Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

21–30 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#22
post #10

>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.” If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#23
This is exactly why Intel's upcoming SGX worries me greatly, too. NSA could get the "key" to all SGX machines and therefore to all applications using SGX to secure themselves properly (ironically enough) [1].

Intel really needs to figure out how to protect the SGX system against such a key robbery, and not by promising to only give access to a couple of employees in the whole company who know a very special hand-shake. Intel needs to modify the SGX system in such a way that you don't have to trust Intel (or anyone hacking Intel) to keep the key secure, even if that means the company not giving itself access to SGX at all (which includes not having the ability to update it).

[1] - http://blog.invisiblethings.org/2013/09/23/thoughts-on-intel...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#24

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

It's interesting because last I checked Obama/NSA were saying they don't collect content, only metadata (that harmless, harmless metadata [1]). If that's the case, why were they so interested in the SIM key?!

[1] - http://justsecurity.org/10311/michael-hayden-kill-people-bas...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#25

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

It's interesting because last I checked Obama/NSA were saying they don't collect content, only metadata (that harmless, harmless metadata [1]). If that's the case, why were they so interested in the SIM key?! [1] - http://justsecurity.org/10311/michael-hayden-kill-people-bas...

The metadata qualifier is about U.S. domestic data gathering.

There's no such limitation on their activities outside of the U.S.

(Hence there is no reason to make an inference about what capabilities they would attempt to build out)

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#26

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

It's interesting because last I checked Obama/NSA were saying they don't collect content, only metadata (that harmless, harmless metadata [1]). If that's the case, why were they so interested in the SIM key?! [1] - http://justsecurity.org/10311/michael-hayden-kill-people-bas...

Strange to see anyone still believing to american officials.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#27

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people"

Nothing new here - as the Belgacom hack has shown already.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#28

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

It's interesting because last I checked Obama/NSA were saying they don't collect content, only metadata (that harmless, harmless metadata [1]). If that's the case, why were they so interested in the SIM key?! [1] - http://justsecurity.org/10311/michael-hayden-kill-people-bas...

Because they were useful for targeted surveillance? Not that I agree with the means or the scope, but there's an above board explanation for the desire to get the keys . Suppose you have a handful of phones in Pakistan or Iran you need access to very covertly (e.g. some rogue guy in the ISI where getting caught snooping has major consequences). The least risky way to access his communications is to get the keys. The least risky way to do that is to get them from the broadest source possible(to obscure who you're really interest in) and the one most removed from your target. So there's a legit reason to want the keys, even if your only targeting a few legit targets.

But the means of doing so is truly questionable, even given all their assertions about trust us and we don't look at everyones stuff.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#29
post #10

>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.” If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

WTF. That is sloppyness on our sholders. And you knew about that? Did you report it up on your line of command?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#30
post #11

[deleted]

You aren't surprised that our government is building a massive dragnet blackmail database. Good for you. You aren't alone and like the rest of us you didn't do anything useful with your prediction. What do you want, a gold sticker?

Tell me again why I (or anyone else) should find the fact that you foresaw this outcome comforting -- or relevant at all.

> Rooms can be bugged.

Yeah but they need a warrant, it costs money to bug a room, and they can't decide to retroactively bug every room their target has ever been in. To make things concrete, do you really think none of these powers would have made a difference if they had had them back when they were trying to sink MLK's platform?

Post reply on HN