A UN group that advises nations on cybersecurity plans to send out an alert about significant vulnerabilities in mobile phone technology that could potentially enable hackers to remotely attack at least half a billion cellphones.
The bug, discovered by German firm, allows hackers to remotely gain control of and also clone certain mobile SIM cards.
Hackers could use compromised SIMs to commit financial crimes or engage in electronic espionage, according to Berlin’s Security Research Labs, which will describe the vulnerabilities at the Black Hat hacking conference that opens in Las Vegas on July 31.
The UN’s Geneva-based International Telecommunications Union (ITU), which has reviewed the research, described it as “hugely significant.”
“These findings show us where we could be heading in terms of cybersecurity risks,” ITU Secretary-General Hamadoun Toure said.
He said the agency would notify telecommunications regulators and other government agencies in nearly 200 countries about the potential threat and also reach out to hundreds of mobile companies, academics and other industry experts.
A spokeswoman for the GSM Association (GSMA), which represents nearly 800 mobile operators worldwide, said it also reviewed the research.
“We have been able to consider the implications and provide guidance to those network operators and SIM vendors that may be impacted,” GSMA spokeswoman Claire Cranton said.
Nicole Smith, a spokeswoman for Gemalto NV, the world’s biggest maker of SIM cards, said her firm supported GSMA’s response.
“Our policy is to refrain from commenting on details relating to our customers’ operations,” she said.
Cracking SIM cards has long been the Holy Grail of hackers because the tiny devices located in cellphones allow operators to identify and authenticate subscribers as they use networks.
Karsten Nohl, the chief scientist who led the research team and will reveal the details at Black Hat, said the hacking only works on SIMs that use an old encryption technology known as Data Encryption Standard.
Nohl said he conservatively estimates that at least 500 million phones are vulnerable to the attacks he will discuss at Black Hat. He added that the number could grow if other researchers start looking into the issue and find other ways to exploit the same class of vulnerabilities.
The ITU estimates that about 6 billion mobile phones are in use worldwide. It plans to work with the industry to identify how to protect vulnerable devices from attack, Toure said.
Once a hacker copies a SIM, it can be used to make calls and send text messages impersonating the owner of the cellphone, said Nohl, who has a doctorate in computer engineering from the University of Virginia.
“We become the SIM card. We can do anything the normal phone users can do,” Nohl said in a telephone interview.
“If you have a MasterCard number or PayPal data on the phone, we get that too,” if it is stored on the SIM, he added.
The newly identified attack method only grants access to data stored on the SIM, which means payment applications that store their secrets outside of the SIM card are not vulnerable to this particular hacking approach.
TRAGEDY STRIKES TAIPEI: The suspect died after falling off a building after he threw smoke grenades into Taipei Main Station and went on a killing spree in Zhongshan A 27-year-old suspect allegedly threw smoke grenades in Taipei Main Station and then proceeded to Zhongshan MRT Station in a random killing spree that resulted in the death of the suspect and two other civilians, and seven injured, including one in critical condition, as of press time last night. The suspect, identified as a man surnamed Chang Wen (張文), allegedly began the attack at Taipei Main Station, the Taipei Fire Department said, adding that it received a report at 5:24pm that smoke grenades had been thrown in the station. One man in his 50s was rushed to hospital after a cardiac arrest
A car bomb killed a senior Russian general in southern Moscow yesterday morning, the latest high-profile army figure to be blown up in a blast that came just hours after Russian and Ukrainian delegates held separate talks in Miami on a plan to end the war. Kyiv has not commented on the incident, but Russian investigators said they were probing whether the blast was “linked” to “Ukrainian special forces.” The attack was similar to other assassinations of generals and pro-war figures that have either been claimed, or are widely believed to have been orchestrated, by Ukraine. Russian Lieutenant General Fanil Sarvarov, 56, head
SAFETY FIRST: Double the number of police were deployed at the Taipei Marathon, while other cities released plans to bolster public event safety Authorities across Taiwan have stepped up security measures ahead of Christmas and New Year events, following a knife and smoke bomb attack in Taipei on Friday that left four people dead and 11 injured. In a bid to prevent potential copycat incidents, police deployments have been expanded for large gatherings, transport hubs, and other crowded public spaces, according to official statements from police and city authorities. Taipei Mayor Chiang Wan-an (蔣萬安) said the city has “comprehensively raised security readiness” in crowded areas, increased police deployments with armed officers, and intensified patrols during weekends and nighttime hours. For large-scale events, security checkpoints and explosives
PUBLIC SAFETY: The premier said that security would be tightened in transport hubs, while President Lai commended the public for their bravery The government is to deploy more police, including rapid response units, in crowded public areas to ensure a swift response to any threats, President William Lai (賴清德) said yesterday after a knife attack killed three people and injured 11 in Taipei the previous day. Lai made the remarks following a briefing by the National Police Agency on the progress of the investigation, saying that the attack underscored the importance of cooperation in public security between the central and local governments. The attack unfolded in the early evening on Friday around Taipei Main Station’s M7 exit and later near the Taipei MRT’s Zhongshan