8 ms·
SIM Cards Have Finally Been Hacked, and the Flaw Could Affect Millions of Phones
- sentenza 13y agoIt's a "known plaintext" attack on DES. Via google translate, here is an article from Heise with more details: http://translate.google.com/translate?sl=auto&tl=en&js=n&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fwww.heise.de%2Fsecurity%2Fartikel%2FDES-Hack-exponiert-Millionen-SIM-Karten-1920898.html http://translate.google.com/translate?sl=auto&tl=en&js=n&pre...
- tptacek 13y agoUnfortunately, "known plaintext" is just about the most general term you can use to describe a crypto attack; it covers a huge number of different attack scenarios.
- sentenza 13y agoSorry, I'm not a crypto guy. It seems that he sends an "Over The Air" SMS that has an incorrect signature and then always recieves a response that he already knows. EDIT: Ok, I just read your other comment and must say that you probably understand a million times more about this than me, so disregard this comment.
- tptacek 13y agoOh, sorry, I wasn't sniping at your comment!
- dlitz 13y agoThis isn't new, but I wonder if it's related: "All SIMs could reject OTA message without Digitial Signature (DS), but this is rarely done as it brings additional pain to gsm providers. Most of the SIMs are correctly secured. Most of the SIMs accept OTA messages that are not encrypted. Some SIMs accept OTA messages that only have a correct Cryptographic Checksum (CC) and some SIMs only require a correct Redundancy Check (RC) and also require counter increase N+1. Most of the SIMs dont require any security feature and accept OTA messages without no RC, CC or DS, for example - Globul. (by marek, TODO: name the networks!)." http://wiki.thc.org/gsm/simtoolkit#head-1c0ca2c9ebd6ac101c90f17c23b8779d1f6adf1f http://wiki.thc.org/gsm/simtoolkit#head-1c0ca2c9ebd6ac101c90...
- tptacek 13y agoKarsten Nohl: also the real deal. Here, for us, are the nut grafs: In early 2011, Nohl’s team started toying with the OTA protocol and noticed that when they used it to send commands to several SIM cards, some would refuse the command due to an incorrect cryptographic signature, while a few of those would also put a cryptographic signature on this error message. With that signature and using a well known cryptographic method called rainbow tables, Nohl was able to crack the encryption key on the SIM card in about one minute. Carriers use this key to remotely program a SIM, and it is unique to each card. This is a little vague and I don't understand the OTA protocol like, at all, but what it sounds like is that there is a case in some implementations of SIM OTA where (a) errors for improperly signed messages are noisy, (b) those errors include some of the plaintext of the improperly signed message, and (c) the error message itself has a signature that is intended to be valid only for the error. Possible next steps: (i) you can table-solve for the signature (presumably this is a MAC, not a signature) for your intended message due to the way plaintext hits the error message, or (ii) you can table-solve for the plaintext of a previously unknown ciphertext by taking that ciphertext, flipping a bit to invalidate the signature, and collecting the error signature.
- ScottBurson 13y agoAt one point he says that he thinks it will take the black hats six months or so to figure out the exploit, but then, in the passage you have quoted, he gives what sound (to my non expert ear) like fairly massive clues. Is it possible he has revealed too much?
- D9u 13y ago*Verizon did not specify why its SIMs were not vulnerable* I was under the impression that Verizon phones don't use SIM cards because their network is CDMA instead of GSM.
- jingo 13y agoHurray for Java applets. But seriously, there is a sunny side to this story: a user could load her own programs onto her SIM. She could gretaly extend the functionality of her phone... with programs that she trusts. Maybe even ones she wrote herself. Imagine... an open platform. Oh gosh, that would be terrible, wouldn't it? Otherwise this story highlights the concept of "minimum viable product" not in the startup world, but as it exists among major industry manufacturers. For example, if SIM manufacturers can get away with using DES, then why invest their time and money in using stronger crypto? There are so many examples of this type of thinking... it's certainly not limited to imlementations of cryptography or SIM cards. No doubt, some would say this is simply Business 101... ask any used car salesman. But it's particularly acute in hardware and software. Do hardware and software worlds makers need higher standards and more serious "quality control"? Beyond the cosmetic appearance of their work, no. Because users are generally indifferent to all else. What they don't know won't hurt them. Did you know you can type encrypted messages directly with a text editor called ed(1)? How cool is that? It's so easy. Who needs PGP? It uses DES, but hey, DES is good enough for SIM cards, so...
- Genmutant 13y agoHow would you extend the functionality? Programming in JavaCard is really not fun (my opinion) and the space and processing power are really limited. The biggest use of it is verifying information (like pins or certificates), but what else would you do that your phone can't?
- jingo 13y agoConsider that some might not program for "fun". They might do it out of necessity: to "scratch itches". Limitation breeds creativity. This is true in general, but certainly in computers. Ever heard of demoscene? By comparison to the constraints we had to work with in the 80's, the power of today's handheld computers (one usage of which is as a "phone") is hardly a limitation. But I guess it would depend on what you are trying to do. I have no idea what you would want to do. Only you know that. As for what others might do, were they to be able to upload their own software to their phones, well, the only way to answer that question is to let them and see what comes out of it. Only a fool would believe he could direct, let alone predict, all the uses that might be made of a particular software program, a particular language or a particular computer. One use of a computer is as a communications device, aka a "phone". Another is a "game console". There are plenty of other uses for handheld computers even if you yourself cannot think of them.
- bcl 13y agoI don't understand the article's description of the sandbox vulnerability. On the iPhone app sandboxing is done by iOS, not in the SIM. Does the reporter just not understand, or is there another layer I'm not aware of?
- Mvandenbergh 13y agoThat's a separate sandboxing system. The SIM has its own sandboxes.
- aroman 13y agoFrom what I could gather, the sandboxing was actually referring to the SIM card itself. It was hard to tell through the layman-ified description, but it sounded like he used some sort of buffer overflow to break out of the sandbox and access other parts of the SIM's memory which he shouldn't have been able to.
- pjmlp 13y agoThis is at the SIM card level. Most SIM cards are actually micro computers that communicate with the host system for certificates, encryption and some provider specific information, besides the common address stuff. Usually the software is done in Assembly, C or JavaCard, with JavaCard use getting increased in the last years. The JavaCard exploits are related to the VMs running the system, which are usually coded in a mix of Assembly and C. JavaCard VMs don't have a JIT due to memory constraints.
- Zoepfli 13y agoArticle mentions "credit card java applets on SIM cards". I've never used one of those, and I know nobody in the western world who does. I always presumed that these sim java applets are crapware that is mercifully hidden on todays smartphones. It's also my impression that Mastercard and Visa paid a hefty stupidity tax by thinking in the 2000s that it would be important to have their software on SIM cards, not foreseeing that smartphone apps would just bypass that whole layer. Anybody know of an application in the western world, on smart phones, where these java applets are really used?
- dobbsbob 13y agoPretty sure Blackberry does in Canada, and I assume everywhere else that their Mastercard payment NFC (paypass) works. They touted it as being extra "secure" due to being on the SIM instead of the phone. No idea if carriers selling Bold and Curve handsets are using DES SIMs vuln to this.
- codebutler 13y agoYes, ISIS uses SIM applets: http://en.wikipedia.org/wiki/Isis_(mobile_payment_system) http://en.wikipedia.org/wiki/Isis_(mobile_payment_system) Google Wallet uses the same type of applets but stored in the phone's SE rather than the SIM card.
- e12e 13y agoI know Telenor in Norway provides a service called BankID that is tied to Telenor SIM cards -- but I don't know anything about the implementation details (or how they've managed to lock the other providers out of the game). BankID is a centralized service for authentication used by banks, and the "other" implementation is based on a (browser) java applet.
- aroman 13y agoWhat I'm curious about is what Nohl meant when he said that it would take six months from the time of his presentation at Black Hat for crackers to develop working exploits based on his findings. And if he is (as the article suggests) working with the phone companies, why not simply wait until they've implemented their patches (if they in fact need them)? If indeed it is as simple to force a sim to run these malicious applets as using some sort of rainbow-table-powered replay attack, what would be the challenge? Or perhaps he was referring to the more lucrative aspect of breaking out of the sim sandbox...
- pbhjpbhj 13y ago>what would be the challenge? // Maybe creating the rainbow tables? [I'm not familiar with any of the details here FWIW, just guessing as that seems the most likely thing that could be estimated to take 6 months].
- muyuu 13y agoWhat are the implications? Can't stand Forbes and their over the top ads, tldr would be appreciated.
- straight_talk_2 13y agoWhy don't you get an ad blocker - e.g. Ad Muncher is a great one.
- muyuu 13y agoI prefer to allow sites to monetise their visits within reason. If they go insane like Forbes then I just avoid them.
- aw3c2 13y agoYou can do that easily with any decent adblocker. You could disable it for all sites but Forbes if you like. Right now, you are just leeching other people's time.
- muyuu 13y agoThanks for the modbombing :-) I'm not leeching other people's time more than any other comment. If you're not interested proceed with the next post.
- Dylan16807 13y agoComments with insights to the article, that don't ask people for favors, are not leeches. Your comment was a leech.
- muyuu 13y agoRefer to GP for instructions. You just wasted my time with your pointless comment. Well you didn't, I could have chosen to ignore it.
- deleted 13y ago[deleted]
- gioele 13y agoA beautiful, although not really accurate, explanation of a buffer overflow: > The way this works is somewhat complex, but Nohl’s virus essentially gave the infected Java software a command it could not understand or complete – eg. asking for the 12th item in a 10-item list, leading the software to forgo basic security checks and granting the virus full memory access, or “root,” in cyber security parlance.
- nqzero 13y agovaguely related question ... is it safe to insert an arbitrary sim card in a phone ? i want to try out some of the gsm mvnos in the states (eg airvoice, ptel and h2o). an at&t or comcast or microsoft has a reputation that's worth billions, so i "trust" them to only be semi-evil and at least semi-responsible. i don't know much of these mvno companies, but assume they're living on the margins and don't have too much to risk. could they, or an enterprising engineer working for them, mess with the sim card to take something of value from me ?
- e12e 13y agoI don't know much about SIM-cards, but in general I would say, no, it's not safe. First there's the possibility of a problem with the phones interface to the SIM-card (possibility of direct exploitation) -- secondly, it's the possibility of putting "other stuff" on the SIM-card. A friend of mine implemented a wifi-posistioning system that got power from the phone's GSM signals (it wasn't using a full wifi stack, just enough to broadcast an 802.11b frame that access points could pick up and triangulate). It was used for positioning in museums, and the phones where used for guiding information (so it wasn't a malicious hack) -- but it does illustrate that there are many possibilities. Put a flash storage chip on there, and record all GSM traffic for example?
- vidarh 13y agoI can't guarantee there's no risk. But in Europe there are hundreds of virtual network operators - dozens in most countries - and I've never heard of any cases of operators (or anyone working for them) "messing with" sim cards, and people here newer think twice about switching sims.
- yaantc 13y agoIt won't harm the phone, but it won't work either. You can find generic SIM card that you can program yourself, but that's not what is used in a phone. Your phone will only work with a SIM card embedding specific applications called SIM for 2G (that's where the name comes from as you see, the physical thingy is named UICC) or USIM for 3G/LTE. And this application embeds security components that will authenticate the card to the operator, either as a direct customer or as a customer of another telco which is a roaming partner. If this authentication fails, you'll have no access. If there's no valid SIM or USIM application your phone modem won't do anything with the card.
- nicolas314 13y agoI have been working on OTA platforms for years with Mobile Network Operators worldwide, and I have yet to meet one that is only using DES for OTA keys. All the ones I know are using 3DES. Not sure where Nohl is getting his estimations from. Half a billion SIMs? Show me the data. For this attack to work remotely you need to send a binary SMS and be able to read the SIM answer, which probably requires some privileged access to an operator's SS7 network. Far from obvious. Since Network Operators are in complete control of SMS traffic, blocking anything that has not been issued by their own OTA platform is just a matter of configuring a filter on an SMS-C -- if not already done.
- mje__ 13y ago+1; I worked on SIMs in the past, and all our customers were using 3DES. They also all required OTA messages to be signed, so I think the chances of half a billion being accurate is crazy talk
- count 13y agoWould (root) access to a microcell work?
- yaantc 13y agoGood question. SMS are transmitted over the NAS layer of the 3GPP stack, which terminates beyond the cell (NB/eNB). There is NAS level security but I don't know if it's end-to-end or only over the air link. Hopefully it's the former but one should dig the specs at 3gpp.org to confirm.
- fulafel 13y agoOperators sometimes think they are using the good stuff but aren't. Same thing happened with COMP128, operators were unknowingly using it for years and years after it was broken and thought fixed in new SIMs.