The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
1–10 of 200 posts
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#2Absolutely everything is compromised.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#3Do they want me to be apathetic about the actions of our government? I'm getting close.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#4This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#5This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/
Yet they do depend on a good RNG, don't they? Is that a given on common smartphones these days?
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#6At this point, we might as well just go back to landlines and fax machines.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#7Absolutely everything is compromised.
...and so deeply.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#8This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/
Yet they do depend on a good RNG, don't they? Is that a given on common smartphones these days?
I'm not sure about hardware RNG, but many if not most phones have sources of 'random' enviornmental data they can use to generate a random number such as cameras and phone movement.
https://security.stackexchange.com/questions/42428/is-genera...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#9[deleted]
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#10>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.”
If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.