Live data from Hacker News

Ask HN: Why are SIM cards still a thing?

news.ycombinator.com

171–180 of 191 posts

Re: Ask HN: Why are SIM cards still a thing?

#171

Earlier quoted context omitted.

They already have control of all your traffic so what's the harm? Take the sim out of your phone in case you are really worried, but that would cut you off the network as well. I'd be far more concerned with the hundreds of microcontrollers running proprietary code.

The SIM, being a physical piece of hardware plugged into my phone, could easily be used as an attack vector for my phone company to root my phone. Hardware plugged into my phone is a much more vulnerable attack surface than control of network traffic.

The point is your phone (if it were secure enough) could treat your SIM card like any other untrusted device accessory, and only let it do stuff it's allowed to do.

[network] [phone] [SIM card]

In theory. Not sure how well practise matches this though.

Re: Ask HN: Why are SIM cards still a thing?

#172

Earlier quoted context omitted.

Carriers do maintain sessions centrally though. These are the HLR and VLR - home location register and visitor location register. This is how "hand offs" between towers work. Handsets don't authenticate to the base station, the base station proxies those back to the MSC, mobile switching center and are looked up in the EIR - Equipment Identity Register.

Do you happen to know of a good breakdown of how mobile networks work? I'd love to know more, but it's hard to get a handle on it to get started.

Sure:

Its helpful to understand the history of mobile/wireless I think since the Telecom industry takes acronyms to an insane level. The terminology changes slightly depending on which generation of mobile is being discussed. This is a good breakdown of the evolution of mobile networks. I think its a good starting point:

http://www1.i2r.a-star.edu.sg/~wongtc/EE5406-Network-Archite...

This is a good resource for understanding more recent and relevant mobile architecture. This has a lot more detail:

http://www.slideshare.net/abhishekshringi/gsm-architecture-1...

If you really want to learn mobile and wireless networking, this is unbeatable and very thorough, I highly recommend it, grab a used copy.

https://www.amazon.com/Wireless-Communications-Andreas-F-Mol...

If you just want the 10K view see:

http://www.telecomspace.com/gsm.html

Re: Ask HN: Why are SIM cards still a thing?

#173

SIM: Subscriber Identity Module almost says it all, on top of that a SIM can store your contacts (up to a certain number). The SIM is what separates your identity from the hardware of the phone (which has its own identity called 'IMEI'). A 'software solution' would need a carrier, that carrier IS the SIM. Another nice benefit of having the SIM device is that it makes it much harder to 'clone' a subscriber ID, somethi…

> on top of that a SIM can store your contacts (up to a certain number). This presented a usability nightmare back in the days of feature phones, where if you didn't specifically say where to store contacts, it would often default to the phone's storage rather than SIM, or if you breached the number of contacts on a SIM you'd have overspill onto the phone memory (sometimes without realising) This presented a lot of u…

It still is an issue - carriers (at least in NZ) still ask you if you've backed up SIM contacts before switching the phone number to a new card.

Re: Ask HN: Why are SIM cards still a thing?

#174
post #124

Earlier quoted context omitted.

/me puts on tinfoil hat the sim card has one important difference. It lives in a device that provides it with 24/7 battery and radio access. That is really worrisome when you think about. A tiny computer running applications you have no idea/access. powered 24/7. Always with you. With access to battery, network, mic, etc. And the other side of the network that could monitor it's traffic for malicious actions is owned…

It's no different than having no SIM, if your phone wants to spy on you, it doesn't need a SIM card. It's the phone that transceives the signals, and it can do so without a SIM card. SIM card authenticates you to the network, but you control the device and the network around the device, there's no need for a SIM card.

so? the point is that the sim IS there already. yeah you can have more vulnerabilities, but that one is a given.

Re: Ask HN: Why are SIM cards still a thing?

#175

Earlier quoted context omitted.

It's no different than having no SIM, if your phone wants to spy on you, it doesn't need a SIM card. It's the phone that transceives the signals, and it can do so without a SIM card. SIM card authenticates you to the network, but you control the device and the network around the device, there's no need for a SIM card.

If there was an open standards-compliant protocol it could be implemented open-source and trusted. You could create an entire open operating system and use open hardware to know everything happening on your phone. That is different than having a SIM, which is a piece of mystery hardware the phone company could do anything with.

the selling point of the sim is that it it "trusted computing". meaning the user is left out by design.

Re: Ask HN: Why are SIM cards still a thing?

#176
post #129
post #124

Earlier quoted context omitted.

/me puts on tinfoil hat the sim card has one important difference. It lives in a device that provides it with 24/7 battery and radio access. That is really worrisome when you think about. A tiny computer running applications you have no idea/access. powered 24/7. Always with you. With access to battery, network, mic, etc. And the other side of the network that could monitor it's traffic for malicious actions is owned…

> powered 24/7 Is it? When you turn on "airplane mode" on a phone, is there a reason for the SIM to still be receiving power at that point?

yes.

the sim has direct access to the radio and other modules, by design. it only needs the actual phone cpu/os for use interface.

if it wants to take the radio out of silent mode it can.

Re: Ask HN: Why are SIM cards still a thing?

#177
post #176
post #129

Earlier quoted context omitted.

> powered 24/7 Is it? When you turn on "airplane mode" on a phone, is there a reason for the SIM to still be receiving power at that point?

yes. the sim has direct access to the radio and other modules, by design. it only needs the actual phone cpu/os for use interface. if it wants to take the radio out of silent mode it can.

That seems like it wouldn't comply with FAA regulations.

I always presumed "airplane mode" was the specific set of features required by the FAA to enable the phone to do the same thing as a phone that's off, from the perspective of potential interference with a plane's communications.

If the SIM can still enable and use the radio despite "airplane mode" being on, then "airplane mode" is not really "a mode for making your phone safe to stay on while on an airplane."

Re: Ask HN: Why are SIM cards still a thing?

#178
post #88

A form of this has existed for a while but never caught on for fairly understandable reasons. Quite a few years ago (2005?) a family member purchased a Samsung-branded dumbphone on a contract. (Monochrome LCD (something like 128x64?), polyphonic ringtones, 3 fixed games, a (really slow, GSM data) WAP browser; that was it. Model SGH-something, I vaguely recall.) It had no SIM card slot. It was locked to the network (O…

It was probably just a CDMA phone - they don't have SIM cards are were actually quite common a while ago.

CDMA phone are worse. It is a way for manufacture of mobile phone to keep you tied to one cellular company.

I always go for GSM supported phones.

Re: Ask HN: Why are SIM cards still a thing?

#179
post #81

Earlier quoted context omitted.

Sadly, encrypting e-mail will break all current anti-spam methods.

Not exactly. Some methods won't be nearly as effective (such as filtering on the message body) but others (such as SPF, DKIM, and RBLs) will still work just as well as they do today. Now that I think about, just the encryption itself will increase the computational cost of sending out spam e-mails. While today a spammer can blast out an e-mail to 100 recipients very quickly, it'll take a fair bit longer to do once th…

A large part of spam detection remains machine learning on message bodies. Something this would make impossible.

As for encrypting the e-mail 100 times. AES acceleration is great in CPU's, and you can cache public keys. The only real-ish bottleneck could be key-generation.

That said, someone else had a decent idea. Require white-listing for encrypted e-mail.

Post reply on HN