750 million phones could be vulnerable in massive SIM security flaw
Karsten Nohl, the founder of German firm Security Research Labs, discovered that sending a fake carrier message to a phone prompted an automated response from 25 percent of DES SIMs that revealed the cards' 56-bit security key. With that key in hand, Nohl was able to send a virus to the SIM with a text message. The virus allowed him to impersonate the phone's owner, intercept text messages, and even make carrier payments. The New York Times cites Nohl as claiming that the entire operation takes "about two minutes" using a regular PC.
Over the past two years, Nohl has tested his method on around 1,000 cards across North America and Europe. DES is used in around three billion mobile SIMs worldwide, of which Nohl estimates 750 million are vulnerable to the attack. Many carriers use SIMs with the stronger triple-DES encryption method, which are not susceptible to Nohl's method, and DES in general has been phased out in favor of AES (Advanced Encryption Standard).
The flaw has been disclosed to the GSMA, an association made up of mobile operators and other companies in the field that oversees the deployment of GSM networks. The GSMA has informed SIM manufacturers and other companies involved of the situation, who are all analyzing how to best deal with the flaw. With the "responsible disclosure" taken care of, Nohl will detail his attack method at the Black Hat security conference on August 1st. He also plans to publish a "comparative list" detailing the SIM card security of each mobile carrier in December. Hopefully by then the at-risk operators will have taken the necessary steps to neutralize the vulnerability.
Posted:
Related Forum: PC General Forum
Source: http://www.theverge.com/2013/7/21/4542782/sim-card-des-security-flaw-security-research-labs
Related Articles
Comments
RuinsPosted:
yes i know right? i don't know what to think right now, Security for everything is crap these days
MattDannerPosted:
G9H Wow that's a lot of people, It's lucky that I have a Iphone.
iPhones have SIM cards..
VeraPosted:
G9H Wow that's a lot of people, It's lucky that I have a Iphone.
i dont even have a phone
Latest Downloads
- 01. My Summer Car: SaveGame (green BMW E30)(0)
- 02. [EU] ADR1FT Trophies Game Save [CUSA02519](0)
- 03. Tekken 2 100% save game file for Retroarch european version(0)
- 04. My Summer Car: SaveGame (living in an apartment)(0)
- 05. Need for Speed: Most Wanted (2005) - SaveGame (100 cars in the showroom)(2)
- 06. Horizon Forbidden West: SaveGame (100%, before DLC) [1.0.38.0](4)
- 07. DREDGE: SaveGame (The Game done 50%)(0)
- 08. Need for Speed: Most Wanted (2005) - SaveGame (100%, 17 cars)(2)
- 09. Signalis: SaveGame (Before the battle with Falke) [1.2.1](0)
- 10. Wraith of Anias | Final Checkpoint Save(1)
- 11. Jalopy SaveGame (Pumped up LaikaGT)(1)
- 12. Assassin's Creed 3 Save Game (Game completed 8%, until Chapter 4)(0)
- 13. Supermarket Simulator SaveGame (Quick start, 172 day, 65lvl)(2)
- 14. Caribbean Legend: SaveGame (before the start of the Dutch Gambit)(1)
- 15. Caribbean Legend: SaveGame (Passed the Secret Organization Gambit) [v1.0.0](1)
Latest Tutorials
- 01. The Redress Of Mira 100% Walkthrough | Trophy & Achievement(599)
- 02. Russian Pinocchio Quick Trophy Guide(803)
- 03. Venatrix Quick Trophy & Achievement Guide(798)
- 04. Call of the Sea 100% Platinum Walkthrough(817)
- 05. Wire Lips 100% Platinum Walkthrough(882)
- 06. The Expanse 100% Platinum Walkthrough | Trophy & Achievement(791)
- 07. Doctor Who: The Edge of Reality - PS4 Platinum P/Thru(730)
- 08. Doctor Who:The Lonely Assassins - 100% Guide(599)
- 09. DAYMARE 1998 PS4 - Full game 100% TROPHY WALKTHROUGH(582)
- 10. Stray Platinum Walkthrough | Trophy & Achievement Guide(608)
- 11. Raji: An Ancient Epic | Complete Gameplay Walkthrough(776)
- 12. Corpse Killer: 25th Anniversary Edition - Longplay(815)
- 13. Song of Horror: Complete Edition Gameplay Walkthrough(557)
- 14. Remoteness 100% All Trophies Walkthrough(850)
- 15. Detective Inspector Mysterious Clues Platinum Walkthrough(645)
"750 million phones could be vulnerable in massive SIM security flaw" :: Login/Create an Account :: 65 comments