#GSM security nightmares keep repeating every few years. A5/4 was approved by 3GPP at the same time as A5/3 (2009), but most vendors were lazy to change from 64bit to 128bit keys on both UE and network side. After the A5/2 and later A5/1 disasters of the past decades, the industry now again wasted 15 years until practial attacks catch up: https://www.iacr.org/cryptodb/data/paper.php?pubkey=34281 https://iacr.org/submit/files/slides/2024/crypto/crypto2024/500/slides.pdf