5 ms·
"We must implement as LAW that a SIM card can provide and only provide a Zero Knowledge Proof ..." Now is a good time to remind everyone that a SIM card is a f
by rsync 2y ago
"We must implement as LAW that a SIM card can provide and only provide a Zero Knowledge Proof ..."
Now is a good time to remind everyone that a SIM card is a full blown computer with CPU, RAM and NV storage.
Further, your carrier can upload and execute code on your SIM card without your knowledge or the knowledge of the higher level application processor functions of your telephone.
- deadso 2y agoIs there any sandboxing to prevent access from the SIM card computer to information on your phone? And if so, absent of some (admittedly not very unlikely) 0day allowing sandbox escape, what would a malicious SIM program be able to do?
- immibis 2y agoYes, the card is a peripheral device to the phone - a hardware security key. It can't steal all your data for the same reason your Yubikey can't. Answer delayed by hours due to HN rate limiting.
- devops99 2y agoBasically this. And, hopefully your USB stack, or your phone's equivalent to SIM interface, doesn't have vulnerabilities that the small computer that is the SIM card could exploit. Operating systems that center their efforts on protecting high risk users like Qubes dedicated a whole copy of Linux running in a Xen VM to interface with USB devices. It'd be great if more information were available on how devices like Google's Pixel devices harden the interface for SIM cards.
- mfkp 2y agoLuckily e-sims are becoming more common.
- immibis 2y agoUnluckily because they can only be issued by registered and licensed members of the GSM alliance, IIRC.