the EU. Only TEA1 is available for radios used by public safety agencies, police agencies, and militaries in countries deemed not friendly to Europe, such as Iran. But it's also used in critical infrastructure in the US and other countries for machine-to-machine communication in industrial control settings such as pipelines, railways, and electric grids.
All four TETRA encryption algorithms use 80-bit keys to secure communication. But the Dutch researchers revealed in 2023 that TEA1 has a feature that causes its key to get reduced to just 32 bits, which allowed the researchers to crack it in less than a minute.
In the case of the E2EE, the researchers found that the implementation they examined starts with a key that is more secure than ones used in the TETRA algorithms, but it gets reduced to 56 bits, which would potentially let someone decrypt voice and data communications. They also found a second vulnerability that would let someone send fraudulent messages or replay legitimate ones to spread misinformation or confusion to personnel using the radios.
The ability to inject voice traffic and replay messages affects all users of the TCCA end-to-end encryption scheme, according to the researchers. They say this is the result of flaws in the TCCA E2EE protocol design rather than a particular implementation. They also say that 'law enforcement end users' have confirmed to them that this flaw is in radios produced by vendors other than Sepura.
But the researchers say only a subset of end-to-end encryption users are likely affected by the reduced-key vulnerability because it depends how the encryption was implemented in radios sold to various countries.
ETSI's Murgatroyd said in 2023 that the TEA1 key was reduced to meet export controls for encryption sold to customers outside Europe. He said when the algorithm was created, a key with 32 bits of entropy was considered secure for most uses. Advances in computing power make it less secure now, so when the Dutch researchers exposed the reduced key two years ago, ETSI recommended that customers using TEA1 deploy TCCA's end-to-end encryption solution on top of it.
But Murgatroyd said the end-to-end encryption algorithm designed by TCCA is different. It doesn't specify the key length the radios should use because governments using the end-to-end encryption have their own 'specific and often proprietary security rules' for the devices they use. Therefore they are able to customize the TCCA encryption algorithm in their devices by working with their radio supplier to select the 'encryption algorithm, key management and so on' that is right for them—but only to a degree.
'The choice of encryption algorithm and key is made between supplier and customer organisation, and ETSI has no input to this selection—nor knowledge of which algorithms and key lengths are in use in any system,' he said. But he added that radio manufacturers and customers 'will always have to abide by export control regulations.'
The researchers say they cannot verify that the TCCA E2EE doesn't specify a key length because the TCCA documentation describing the solution is protected by non-disclosure agreement and provided only to radio vendors. But they note that the E2EE system calls out an 'algorithm identifier" number, which means it calls out the specific algorithm it's using for the end-to-end encryption. These identifiers are not vendor specific, the researchers say, which suggests the identifiers refer to different key variants produced by TCCA—meaning TCCA provides specifications for algorithms that use a 126 bit key or 56 bit key, and radio vendors can configure their devices to use either of these variants, depending on the export controls in place for the purchasing country.
Whether users know their radios could have this vulnerability is unclear. The researchers found a confidential 2006 Sepura product bulletin that someone leaked online, which mentions that 'the length of the traffic key … is subject to export control regulations and hence the [encryption system in the device] will be factory configured to support 128, 64, or 56 bit key lengths.' But it's not clear what Sepura customers receive or if other manufacturers whose radios use a reduced key disclose to customers if their radios use a reduced-key algorithm.
'Some manufacturers have this in brochures; others only mention this in internal communications, and others don't mention it at all,' says Wetzels. He says they did extensive open-source research to examine vendor documentation and ' found no clear sign of weakening being communicated to end users. So while … there are 'some' mentions of the algorithm being weakened, it is not fully transparent at all.'
Sepura did not respond to an inquiry from WIRED.
But Murgatroyd says that because government customers who have opted to use TCCA's E2EE solution need to know the security of their devices, they are likely to be aware if their systems are using a reduced key.
'As end-to-end encryption is primarily used for government communications, we would expect that the relevant government National Security agencies are fully aware of the capabilities of their end-to-end encryption systems and can advise their users appropriately,' Murgatroyd wrote in his email.
Wetzels is skeptical of this, however. 'We consider it highly unlikely non-Western governments are willing to spend literally millions of dollars if they know they're only getting 56 bits of security,' he says.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Forbes
an hour ago
- Forbes
Do Not Keep These ‘High Risk' Apps On Your iPhone Or Android
While TikTok has generated the most headlines when it comes to allegations of your data being secretly sent to China, it turns out that a much bigger threat could have been been hiding on your phone all this time. And this one is much more dangerous. It has taken a spate of porn bans — first in the U.S. and now in Europe to flush out this risk. As much as smartphone users need their TikTok fix, porn is an even bigger draw. And tens of millions of users are suddenly masking their internet traffic for the first time, pretending to be somewhere they are not to bypass those bans. This is done by way of virtual private networks or VPNs. The same technology that failed to circumvent TikTok's short-lived U.S. ban in January. But for porn, VPNs work just fine. vpnMentor saw a 'staggering' 6,000% surge in U.K VPN use after restrictions came into effect. The same explosive growth seen in the U.S. and France. Many of the installed VPNs were free apps topping App Store and Play Store charts. But many of these have a nasty, hidden secret. As Top10VPN's Simon Migliano warns, "despite being made aware of glaring privacy failures and opaque corporate structures, Google and Apple continue to permit these high-risk apps on their platforms.' A month ago, the Tech Transparency Project (TTP) issued a report into free VPNs, warning that 'millions of Americans have downloaded apps that secretly route their internet traffic through Chinese companies.' It reported on this same threat in April. 'Apple and Google app stores continue to offer private browsing apps that are surreptitiously owned by Chinese companies… six weeks after they were identified.' 'In light of these findings," Migliano warns, "I strongly urge users to avoid Chinese-owned VPNs altogether." He says 'the risks are too great' to keep them on your phone. As BeyondTrust's James Maude told me 'if you aren't paying for a product, you are the product. These VPNs are a perfect example of the hidden costs of free apps where users seeking privacy are potentially unknowingly feeding data to a foreign nation state." Google told me it is "committed to compliance with applicable sanctions and trade compliance laws. When we locate accounts that may violate these laws, our related policies or Terms of Service, we take appropriate action.' While Apple says it enforces App Store rules but does not differentiate its handling of apps by the location of their developers, albeit VPNs are prohibited from sharing data. My advice is to open either the App Store on your iPhone or the Play Store on your Android, and then search for 'free VPN.' You should delete any apps listed as installed on your phone that highlight that 'free VPN" tag, unless they are linked to blue-chip, western technology firms that provide other security offerings. Meanwhile, here's the TTP list of Chinese apps you should search for: Apple App Store: Google Play Store:
Yahoo
3 hours ago
- Yahoo
Developer unveils AI-powered innovation that could boost EV performance: 'Making a significant contribution'
German engineers are taking more precise measurements inside the cramped, hot confines of electric vehicle motors. And their innovative diagnostic setup will have range-boosting potential, according to a news release from developer ZF. The product, called TempAI, uses artificial intelligence to improve temperature control by 15%. It's an invention that boosts efficiency, reduces the need for rare and expensive materials, and shortens development times from months to days, per ZF. "We are proud to bring this innovation into series production and thus making a significant contribution to more efficient e-mobility," Otmar Scharrer, ZF's head of development for electrified powertrain technology, said in the release. Generally, electric motors use power from the battery to drive the wheels. Cooling systems, controllers, and other tech are typically part of the setups, per the U.S. Department of Energy. ZF's AI software doesn't require more hardware add-ons. The temperature analysis requires low energy but provides fast, actionable metrics for existing control units. As a result, the motors can operate to their safest limit, giving 6% more peak power, while reducing energy consumption up to 18%. The performance was proved during testing, according to ZF. "This technology enables us to further increase the efficiency and reliability of our drives. At the same time, TempAI demonstrates how data-driven development can be not only faster, but also more sustainable and more powerful," Dr. Stefan Sicklinger, head of AI, digital engineering, and validation in research and development, said in the release. AI is being used by experts at the University of Liverpool to develop a better EV battery electrolyte. In China, advanced computing is helping scientists better understand nuclear fusion reactors. At ZF, it is giving experts an inside look at e-motors through millions of data points. "TempAI is a real technological breakthrough for the temperature management of electric drives." Scharrer said in the release. The improved performance could help increase already strong EV numbers. BloombergNEF reported that experts expect 22 million EVs to be sold globally this year. It would be a 25% jump from last year. Would you be more likely to get an EV if it came with a free home charger? Definitely Depends what the car costs Depends how fast it charges Not really Click your choice to see results and speak your mind. That's despite slowing numbers stateside — mainly due to fossil-friendly energy policy that leverages "a mighty federal arsenal," according to Politico. EV tax credits worth up to $7,500 are being retired years early, on Sept. 30, CNBC reported. The clean energy cutbacks are part of President Donald Trump's spending bill. Still, certain states provide their own incentives. That's in addition to the approximately $1,500 a year EV owners can save in gas and service costs. What's more, each EV that replaces a gas-guzzling ride prevents thousands of pounds of heat-trapping air pollution annually, according to the DOE. Tailpipe exhaust and other fumes are released when fossil fuels are burned, polluting the air with toxic substances that contribute to 6.5 million deaths worldwide a year, per the National Institute of Environmental Health Sciences. Hastening the shift to cleaner transportation can help clear the air. At ZF, the team thinks its AI-powered motor monitoring will be an important process during development that replaces costly measurements taken during operation and improves EV performance. "The result: more power, less unused reserves — and a leap in efficiency that pays off," per the release. Join our free newsletter for weekly updates on the latest innovations improving our lives and shaping our future, and don't miss this cool list of easy ways to help yourself while helping the planet.
Yahoo
5 hours ago
- Yahoo
Nebius' Q2 Loss Widens Y/Y, Revenues Rise on AI Demand, Stock Up
Nebius Group N.V. NBIS reported second-quarter 2025 adjusted net loss of $91.5 million, 49% wider than a loss of $61.6 million incurred a year ago. The company's revenues surged 625% year over year to $105.1 million. The increase in sales was primarily driven by strong performance in the company's core business and excellent execution by the TripleTen team. With R&D hubs across Europe, North America and Israel, Nebius' core business is an AI cloud platform designed for intensive workloads, powered by in-house developed software and hardware. Nebius provides AI builders with the compute power, storage, managed services and tools required to build, fine-tune and deploy their models. The Group also operates businesses under distinct brands, including Avride (autonomous driving technology) and TripleTen (a leading U.S.-based edtech platform for tech career reskilling). The Group also holds equity interests in other companies, including ClickHouse and Toloka. In the second quarter, following the completion of the investment transaction in Toloka—an AI development platform—Nebius ceased to hold majority voting power in the company. As a result, Toloka is no longer included in Nebius' consolidated financial statements and is now accounted for as an equity method investment. Toloka's results from prior periods have been reclassified as discontinued operations. As of June 30, 2025, there were outstanding employee stock options to purchase up to 7.5 million additional shares, with a weighted average exercise price of $87.83 per share, along with unvested restricted share units (RSUs) covering approximately 6.7 million shares. Following the earnings announcement, shares of the company jumped 19% in the trading session yesterday. Shares of the company have surged 59.4% in the past six months compared with the Zacks Internet - Software and Services industry's growth of 12.4%. Image Source: Zacks Investment Research Other Details NBIS reported an adjusted EBITDA loss of $21 million for the second quarter, narrower than the $58.1 million loss in the prior-year quarter. The company achieved positive EBITDA in its core AI infrastructure business earlier than previously projected. Sales, general and administrative expenses decreased 10% year over year to $68.2 million. Total operating costs and expenses increased 71% to $216.3 million As of June 30, 2025, NBIS' net income from operations was $502.5 million against a loss of $116.9 million in the year-ago period. Balance Sheet and Cash Flow As of June 30, 2025, NBIS had $1,679.3 million of cash and cash equivalents compared with $1,447 million as of March 31, 2025. Outlook Nebius continues to see strong momentum in its business, with demand for AI compute remaining exceptionally high. The company updated its full-year outlook. It raised its guidance for annualized run rate (ARR) revenue from the previous range of $750 million to $1 billion to a new range of $900 million to $1.1 billion. This increase is based on closed contracts for both existing and upcoming capacity, along with anticipated sales for the remainder of 2025. For core business revenue, the company is maintaining its guidance of $400 million to $600 million. For group revenue, the company has reaffirmed its previous guidance of $450 million to $630 million. This excludes the 2025 revenue guidance of $50 million to $70 million previously provided for Toloka. Nebius Group N.V. Price, Consensus and EPS Surprise Nebius Group N.V. price-consensus-eps-surprise-chart | Nebius Group N.V. Quote Adjusted EBITDA, as previously stated, is expected to be slightly positive at the group level by year-end, though the company still anticipates a full-year loss. NBIS maintained its capital expenditure guidance of approximately $2 billion for 2025. NBIS's Zacks Rank Nebius currently carries a Zacks Rank #4 (Sell). You can see the complete list of today's Zacks #1 (Strong Buy) Rank stocks here. Recent Performance of Other Companies Tyler Technologies, Inc. TYL reported better-than-expected second-quarter 2025 results. The company reported second-quarter non-GAAP earnings of $2.91 per share, which beat the Zacks Consensus Estimate by 4.7% and increased 21.3% year over year. Tyler Technologies' second-quarter revenues increased 10.2% year over year to $596.1 million. The top line topped the Zacks Consensus Estimate of $586.2 million by 1.7%. Shares of TYL increased 4.3% in the past year. Red Violet, Inc. RDVT came out with quarterly earnings of 28 cents per share, in line with the Zacks Consensus Estimate. This compares to earnings of 28 cents per share a year ago. Red Violet posted revenues of $21.8 million for the quarter ended June 2025, surpassing the Zacks Consensus Estimate by 1.51%. This compares to year-ago revenues of $19.1 million. Shares of RDVT have gained 58.1% in the past year. RingCentral RNG came out with quarterly earnings of $1.06 per share, beating the Zacks Consensus Estimate of $1.02 per share. This compares to earnings of 91 cents per share a year ago. RingCentral posted revenues of $620.4 million for the quarter ended June 2025, surpassing the Zacks Consensus Estimate by 0.43%. This compares to year-ago revenues of $592.91 million. Shares of RNG lost 9.2%in the past year. Want the latest recommendations from Zacks Investment Research? Today, you can download 7 Best Stocks for the Next 30 Days. Click to get this free report Ringcentral, Inc. (RNG) : Free Stock Analysis Report Tyler Technologies, Inc. (TYL) : Free Stock Analysis Report Red Violet, Inc. (RDVT) : Free Stock Analysis Report Nebius Group N.V. (NBIS) : Free Stock Analysis Report This article originally published on Zacks Investment Research ( Zacks Investment Research Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data