Live data from Hacker News

SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

forbes.com

61–70 of 97 posts

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#61
post #54
post #9

Hurray for Java applets. But seriously, there is a sunny side to this story: a user could load her own programs onto her SIM. She could gretaly extend the functionality of her phone... with programs that she trusts. Maybe even ones she wrote herself. Imagine... an open platform. Oh gosh, that would be terrible, wouldn't it? Otherwise this story highlights the concept of "minimum viable product" not in the startup wor…

I don't think this is a reasonable assessment at all. SIM manufacturers use 3DES, not DES, which - while not recommended for new systems - is still pretty damn secure. I don't think you've really understood the complexity of the SIM - there are literally thousands and thousands of pages of specification, which means that any sim will interoperate with any phone. A SIM is not an "MVP" by any stretch of the imagination…

You're right. DES repeated thrice is better than DES. But I wonder why 3DES is not recommended for new systems? Hmmm....

You're wrong on the SIM as an MVP idea. I guess I'm not communicating clearly enough. What I mean is the computer ("phone") itself, of which the smart card subsystem (e.g. SIM card system) is a part, is of inferior quality. This is only my opinion.

I understand there are barriers to entry in place. But how does that relate to low quality, minimally viable products? I'll let you or someone else answer that.

Maybe we need to remove the barriers, lower the cost of entry and lower the complexity (simplify)? No, those sound like ignoble pursuits.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#62
post #46
post #40

Earlier quoted context omitted.

I thought we were talking about SIM cards. Can I upload software to my SIM card? No. Most phones accept some type of SIM card, while not all phones have a means of user-controlled offline external storage (microSD, etc.). Why can't the user access a SIM card? Why can't she look at the software stored on a SIM card? The SIM card slot is pretty much off-limits to the user. Yet the user owns the phone. This is like buyi…

Do you program your PC BIOS or firmware?

Yes.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#63
post #40

Earlier quoted context omitted.

I thought we were talking about SIM cards. Can I upload software to my SIM card? No. Most phones accept some type of SIM card, while not all phones have a means of user-controlled offline external storage (microSD, etc.). Why can't the user access a SIM card? Why can't she look at the software stored on a SIM card? The SIM card slot is pretty much off-limits to the user. Yet the user owns the phone. This is like buyi…

You do not own the SIM card, it remains full property of your network operator. As such, they have a right to keep you off-limits. FYI: the main Javacard applet on a SIM card is the GSM applet, the one you use to authenticate against your network. Other applets are useful for network operators: IMEI tracking sends them your phone ID to help them configure it correctly -- it is also used to track stolen phones. Anothe…

Who says there can only be one SIM card? What if the user can have her own SIM card? Who says SIM cards are only useful with cell networks? What if the user has her own network? Is that impossible, now and forever? What if she has her own authentication and encryption needs, apart from some telecom's network?

Yes, the telecom owns the card they give you. Indeed, that is their property. But they don't need to own the smart card standard and use it to exclude users from using the slot.

Imagine if the motherboard you bought would had certain slots that were off-limits to you and open to use only by certain companies.

As for "glorified assemler", have you considered something more succinct, like FORTH. There's nothing glorious about Java.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#64
post #9

Hurray for Java applets. But seriously, there is a sunny side to this story: a user could load her own programs onto her SIM. She could gretaly extend the functionality of her phone... with programs that she trusts. Maybe even ones she wrote herself. Imagine... an open platform. Oh gosh, that would be terrible, wouldn't it? Otherwise this story highlights the concept of "minimum viable product" not in the startup wor…

How would you extend the functionality? Programming in JavaCard is really not fun (my opinion) and the space and processing power are really limited. The biggest use of it is verifying information (like pins or certificates), but what else would you do that your phone can't?

I would like to be able to take an older smartphone and use it as a smartcard-like device but with a full-fledged computer on it. For example, being able to use a Motorola Droid with a USB cable as a password manager. Keep the key secured on the SIM card. Use the touchscreen to enter the unlock password, and choose a password off a list. Send the password to a computer over USB by emulating a keyboard, or a custom driver that creates a secure channel to a specific app for authentication.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#65
post #46

Earlier quoted context omitted.

Do you program your PC BIOS or firmware?

I wish! I hate my PC's bios. So many superfluous timeouts, so much waiting around (clearly braindead programming that doesn't do hardware well). A stupid text based config interface. Nothing about the BIOS is good.

You mean, besides providing a standard way to access hardware that ARM systems still don't have to this day?

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#67
post #42
post #41

Earlier quoted context omitted.

You can do that easily with any decent adblocker. You could disable it for all sites but Forbes if you like. Right now, you are just leeching other people's time.

Thanks for the modbombing :-) I'm not leeching other people's time more than any other comment. If you're not interested proceed with the next post.

Comments with insights to the article, that don't ask people for favors, are not leeches. Your comment was a leech.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#68
post #65

Earlier quoted context omitted.

I wish! I hate my PC's bios. So many superfluous timeouts, so much waiting around (clearly braindead programming that doesn't do hardware well). A stupid text based config interface. Nothing about the BIOS is good.

You mean, besides providing a standard way to access hardware that ARM systems still don't have to this day?

And all this time, I thought my x86-64 workstation was BIOS free!

http://en.wikipedia.org/wiki/Unified_Extensible_Firmware_Int...

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#69
post #32
post #28

Earlier quoted context omitted.

Its all about full disclosure for ethical reasons. Can't say that about them white hats.

I don't know what this comment means. Could you, or someone else, explain it? Who are the "white hats"? Why do they have different perspectives on full disclosure than other people? Who are those other people?

Maybe a riff on the burgeoning "green hat" practice of selling exploits instead of simply disclosing them, versus black hats releasing them publicly for free?

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#70
post #58
post #3

Karsten Nohl: also the real deal. Here, for us, are the nut grafs: In early 2011, Nohl’s team started toying with the OTA protocol and noticed that when they used it to send commands to several SIM cards, some would refuse the command due to an incorrect cryptographic signature, while a few of those would also put a cryptographic signature on this error message. With that signature and using a well known cryptographi…

I strongly suspect that the attack uses the known plaintext of the error message to solve directly for the DES key (which is only an effective 56 bits). I wouldn't be surprised if it used the old FIPS DES-based MAC.

This appears to be confirmed - from https://srlabs.de/rooting-sim-cards/ :

  A rainbow table resolves this plaintext-signature tuple to
  a 56-bit DES key within two minutes on a standard computer.
  The cracked DES key enables an attacker to send properly
  signed binary SMS, which download Java applets onto the SIM.
It's particularly sad that the same key is used for the MAC in both directions (network-to-SIM and SIM-to-network).
Post reply on HN