Live data from Hacker News

Ask HN: Why are SIM cards still a thing?

news.ycombinator.com

101–110 of 191 posts

Re: Ask HN: Why are SIM cards still a thing?

#101
> Using SIM cards in mobile phones seems antiquated.

In the U.S., LTE is the first time that CDMA phones have had sim cards, that's ~2 years ago.

The software solution (using IMEI and PUK) is the old technology. It's less secure; verizon and sprint will charge you ~$40 activation fees, etc.

Re: Ask HN: Why are SIM cards still a thing?

#102
post #25

On the contrary, it is the result of a concerted effort to reduce friction. With SIM cards, users can switch to a new phone by just moving the SIM, or switch to a new provider while keeping their phone (assuming its unlocked) by just replacing the SIM. Prior to SIM cards phones where frequently programmed to be tied to a specific provider. A pure software solution could work, but requires the network operators to be…

Unless you personally know some heads of some major carriers you can't say that and also it's unlikely carriers do things to reduce friction.

Unlocked phones are still relatively rare in the US so I don't agree with your second point either.

Network operators trust Gemalto, etc to write the SIM card software and also the provisioning and tower software. They also trust the phone manufacturer software as they rigorously test it before it's pushed to it's subs. That's actually why updates take so long (excl apple, of course).

Note that I have actually worked for some major carriers and have been in discussions with VPs discussing this very issue. See my other answer further down the thread.

Re: Ask HN: Why are SIM cards still a thing?

#103
post #47

Earlier quoted context omitted.

The same idea is used in Norway. Most banks and public services (e.g. tax returns) use this system for online two-factor authentication. [1] https://www.bankid.no/en/

Didn't NIST just say two factor via mobile is a "bad idea"? Have Norway or Estonia responded? EDIT: Thank you whoever downvoted an honest question that added to the discussion

I think that was for SMS, not specifically mobile.

Re: Ask HN: Why are SIM cards still a thing?

#104
post #47

Earlier quoted context omitted.

The same idea is used in Norway. Most banks and public services (e.g. tax returns) use this system for online two-factor authentication. [1] https://www.bankid.no/en/

Didn't NIST just say two factor via mobile is a "bad idea"? Have Norway or Estonia responded? EDIT: Thank you whoever downvoted an honest question that added to the discussion

The bad idea is being sent a (potentially interceptable) SMS with a code.

The Estonian method is described as using a private key present on the SIM card, just like a normal smart card used for authenticating/signing.

Re: Ask HN: Why are SIM cards still a thing?

#105
post #10

For some perspective, check electronupdate's recent 'decapping': http://electronupdate.blogspot.com.au/2016/10/decap-of-cell-... It is not just a little block of secure RAM labelled a 'smartcard'. It contains as much CPU as a low end phone. Amazing.

And it runs Java!

If anyone is interested, there is a very interesting talk at Defcon 21 called "The Secret Life of SIM cards". They managed to run their own network and sold SIM cards at the conf for EFF. https://simhacks.github.io/defcon-21/

Re: Ask HN: Why are SIM cards still a thing?

#106
post #84

Earlier quoted context omitted.

But why? Multi-SIM phones are cheap and easy to come by.

Not in the US

To be fair, "multi-" here typically means "dual-", but even w/o going to Alibaba, they're definitely out there:

  - http://www.androidauthority.com/best-dual-sim-android-phones-529470/
When I had to travel a lot, I had a small booklet of sim-cards that I could pop into my single-SIM phone (this was the 90s), in most regions I visited to get (much) cheaper rates than I was getting for world-wide roaming from AT&T at the time (this was before AT&T was really Southwestern Bell). Except Japan. (Curse you, and your island-nation cell-phone local-only standards, Japan!)

Re: Ask HN: Why are SIM cards still a thing?

#107
Personally I really appreciate the fact that providers have SIMs. Verizon (major network in the USA) used to NOT have SIMs, and it was a huge pain to change phones out. Now it's as simple as swapping out the SIM.

I hear you that it should be doable in software, although I'd argue that if anything you should still need the SIM as a sort of second factor. (Otherwise you run the risk of people stealing your phone account remotely).

Re: Ask HN: Why are SIM cards still a thing?

#108

The SIM card is a smart card, i.e. a secure piece of hardware, that protects the telephone network from the subscriber - most importantly, it ensures that the network has someone to bill. In most western countries, SIMs do little else; however, they are full application platforms, allowing stuff like Kenya's mobile payment network https://en.wikipedia.org/wiki/M-Pesa . For what it's worth, you really don't want to ha…

Even small carriers have software customizations done to phone firmware deployed on their network. This is common.

I believe he's contrasting this between a built-in solution. So say Samsung would put a hardwired UICC (SIM) in the phone and ATT say would make Samsung give ATT an "area" (Security Domain" in UICC parlance) to provision. For all intents and purposes it would work the same. If you wantd to switch carriers I'm guessing there would be a 'virtual' switch SIM app or some such.

If you're bored, you can read about it here:

https://www.globalplatform.org

Re: Ask HN: Why are SIM cards still a thing?

#109
post #25

On the contrary, it is the result of a concerted effort to reduce friction. With SIM cards, users can switch to a new phone by just moving the SIM, or switch to a new provider while keeping their phone (assuming its unlocked) by just replacing the SIM. Prior to SIM cards phones where frequently programmed to be tied to a specific provider. A pure software solution could work, but requires the network operators to be…

Unless you personally know some heads of some major carriers you can't say that and also it's unlikely carriers do things to reduce friction. Unlocked phones are still relatively rare in the US so I don't agree with your second point either. Network operators trust Gemalto, etc to write the SIM card software and also the provisioning and tower software. They also trust the phone manufacturer software as they rigorous…

> > With SIM cards, users can switch to a new phone by just moving the SIM, or switch to a new provider while keeping their phone (assuming its unlocked) by just replacing the SIM.

> Unlocked phones are still relatively rare in the US so I don't agree with your second point either.

As you point out, where GSM networks are concerned, this observation is mostly specific to the US - swapping phones and swapping SIMs has been a reality in the rest of the world for years.

Instead, the main source of friction is frequency bands. When swapping phones, it's not often an issue when switching between locally distributed phone models, since they are the Asia/international models with more band compatibility. When swapping SIMs domestically, it's not an issue for the same reason. When swapping SIMs internationally, phone service typically works, but if you want high speed data _then_ you check for band compatibility.

I'd say that for most of the world, the reduction in friction is real. It's a pity that the US market is so different.

Re: Ask HN: Why are SIM cards still a thing?

#110

SIM: Subscriber Identity Module almost says it all, on top of that a SIM can store your contacts (up to a certain number). The SIM is what separates your identity from the hardware of the phone (which has its own identity called 'IMEI'). A 'software solution' would need a carrier, that carrier IS the SIM. Another nice benefit of having the SIM device is that it makes it much harder to 'clone' a subscriber ID, somethi…

When ppl mention a "software SIM" they mean the same basic chip embedded in the handset that you can switch with software. It has the same level of security as removable chips.
Post reply on HN