Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But what you describe is not unique to telcos. And while I agree, you're talking about telco installation and operations, which is only one part.

Like I said, absolutely everything is broken. I've not seen this in other industries.

I've seen a vendor tell a telco "if you change the password from 'Secret' then your support contract is void", so yes, this part is completely broken.

But it's everything. Standards are broken, implementation is broken, one chassi running Linux with different architectures on the chassi, control card, and line cards. (x86, MIPS, and Sparc, not in that order). Another solution that had three boxes where they so shipped the org chart. One box ran linux, another freebsd, and the third openbsd. Why? "Uhm… well we have an openbsd core committer employed, so…".

And honestly that last example was one of the better ones. I had to read them RFCs to convince them their implementation was broken, but still.

Oh no, now you got me ranting about all sorts of things. Back on topic.

Take crypto. Some team designed the crypto in every single generation of phones. For more than 40 years the best possible interpretation of what they did is that they gave the job to someone fresh out of school, who said "neat! Crypto, that sounds exciting. I'll make some shit up, it'll be great!". But even then that can't be true. The crypto is too good to have been made by a newgrad. A newgrad's crypto would have been broken in 5 minutes my experienced attackers, but it took quite a while to crack e.g. A5/1, and some amount of resources.

It's baffling. It's both a lot of effort to make their shitty crypto, and also completely wasted. If they wanted to be lazy they should have slapped AES-ECB on it and called it a day. It would still have been shitty, but it would have been done in 5 minutes.

But maybe you're onto something there too. You can't make the cash by slapping on AES-ECB on anything. You need to make it look like it took all the billable time you charged for. And it probably did take all that time. I couldn't make something as good as A5/1 from scratch if my life depended on it.

But that is malice. And that's what I'm getting at. Whatever teams designed the crypto in phones for over 40 years have been malicious. They are at best liars and fraudsters, and at worst compromised by spy agencies and organized crime.

I can understand one generation. If it's just once you're just incompetent. But every single generation for half a century? Now you know what you're doing, and it's malicious.

There are people not born the first time these people screwed up, who now have grandchildren.

Yes, all big infrastructure has waste and corruption, but mobile networks don't have a single competently designed piece of infrastructure.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: