Total Pageviews

Showing posts with label 5g. Show all posts
Showing posts with label 5g. Show all posts

Sunday, 28 June 2020

5G网络的可怕潜力

刚得到消息:中国将在两周后发放5G手机号:
2018年1月,国家安全委员会战略规划高级主管 Robert Spalding 在白宫街对面的艾森豪威尔行政大楼办公室里看到了Axios的突发新闻警报。
这则快讯的标题是:“特朗普政府考虑将5G网络国有化”。
这位空军准将 Spalding 已在军队服役了近三十年,曾经作为国防部长驻北京工作。在国安委,他正在研究如何确保5G可以防止网络攻击。
“我并不是在政策角度上考虑这个问题的,”他说,“这个问题是关于物理学的,关于什么是可能的。”
令 Spalding 感到意外的是,Axios 的报道是基于他在一年中大部分时间里一直在研究的一份报告的泄露。
两个词可以解释我们当前的无线网络与5G之间的区别:速度和延迟。 5G预计会快一百倍,如果你相信炒作的话。(可以在不到4秒的时间内下载两小时的电影)该速度将减少并可能消除延迟。
再次,如果你相信炒作的话,这将导致一个全新的物联网,从烤面包机到狗项圈、从透析泵到跑鞋的所有东西,都将被连接起来。
远程机器人手术将成为常规,军方将开发高端超音速武器,自动驾驶汽车将沿着智能高速公路快速行驶……
赌注非常高。据估计,到2035年,5G将为全球经济注入12万亿美元,仅在美国就能增加2,200万个新工作岗位。我们被告知,这个5G世界将迎来第四次工业革命。
一个完全连通的世界也将特别容易遭受网络攻击。
甚至在引入5G网络之前,骇客就已经攻破了市政大坝系统的控制中心,阻止了一辆联网汽车(当时它沿着州际公路行进),并破坏了家用电器。
勒索软件、恶意软件、身份盗窃和数据泄露,已经变得如此普遍,以至于更多的美国人害怕成为网络犯罪而不是暴力犯罪的受害者
向在线世界添加更多设备注定会创造更多的遭受破坏的机会。 “5G可不仅适用于冰箱,” Spalding 说。
“它几乎是一切 —— 可以真正杀死人的。这是一种我们以前从未体验过的完全不同的威胁。”
Spalding 的解决方案是从头开始构建5G网络,将网络防御融入其设计中。
因为这将是一项艰巨的任务,他最初建议联邦政府支付一笔费用,并且基本上将任务出租给电信公司。
但他现在已经放弃了这个想法。他说,后来的草案提出了主要的电信公司 — Verizon、AT&T、Sprint 和 T-Mobile 这几大巨头组成一个独立的公司,共同构建该网络并共享它。
“它本来是一个全国性的网络,而不是一个国有化的网络”,Spalding 说。
“他们可以建立这个网络,然后向他们的零售客户出售带宽。政府永远不会拥有这个网络。它始终是关于,我们如何让行业真正保护系统?”
2017年,Verizon 宣布将在十一个城市推出5G,包括达拉斯、安娜堡、迈阿密和丹佛。AT&T也正在十几个城市测试其服务。T-Mobile专注于斯波坎。
在大多数情况下,他们在现有基础设施之上构建新服务,并继承原有的漏洞。克莱姆森大学教授 Thomas Hazlett 告诉我,“这只是过渡部分。会进行各种各样的实验,在市场上进行试验,并且进行各种部署,这些部署可以与旧系统真正区分开来。”
与此同时,运营商之间开始争夺地位。 Sprint 和 T-Mobile 提起了诉讼,声称AT&T的5GE服务(其中“E”代表“进化”)仅仅是4G的另一个名字。
根据 Spalding 的说法,当运营商听说政府正在考虑将其行业的未来“国有化”时,他们很快就会动员起来共同反对这一提议。
“随后我跟人们谈过,他们说他们从未见过这个行业可以如此迅速地团结起来,” Spalding 说。
他们在政府、国会和官僚机构中得到了支持,他们拥有如此庞大的政治游说队伍,而且是全面而迅速的采取了行动。”
Axios 的报道在周日发布。第二天,联邦通信委员会主席 Ajit Pai 彻底拒绝任何将互联网国有化的想法,称 “市场,而不是政府,最有利于推动创新和投资。”
到了周三,Spalding 失业了。 “对我长期以来的贡献没有任何感谢,” Spalding 告诉我。 “只是让我滚出去,别再回来了”。
华为是中国消费电子和电信设备制造商,目前是5G技术的全球领导者。其首席执行官任正非被华盛顿(尤其是特朗普)指责为中国情报的通道。
在“华盛顿邮报”的一篇专栏文章中,阿肯色州的共和党参议员 Tom Cotton 和德克萨斯州的 John Cornyn 表示,该公司是由中国政府补贴资助的公司,作为一种特洛伊木马可以“让中国有效”地控制数字制高点。
他们讲述了在亚的斯亚贝巴总部安装华为服务器的非洲联盟遭遇监视的故事,他们发现这些服务器每晚都在向中国发送敏感数据。
参议员指出,虽然华为强烈否认它是中国政府的代理人,但该公司受制于中国法律,这些法律要求公司与国家情报机构合作。
伦敦时报报道了CIA声称有证据表明,华为已从解放军以及中国情报部门的分支机构取款。
不过,欧盟准备拒绝美国的恳求,葡萄牙和德国等国家也表示愿意使用华为设备(原因详见上面的延伸阅读,那是来自欧洲的分析)。
加拿大已经依靠华为进行过至少一次5G试验。甚至美国自己的 AT&T 也继续在墨西哥使用华为设备
华为设备比其西方竞争对手的设备更便宜,创新委员会(dib)的研究人员说。在很多情况下该委员会为国防部长提供新技术方面的建议。
截至今年年初,华为占据了全球电信设备市场近30%的份额,其收入比前一年高出百分之三十九。
据该公司称,其持续增长“将使中国能够推广其首选的5G网络标准和规范,并将在未来塑造全球5G产品市场。”
有很好的理由可以让一家公司看起来像工业网络间谍。但禁止华为硬件无法保护这些网络。
即使在没有华为设备的情况下,该系统仍然可能依赖于在中国开发的软件,并且软件可以被恶意行为者远程重新编程
连接到5G网络的每台设备都可能仍然容易被骇客攻击。
目前在R街研究所负责国家安全计划的总法律顾问、前FBI官员 James Baker 说,“有人担心,从网络角度来看,连接到5G网络的设备不会非常安全。这给系统带来了巨大的漏洞,因为这些设备可以随时变成肉鸡,你可以拥有一个用来攻击不同部分的庞大僵尸网络”
今年1月,奥巴马时代联邦通信委员会主席 Tom Wheeler 在纽约时报发表了一篇题为 “如果5G如此重要为什么不安全?”的文章。特朗普政府已经把 Wheeler 辞退了。
最值得注意的是,在最近的国际标准谈判中,美国取消了5G的技术规范中包括网络防御的要求
“这是有史以来第一次,”Wheeler 写道,“在设计每一种新的网络标准时,网络安全都需要作为一种预见 —— 直到特朗普的FCC废除它”。
该机构还拒绝了建立和运营美国数字网络的公司负责监督其安全性的观点。这可能是预期内的,但目前的FCC确实不认为网络安全是其领域的一部分。
特朗普政府热衷于赢得它所谓的“5G竞赛”,可能更有兴趣试图制止华为 — 以及中国的技术发展。新FCC主席 Ajit Pai 最近宣布该委员会将阻止另一家中国公司中国移动在美国的运营,并再次引用安全问题。
经济学家兼技术政策研究所主席 Scott Wallsten 表示,“如果我们没有与中国有其他贸易问题,那么接受[政府]的安全声明就更容易了。但当它与所有其他贸易问题混淆时,就会让人更加怀疑。”
特朗普签署了一份关于“为美国的未来制定可持续战略”的备忘录,几周后,FCC拍卖了新的无线电频谱(还有另一场拍卖计划在今年晚些时候举行)。
开辟新频谱对于实现5G承诺的超高速度至关重要。
大多数美国运营商正在计划将其服务迁移到该频谱的较高部分,可以允许巨大的数据流通过(较低的部分速度没那么快,但可靠)。
直到最近,这些被称为毫米波的高频频段还无法用于互联网传输,但天线技术的进步将使其成为可能,至少在理论上如此。
在实践中,毫米波是很挑剔的:它们只能短距离传输 —— 大约一千英尺 —— 并且会被墙壁、树叶、人体和下雨所阻碍。
为了适应这些限制,至少必须在建筑物内和每个城市街区安装大量的5G蜂窝式中继。例如,安装在1300万个电线杆上的中继将为美国一半以上人口提供5G速度,安装成本约为4,000亿美元
农村地区有太多树木和太少的人口,可能不适用。
部署数以百万计的无线中继而且彼此如此靠近,因此已经引发了人类身体健康方面的担忧。
两年前,来自36个国家的180名科学家和医生呼吁欧盟暂停对5G的采用,直到研究得出切实结论关于低水平辐射增加所产生的影响。
今年2月,来自康涅狄格州的民主党参议员 Richard Blumenthal 参加了FCC和FDA在没有评估其健康风险的情况下推进5G的任务。“我们对此视而不见”,他总结说。
基于数百万个中继、天线和传感器的系统也提供了以前无法想象的监控潜力。
电信公司已向营销人员出售位置数据,执法部门也使用类似数据跟踪抗议者。
5G将前所未有地准确记录某人来自哪里、他们去了哪里、以及他们在做什么。
与面部识别和人工智能相结合,5G的数据流和定位功能将使匿名彻底成为历史文物。
在中国,已经安装了35万个5G中继,再加上一个广泛的监控摄像头网络,每个监视器都配备了面部识别技术,使得当局能够跟踪任何人。
“这种做法使中国成为了应用下一代技术监视其所有人口的先驱,开启了自动化种族主义的新时代。”
美国至少目前还没到这个地步。但是随着5G开始推出,捕获和利用来自个人、企业和政府的新数据流的争议将变得更加激烈。
建立对系统的保障似乎是一个明显和必要的目标。
Spalding 现在是哈德森研究所的高级研究员,并就企业和其他机构对中国提出的网络安全威胁提供建议。他警告说,危险并不仅限于单一的民族国家。
这允许极权政权 — 或任何政府 — 完全了解你所做的一切,”他说。
“因为当权者永远想要规范你的思考方式、你的行为方式、你做的一切事。问题在于,大多数人仍没有意识到这个世界正在变得非常危险”。⚪️
⚠️以下这些内容都是5G才能实现的 —— 请注意绝对不止这些

Wednesday, 29 April 2020

5G Security

Bruce Schneier 是信息安全领域的大牛(搞密码学的应该都知道他)。以下是他的一篇博文,谈“5G 网络的安全问题”。
5G Security @ Schneier
  他开篇就点到了咱们天朝(中国公司会迫于政府压力,在网络设备中内置后门)。然后他又说:即使完全禁止中国公司参与 5G 网络,依然是【不够】滴。
  在文章的后续部分,他指出了 5G 网络可能会有如下三大问题:
问题1——5G 标准太复杂
首先,这会导致软件的实现也太复杂,软件代码一旦复杂,潜在的漏洞就更多,也更难发现/修复。
其次,这会导致软件对标准协议的实现不够完全(只是【部分实现】了协议),同样会导致安全问题。
问题2——向后兼容性
熟悉网络攻击的同学,应该听说过【降级攻击】。这类攻击经常出现在“TLS/SSL、Wi-Fi、移动通讯网络”之类的场景中。
由于 5G 网络必须大量兼容 4G 协议,攻击者可以采用某种技巧,诱导设备降级到 4G 协议,然后再利用 4G 协议的弱点。
问题3——5G 标准中,很多“安全选项”不是强制滴
这个要由“标准委员会”来背锅。由于标准中的一些安全选项属于【可选】选项(非强制性),设备制造商通常不去实现它们。
(对设备制造商而言)实现的选项越少,开发就越简单,开发成本也越低。另外,很多设备制造商还面临竞争压力,为了让产品尽快上市,他们倾向于不完成那些【可选】的协议选项。
--------------------------

5G Security

The security risks inherent in Chinese-made 5G networking equipment are easy to understand. Because the companies that make the equipment are subservient to the Chinese government, they could be forced to include backdoors in the hardware or software to give Beijing remote access. Eavesdropping is also a risk, although efforts to listen in would almost certainly be detectable. More insidious is the possibility that Beijing could use its access to degrade or disrupt communications services in the event of a larger geopolitical conflict. Since the internet, especially the "internet of things," is expected to rely heavily on 5G infrastructure, potential Chinese infiltration is a serious national security threat.
But keeping untrusted companies like Huawei out of Western infrastructure isn't enough to secure 5G. Neither is banning Chinese microchips, software, or programmers. Security vulnerabilities in the standards­the protocols and software for 5G­ensure that vulnerabilities will remain, regardless of who provides the hardware and software. These insecurities are a result of market forces that prioritize costs over security and of governments, including the United States, that want to preserve the option of surveillance in 5G networks. If the United States is serious about tackling the national security threats related to an insecure 5G network, it needs to rethink the extent to which it values corporate profits and government espionage over security.
To be sure, there are significant security improvements in 5G over 4G­in encryption, authentication, integrity protection, privacy, and network availability. But the enhancements aren't enough.
The 5G security problems are threefold. First, the standards are simply too complex to implement securely. This is true for all software, but the 5G protocols offer particular difficulties. Because of how it is designed, the system blurs the wireless portion of the network connecting phones with base stations and the core portion that routes data around the world. Additionally, much of the network is virtualized, meaning that it will rely on software running on dynamically configurable hardware. This design dramatically increases the points vulnerable to attack, as does the expected massive increase in both things connected to the network and the data flying about it.
Second, there's so much backward compatibility built into the 5G network that older vulnerabilities remain. 5G is an evolution of the decade-old 4G network, and most networks will mix generations. Without the ability to do a clean break from 4G to 5G, it will simply be impossible to improve security in some areas. Attackers may be able to force 5G systems to use more vulnerable 4G protocols, for example, and 5G networks will inherit many existing problems.
Third, the 5G standards committees missed many opportunities to improve security. Many of the new security features in 5G are optional, and network operators can choose not to implement them. The same happened with 4G; operators even ignored security features defined as mandatory in the standard because implementing them was expensive. But even worse, for 5G, development, performance, cost, and time to market were all prioritized over security, which was treated as an afterthought.
Already problems are being discovered. In November 2019, researchers published vulnerabilities that allow 5G users to be tracked in real time, be sent fake emergency alerts, or be disconnected from the 5G network altogether. And this wasn't the first reporting to find issues in 5G protocols and implementations.
Chinese, Iranians, North Koreans, and Russians have been breaking into U.S. networks for years without having any control over the hardware, the software, or the companies that produce the devices. (And the U.S. National Security Agency, or NSA, has been breaking into foreign networks for years without having to coerce companies into deliberately adding backdoors.) Nothing in 5G prevents these activities from continuing, even increasing, in the future.
Solutions are few and far between and not very satisfying. It's really too late to secure 5G networks. Susan Gordon, then-U.S. principal deputy director of national intelligence, had it right when she said last March: "You have to presume a dirty network." Indeed, the United States needs to accept 5G's insecurities and build secure systems on top of it. In some cases, doing so isn't hard: Adding encryption to an iPhone or a messaging system like WhatsApp provides security from eavesdropping, and distributed protocols provide security from disruption­regardless of how insecure the network they operate on is. In other cases, it's impossible. If your smartphone is vulnerable to a downloaded exploit, it doesn't matter how secure the networking protocols are. Often, the task will be somewhere in between these two extremes.
5G security is just one of the many areas in which near-term corporate profits prevailed against broader social good. In a capitalist free market economy, the only solution is to regulate companies, and the United States has not shown any serious appetite for that.
What's more, U.S. intelligence agencies like the NSA rely on inadvertent insecurities for their worldwide data collection efforts, and law enforcement agencies like the FBI have even tried to introduce new ones to make their own data collection efforts easier. Again, near-term self-interest has so far triumphed over society's long-term best interests.
In turn, rather than mustering a major effort to fix 5G, what's most likely to happen is that the United States will muddle along with the problems the network has, as it has done for decades. Maybe things will be different with 6G, which is starting to be discussed in technical standards committees. The U.S. House of Representatives just passed a bill directing the State Department to participate in the international standards-setting process so that it is just run by telecommunications operators and more interested countries, but there is no chance of that measure becoming law.
The geopolitics of 5G are complicated, involving a lot more than security. China is subsidizing the purchase of its companies' networking equipment in countries around the world. The technology will quickly become critical national infrastructure, and security problems will become life-threatening. Both criminal attacks and government cyber-operations will become more common and more damaging. Eventually, Washington will have do so something. That something will be difficult and expensive­let's hope it won't also be too late.