Tuesday, July 23, 2013

Some SIM cards can be hacked 'in about two minutes' with a pair of text messages

Some SIM cards can be hacked 'in about two minutes' with a pair of text messages

Every phone needs a SIM card, and you'd think such a ubiquitous standard would be immune to any hijack attempts. Evidently not, as Karsten Nohl of Security Research Labs -- who found a hole in GSM call encryption several years ago -- has uncovered a flaw that allows some SIM cards to be hacked with only a couple of text messages. By cloaking an SMS so it appears to have come from a carrier, Nohl said that in around a quarter of cases, he receives an error message back containing the necessary info to work out the SIM's digital key. With that knowledge, another text can be sent that opens it up so one can listen in on calls, send messages, make mobile purchases and steal all manner of data.

Apparently, this can all be done "in about two minutes, using a simple personal computer," but only affects SIMs running the older data encryption standard (DES). Cards with the newer Triple DES aren't affected; also, the other three quarters of SIMs with DES Nohl probed recognized his initial message as a fraud. There's no firm figure on how many SIMs are at risk, but Nohl estimates the number at up to 750 million. The GSM Association has been given some details of the exploit, which have been forwarded to carriers and SIM manufacturers that use DES. Nohl plans to spill the beans at the upcoming Black Hat meeting. If you're listening, fine folks at the NSA, tickets are still available.

Filed under: ,

Comments

Source: New York Times

Source: http://feeds.engadget.com/~r/weblogsinc/engadget/~3/OJ9uC1XABWQ/

marlins park marbury v. madison 2013 lincoln mkz burger king mary j blige google project glass google goggles one tree hill

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.