Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

61–70 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#62
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system with hardware that is much more open.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#63

Sadly this would be an excellent application for the CFAA except that they agencies involved are immune from its prosecution.

Maybe so, but ...

> Additionally, the spy agency targeted unnamed cellular companies’ core networks, giving it access to “sales staff machines for customer information ...

So these corporations had customers' personal data stolen. I believe they're obligated to inform those customers, and possibly other obligations. (No direct knowledge, just spouting off what I've read during the Target and Home Depot breaches.)

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#64
post #35
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

Except more and more, calls are going over VoIP, which is essentially never encrypted. Even calls from one landline to another, even to a neighbor, might end up on VoIP. And in any given call, there are probably multiple resellers. Each with full capability to intercept, redirect, modify, etc. any call. And tech support is often given access to capture any call, as a troubleshooting measure.

Even companies like AT&T, who you'd think with exorbitant prices would always pay for proper direct connections, actually try to find the cheapest bidder in any way possible. For some destinations, they might a list that's 20+ resellers deep.

In short, tapping major connectivity points is probably enough to capture a lot of calls even if you place them from a landline. (Not to mention there's no real security mindset in telecom at all.)

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#65
post #35
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

As Stalin said, quantity has a quality all its own.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#66

Earlier quoted context omitted.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…

Why does there have to be any key transfer at all? Why are they not generated in a more decentralized manner, at the manufacturer for example? Why are there servers for the NSA to hack where they can exfiltrate the keys in the first place?

Information minimization and avoiding single points of failures could have prevented this.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#67
post #34

Earlier quoted context omitted.

You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone. So it's not that different, a bit easier, yes. But you still have to physically go there.

Not if you have access to the carrier's internal network...

If you have access to the internal network you don't need SIM card keys which is the subject here.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#70
post #41

Earlier quoted context omitted.

Sure. Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.

Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.

Can you please provide your definition of intelligence?

I would argue that theoretically, a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.

Post reply on HN