5 ms·
Without a SIM card it would be a lot harder to do my taxes, access my online bank, check my insurance, etc., because the SIM card is used to veriy my identity u
by torh 7y ago
Without a SIM card it would be a lot harder to do my taxes, access my online bank, check my insurance, etc., because the SIM card is used to veriy my identity using a solution called BankID. (https://www.bankid.no/en/company/ https://www.bankid.no/en/company/)
It's a lot easier then the alternative with OTP codes, especially since BankID is now supported by a lot of different sites and services. From government, banking, phone companies, etc.
- pjc50 7y agoHow has Norway solved the "slamming" problem, where attackers ring the phone company and get a duplicate SIM?
- kiloreven 7y agoThe BanID SIM-application has to be installed over the air and activated through online banking. It's bound to one physical SIM, so an attacker would need to get into the online banking in the first place to reinstall the SIM app onto the new card. I believe the auth keys are stored on the SIM as part of this solution, and regenerated every time it's reactivated, invalidating the existing SIM.
- pjc50 7y agoThis is .. remarkably sensible, and a good example of using the secure elements of the SIM card for the intended purpose. Makes me wonder why more places don't do this.
- Aardwolf 7y agoWhy does this have to involve a SIM card though? Why not use the device itself, e.g. authenticator?
- TazeTSchnitzel 7y agoSweden briefly had a SIM card-based system before scrapping it in favour of a pure smartphone app.
- kiloreven 7y agoIt's possible to use OTP and password as well, which requires a physical OTP generator. But that's actually more cumbersome than using the SIM alternative in my experience. I believe using the SIM adds layers of security that OTP apps can't compete with, including increased difficulty cloning the private key. I assume that accessing the relevant parts of the SIM is way harder and requires completely different vectors than attacking the OS.
- Aardwolf 7y agoSince the early 2000's, banks in Europe gave physical OTP devices. While somewhat inconvenient if you don't have it with you, I still liked it better than alternatives that are popping up lately: SMS based authentication, an app that generates a code from a QR-like pattern displayed on your computer screen (neat but they didn't think of the case where the screen displaying the QR pattern would be the phone itself, or the fact that you're letting their app see what else is on your computer screen) and paper cards with a finite amount of numbers on them. In fact I'd prefer TOTP as supported by authenticator as a better phone based alternative since it's standard and you can control if and how you want to securely back up the codes rather than have a plethora of different systems.
- fpoling 7y agoBankId works even with non-smart phones. Plus it’s storage of private keys is more secure than the crypto-storage on cheaper smart-phones.
- deleted 7y ago[deleted]
- icebraining 7y agoA SIM card contains a crypto module that can perform operations (signing, encrypting, etc) while not allowing the device to read the private key. Some phones include a chip like that too, but many don't.
- wtmt 7y agoHow does this actually work on something like iOS, which I believe is a lot more restrictive and may not allow access to the SIM except through carrier services (which are in turn susceptible to attacks, including bribes, social engineering, etc.)?
- kiloreven 7y agoThe carrier is involved in transmitting and triggering the challenge as well, and I'm pretty confident that it works on iOS, though I've never tried myself. The authentication works like this: 1. User fills out form with enough public and semi-private infoemation to securely identify the user (usually phone number and date of birth or social security number) 2. The user is presented with a random two-word string 3. The same message appears on the user's phone. If the words are the same, the user proceeds to input a PIN. The PIN is only stored on the SIM, and is chosen by the user. 4. A response is sent from the phone and the user gets logged in. I assume that the challenge response employs asymmetric authentication, storing a private key for the SIM and public key for BankID on the SIM. I'm not familiar enough with how the underlying crypto works to guess what kind of attacks they'd be suceptible to, but considering that the authentication is used for most public services in Norway (including taxes, welfare, medical records and document signing) as well as some private services (banking, insurance), I'll believe that the proper due diligence has been done. There is a big focus on using these platforms securely, and BankID recently ran an at campaign with some TV spots, telling how people should never share their BankID login, not even with their loved ones - https://youtu.be/OFJmX7A--w4 https://youtu.be/OFJmX7A--w4
- Nextgrid 7y agoiOS supports STK, which allows the SIM to ask the phone to draw rudimentary UIs and ask for user-input. It would work just as well as on a dumb phone.
- Shalle135 7y agoIn Sweden the banks issue the BankID instead, the certificate is tied to the phone/pc it’s downloaded to and is not connected to the phone# at all. You can however connect for example ”Swish” to your bank accounts for seamless transactions through youe phone# but it too has to be authenticated with bankid. I’ve never really heard of a case when the bankid/authentication to any Swedish banks has been compromised with the exception of the users signing in fraudulent actors.
- kwhitefoot 7y agoThe SIM will be sent to the registered address of the owner. So you will have to intercept the post as well. And the PIN will be sent in a separate envelope on a different day. That plus the other things like storing the encrypted keys in the SIM card activated by logging in to a bank by some other means make it pretty secure.
- Ayesh 7y agoNot sure about Norway, but in the Netherlands, you have to note down the PUK code. You can't get a replacement SIM card without PUK code. This is for prepaid though.
- goblin89 7y agoIsn’t BankID subject to the same old issues with cellular networks that make SMS 2FA insecure? Mobile provider support human factor, connection MITM’ing, etc. (https://news.ycombinator.com/item?id=16810266 https://news.ycombinator.com/item?id=16810266) Edit: from sibling threads I can see that issuing a duplicate SIM card in Norway may require a very dedicated attacker, but mass-spoofing cell towers could still be an issue. I don’t know why do companies dislike non-SIM-associated OTP tokens so much…
- tjoff 7y agoNot at all. And the comment you link to is "just" social engineering. Tricking people into signing in someone else and then signing their transactions. Akin to "hey I'm from paypal please give me your password so I can verify it is you". Or "I'm from Microsoft support, you have a virus please run this executable so that we can help you". But it is a problem. And they explicitly target old and other people that (statistically) treat any computer stuff as black magic and are more likely to trust a stranger because they say they are calling from a bank/whatever.
- deleted 7y ago[deleted]
- kickling 7y agoIs that the same as BankID in sweden? That is not 'connected' to the sim card, but to the device itself.
- kwhitefoot 7y agoReally? In Norway BankID is quite definitely connected to the SIM card.
- TazeTSchnitzel 7y agoNorway's BankID and Sweden's BankID are different products by different companies that happen to have the same name. Sweden did briefly have a SIM card-based version of its BankID, but it was quickly replaced with the smartphone app-based “Mobile BankID”.
- galphanet 7y agoIn Switzerland we have MobileID which is basically the same thing as Norway's Bank If : using a sim card as a smart card.
- ginko 7y ago> because the SIM card is used to veriy my identity using a solution called BankID. That's BankID over mobile. You can also use a key fob like this[1] + a password to authenticate. I use it when traveling and using a prepaid SIM occasionally. [1] https://bank.obos.no/globalassets/bilder-alternative-str/signering_kodebrikke2.png.jpg https://bank.obos.no/globalassets/bilder-alternative-str/sig...