8 ms·
Gemalto's findings of its investigations into the alleged hacking of SIM cards
- rsm439 12y agoPlease pardon my naiveté, but is it even possible for a company that operates in 85 countries to do a thorough security audit in the six days since this news started making the rounds? The rapidity of their response makes me uneasy.
- gerty 12y agoIt appeared in the press a week ago but Gemalto should have been informed earlier. Still seems like a small amount of time. It took Belgacom much longer to deal with it.
- skolor 12y agoFrom the article, it sounds like they just looked at old incident reports and said "yup, these two are 'sophisticated,' they could be the NSA/GCHQ." Its a little disturbing that the "sophisticated" attacks they detected don't really sound all that sophisticated. Is spoofing an email and sending a PDF/Office exploit really considered sophisticated? While its a step above the most basic script-kiddie type stuff, that isn't unreasonable for even normal pentesting to do, and I wouldn't consider it an indicator of a nation-state attacker at all. Even if the attack was using 0-day in the attachment viewer, its not unheard of for malware kits to employ similar techniques. It definitely says something that those attacks were at least partially successful against systems Gemalto thinks could have resulted in the theft of sensitive crypto keys.
- joosters 12y agoIs spoofing an email and sending a PDF/Office exploit really considered sophisticated? Maybe. I'd say a targeted email, using a believable, researched sender address and relevant contents, would be fairly sophisticated. It would certainly be way more effective than the bulk 'please pay this generic invoice' exploits that I get spammed with.
- AlyssaRowan 12y agoSpear phishing, as its nicknamed? If something is sophisticated enough to work, don't knock it! There's no fundamental difference between the basic techniques used by malicious hackers, organised crime, pentesters or nation-state adversaries doing offensive "cyber-operations" (ugh): the only big difference is the budget (time, personnel, money), how likely they are to get away with it, and how aggressive they are.
- snowwrestler 12y ago> Is spoofing an email and sending a PDF/Office exploit really considered sophisticated? Generically, no, but the details can vary widely. If the email looks exactly like an internal email, and appears to come "from" someone the target knows, and the content references processes, info, or idioms common to that company or person, then that would be pretty darn sophisticated. Not technologically (an email is an email, after all), but socially. From the technology side, the specifics of the exploit, and what the malware tries to do in the PC/network after the spear phish succeeds, can also indicate varying levels of sophistication. If the spear phish contained a zero-day OS exploit (previously unknown vulnerability), that would be pretty darn sophisticated. I have no knowledge of the particulars of Gemalto--just speaking generally about how a spear phish attempt might be evaluated.
- kbart 12y agoThey might have discovered attack much earlier and hoping nobody else will find out, after all, it was made by government agencies so stolen data supposed to be in "safe hands" anyway. No proof, just a thought.
- Cthulhu_ 12y agoI'm pretty sure that they had a report still lying around from that period - which, for pretty obvious reasons, they wouldn't publish to the public until today, and even then only referring to it in a press release to reassure everyone that probably nothing happened.
- eps 12y agoNot a big deal. Just carry on. Please. * But be vigilant!
- Jolijn 12y agoWhew, that was quick wasn't it! Four to five years after the hacks happened, Gemalto says it was all not so bad, they really really checked this time and they have super duper server logs they grepped twice to be sure.
- mootothemax 12y agoFour to five years after the hacks happened, Gemalto says it was all not so bad, they really really checked this time and they have super duper server logs they grepped twice to be sure. That's a bit unfair. Gemalto say: - "The risk of the data being intercepted as it was shared with our customers was greatly reduced with the generalization of highly secure exchange processes that we had put in place well before 2010." - "The report... also states that when operators used secure data exchange methods the interception technique did not work." - "Gemalto has never sold SIM cards to four of the twelve operators listed in the documents, in particular to the Somali carrier where a reported 300,000 keys were stolen." - "A list claiming to represent the locations of our personalization centers shows SIM card personalization centers in Japan, Colombia and Italy. However, we did not operate personalization centers in these countries at the time." There's a lot of valid points in Gemalto's report, and it seems dishonest to write it off so pettily.
- Jolijn 12y ago> There's a lot of valid points in Gemalto's report, and it seems dishonest to write it off so pettily. I agree they have valid points that are worth setting the record straight on. But conveniently for Gemalto they distract from the core issue, which in my opinion is that they have been owned and are in denial of it. Hopefully it's just PR and they are scrambling internally to keep spies out.
- yuhong 12y agoObviously the key theft made it easier, but remember that 2G/GSM still only uses 64-bit encryption keys even in A5/3 and GEA3.
- scintill76 12y agoCan anyone elaborate on why it's supposedly only a problem for 2G? "If someone intercepted the encryption keys used in 3G or 4G SIMs they would not be able to connect to the networks and consequently would be unable to spy on communications." Why not? I feel like there is a "merely" missing from this sentence -- if so, what more than keys do they need to spy? Are they basing this on the specific type of key discussed in the documents? I don't know a lot about it, but I'm inclined to believe there are valuable keys burned-in to 3G+ cards too. I also wonder if there is a downgrade attack to force 2G, so that those keys are not completely worthless.
- thornjm 12y agoHopefully someone more knowledgable can weigh in, but as I understand the key stored on a 3G sim is more useful for authentication/identification rather than encryption. 3G/4G somehow uses random, short lived keys for encrypted communication, which change frequently enough to be a pain. EDIT: It has been a while since I studied this, but I believe the shared key is used for trust - that this isn't a fake base station and the client is who they say they are. Then they use the equivalent of public key cryptography to establish short lived encryption keys. Stealing keys would probably enable a MitM only?
- scintill76 12y agoThat sounds plausible. One problem I still see is that if $agency gets the authentication key, they can impersonate the user and possibly hijack their traffic. Maybe not as bad as passive decryption in some ways.
- lucaspiller 12y agoI think that is actually worse. Say a person isn't liked by the current regime, but they haven't got any solid (i.e. legally useable in court) evidence to put them away. The agency could log onto the GSM network and impersonate that person performing an illegal act they know will be picked up by law enforcement.
- r0h1n 12y agoFirstly, I'm amazed that a large global corporation has put out a press release saying it has "reasonable grounds to believe that an operation by NSA and GCHQ probably happened." Wow. That said, I wonder if Gemalto really had any other option than to say its keys weren't stolen. What might be the cost of replacing all affected SIM cards?
- RexRollman 12y agoThe SIM cards aren't going to be replaced even if true. I just don't see that happening.
- mike_hearn 12y agoAs they point out, SIM churn is not an uncommon thing especially in the poorer countries these agencies were targeting. Even in the worst case scenarios where every SIM had to be replaced, they'd probably just allow natural rollover to occur over a multi-year period. But it seems like that isn't really needed because the stolen keys were mostly replaced already anyway. Anyone who suspects they might be a person of interest can always just request a new one from their carrier.
- toyg 12y ago> Anyone who suspects they might be a person of interest can always just request a new one from their carrier. I doubt SIMs are manufactured just-in-time for each individual customer; more likely, carriers order batches of hundreds/thousands/millions SIMs. Without a recall program, it will take years before you can be confident that your freshly-acquired SIM is not compromised. I'd say it's safe to assume that from now on, any cellphone communication can be trivially intercepted by NSA/GCHQ. The most paranoid already assumed that, but now we have confirmation.
- higherpurpose 12y agoOnly if you assume that the last time they stole the Gemalto keys was in 2011. The Snowden documents themselves go up to 2012.
- hurin 12y agoCould someone explain to me the significance of having the keys as opposed to simply breaking A5/1 or A5/2 (Which is considered to be trivial)? Especially since A5/3 (which is also known to be insecure at least theoretically) can be downgraded to either of those or even A5/0? Is the advantage solely that they don't need to intercept the traffic as a middleman to ask the target to downgrade?
- kabouseng 12y agoThe difference would be, that with the keys you could just listen in and capture all the traffic. If you had to force cell phone connections to A5/0, you would have to: 1) Have to both receive and transmit. 2) Have a stronger connection than any other nearby cell towers. 3) Have a backbone connection back into the network so that you can actually negotiate phone calls to users connected to other cell phone towers. 4) Have to be able to handle multiple simultaneous connections. Some MITM spoof cell towers only establish a connection for the person of interest, and all other devices in the area loses connection. A pretty tell tale sign of a rogue base station operating in an area. So in short it is much easier just to have the keys...
- hurin 12y agoThat's what I assumed (but I wondered if there was some other advantage I was missing). Are not all the ciphers breakable post collection anyways? Is it fair to say that this is effectively for the purpose of blanket non-targeted surveillance? Where by having the keys in their possession it gives them a shortcut for bulk analysis and saving CPU time that would otherwise be spent breaking encryption. And a cpu-processing-savings advantage justified cyber-attacking a foreign civilian corporation?
- rkangel 12y agoWith the keys, you can do data collection now, and cracking later. You can do mass interceptions and then decide which calls you want to look at.
- zumtar 12y agoThis statement from Gemalto seems quite naive considering the leaked documents state that the operations to obtain the private keys were successful. They talk about the deployment of a "secure transfer system" BUT that will only help if that is the only time that data is ever transferred between two entities and assumes that the data will be kept securely. The Ki database has to be distributed to so many places in and around the network that it isn't surprising that it is schlepped around using insecure means. Of course in an ideal world the keys should never be accessible by a human, they should have been generated in a set of HSMs at the SIM manufacturer that are transferred physically to the network operator. In reality this doesn't happen as that takes time and money and is an overall logistical nightmare. Mobile carriers use lots of professional services "experts" from the vendors they buy from, it is rare to have in-house engineers running and maintaining the systems as those tasks are usually outsourced. Such engineers will have done a 4 week course with Nokia-Siemens-Networks, Huawei or Ericsson and they are sent out into the field with a crappy laptop and a few tools, they are just expensive "remote hands" without any real knowledge. This is how it would play out from a 3rd level support/engineer back at Telco HQ - In-house expert: Hi Mr Field Engineer, I need you to restore that HLR you are looking at, I can't reach it from here, and I need to send you a file securely to restore to that node, do you use PGP? Do you have the emergency encrypted USB stick with you? Outsourced Engineer: PGP? I don't know how to program, isn't that for making web-sites? USB stick, yes I have a new one in my bag I bought for downloading movies. In-house expert: No, that is PHP, don't worry about that for now, do you have any decryption software on your laptop? Outsourced Engineer: No, but my laptop is already unlocked, I've typed in my account and password. In-house expert: I have my boss screaming at me and the call-center is overloaded with complaints, do you know how to use SCP? Outsourced Engineer: SCP? In-house expert: OK, how about FTP, do you have an FTP client? Outsourced Engineer: Yes, I've got that, I use it for sending firmware to Cisco routers. In-house expert: No, not TFTP, FTP! Do you know what that is? Outsourced Engineer: Huh? In-house expert: OK, how about a corporate email account? Outsourced Engineer: No, I'm working for "XYZ Solutions" and I'm on a probationary period, I have a hotmail account, does that help? In-house export: OK, I suppose that will have to do, please just delete the email from hotmail and make sure you delete that file later from your PC. Outsourced Engineer: OK, you mean just drag it to trash on this 4 year old Windows XP laptop I'm using? sigh
- spacefight 12y ago"The attacks against Gemalto only breached its office networks and could not have resulted in a massive theft of SIM encryption keys" That's what they think...
- TeMPOraL 12y agoI see two totally separate threads of discussion here, so I have to ask - which way is it? Is Gemalto a poor company that got pwnd by Five Eyes, or are they just a bunch of spooks in corporate suits[0]? Because the latter paints the situation in a completely different light. [0] - https://news.ycombinator.com/item?id=9106179 https://news.ycombinator.com/item?id=9106179
- e12e 12y ago"If someone intercepted the encryption keys used in 3G or 4G SIMs they would not be able to connect to the networks and consequently would be unable to spy on communications." I don't understand this. First, it's well known that intelligence services passively listen to and collect any and all radio traffic. The issue then is can that traffic be decrypted, not can the traffic be spied on. Related to that is of course the use of frequency hopping -- but as I understand it, if frequency hopping uses N bands, and you have N antennas/radios at your disposal, you could listen and record all of them. Secondly, we all know that if you have a sim card, you can connect to a 3g/4g network. What they seem to be implying, is that 3g/4g uses asymmetric encryption (certificates) for authentication, and that only the sim card knows its own secret key. Does anyone know is this is true? Did 3g/4g move away from shared-secret to asymmetric keys? I hope I'm missing something -- because if not this press release is basically full of placating lies.
- microcolonel 12y ago“…customized algorithms for each operator” What are they smoking?
- deleted 12y ago[deleted]
- packetized 12y agoThis seems to have been released with breathtaking speed. Was it canned, or did they previously know that these revelations would come to light?
- garrettheaver 12y agoI wouldn't have said it was fast to the extent I'd be suspicious. Given the nature of the business they're in and the security risks they're well aware of, I'd say they have a plan of action on what to do in the event of a confirmed or potential breach and they just put that into action immediately.
- pg_is_a_butt 12y agodid you read the post at all? the attacks happened YEARS ago. they knew about them then and said nothing. either you're an idiot, or you think "immediately" means "years later only after evidence comes to light publicly"
- chiph 12y ago> Gemalto will continue to monitor its networks and improve its processes. I wonder if they're going to reissue the root key. And if they do, how can I, as an AT&T Wireless customer, know that my new SIM is using it?
- rkangel 12y agoAre you sure there is such a thing as a root key? Root keys apply to X509 and certificate signing, which isn't applicable here. They're likely just to be generating keys randomly (in the technical sense of the word).
- chiph 12y agoLooks like I misunderstood how the leak happened. I was thinking they infiltrated Gemalto's infrastructure and stole the signing key. But it looks like the keys (lots of them - one per SIM) were stolen while they were in transit, because of weak/no transmission security. Since I have no way of knowing if my personal SIM key was stolen, I'll have to wait until AT&T works their way through their existing stock of SIMs and then request a new one. And hopefully get one that wasn't exposed.
- discardorama 12y agoFTA: > In July 2010, a second incident was identified by our Security Team. This involved fake emails sent to one of our mobile operator customers spoofing legitimate Gemalto email addresses. The fake emails contained an attachment that could download malicious code. We immediately informed the customer and also notified the relevant authorities both of the incident itself and the type of malware used. I'm not buying this. If the fake emails were sent to the customer, wouldn't the operator be the one who detects the malicious address? So how is Gemalto informing the customer that the mails are malicious?
- pg_is_a_butt 12y agoif anyone on any of the networks at any time connected to any of the other networks, their entire theory goes out the window, and i think it's a fair assumption that such a thing happens on a daily basis. you can't air gap people from their data.
- LLWM 12y agoHopefully this will finally shut up the people who complain that the NSA's behavior will damage the US tech industry. If they are interested in compromising a system, being non-American just means they will break in the hard way. At least American companies can theoretically be secure if they are willing to grant authorized access when requested.