750 million phones could be vulnerable in massive SIM security flaw

4.6
The New York Times reports that a security researcher has found a vulnerability in the encryption used by some mobile SIM cards that could let hackers remotely take control of a phone. The flaw relates to cards using DES (Data Encryption Standard) for encryption — it's an older standard that's being phased out by some manufacturers, but is still used by hundreds of millions of SIMs.

Karsten Nohl, the founder of German firm Security Research Labs, discovered that sending a fake carrier message to a phone prompted an automated response from 25 percent of DES SIMs that revealed the cards' 56-bit security key. With that key in hand, Nohl was able to send a virus to the SIM with a text message. The virus allowed him to impersonate the phone's owner, intercept text messages, and even make carrier payments. The New York Times cites Nohl as claiming that the entire operation takes "about two minutes" using a regular PC.

Over the past two years, Nohl has tested his method on around 1,000 cards across North America and Europe. DES is used in around three billion mobile SIMs worldwide, of which Nohl estimates 750 million are vulnerable to the attack. Many carriers use SIMs with the stronger triple-DES encryption method, which are not susceptible to Nohl's method, and DES in general has been phased out in favor of AES (Advanced Encryption Standard).

The flaw has been disclosed to the GSMA, an association made up of mobile operators and other companies in the field that oversees the deployment of GSM networks. The GSMA has informed SIM manufacturers and other companies involved of the situation, who are all analyzing how to best deal with the flaw. With the "responsible disclosure" taken care of, Nohl will detail his attack method at the Black Hat security conference on August 1st. He also plans to publish a "comparative list" detailing the SIM card security of each mobile carrier in December. Hopefully by then the at-risk operators will have taken the necessary steps to neutralize the vulnerability.

Posted:
Related Forum: PC General Forum

Source: http://www.theverge.com/2013/7/21/4542782/sim-card-des-security-flaw-security-research-labs

Comments

"750 million phones could be vulnerable in massive SIM security flaw" :: Login/Create an Account :: 65 comments

If you would like to post a comment please signin to your account or register for an account.

SCOPosted:

AzzaLT
ooh Wow, that's sketchy. Sucks for some people. ha


So you don't own a mobile phone?


just because he said that doesnt mean that he doesnt have one... maybe knows he's not been affected by this...

gtapro151Posted:

AzzaLT
ooh Wow, that's sketchy. Sucks for some people. ha


So you don't own a mobile phone?


i dought it affects any iphone since the 4 and thats what 99% of us have is a iphone lol

GrimgazPosted:

That realy scary maybe we wil find some more Ghost info from these hackers nah jk this is preety scary tho

AzzaLTPosted:

ooh Wow, that's sketchy. Sucks for some people. ha


So you don't own a mobile phone?

KatsumiPosted:

daw 750 million ?! Woah.


Hopefully the majority of these people end up switching their sim cards. 750 Million makes up a good percentage of mobile phone users..

DawPosted:

750 million ?! Woah.

oohPosted:

Wow, that's sketchy. Sucks for some people. ha

MaggardoPosted:

Sucks to be the people with these phones!:/

PlusnetPosted:

Titanium Getting a new SIM card isn't that hard. Usually the carrier would give them to you for free especially with this going on.


Yeah, they would have to.

AlbericiPosted:

Gossip I dont see anyone really getting hacked...


Well because I am sure this has just been found and getting the word around. Sounds like some NSA crap to me to be honest.