Skip to content

Comment on Gemalto's findings of its investigations into the alleged hacking of SIM cardsparent

Comments

Are you sure there is such a thing as a root key? Root keys apply to X509 and certificate signing, which isn't applicable here. They're likely just to be generating keys randomly (in the technical sense of the word).

Looks like I misunderstood how the leak happened. I was thinking they infiltrated Gemalto's infrastructure and stole the signing key. But it looks like the keys (lots of them - one per SIM) were stolen while they were in transit, because of weak/no transmission security.

Since I have no way of knowing if my personal SIM key was stolen, I'll have to wait until AT&T works their way through their existing stock of SIMs and then request a new one. And hopefully get one that wasn't exposed.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.