The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
61–70 of 200 posts
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#62This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#63Sadly this would be an excellent application for the CFAA except that they agencies involved are immune from its prosecution.
> Additionally, the spy agency targeted unnamed cellular companies’ core networks, giving it access to “sales staff machines for customer information ...
So these corporations had customers' personal data stolen. I believe they're obligated to inform those customers, and possibly other obligations. (No direct knowledge, just spouting off what I've read during the Target and Home Depot breaches.)
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#64Earlier quoted context omitted.
The old technologies required more effort (somebody had to go physically tap the wire).
When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…
Even companies like AT&T, who you'd think with exorbitant prices would always pay for proper direct connections, actually try to find the cheapest bidder in any way possible. For some destinations, they might a list that's 20+ resellers deep.
In short, tapping major connectivity points is probably enough to capture a lot of calls even if you place them from a landline. (Not to mention there's no real security mindset in telecom at all.)
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#65Earlier quoted context omitted.
The old technologies required more effort (somebody had to go physically tap the wire).
When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#66Earlier quoted context omitted.
I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.
I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…
Information minimization and avoiding single points of failures could have prevented this.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#67Earlier quoted context omitted.
You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone. So it's not that different, a bit easier, yes. But you still have to physically go there.
Not if you have access to the carrier's internal network...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#68Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#69http://www.cso.com.au/mediareleases/21603/gemalto-releases-f...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#70Earlier quoted context omitted.
Sure. Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.
Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.
I would argue that theoretically, a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.