5 ms·
Ahh this is so useful that it's at the top of HN. We've (probably) arrived at one of those "hidden" dominant operating systems out there in the world: JavaCard
by numair 5y ago
Ahh this is so useful that it's at the top of HN.
We've (probably) arrived at one of those "hidden" dominant operating systems out there in the world: JavaCard OS. It's not just (probably) in your cell phone SIM, it's also (probably) in your credit cards. Add all of those devices up, and you realize that, in a weird way, if aliens were to inspect the activity of humans, they'd say, "the humans seem to be using some sort of weird thing they call 'JavaCard OS' to run their society."
If anyone is a JavaCard OS master, shoot me an email - numair@numair.com. I'm having some IC card issues that could use some external input...
In terms of the linked article, I think this part makes it clear what's going on, if we are to take an innocent view on things:
> After the lab work, deposition of an AT&T employee revealed that the only other trigger is a firmware update of the baseband processor. That is also consistent with the SIM requesting the IMEISV, since the “SV” part means “software version”, and it is updated every time the baseband processor loads new firmware. In this particular case, the phone had recently downloaded an update that included new baseband firmware. That was almost certainly the trigger for this message.
If I was a network engineer, I'd probably want a way to figure out whenever someone's putting new equipment on my network. This is a brilliantly sneaky way to do it. There's probably other uses for this, though, and you can imagine that your favorite intelligence agencies have thought about it long before it showed up in a Hacker News article...
- TheRealDunkirk 5y agoIs this the card "technology" that ran DirectTV tuners as well? I had a friend who was, at one point, running 7 hacked systems, and recording everything he could to burn to DVD, but I never got into that.
- _joel 5y agoThey use C.A.M.s with smart cards that are embedded with a microcontroller. https://en.wikipedia.org/wiki/Conditional-access_module https://en.wikipedia.org/wiki/Conditional-access_module
- zionic 5y ago>a friend uh huh! :)
- TheRealDunkirk 5y agoIf I had hacked 7 units -- and hacked scores of cards for other people -- I wouldn't had to have asked that question.
- cronix 5y agoAll cable systems in the US are mandated to supply users with those "CableCards" if they request them to decrypt cable tv channels, so you can use your own tuners and not be forced to rent one forever from the cable company. So, it wasn't just Dish. TiVo also uses them. The first one was free and the second one was $1.50/mo. Each could decrypt 4 simultaneous channels. I used them for about 15 years until cancelling cable earlier in the year. $1.50 vs a $30 cable box saved quite a bit over the years. Here's the page on xfinity for them. They're just PCMCIA cards, which used to be popular. My first laptop had a PCMCIA port which I used for a GPS device in the 90s before they were all-in-one chips. https://www.xfinity.com/support/articles/about-cablecards https://www.xfinity.com/support/articles/about-cablecards
- _joel 5y agoA long, long time ago it was possible to decrypt the original VideoCrypt with a serial connection attached to a smart card that ran software like 'Voyager' that could decrypt or bypass the keys/locks necessary to decode. This was running on a 286 laptop. Seems like an absolute lifetime ago now.
- Bellyache5 5y agoAnd before CableCards some cable settop boxes had FireWire/IEEE1394 ports on them that provided the raw video stream. You still had to rent the cable box though.
- raybb 5y agoGiven the importance you stated, the Wikipedia page could use some love https://en.wikipedia.org/wiki/Java_Card_OpenPlatform https://en.wikipedia.org/wiki/Java_Card_OpenPlatform
- ganzuul 5y agoIf the SIM can act as a TPM for the binary blobs and report tampering, it could be the TLAs have actually been doing what they are supposed to be doing: securing infrastructure.
- fragmede 5y agoIf my cellphone's code can be used to "hack" my carrier, we're one open source project away from game over. Which in some ways is the SS7 hack, but I having been following the cell phone companies responses, so maybe that did get secured against.
- bobberkarl 5y agoThe sim cards cannot be used as a secure element or a TPM in most android phones. The SWI lines that connects the SIM to Android are cut in most hardware designs. Google cuts them in the nexus (with one nexus having a notable exception), Samsung cut them and forces you to use their embedded secure element.
- bobberkarl 5y agoI worked on javacard for 2 years. I was working on bringing iso 14443 bus cards to the mobile with nfc. (Previous failed startup)
- numair 5y agoCan you send me an email? Your bio on HN is empty...
- bobberkarl 5y agoDone! Let's move this conversation to web2.0.
- kgermino 5y agoNot for nothing: so is yours. The email field isn’t publicly visible, so you need to put it in the about field.
- numair 5y agoThanks for the reminder!
- lxgr 5y agoNot a Java Card expert by any means (more of an interested party), but are you able to share what you're working on? I'm always curious about new smart card use cases :)
- numair 5y agoIt’s the next thing on my list of things to write — and related to a very weird security vulnerability I’ve found in a lot of corporate workflows — so, it should be done sometime this month.
- exikyut 5y ago!! I opened https://numair.com https://numair.com in a new tab so I could stumble on it in a bit (figuring this info would turn up there), only to discover a parking page (and TLS cert Chrome did not like). Double-checked the spelling twice. Is it just an email domain? Where can I eventually read about this? Very idly curious :)
- numair 5y agoYikes, sorry — this is one of those domains that got registered in the InterNIC days and transferred off years later, so I never bothered to move the A record to an IP that doesn’t use an obnoxious parking page. I’ll add that to the to-do list. It is very much email-only at this point. I’ll probably publish the paper on my company website, once that’s up — having a bit of an identity crisis at the moment to figure out whether everything gets done in English, or Japanese, or both — probably both...
- exikyut 5y agoAh, I see! Very cool. (And also cool to learn that domains showing parking pages can send/receive legitimate email. I would never have expected that!) It would make a lot of sense to translate to Japanese if the issue is Japan-specific, but I can also see good justifications in simply releasing papers in all the languages :). That being said, if I had to pick a language to prioritize, well, it'd be the language with the widest security audience. Yep. Look forward to seeing the paper :) (thanks for the email)