4 ms·
I have been working on OTA platforms for years with Mobile Network Operators worldwide, and I have yet to meet one that is only using DES for OTA keys. All the
by nicolas314 13y ago
I have been working on OTA platforms for years with Mobile Network Operators worldwide, and I have yet to meet one that is only using DES for OTA keys. All the ones I know are using 3DES. Not sure where Nohl is getting his estimations from. Half a billion SIMs? Show me the data.
For this attack to work remotely you need to send a binary SMS and be able to read the SIM answer, which probably requires some privileged access to an operator's SS7 network. Far from obvious. Since Network Operators are in complete control of SMS traffic, blocking anything that has not been issued by their own OTA platform is just a matter of configuring a filter on an SMS-C -- if not already done.
- mje__ 13y ago+1; I worked on SIMs in the past, and all our customers were using 3DES. They also all required OTA messages to be signed, so I think the chances of half a billion being accurate is crazy talk
- count 13y agoWould (root) access to a microcell work?
- yaantc 13y agoGood question. SMS are transmitted over the NAS layer of the 3GPP stack, which terminates beyond the cell (NB/eNB). There is NAS level security but I don't know if it's end-to-end or only over the air link. Hopefully it's the former but one should dig the specs at 3gpp.org to confirm.
- fulafel 13y agoOperators sometimes think they are using the good stuff but aren't. Same thing happened with COMP128, operators were unknowingly using it for years and years after it was broken and thought fixed in new SIMs.