Live data from Hacker News

SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

forbes.com

71–80 of 97 posts

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#71
post #66

Earlier quoted context omitted.

http://www.coreboot.org

How many PCs ship with it?

Usually, whatever software PC's "ship with" is crapware. Go figure.

"Crapware" is just my opinion. Although I've heard others note the same thing.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#72
post #42

Earlier quoted context omitted.

Thanks for the modbombing :-) I'm not leeching other people's time more than any other comment. If you're not interested proceed with the next post.

Comments with insights to the article, that don't ask people for favors, are not leeches. Your comment was a leech.

Refer to GP for instructions.

You just wasted my time with your pointless comment. Well you didn't, I could have chosen to ignore it.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#73
post #64

Earlier quoted context omitted.

How would you extend the functionality? Programming in JavaCard is really not fun (my opinion) and the space and processing power are really limited. The biggest use of it is verifying information (like pins or certificates), but what else would you do that your phone can't?

I would like to be able to take an older smartphone and use it as a smartcard-like device but with a full-fledged computer on it. For example, being able to use a Motorola Droid with a USB cable as a password manager. Keep the key secured on the SIM card. Use the touchscreen to enter the unlock password, and choose a password off a list. Send the password to a computer over USB by emulating a keyboard, or a custom dr…

Sounds like a lot of work. I don't trust LastPass et al., and really just need a single encrypted password file. My method doesn't provide a driver secure channel, but it is achievable today.

1) Buy a slim ipod touch 2) Jailbreak (unnecessary) 3) App CryptMe allows transfer of plaintext from your computer through iTunes, password unlock on the device, quick search (nice), and according to Firewall iP (Cydia program) doesn't connect to the internet (or you could just always keep wifi off).

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#74
post #54
post #9

Hurray for Java applets. But seriously, there is a sunny side to this story: a user could load her own programs onto her SIM. She could gretaly extend the functionality of her phone... with programs that she trusts. Maybe even ones she wrote herself. Imagine... an open platform. Oh gosh, that would be terrible, wouldn't it? Otherwise this story highlights the concept of "minimum viable product" not in the startup wor…

I don't think this is a reasonable assessment at all. SIM manufacturers use 3DES, not DES, which - while not recommended for new systems - is still pretty damn secure. I don't think you've really understood the complexity of the SIM - there are literally thousands and thousands of pages of specification, which means that any sim will interoperate with any phone. A SIM is not an "MVP" by any stretch of the imagination…

We've read here recently, re: Snowden in Hong Kong, (rooted?) phones and ($5?) SIMs are inexpensive and popular in HK. Are there varieties of --I don't know, what-- `rooted(?)', `unformatted(?)' SIMs that become desirable to a knowledgeable hacker community, beyond what consumers get with their service?

edit: I just now found on HN front page:

https://srlabs.de/rooting-sim-cards/

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#75
post #70
post #58

Earlier quoted context omitted.

I strongly suspect that the attack uses the known plaintext of the error message to solve directly for the DES key (which is only an effective 56 bits). I wouldn't be surprised if it used the old FIPS DES-based MAC.

This appears to be confirmed - from https://srlabs.de/rooting-sim-cards/ : A rainbow table resolves this plaintext-signature tuple to a 56-bit DES key within two minutes on a standard computer. The cracked DES key enables an attacker to send properly signed binary SMS, which download Java applets onto the SIM. It's particularly sad that the same key is used for the MAC in both directions (network-to-SIM and SIM-to-ne…

Also sad that it's refereed to as a signature.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#76

I have been working on OTA platforms for years with Mobile Network Operators worldwide, and I have yet to meet one that is only using DES for OTA keys. All the ones I know are using 3DES. Not sure where Nohl is getting his estimations from. Half a billion SIMs? Show me the data. For this attack to work remotely you need to send a binary SMS and be able to read the SIM answer, which probably requires some privileged a…

Would (root) access to a microcell work?

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#77
post #65

Earlier quoted context omitted.

I wish! I hate my PC's bios. So many superfluous timeouts, so much waiting around (clearly braindead programming that doesn't do hardware well). A stupid text based config interface. Nothing about the BIOS is good.

You mean, besides providing a standard way to access hardware that ARM systems still don't have to this day?

Having a specification and a reference implementation is possible without the reference implementation being proprietary... Personally I would much prefer that.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#78
post #13

Article mentions "credit card java applets on SIM cards". I've never used one of those, and I know nobody in the western world who does. I always presumed that these sim java applets are crapware that is mercifully hidden on todays smartphones. It's also my impression that Mastercard and Visa paid a hefty stupidity tax by thinking in the 2000s that it would be important to have their software on SIM cards, not forese…

Yes, ISIS uses SIM applets: http://en.wikipedia.org/wiki/Isis_(mobile_payment_system) Google Wallet uses the same type of applets but stored in the phone's SE rather than the SIM card.

I know Telenor in Norway provides a service called BankID that is tied to Telenor SIM cards -- but I don't know anything about the implementation details (or how they've managed to lock the other providers out of the game).

BankID is a centralized service for authentication used by banks, and the "other" implementation is based on a (browser) java applet.

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#79
post #37

vaguely related question ... is it safe to insert an arbitrary sim card in a phone ? i want to try out some of the gsm mvnos in the states (eg airvoice, ptel and h2o). an at&t or comcast or microsoft has a reputation that's worth billions, so i "trust" them to only be semi-evil and at least semi-responsible. i don't know much of these mvno companies, but assume they're living on the margins and don't have too much to…

I don't know much about SIM-cards, but in general I would say, no, it's not safe. First there's the possibility of a problem with the phones interface to the SIM-card (possibility of direct exploitation) -- secondly, it's the possibility of putting "other stuff" on the SIM-card.

A friend of mine implemented a wifi-posistioning system that got power from the phone's GSM signals (it wasn't using a full wifi stack, just enough to broadcast an 802.11b frame that access points could pick up and triangulate). It was used for positioning in museums, and the phones where used for guiding information (so it wasn't a malicious hack) -- but it does illustrate that there are many possibilities.

Put a flash storage chip on there, and record all GSM traffic for example?

Re: SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones

#80
post #66

Earlier quoted context omitted.

http://www.coreboot.org

How many PCs ship with it?

I think at least some Chromebooks use it. It finds use in HPC clusters and embedded/industrial settings as well.
Post reply on HN