Live data from Hacker News

Ask HN: Why are SIM cards still a thing?

news.ycombinator.com

161–170 of 191 posts

Re: Ask HN: Why are SIM cards still a thing?

#161
post #124

Earlier quoted context omitted.

/me puts on tinfoil hat the sim card has one important difference. It lives in a device that provides it with 24/7 battery and radio access. That is really worrisome when you think about. A tiny computer running applications you have no idea/access. powered 24/7. Always with you. With access to battery, network, mic, etc. And the other side of the network that could monitor it's traffic for malicious actions is owned…

It's no different than having no SIM, if your phone wants to spy on you, it doesn't need a SIM card. It's the phone that transceives the signals, and it can do so without a SIM card. SIM card authenticates you to the network, but you control the device and the network around the device, there's no need for a SIM card.

If there was an open standards-compliant protocol it could be implemented open-source and trusted. You could create an entire open operating system and use open hardware to know everything happening on your phone. That is different than having a SIM, which is a piece of mystery hardware the phone company could do anything with.

Re: Ask HN: Why are SIM cards still a thing?

#162
post #99
post #84

Earlier quoted context omitted.

Not in the US

Well, of course it's hard to come by a dual-sim iPhone. You need to look for other brands.

Go to Shenzhen. They like to make iPhone clones that are cheaper while having better specs, including multiple SIM card support.

Re: Ask HN: Why are SIM cards still a thing?

#163
post #82

Earlier quoted context omitted.

Because username and password is a disaster for security. It's sole purpose is let ANY guy ANY where on the planet connect to your account. SIM cards are cryptographic hardware tokens. They are much more secure than passwords. In fact, they do need a password as well on top of the hardware token, that's the 'PIN code' you have to enter when you (re)boot your phone.

In practice SIM cards don't give you much physical security anyway. I transferred my mobile phone number etc over to a new SIM card the other week and all I needed was name, address, DOB and proof of ID... of course my network didnt have any of these on file yet, so I had to first tell them these details, and then show ID to verify that I was who I had just told them that I should be. Yeah... this is the state of con…

SIM cards come from an era where mobile phone contracts were much less common and more expensive, and therefore cloning phones cost the providers a lot of money. I assume the security requirements for reissuing SIMs were also higher back then.

Re: Ask HN: Why are SIM cards still a thing?

#164

Earlier quoted context omitted.

It's no different than having no SIM, if your phone wants to spy on you, it doesn't need a SIM card. It's the phone that transceives the signals, and it can do so without a SIM card. SIM card authenticates you to the network, but you control the device and the network around the device, there's no need for a SIM card.

If there was an open standards-compliant protocol it could be implemented open-source and trusted. You could create an entire open operating system and use open hardware to know everything happening on your phone. That is different than having a SIM, which is a piece of mystery hardware the phone company could do anything with.

They already have control of all your traffic so what's the harm? Take the sim out of your phone in case you are really worried, but that would cut you off the network as well.

I'd be far more concerned with the hundreds of microcontrollers running proprietary code.

Re: Ask HN: Why are SIM cards still a thing?

#165

The actual reason it's still a thing is because changing how thousands of network operators work in over 200 countries is quite difficult to coordinate. Even Apple tried to push a soft-SIM and couldn't get it going. But I'm glad for it, because the foresight of the designers of GSM to put your private key in a smartcard has absolutely improved consumer choice worldwide. I can buy an unlocked phone, travel to any coun…

Samsung succeeded with its eSIM implementation on the Gear S2 smartwatch, which works on a limited number of mobile operators.

http://www.theverge.com/2016/2/18/11044624/esim-wearable-sma...

Re: Ask HN: Why are SIM cards still a thing?

#166
post #54

Earlier quoted context omitted.

The SIM protects the carrier against "account sharing". It allows them to be sure that a subscriber is only using one phone at once - although it's portable between phones. It means that carriers don't have to maintain "sessions" centrally. The SIM can authenticate you to the base station without the base station having to check back to see if you're logged in elsewhere - vital in reducing the latency of cell changes…

Carriers do maintain sessions centrally though. These are the HLR and VLR - home location register and visitor location register. This is how "hand offs" between towers work. Handsets don't authenticate to the base station, the base station proxies those back to the MSC, mobile switching center and are looked up in the EIR - Equipment Identity Register.

Do you happen to know of a good breakdown of how mobile networks work? I'd love to know more, but it's hard to get a handle on it to get started.

Re: Ask HN: Why are SIM cards still a thing?

#167

Earlier quoted context omitted.

If there was an open standards-compliant protocol it could be implemented open-source and trusted. You could create an entire open operating system and use open hardware to know everything happening on your phone. That is different than having a SIM, which is a piece of mystery hardware the phone company could do anything with.

They already have control of all your traffic so what's the harm? Take the sim out of your phone in case you are really worried, but that would cut you off the network as well. I'd be far more concerned with the hundreds of microcontrollers running proprietary code.

The SIM, being a physical piece of hardware plugged into my phone, could easily be used as an attack vector for my phone company to root my phone. Hardware plugged into my phone is a much more vulnerable attack surface than control of network traffic.

Re: Ask HN: Why are SIM cards still a thing?

#168
OEM software quality is so diverse that they can't be trusted to execute something as sensitive as identity.

It also is a classic telco hedge.

Step 1) We need towers to make this thing work. Let's build towers.

Step 2) These towers are super expensive and make the expense amortization complicated. Let's sell the towers and then lease from the buyer.

Step 3) oh crap. There is no encryption and people are cloning handsets. Let's use SIM cards to separate sensitive operations from the rest of the device.

Step 4) manufacturing sims is complicated. Let's buy sims from other suppliers and make them sign off on unlimited liability clauses if their identity solution is compromised.

It is all about two things: Preventing a single player from having too much power on the ecosystem and transferring financial risk. There is no evil plan. It's all rather mundane.

Re: Ask HN: Why are SIM cards still a thing?

#169
post #99

Earlier quoted context omitted.

Well, of course it's hard to come by a dual-sim iPhone. You need to look for other brands.

Go to Shenzhen. They like to make iPhone clones that are cheaper while having better specs, including multiple SIM card support.

The iPhone-lookalike phones you can buy in China don't run iOS, so I don't consider them 'clones'.

Re: Ask HN: Why are SIM cards still a thing?

#170

Earlier quoted context omitted.

They already have control of all your traffic so what's the harm? Take the sim out of your phone in case you are really worried, but that would cut you off the network as well. I'd be far more concerned with the hundreds of microcontrollers running proprietary code.

The SIM, being a physical piece of hardware plugged into my phone, could easily be used as an attack vector for my phone company to root my phone. Hardware plugged into my phone is a much more vulnerable attack surface than control of network traffic.

The baseband is already at the beck-and-call of your telco provider and has much better access to the hardware than the SIM card.
Post reply on HN