The Great SIM Heist How Spies Stole the Keys to the Encryption Castle

Sarbajit Roy <[email protected]>
Newsgroups gmane.org.telecom.india-gii
Message-ID <CABun1Ly3SpodMFOwEJRGVgmhUFaA1_RCzQnGj29b-X3Sc55+8w@mail.gmail.com>
https://firstlook.org/theintercept/2015/02/19/great-sim-heist/

*EXCERPT*

*AMERICAN AND BRITISH* spies hacked into the internal computer network of
the largest manufacturer of SIM cards in the world, stealing encryption
keys used to protect the privacy of cellphone communications across the
globe, according to top-secret documents provided to *The Intercept* by
National Security Agency whistleblower Edward Snowden.

The hack was perpetrated by a joint unit consisting of operatives from the
NSA and its British counterpart Government Communications Headquarters, or
GCHQ. The breach, detailed in a secret 2010 GCHQ document
<https://firstlook.org/theintercept/document/2015/02/19/cne-access-core-mobile-networks-2/>,
gave the surveillance agencies the potential to secretly monitor a large
portion of the world’s cellular communications, including both voice and
data.

The company targeted by the intelligence agencies, Gemalto
<http://www.gemalto.com/>, is a multinational firm incorporated in the
Netherlands that makes the chips used in mobile phones and next-generation
credit cards. Among its clients are AT&T, T-Mobile, Verizon, Sprint and
some 450 wireless network providers around the world. The company operates
in 85 countries and has more than 40 manufacturing facilities. One of its
three global headquarters is in Austin, Texas and it has a large factory in
Pennsylvania.

In all, Gemalto produces some 2 billion SIM cards a year. Its motto is
“Security to be Free.”

With these stolen encryption keys, intelligence agencies can monitor mobile
communications without seeking or receiving approval from telecom companies
and foreign governments. Possessing the keys also sidesteps the need to get
a warrant or a wiretap, while leaving no trace on the wireless provider’s
network that the communications were intercepted. Bulk key theft
additionally enables the intelligence agencies to unlock any previously
encrypted communications they had already intercepted, but did not yet have
the ability to decrypt.

_______________________________________________
India-gii mailing list
India-gii-IAPFreCvJWP2/[email protected]
https://lists.india-gii.org/mailman/listinfo/india-gii
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.