4 ms·
The networks are insecure by standard. They are designed such that they can have "lawful intercept" by government entities. The key material on the SIM card is
by huslage 1y ago
The networks are insecure by standard. They are designed such that they can have "lawful intercept" by government entities. The key material on the SIM card is readily transferred between the carrier and SIM/eSIM card manufacturers, which enables multiple levels of supply chain attacks if the material is mishandled.
IMSI-catchers are not considered a security hole by the carriers or the standards bodies. SUCI/SUPI was put in at the request of phone vendors, if I remember correctly, and is still the only piece of public key cryptography in the networks. Everything else is symmetric keys.
- vv_ 1y agoFyi the above isn't some conspiracy theory as it is standardized by 3GPP: https://www.etsi.org/deliver/etsi_ts/133100_133199/133106/14.00.00_60/ts_133106v140000p.pdf https://www.etsi.org/deliver/etsi_ts/133100_133199/133106/14... Here's an interesting quote from the above: "Depending on national requirements, the CSP may be required to report the location of the Target at the beginning and end of CS calls and PS and IMS sessions on a per warrant or per intercept basis. It may also be a national requirement for the CSP to report the location of the Target [...]"