A hacker broke GSM encryption. Are your calls at risk?
The famous 2009 break of the A5/1 cipher in 2G (GSM) networks is now a classic of telecommunications security. We revisit what Karsten Nohl's discovery involved — and explain what it means for the security of calls in the 3G/4G/5G era.

GSM's protections turned out to be weaker than operators had assumed. (illustrative image)
In 2009 the German cryptologist Karsten Nohl publicly demonstrated that the A5/1 algorithm — which encrypts calls in 2G (GSM) networks — can be broken using widely available equipment. Did this mean that every call was exposed to eavesdropping? Not exactly — and the affair had a second layer.
A sensation at the hacker congress
Nohl revealed his discovery at the Chaos Communication Congress 2009 — the annual gathering of the international hacker scene, held since 1984 (the first editions in Hamburg; the 2009 congress was hosted by Berlin). Importantly, the German published the cracked code not to make eavesdropping easier, but on the contrary — to better protect GSM users' calls from unauthorised parties.
To break the encryption, the engineer used equipment worth just a few thousand dollars together with a set of so-called rainbow tables. The tables alone allowed the session key to be reconstructed and previously intercepted traffic to be decrypted — actual eavesdropping still required separate equipment to capture the radio signal.
GSM's protections are insufficient
The whole situation clearly shows that the existing protections of GSM networks are insufficient. The publicity around the case has one goal: to force mobile network operators to implement stronger mechanisms for protecting their customers' privacy.
In 2009 the scale was enormous — the vast majority of the roughly 4.3 billion phone users relied on GSM at the time, so the discovery put real pressure on the industry and on the GSM Association.
What it means today
The weaknesses of A5/1 have been known for years, and 2G networks are being gradually switched off in Poland and across Europe. Newer standards use far stronger cryptography: 3G (UMTS) uses the UEA1/UEA2 algorithms — based on the KASUMI and SNOW 3G ciphers — while 4G/LTE and 5G use ciphers from the AES, SNOW 3G and ZUC families, with mutual authentication of the network and the device. From an evidentiary perspective, passive "over-the-air" interception is now much harder and in practice remains the domain of specialised agencies — in proceedings, call data is obtained primarily by lawful means: from the operator (data retention) or from seized devices.