Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

41–50 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#41
post #37

Earlier quoted context omitted.

Preface: this is not a defense. It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.

Sure. Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.

Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#42
post #10

>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.” If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.

I came here to comment on this too. This is astounding. I can't even. Moxie et al. are looking better and better with each week that goes by.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#43

Earlier quoted context omitted.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

WTF. That is sloppyness on our sholders. And you knew about that? Did you report it up on your line of command?

There are three things that happen when you report negligence "up the line of command".

1. You get ignored.

2. Your boss (or coworkers) make you want to quit.

3. You get fired.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#45
post #35
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

I, too, look forward to the day when we live in a world just like the ending of Transcendence.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#46
post #35
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

Somebody told me that post-Snowden, the NSA started processing some high-value internal paperwork with fancy typewriters to prevent signals intelligence attacks. Apparently the typewriters have little signatures embedded in each letter that are unique per typewriter operator.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#47

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.

I don't remember the reporting on the Belgacom hack mentioning that they were casually querying X-KEYSCORE as they reportedly did here to identify potential targets.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#48
post #10

>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.” If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously I'm not going to comment on the details of the cryptography involved, but it was much more considered than "simple encryption methods or no encryption at all."

Notably this mechanism would not protect the keys against an attacker who was inside Gemalto's or the customer's secure network, as seems to be the case here.

I'd be interested in knowing which keys specifically you are talking about.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#50
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

The problem with these sorts of on-phone-afterthoughts are that they are just lipstick on a pig.

You are still being tracked (GSM, wifi) and vulnerable to local hacks. Due to the nature of the devices (millions of identical devices are produced for major models), their distribution patterns (model selection led by fashion and price point), their homogeneity (two dominant embedded OS platforms only), their complexity (leading to a very large potential attack surface), and their ubiquitousness (your phone number, IMEI, local physical cell, or email address is probably terribly easy to find) it would be extremely foolhardy to rely upon the security of a modern, commercially available handset.

Post reply on HN