Earlier quoted context omitted.
/me puts on tinfoil hat the sim card has one important difference. It lives in a device that provides it with 24/7 battery and radio access. That is really worrisome when you think about. A tiny computer running applications you have no idea/access. powered 24/7. Always with you. With access to battery, network, mic, etc. And the other side of the network that could monitor it's traffic for malicious actions is owned…
It's no different than having no SIM, if your phone wants to spy on you, it doesn't need a SIM card. It's the phone that transceives the signals, and it can do so without a SIM card. SIM card authenticates you to the network, but you control the device and the network around the device, there's no need for a SIM card.
Ask HN: Why are SIM cards still a thing?
161–170 of 191 posts
Re: Ask HN: Why are SIM cards still a thing?
#162Re: Ask HN: Why are SIM cards still a thing?
#163Earlier quoted context omitted.
Because username and password is a disaster for security. It's sole purpose is let ANY guy ANY where on the planet connect to your account. SIM cards are cryptographic hardware tokens. They are much more secure than passwords. In fact, they do need a password as well on top of the hardware token, that's the 'PIN code' you have to enter when you (re)boot your phone.
In practice SIM cards don't give you much physical security anyway. I transferred my mobile phone number etc over to a new SIM card the other week and all I needed was name, address, DOB and proof of ID... of course my network didnt have any of these on file yet, so I had to first tell them these details, and then show ID to verify that I was who I had just told them that I should be. Yeah... this is the state of con…
Re: Ask HN: Why are SIM cards still a thing?
#164Earlier quoted context omitted.
It's no different than having no SIM, if your phone wants to spy on you, it doesn't need a SIM card. It's the phone that transceives the signals, and it can do so without a SIM card. SIM card authenticates you to the network, but you control the device and the network around the device, there's no need for a SIM card.
If there was an open standards-compliant protocol it could be implemented open-source and trusted. You could create an entire open operating system and use open hardware to know everything happening on your phone. That is different than having a SIM, which is a piece of mystery hardware the phone company could do anything with.
I'd be far more concerned with the hundreds of microcontrollers running proprietary code.
Re: Ask HN: Why are SIM cards still a thing?
#165The actual reason it's still a thing is because changing how thousands of network operators work in over 200 countries is quite difficult to coordinate. Even Apple tried to push a soft-SIM and couldn't get it going. But I'm glad for it, because the foresight of the designers of GSM to put your private key in a smartcard has absolutely improved consumer choice worldwide. I can buy an unlocked phone, travel to any coun…
http://www.theverge.com/2016/2/18/11044624/esim-wearable-sma...
Re: Ask HN: Why are SIM cards still a thing?
#166Earlier quoted context omitted.
The SIM protects the carrier against "account sharing". It allows them to be sure that a subscriber is only using one phone at once - although it's portable between phones. It means that carriers don't have to maintain "sessions" centrally. The SIM can authenticate you to the base station without the base station having to check back to see if you're logged in elsewhere - vital in reducing the latency of cell changes…
Carriers do maintain sessions centrally though. These are the HLR and VLR - home location register and visitor location register. This is how "hand offs" between towers work. Handsets don't authenticate to the base station, the base station proxies those back to the MSC, mobile switching center and are looked up in the EIR - Equipment Identity Register.
Re: Ask HN: Why are SIM cards still a thing?
#167Earlier quoted context omitted.
If there was an open standards-compliant protocol it could be implemented open-source and trusted. You could create an entire open operating system and use open hardware to know everything happening on your phone. That is different than having a SIM, which is a piece of mystery hardware the phone company could do anything with.
They already have control of all your traffic so what's the harm? Take the sim out of your phone in case you are really worried, but that would cut you off the network as well. I'd be far more concerned with the hundreds of microcontrollers running proprietary code.
Re: Ask HN: Why are SIM cards still a thing?
#168It also is a classic telco hedge.
Step 1) We need towers to make this thing work. Let's build towers.
Step 2) These towers are super expensive and make the expense amortization complicated. Let's sell the towers and then lease from the buyer.
Step 3) oh crap. There is no encryption and people are cloning handsets. Let's use SIM cards to separate sensitive operations from the rest of the device.
Step 4) manufacturing sims is complicated. Let's buy sims from other suppliers and make them sign off on unlimited liability clauses if their identity solution is compromised.
It is all about two things: Preventing a single player from having too much power on the ecosystem and transferring financial risk. There is no evil plan. It's all rather mundane.
Re: Ask HN: Why are SIM cards still a thing?
#169Earlier quoted context omitted.
Well, of course it's hard to come by a dual-sim iPhone. You need to look for other brands.
Go to Shenzhen. They like to make iPhone clones that are cheaper while having better specs, including multiple SIM card support.
Re: Ask HN: Why are SIM cards still a thing?
#170Earlier quoted context omitted.
They already have control of all your traffic so what's the harm? Take the sim out of your phone in case you are really worried, but that would cut you off the network as well. I'd be far more concerned with the hundreds of microcontrollers running proprietary code.
The SIM, being a physical piece of hardware plugged into my phone, could easily be used as an attack vector for my phone company to root my phone. Hardware plugged into my phone is a much more vulnerable attack surface than control of network traffic.