Comment Re:GSM encryption is not all that trivial (Score 3, Interesting) 176
An attack is very simple. You need to implement a Man in the Middle Attack. All you need to do is have your own base station. Low power base station are becoming cheaper, even to the extent that they are being put into aircraft.
There is no authentication under GSM of the base station. The base station can switch encryption on and off between the base station and the phone. The phone will not warn you that encryption has switched off!
Therefor to eavesdrop on a phone, when you can not get a tap at an exchange you need to buy yourself a small portable base station (Getting cheaper all the time), follow your victim, and listen.