About Karsten Nohl
Born 1981. Karsten Nohl is a German engineer.
Karsten Nohl (born 11 August 1981) is a German cryptography expert and hacker. His areas of research include Global System for Mobile Communications (GSM) security, radio-frequency identification (RFID) security, and privacy protection.
Life Nohl grew up in the Rhineland area of Germany and studied electrical engineering at the SRH University Heidelberg from 2001 to 2004. Karsten has also served as interim CISO for the Indian corporation Jio from 2014 to 2017, as well as, for the Malaysian corporation Axiata in 2017.
Legic security Together with Henryk Plötz, Nohl gave a presentation in December 2009 documenting the flawed security of Legic Prime RFID security. The talk demonstrated how the system employed multiple layers of strange and obscure techniques in lieu of standard encryption and cryptographic protocols. This allowed cards to be read, emulated, and even for arbitrary master tokens to be created.
Car immobilizers At SIGINT-2013, Nohl gave a presentation on the insecurity of electronic car immobilizers used to prevent vehicle theft, documenting vulnerabilities in the three most widely used systems: DST40 (Texas Instruments), Hitag 2 (NXP Semiconductors) and Megamos (EM Micro).
Mobile network security deDECTed.org Nohl was part of the project group deDECTed.org , which in 2008 at 25C3 pointed out serious deficiencies in the DECT protocol.
In April 2010, Nohl, together with Erik Tews and Ralf-Philipp Weinmann, published details on the cryptographic analysis of DECT proprietary and secret encryption algorithm used (DECT standard cipher), which is based on reverse engineering of DECT hardware and descriptions from a patent specification.
A5/1 Security Project In the summer of 2009 Nohl introduced the A5/1 Security Project. The project demonstrated an attack on the GSM encryption standard A5/1 using Rainbow Tables. With the help of volunteers, the key tables were calculated in a few months and published on the 26C3 in December 2009.
The GSM Association described Nohl's plans as illegal and denied that wiretapping was actually possible. He replied that his research was purely academic.
As early as 2008, the hacker group THC had begun with the pre-calculation of key tables for A5 / 1, but probably never published the tables because of legal problems. The pair showed that the GSM encryption can be cracked "in about 20 seconds" and that calls can be recorded and played back.
GPRS security At Chaos Communication Camp 2011, Nohl and Luca Melette gave a presentation showing how GPRS networks do not securely encrypt their mobile traffic. The pair stated that they had recorded data transmissions in the networks of several German mobile providers, including Deutsche Telekom, O2 Germany, Vodafone and E-Plus. Through "Over The Air (OTA)" communication, such as SMS messages, it is possible to provide a SIM card with updates, applications, or new encryption keys. Such messages are digitally signed with DES, 3DES or AES. Nohl and his colleagues analyzed Android firmware images from various smartphone vendors. In some cases, a so-called "patch gap" was found, where vendors had not applied all security patches that otherwise should have been present based on the monthly patch level date specified in the firmware. Nohl released an updated version of the open source “Snoopsnitch” app with new features to allow users to run tests on their Android phones to check for a "patch gap" on their device.
Security of payment and booking systems Attacks on the Electronic Cash protocol At the 32C3, Nohl and colleagues presented an attack on the EC card protocols ZVT and Poseidon, which are a dialect of ISO 8583. Both protocols are the most common payment protocols in German-speaking countries.
Security gaps in travel booking systems At the 33C3, Nohl and colleagues highlighted security holes in Amadeus, Sabre, and Travelport, three of the largest Global Distribution Systems (GDS) which combined, handle approximately 90% of worldwide flight reservations and a large proportion of hotel, car rental, and other travel bookings.
IT security research BadUSB At Black Hat 2014, Nohl and Jacob Lell presented on security risks associated with USB devices. The USB standard is versatile and includes many different classes of devices. Their research is based on the reprogramming of USB controller chips, which are widely used and found in USB sticks. There is no effective protection against reprogramming, so a harmless USB device can be converted and used as a malicious device in many ways.
Possible scenarios for abuse include: A USB device can emulate a keyboard and issue commands on behalf of the logged-in user to install malware on their computer, malware which would also infect other USB devices connected. A USB device can pretend to be a network card, change the computer's DNS setting, and redirect traffic. A modified USB stick or a USB hard drive can load a small virus during the boot process, which infects the operating system before booting.
Preventing such attacks is not yet possible because malware scanners have no access to the firmware version of USB devices and behavior detection is difficult. USB firewalls that can block only certain device classes do not (yet) exist. The usual process to remove malware - reinstalling the operating system - fails here because the USB stick that installs the operating systems may itself already be infected, as well as a built-in webcam or other USB devices.
In addition, a proof of concept for Android devices was released to test the security.
Don’t just read it —
keep it.
Full-length biographies made to live with: read them, listen on the way to work, watch them tonight.
- E-book
- Audio
- Video
Instant download · yours to keep · every purchase keeps this site free
Important facts
People in Karsten Nohl's life
Named in this biography and alive at the same time
Contemporaries
People whose lives overlapped Karsten Nohl's
Frequently asked questions
Who is Karsten Nohl?
German cryptography expert and hacker (born 1981)
When was Karsten Nohl born?
Karsten Nohl was born on 11 August 1981.
What is Karsten Nohl's occupation?
Karsten Nohl is an engineer.
What nationality is Karsten Nohl?
Karsten Nohl is German.
Sources & further reading
Cite this page
APA: Biography.guide. (2026). Karsten Nohl. https://biography.guide/karsten-nohl/
MLA: "Karsten Nohl." Biography.guide, https://biography.guide/karsten-nohl/.
Chicago: "Karsten Nohl." Biography.guide. https://biography.guide/karsten-nohl/.
Data last updated: 2026-09-22 · Spot an error? Report a correction.
Portrait: Wikimedia Commons · author & licence
Page generated 2026-09-27 05:02 UTC