{"id":393,"date":"2013-07-22T20:54:49","date_gmt":"2013-07-22T20:54:49","guid":{"rendered":"http:\/\/domonkos.tomcsanyi.net\/?p=393"},"modified":"2013-07-22T20:58:59","modified_gmt":"2013-07-22T20:58:59","slug":"sim-cards-are-broken","status":"publish","type":"post","link":"https:\/\/domonkos.tomcsanyi.net\/?p=393","title":{"rendered":"SIM cards are broken"},"content":{"rendered":"<p>Today&#8217;s news is that Karsten Nohl did it again. This German security researcher is slowly, but constantly rising in my eyes to become one of those few heroic people that I think are changing and shaping our world to make it better. I simply love his work and his results, they are just plainly fenomenal.<\/p>\n<p>Now he did it again, he cracked yet another aspect of GSM-3G which hasn&#8217;t really been looked at. He was able to remotely crack the encryption key of a SIM card and then get root access on it, meaning that he is able to modify the applications running the SIM card and also install new applications for example a malware on it.<\/p>\n<p>This actually leads to sending SMS in the name of the victim, or actually cloning the whole card (some cards&#8217; Java Sandboxes could be bypassed leading to a full memory access of the SIM card).<\/p>\n<p>With the rise of new NFC payment systems which use SIM card Java Apps to perform authorization of payments this kind of access and behavior is certainly frightening.<\/p>\n<p>Read the <a href=\"http:\/\/www.forbes.com\/sites\/parmyolson\/2013\/07\/21\/sim-cards-have-finally-been-hacked-and-the-flaw-could-affect-millions-of-phones\/\">whole story at Forbes<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today&#8217;s news is that Karsten Nohl did it again. This German security researcher is slowly, but constantly rising in my eyes to become one of those few heroic people that I think are changing and shaping our world to make it better. I simply love his work and his results, they are just plainly fenomenal. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false},"categories":[3],"tags":[],"_links":{"self":[{"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=\/wp\/v2\/posts\/393"}],"collection":[{"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=393"}],"version-history":[{"count":4,"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=\/wp\/v2\/posts\/393\/revisions"}],"predecessor-version":[{"id":397,"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=\/wp\/v2\/posts\/393\/revisions\/397"}],"wp:attachment":[{"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/domonkos.tomcsanyi.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}