Live data from Hacker News

Ask HN: Why are SIM cards still a thing?

news.ycombinator.com

71–80 of 191 posts

Re: Ask HN: Why are SIM cards still a thing?

#71
post #70

Earlier quoted context omitted.

Flip phones have some of the best protections available: the sensors aren't there. You can't leak your location if there is no GPS module in your phone, you can't have your camera hacked if there is no camera and so on. I'd prefer all this stuff came with physical switches so it can be enabled/disabled in a hack-proof manner.

Location tracking is possible without GPS module https://en.wikipedia.org/wiki/Mobile_phone_tracking What's your threat model? https://ssd.eff.org/en/module/introduction-threat-modeling For most people mass surveillance is a more realistic threat than the NSA hacking their camera.

Corporations merging their databases. This is happening in real time, right now.

I don't have any illusions about being able to stay private from the eyes of nation state level adversaries but commercial entities can still be kept out if you try.

Re: Ask HN: Why are SIM cards still a thing?

#72

Earlier quoted context omitted.

Doesn't every login form on the web also protect the respective operator from the subscriber? Why can't a "software SIM" simply be a username and a password? My explanation is that it's difficult to change something that literally the entire world uses.

We're moving away from usernames and passwords though, into 2-factor systems such as... smart cards (Chip and PIN). Regressing phones back into usernames and passwords is a clear step backwards in security.

Yes, and remember too that SIMs are standardised technology from the mid-1990s, originating in GSM. It's not a trivial matter to change security in globally standardised technology.

(and Even if you did, it would need to be backward-compatible and still support SIM cards)

There is a good deal more to telecoms tech than just the tech side - the standardisation process brings a whole bunch of competitor companies into a room to develop a solution, incrementally over a number of years.

This applies from physical aspects all the way up to higher level concerns like security. It's a fascinating development process.

Re: Ask HN: Why are SIM cards still a thing?

#73
post #65

Earlier quoted context omitted.

I'd argue that if someone wants to get a flip phone for privacy reasons they should be able to not download shady apps and give them permissions without thinking.

Flip phones have some of the best protections available: the sensors aren't there. You can't leak your location if there is no GPS module in your phone, you can't have your camera hacked if there is no camera and so on. I'd prefer all this stuff came with physical switches so it can be enabled/disabled in a hack-proof manner.

You can't leak your location if there is no GPS module in your phone

While not as precise, you can definitively leak your location by scanning for the surrounding cell towers, especially in a city, which usually have hundreds or thousands of them (Manhattan alone has eleven, for example). I used to run a Python script on my Nokia phone that logged the tower ID, and I could reliable tell when I got to work, home, etc.

And that's just for people who control your phone. Your operator has U-TDOA¹, which is typically accurate to 50m.

The camera part is true, but tape is cheap :)

¹ https://en.wikipedia.org/wiki/U-TDOA

Re: Ask HN: Why are SIM cards still a thing?

#74

Earlier quoted context omitted.

Flip phones have some of the best protections available: the sensors aren't there. You can't leak your location if there is no GPS module in your phone, you can't have your camera hacked if there is no camera and so on. I'd prefer all this stuff came with physical switches so it can be enabled/disabled in a hack-proof manner.

You can't leak your location if there is no GPS module in your phone While not as precise, you can definitively leak your location by scanning for the surrounding cell towers, especially in a city, which usually have hundreds or thousands of them (Manhattan alone has eleven, for example). I used to run a Python script on my Nokia phone that logged the tower ID, and I could reliable tell when I got to work, home, etc.…

Sure, but that's telcos and the local law enforcement. It's not google, facebook, 500 advertising networks and a whole pile of other parties.

It's also not accurate to within enough resolution start targeting advertising and other nuisance information at me even if there was a way to present me that (which there isn't).

I'm well aware of the power of triangulation, I used to go fox hunting.

http://www.homingin.com/

Re: Ask HN: Why are SIM cards still a thing?

#75

The SIM card is a smart card, i.e. a secure piece of hardware, that protects the telephone network from the subscriber - most importantly, it ensures that the network has someone to bill. In most western countries, SIMs do little else; however, they are full application platforms, allowing stuff like Kenya's mobile payment network https://en.wikipedia.org/wiki/M-Pesa . For what it's worth, you really don't want to ha…

Doesn't every login form on the web also protect the respective operator from the subscriber? Why can't a "software SIM" simply be a username and a password? My explanation is that it's difficult to change something that literally the entire world uses.

[deleted]

Re: Ask HN: Why are SIM cards still a thing?

#76
After Apple "broke the back" of the telco monopoly with their 2007 5-year deal with AT&T[0] it's been a slow progression in North America to the European-style subscriber-owned phones that are compatible across most networks.

I, and many others were surprised at that deal because, up to that point, ppl had essentially carrier-owned phones and long contracts that locked subs (subscribers) to their network. This deal would allow ppl to install any software from the app store without telco approval.

Telcos see the SIM card as their last beachhead. They are looking for at least 2 revue streams from this NFC SE (Secure Element)[1] real estate:

1 Identity verification - Telcos rent "space" on the SE on which you store health cards, passports, driver's licenses, etc. 2 Cards - Telcos rent "space" on which you store credit, gift, debit cards.

Carriers and Issuers (the bank that issues your credit card) are now fighting over that potential revenue stream (spoiler: it's tiny) while Apple has gone and deployed it with Apple Watch et al and is making a cut of the transaction fee. In contrast, the transaction fee is a huge stream however one can imagine the fun of negotiating a contract between all the parties involved (likely all multibillion dollar companies with teams of lawyers).

Apple had tried to push a software SIM (containing a SE) but the carriers, from their POV, rightly and vigorously fought and will continue to fight against that[2]. Google is also trying with Android Wallet/Pay/...

I suspect Apple will eventually use the same "wedge" approach with one of the US carriers and the others will fall in line.

[0] https://www.engadget.com/2010/05/10/confirmed-apple-and-atan... [1] https://en.wikipedia.org/wiki/Near_field_communication#Appli... [2] http://www.thememo.com/2015/07/30/five-years-on-apples-battl...

Re: Ask HN: Why are SIM cards still a thing?

#77
post #54

Earlier quoted context omitted.

Most of the internet runs on usernames/passwords. I understand that a hardware token (with a PIN) is more secure. But is it worth the added complexity?

The SIM protects the carrier against "account sharing". It allows them to be sure that a subscriber is only using one phone at once - although it's portable between phones. It means that carriers don't have to maintain "sessions" centrally. The SIM can authenticate you to the base station without the base station having to check back to see if you're logged in elsewhere - vital in reducing the latency of cell changes…

>It allows them to be sure that a subscriber is only using one phone at once

Only on home network, everybody who knows your IMSI and have low level access to phone network can clone your identity in roaming.

Re: Ask HN: Why are SIM cards still a thing?

#78
post #57

Earlier quoted context omitted.

Actually there is at least one company already offering Remote-Sim-Provisioning. https://medium.com/@ComfortWay_Glob/cwsim-freedom-of-connect... They are selling local data-plans abroad without switching the SIM card by implementing RSP. Calls are coming in 2017, also promising a portable phone number later that year.

another interesting company in this space is FlexiroamX, they have a super flat sim that sticks on top of your existing sim. It lets you soft-switch the SIM using a "SIM Application" (like mentioned elsewhere in the thread) - appears as if it unplugs and replugs to the phone. See picture of the process here: https://twitter.com/lathiat/status/758979125751054336 Works fantastically and gives me $30/GB data in pretty m…

>$30/GB

Some European operators still have cheaper roaming data plans

Re: Ask HN: Why are SIM cards still a thing?

#79

The actual reason it's still a thing is because changing how thousands of network operators work in over 200 countries is quite difficult to coordinate. Even Apple tried to push a soft-SIM and couldn't get it going. But I'm glad for it, because the foresight of the designers of GSM to put your private key in a smartcard has absolutely improved consumer choice worldwide. I can buy an unlocked phone, travel to any coun…

IMO the fact that the device subsidy is so popular with both consumers and network operators in the US means that all of this ostensibly anti-consumer stuff will be with us for a while. The (hard) SIM cards don't even offer the desired portability if you have to go beg for the device to be unlocked.

Re: Ask HN: Why are SIM cards still a thing?

#80
post #10

For some perspective, check electronupdate's recent 'decapping': http://electronupdate.blogspot.com.au/2016/10/decap-of-cell-... It is not just a little block of secure RAM labelled a 'smartcard'. It contains as much CPU as a low end phone. Amazing.

And it runs Java!

Runs Java or the phone runs Java code stored on the SIM?
Post reply on HN