Live data from Hacker News

SIM Vulnerability leads to information disclosure via malicious SMS

simjacker.com

41–50 of 60 posts

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#41
post #14

Does this break SMS 2FA?

SMS 2FA can bite you in the ass. Since the phone is with you all the time, there is a higher chance of something happening to it that makes it damaged enough for you to not be able to use it. Now, you are in possession of the password, the IP is the same as the one you signed up with, you have access to your e-mail, but you still cannot access your account. You contact support, you tell them the same thing. They will…

The reason why companies love SMS 2FA is because most people keep their phone number. In a scenario like you described, most people would walk into a store, show ID, and get a new SIM.

This way, the company using SMS 2FA has effectively outsourced this recovery path to the phone companies. Instead of handling recovery (and potentially liability for getting it wrong) themselves, they can just tell you to go recover the phone number. And when the phone company gets it wrong, you get stuck in a nightmare of finger-pointing instead of having a clear culprit to hold responsible.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#42

Unsurprising, and I don't think it's a backdoor like ME, but just plain incompetence (or malpractice). It's only a matter of time and location when a exploit like this is discovered. I highly recommend this hilarious paper, Fuzzing the GSM Protocol ( https://www.ru.nl/publish/pages/769526/scriptie-brinio-final... ). By feeding the phones with random GSM data with a Software-Defined Radio, it showed most dumb and smar…

> no isolation between the baseband processor and the main system. There’s barely any connection between the baseband processor and the application processor on a smartphone. Notice for all your examples, it’s denial of service for the functions of the baseband processor by a bug in the code run by the baseband processor. It doesn’t get access to the data available to the application processor. Except for the oldscho…

Barely any connection? Like if there is only a single wire, it's fine because the data exfiltration / os manipulation takes long? Oh please. These two processors are interconnected and most of phones run some unknown untrustworthy software on both of them.

Some attacks: https://www.fsf.org/blogs/community/replicant-developers-fin...

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#43
post #34
post #31

Earlier quoted context omitted.

That's not the case. SIM cards hold the permanent key for authentication and perform key derivation. Mobile data doesn't pass the SIM card; it does not perform the encryption and decryption.

Good point--I tend to forget that. The rather vague article seems to indicate the actual SMS content is being sent to the SIM, though. Why is that?

Dumb/feature phones saved SMS messages to the SIM card as simple cards have a limited amount of memory that is dedicated to a crude phonebook and SMS store. Smartphones and smarter feature phones (can) use their own storage for that. You could disable/enable the phonebook/save to SIM features on feature phones and early smartphones.

(I'm talking about win CE and symbian phones being early smartphones here)

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#44
post #14

Does this break SMS 2FA?

SMS 2FA can bite you in the ass. Since the phone is with you all the time, there is a higher chance of something happening to it that makes it damaged enough for you to not be able to use it. Now, you are in possession of the password, the IP is the same as the one you signed up with, you have access to your e-mail, but you still cannot access your account. You contact support, you tell them the same thing. They will…

>Any experiences or thoughts?

I used to have Ting for phone service, you can require mfa/lock number porting, disable or activate or change a device/sim, toggle voice sms and data and forward calls from their multi factor authenticated dashboard. Requested an extra sim and kept a dumb cdma phone lying around in case I broke lost or someone stole my phone. Also used an app to sync texts in case of broken scren. Now I use verizon and keep a spare cdma device, you can change devices from their web portal in combination with a message syncing app. You could also port your # to google voice for similar features but I assumed google will scrap it with little notice so I have not.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#45

I obtained a low-tech phone for SMS and phone calls. I then turned my Samsung Android back into a PDA by removing the SIM chip. I explain to my clients when they express astonishment at my low-tech phone that I am protecting their security, as I have the PDA sync with my Exchange Server, where I keep sensitive info to provide them support and I do not allow the low-tech phone to access my Exchange Server. I also tell…

I would personally much rather have my text messages and VoIP phone calls encrypted (usually iMessage and FaceTime audio, but Signal and WhatsApp are popular with Android users), which AFAIK is only available on smartphones, than split out calling and texting from a primary phone.

I’ve also heard that Apple doesn’t allow the baseband direct access to the application processor’s memory, but I don’t know how true that is. There doesn’t seem to be much thought given to this on Android phones.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#46
post #42

Earlier quoted context omitted.

> no isolation between the baseband processor and the main system. There’s barely any connection between the baseband processor and the application processor on a smartphone. Notice for all your examples, it’s denial of service for the functions of the baseband processor by a bug in the code run by the baseband processor. It doesn’t get access to the data available to the application processor. Except for the oldscho…

Barely any connection? Like if there is only a single wire, it's fine because the data exfiltration / os manipulation takes long? Oh please. These two processors are interconnected and most of phones run some unknown untrustworthy software on both of them. Some attacks: https://www.fsf.org/blogs/community/replicant-developers-fin...

Which has absolutely nothing to do with isolation. The two processors are not ‘interconnected’, they are separate and can only communicate through defined interfaces. That’s isolation. If there is a backdoor on one processor that grants access to the other the problem is that backdoor and not some nebulous interconnection.

If your computer runs a backdoor that grants access to anyone who can access it over the network, the problem that someone from China can now control your computer is not the fault of the Internet. It’s the fault of that program.

And also ‘most of phones’ in the article is ‘Android phones’ and then it’s watered down even more to ‘Samsung Galaxy phones’. ‘In most devices, for all we know, [...]’. No.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#47

I obtained a low-tech phone for SMS and phone calls. I then turned my Samsung Android back into a PDA by removing the SIM chip. I explain to my clients when they express astonishment at my low-tech phone that I am protecting their security, as I have the PDA sync with my Exchange Server, where I keep sensitive info to provide them support and I do not allow the low-tech phone to access my Exchange Server. I also tell…

Isn't connecting to Microsoft being online? Unless you're running exchange on an OFFLINE, LOCAL NETWORK your outgoing traffic to Google will contain metadata and you're not stopping anything by removing the SIM card other than inconveniencing yourself.

It still calls home, it's still online. Lock down Microsoft and Google's IPs permanently, outbound, on all networks you use or this won't work.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#48
so many companies who offer these services since forever. verint, gamma, etc. etc.

1 or 2 binary sms sent and you have someones phone depending on your flavor of attack.

sim card runs java. with sim pin you can even just send apdu requests to read its filesystem...

don't know why now all of a sudden this is a hot topic. it's the whole design of the mobile infrastructure to be able to do this...

just think about it: if you clone someones phone via such method, and they get called, you get called. if you then pickup within ~1 second of them picking up, your speaker is enabled but microphone is disabled so they can't hear you snooping in on them.... that is by design.

between carriers everything is unauthenticated, to enable this at global scale... by design.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#49
post #11

Title is misleading. No "hijacking" is taking place, they are obtaining the Cell ID (approximate location) and IMEI info from the phone, by sending it a malicious SMS containing SIM card instructions. Details; https://www.adaptivemobile.com/blog/simjacker-next-generatio... A better title IMHO; SIM Vulnerability leads to information disclosure via malicious SMS.

For me, sending SMS messages on your behalf (without you even knowing) or dialling premium rate numbers is definitely hijacking.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#50
post #42

Earlier quoted context omitted.

Barely any connection? Like if there is only a single wire, it's fine because the data exfiltration / os manipulation takes long? Oh please. These two processors are interconnected and most of phones run some unknown untrustworthy software on both of them. Some attacks: https://www.fsf.org/blogs/community/replicant-developers-fin...

Which has absolutely nothing to do with isolation. The two processors are not ‘interconnected’, they are separate and can only communicate through defined interfaces. That’s isolation. If there is a backdoor on one processor that grants access to the other the problem is that backdoor and not some nebulous interconnection. If your computer runs a backdoor that grants access to anyone who can access it over the networ…

Well they do not read directly each other's memory, but still the baseband processor is electrically connected and so can exfiltrate data from or manipulate the application processor. On the other hand, if you have two phones glued together, one for voice/sms, one for internet access via independent network without microphone, the first one cannot exfiltrate/manipulate the second one and the second one cannot record your voice. That is isolation.
Post reply on HN