Are you sure there is such a thing as a root key? Root keys apply to X509 and certificate signing, which isn't applicable here. They're likely just to be generating keys randomly (in the technical sense of the word).
Looks like I misunderstood how the leak happened. I was thinking they infiltrated Gemalto's infrastructure and stole the signing key. But it looks like the keys (lots of them - one per SIM) were stolen while they were in transit, because of weak/no transmission security.
Since I have no way of knowing if my personal SIM key was stolen, I'll have to wait until AT&T works their way through their existing stock of SIMs and then request a new one. And hopefully get one that wasn't exposed.
Comments
I wonder if they're going to reissue the root key. And if they do, how can I, as an AT&T Wireless customer, know that my new SIM is using it?
Are you sure there is such a thing as a root key? Root keys apply to X509 and certificate signing, which isn't applicable here. They're likely just to be generating keys randomly (in the technical sense of the word).
Looks like I misunderstood how the leak happened. I was thinking they infiltrated Gemalto's infrastructure and stole the signing key. But it looks like the keys (lots of them - one per SIM) were stolen while they were in transit, because of weak/no transmission security.
Since I have no way of knowing if my personal SIM key was stolen, I'll have to wait until AT&T works their way through their existing stock of SIMs and then request a new one. And hopefully get one that wasn't exposed.