Earlier quoted context omitted.
Preface: this is not a defense. It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.
Sure. Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.
The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
41–50 of 200 posts
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#42>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.” If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#43Earlier quoted context omitted.
I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.
WTF. That is sloppyness on our sholders. And you knew about that? Did you report it up on your line of command?
1. You get ignored.
2. Your boss (or coworkers) make you want to quit.
3. You get fired.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#44Absolutely everything is compromised.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#45Earlier quoted context omitted.
The old technologies required more effort (somebody had to go physically tap the wire).
When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#46Earlier quoted context omitted.
The old technologies required more effort (somebody had to go physically tap the wire).
When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#47Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…
"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#48>>The document noted that many SIM card manufacturers transferred the encryption keys to wireless network providers “by email or FTP with simple encryption methods that can be broken … or occasionally with no encryption at all.” If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.
I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.
Notably this mechanism would not protect the keys against an attacker who was inside Gemalto's or the customer's secure network, as seems to be the case here.
I'd be interested in knowing which keys specifically you are talking about.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#49Statists are gonna state, I guess.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#50This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/
You are still being tracked (GSM, wifi) and vulnerable to local hacks. Due to the nature of the devices (millions of identical devices are produced for major models), their distribution patterns (model selection led by fashion and price point), their homogeneity (two dominant embedded OS platforms only), their complexity (leading to a very large potential attack surface), and their ubiquitousness (your phone number, IMEI, local physical cell, or email address is probably terribly easy to find) it would be extremely foolhardy to rely upon the security of a modern, commercially available handset.