Every story and rumor about global eavesdropping has been confirmed by a new leak from Edward Snowden's documents. In April 2010, the NSA and the British GCHQ joined forces to hack into Gemalto, one of the largest SIM card manufacturers on the planet. It's unclear exactly how many SIM encryption keys the agencies stole, but Gemalto produces two billion cards a year....

NSA and GCHQ Hacked SIM Card Manufacturers to Eavesdrop on Calls
NSA

The target: Gemalto

It didn't take long before Big Brother came to mind again. Compared with this, the incident involving Samsung televisions seems trivial, and the worst part is that almost five years passed before anyone realized what had happened. Gemalto is one of the world's most important SIM card manufacturers, with the capacity to produce around two billion cards a year and supply 450 telecommunications companies in 85 countries. It goes without saying that Gemalto is a critical player in the mobile universe, and that made it the ideal target for the “security” agencies. In April 2010, an operation organized by the British GCHQ and elements of the NSA managed to penetrate Gemalto's infrastructure, stealing an undetermined number of SIM encryption keys.

NSA and GCHQ Hacked SIM Card Manufacturers to Eavesdrop on Calls
Gemalto makes two billion cards per year.

What the stolen keys mean

In its early days, the SIM card played a much humbler role, but today it has the technological resources to protect voice, data and text connections on a device. This encryption key, also known as “Ki”, is stored on the chip and held by the mobile company. If the key is correct, the corresponding “handshake” is negotiated and the communication is protected. However, all the NSA and GCHQ have to do to listen in on conversations with these keys in their possession is set up fake towers (like the famous “Stingrays”), something that is entirely within their capabilities. As if that were not enough, the keys also allow the retroactive decryption of any conversations the agencies have stored.

The operation included intrusions on billing servers (to suppress any additional charges that might raise suspicion), computers in sales departments, engineering systems and authentication servers. The biggest prize for the agencies is the ability to avoid all legal restrictions when establishing a wiretap, along with the low risk of detection. In fact, Gemalto had no idea how such a theft was carried out, but the company's brutal mistake was transferring Ki values to telecom companies via FTP and email.

SIM cards are not only used in smartphones and basic phones, but also in 3G modems, next-generation credit cards and electronic passports. Granted, a set of such valuable keys concentrated in a single place does not seem like the brightest security solution, and in recent years we have come across various vulnerabilities in SIM cards. But this is yet another demonstration that the authorities no longer have any limits and that companies continue to make absurd security mistakes. There is no point in encrypting heaven and earth if someone is foolish enough to send the key over an open email...

Source: