Let's talk about the near future of cellular networks, shall we ? The race to the "5G Logo" is raging, yet 5GSA (Stand-Alone, fully featured network, not 5G New Radio on 4G Core) is still far down the roadmap. Why is that ? 1/18
First off, 4G core networks are already running, mostly on single or dual vendor proprietary software stacks. Why change something that "works" ? For new features, to whom commercial uses have not yet been built by marketing. 2/18
Next is the "disruption" provoked by the Sino-American economical war : while Asian vendors have their proprietary stacks up and running, 'muricans want to "break them open" by promoting Open RAN instead. The thinking is simple : 3/18
Open RAN promise is to disaggregate the network functions into smaller blocks, creating new interfaces, to lower the barrier of entry to the 5GSA core software market, hence their reliance on Asian vendors. But it's not yet ready. 4/18
See, new interfaces means larger overall code-base. More code means more bugs. More interfaces means more attack-surface. And interoperability requires heavy testing, so the barrier is not that lower and the result far from optimal. 5/18
When it comes to mobile networks, the security scheme is mostly that we inherited from fixed TDM network : there's none, but perimeter measures. Participants in core-network signalling (eg. MVNOs) are "contractually trusted" 6/18
Still, if an MVNO' EPC, or even just its public facing IMS (for VoWiFi and the likes) got breached, that's a serious threat like MitM SMS-based 2FAs. Control SMS are generally filtered, so basebands should be safe on 4G. 7/18
When it comes to Open RAN, the problem is slightly more insidious : numerous vendors will each play their part in the stack, which is far larger and will take years to mature to decent security standards. 8/18
Remember, the original motive for it is purely strategic between US and China. EU hasn't been involved, but its MNOs and vendors began to follow the 'murican shepherd by fear of Huawei being too effective. 9/18
"Security By Design" is a set of principles that imply always getting to the most simplistic design for a given purpose, as per RFC1925. Open RAN is the opposite of that : it is structurally unsafe by it's implied complexity. 10/18
Would an All-In-One blackbox sold by Huawei be safer than that ? Sure ! What is not is having 40 of their engineers on your floors running the network they sold to you. At that point your organization is breached. 11/18
In the EU, we do have small tech companies that do abide the proper design principles. @EuclidiaEurope members have been working on Simple RAN handbook.rapid.space/RS-Presentatio… 12/18
The good thing with simplicity is that it leads to shorter Time To Market. Simple RAN works _today_, not in two years. Sure, there's always room for improvement, but the fun part is that it's used in Asia and Africa, not EU yet 13/18
5GNR offers more bandwidth, but the political game makes Open RAN or Huawei proprietary 5G-SA unavailable yet. If we want the full promise of 5G (splicing, efficient M2M, Mobile Edge Compute), we maybe should reconsider… 14/18
First, security comes from simplicity and transparency. When you can read the code (possible with Simple RAN, not with the others) it's easier to spot and fix bugs. 15/18
Second, safety also comes from simplicity and transparency : when you operate a network with shared open processes, you'll iterate and better them faster. 16/18
Third, why having to choose between US or CN sides when we have our own stacks already available ? And why do EU vendors and MNOs waste time with a bad-by-design approach instead of pitching in ? 17/18
I'm talking to you @ThierryBreton @BERECeuropaeu @nokia @EricssonLabs @Arcep @orange : when shall we start working towards proper solutions ? Thanks to @p1security @elenaneira and many others for the inputs and inspiration. 18/18

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Jérôme Nicolle

Jérôme Nicolle Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @chiwawa_42

15 Nov
Message à caractère d'alerte à tous mes confrères des telcos : les JO2024 vont poser un énorme problème opérationnel. cc @aota_fr @ielo_group #FRnOG cc @Arcep @Paris2024 . Voici pourquoi : 1/8
@Orange_France, en tant que "Top Partenaire" des jeux, va fournir tout le réseau de fibres noires nécessaire au fonctionnement des jeux. Alors que c'est un produit hors catalogue @WholesaleOrange, cc @Adlc_ 2/8
Une des exigence du CIO est de souder les tampons des chambres télécom dans lesquels passent tous les câbles utilisés. Orange a accepté. Sauf que d'autres câbles, d'autres opérateurs passent aussi par là, via la convention LGC-BLO 3/8
Read 9 tweets
2 Nov
Woah, il est trop cool ce thread. Pour l'occasion, Je vais vous expliquer comment l'objectif "Net0" se matérialise pour un opérateur télécom.

GreanWashing 101, c'est parti ! 1/10

Il y a plein de facteurs d'émissions pour faire tourner un réseau. Sa construction, sa maintenance, ses équipements, tous les gens qui assurent ça, leurs déplacements et leurs lieux de travail… C'est un gros chantier. 2/10
Le premier point à bien comprendre, dans le cas d'Orange surtout, c'est que globalement, le réseau existe.

Sur tous ses marchés, pas seulement en France, on va donc décompter ce qu'on décommissionne de l’empreinte de ce qu'on ajoute. 3/10
Read 10 tweets
20 Apr
Voudriez-vous savoir pourquoi un ingénieur peut être opposé à #TousAntiCOVID ? Il ne s'agit pas de dogmatisme ou d'idéologie comme le résument souvent ses promoteurs condescendants, mais de problèmes bien identifiés. Un Thread 1/18
Quelques faits pour commencer : - Même avec la meilleure volonté du monde et les intentions les plus louables, le savoir-faire industriel disponible en terme de programmation s'étiole, et le code produit comporte nécessairement des failles. 2/18
Ce n'est pas dû qu'à l'incompétence ou au manque de moyens, mais une conséquence de l'accroissement de la complexité des systèmes informatiques à force d'empilement des couches et d'inflation des bases de code. 3/18
Read 18 tweets
21 Sep 20
The #TikTok ban story is somehow magical.

In the past, we suspected China to spy upon its users.

Trump's insistence about getting US investors onboard, thus able to enforce the CLOUD Act, gives us *certainty* the U.S. plan to spy upon them.

This reveals a bigger issue… 1/11
The CLOUD Act allows for U.S. agencies to access any *thing* on any server run by a U.S. backed company anywhere in the world. There are rules but @snowden showed us that they're quite lax. The NSA can do about whatever it wants. 2/11
For instance, PRISM was then NSA's program to automate the retrieval of data from social networks and large mail providers. One of the latter, GMail, is already known to *read* the content of every mail for "advertisement" purposes, so they have the content too. 3/11
Read 11 tweets
17 Sep 20
Tiens une petite anecdote qui s'est passée à Grenoble et qui aurait pu être évitée par la #5G, surtout si elle est correctement régulée et mutualisée. Ou la 4G mieux régulée dans une moindre mesure. Coucou @EricPiolle ! Un #Thread 1/12
Un des apports du protocole 5G, qui n'a rien à voir avec les fréquences rappelons-le, c'est qu'il facilite la mutualisation, la cohabitation, l'itinérance entre réseaux, et la mise en place de réseaux indépendants de ceux des opérateurs 2/12
En mai, des activistes survoltés ont incendié des sites mobiles. Tous les opérateurs ont été impactés, mais un plus que les autres : plus aucune couverture sur la zone. Pas de bol, les pompiers ont leur parc mobile chez lui. leparisien.fr/faits-divers/d… 3/12
Read 15 tweets
16 Sep 20
«Moratoire», «Amish», «Obscurantisme», «sectarisme» : Il n'y a que moi de voir ce genre de mots employés dans un "débat" sur un sujet technique ? Allez, encore un #Thread. #Parlons5G 1/13
Bon alors déjà, le dossier était très mal préparé coté gouvernement. On a vraiment l'impression qu'ils ne savent pas de quoi ils parlent. Un point simple : ils mélangent deux sujets : le protocole et les fréquences. 2/13
Coté protocole, on met à jour des équipements pour ajouter des fonctions, voire on ré-achitecture le cœur de réseau pour le rendre plus souple et économe. On ne touche pas aux fréquences, on réutilises les actuelles 3/13
Read 14 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Thank you for your support!

Follow Us on Twitter!

:(