As promised, Gemalto held a press conference today to respond to a report that they were hacked by U.K. and U.S. intelligence types and encryption codes that would let them spy on smartphone users were stolen. Now News.com has a pretty comprehensive report. But it can be summed up like this:
“The attacks against Gemalto only breached its office networks and could not have resulted in a massive theft of SIM encryption keys,” Gemalto said in a statement at a press conference held in response to a report in the Intercept alleging a massive theft by the US National Security Agency and UK Government Communications Headquarters. The report said millions of SIM card encryption keys had been stolen through the joint NSA and GCHQ operation.
Gemalto then lays out why this is the case. And they also let the world know that 2G networks would be the ones under threat. Both 3G and 4G networks are apparently safe. But the core message is this: There’s nothing to see here. Move along.
Though, they did let this cat out of the bag:
However, Gemalto said, it appears that other SIM card manufacturers were targeted, so privacy and security concerns can’t be dispelled. For example, the spy agency documents pointed to 300,000 keys stolen from a Somali carrier that isn’t a Gemalto customer. Indeed, that’s the case for four of the 12 carriers identified in the documents, Gemalto said.
Lovely. Clearly this story isn’t over and neither is the concern that this will generate.
UK Police Get Around iPhone Security In A Crafty Way
Posted in Commentary with tags Apple, UK on December 5, 2016 by itnerdAs it’s been reported for a while now, Apple is a company that favors user privacy over being able to co-operate with law enforcement. That creates an interesting situation. How does law enforcement get their hands on the data that’s inside an iPhone that is locked? UK cops have a crafty way of doing this according to the BBC:
Gabriel Yew had been under investigation for the suspected manufacture of fake cards that gangs were using across Europe to buy luxury goods. Detectives suspected that he was using an iPhone exclusively to communicate to other members of the network but knew if they arrested him, he could refuse to unlock it and they would never see incriminating evidence.
They considered whether they could legally force a suspect’s finger or thumb on to the device’s fingerprint reader to unlock it, but found they had no such power.
However, they concluded they could stage their own lawful “street robbery” – using a similar snatch technique to a thief – and in June a team set out to do precisely that.
Undercover surveillance officers trailed Yew and waited for him to unlock his phone to make a call – thereby disabling the encryption.
One officer then rushed in to seize the phone from Yew’s hand – just as would happen in a criminal mugging. As his colleagues restrained the suspect, the officer continually “swiped” through the phone’s screens to prevent it from locking before they had downloaded its data.
“The challenges of pin code access and encryption on some phones make it harder to access evidence in a timely fashion than ever before,” said Det Ch Insp Andrew Gould who led the operation.
“Officers had to seize Yew’s phone from him in the street. This evidence was crucial to the prosecution.”
Well, that’s crafty for sure. And it’s likely legal to boot. But I can see one way for the bad guys to protect themselves from this. All they have to do is keep a finger on the sleep button if they have an iPhone 6 or 7. If they do that, it’s just one finger twitch then back into their pocket in a locked and secured state. I’m also sure that some high tech means to avoid this situation will appear as well (if they haven’t already). So this may just be the start of an “arms race” between the bad guys who want to protect what’s on their phones, and law enforcement who wants access to that data.
1 Comment »