Live data from Hacker News

SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

forbes.com

21–30 of 97 posts

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#21
post #13

Article mentions "credit card java applets on SIM cards". I've never used one of those, and I know nobody in the western world who does. I always presumed that these sim java applets are crapware that is mercifully hidden on todays smartphones. It's also my impression that Mastercard and Visa paid a hefty stupidity tax by thinking in the 2000s that it would be important to have their software on SIM cards, not forese…

Pretty sure Blackberry does in Canada, and I assume everywhere else that their Mastercard payment NFC (paypass) works. They touted it as being extra "secure" due to being on the SIM instead of the phone. No idea if carriers selling Bold and Curve handsets are using DES SIMs vuln to this.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#23
post #17

Earlier quoted context omitted.

At one point he says that he thinks it will take the black hats six months or so to figure out the exploit, but then, in the passage you have quoted, he gives what sound (to my non expert ear) like fairly massive clues. Is it possible he has revealed too much?

Well, he's talking about it at Black Hat, right? Black Hat talks are usually full-disclosure.

Looks like it. https://www.blackhat.com/us-13/briefings.html#Nohl

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#24
post #13

Article mentions "credit card java applets on SIM cards". I've never used one of those, and I know nobody in the western world who does. I always presumed that these sim java applets are crapware that is mercifully hidden on todays smartphones. It's also my impression that Mastercard and Visa paid a hefty stupidity tax by thinking in the 2000s that it would be important to have their software on SIM cards, not forese…

Yes, ISIS uses SIM applets: http://en.wikipedia.org/wiki/Isis_(mobile_payment_system)

Google Wallet uses the same type of applets but stored in the phone's SE rather than the SIM card.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#27
post #23
post #17

Earlier quoted context omitted.

Well, he's talking about it at Black Hat, right? Black Hat talks are usually full-disclosure.

Looks like it. https://www.blackhat.com/us-13/briefings.html#Nohl

He'll be presenting the same subject at OHM on 03/08/2013 too: https://program.ohm2013.org/event/169.html

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#28
post #17

Earlier quoted context omitted.

At one point he says that he thinks it will take the black hats six months or so to figure out the exploit, but then, in the passage you have quoted, he gives what sound (to my non expert ear) like fairly massive clues. Is it possible he has revealed too much?

Well, he's talking about it at Black Hat, right? Black Hat talks are usually full-disclosure.

Its all about full disclosure for ethical reasons. Can't say that about them white hats.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#29
post #20

What are the implications? Can't stand Forbes and their over the top ads, tldr would be appreciated.

Here's the primary bit the article says about implications:

"The two-part flaw, based on an old security standard and badly configured code, could allow hackers to remotely infect a SIM with a virus that sends premium text messages (draining a mobile phone bill), surreptitiously re-direct and record calls, and —with the right combination of bugs —carry out payment system fraud."

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#30
post #9

Hurray for Java applets. But seriously, there is a sunny side to this story: a user could load her own programs onto her SIM. She could gretaly extend the functionality of her phone... with programs that she trusts. Maybe even ones she wrote herself. Imagine... an open platform. Oh gosh, that would be terrible, wouldn't it? Otherwise this story highlights the concept of "minimum viable product" not in the startup wor…

How would you extend the functionality? Programming in JavaCard is really not fun (my opinion) and the space and processing power are really limited. The biggest use of it is verifying information (like pins or certificates), but what else would you do that your phone can't?

Consider that some might not program for "fun".

They might do it out of necessity: to "scratch itches".

Limitation breeds creativity. This is true in general, but certainly in computers. Ever heard of demoscene? By comparison to the constraints we had to work with in the 80's, the power of today's handheld computers (one usage of which is as a "phone") is hardly a limitation. But I guess it would depend on what you are trying to do. I have no idea what you would want to do. Only you know that.

As for what others might do, were they to be able to upload their own software to their phones, well, the only way to answer that question is to let them and see what comes out of it.

Only a fool would believe he could direct, let alone predict, all the uses that might be made of a particular software program, a particular language or a particular computer.

One use of a computer is as a communications device, aka a "phone". Another is a "game console". There are plenty of other uses for handheld computers even if you yourself cannot think of them.

Post reply on HN