News / Science & Technology

UN Warns on Mobile Cybersecurity Bugs to Prevent Attacks

A woman holds up a SIM card, which she won in a June lottery, in Rangoon, Burma, June 24, 2013. A woman holds up a SIM card, which she won in a June lottery, in Rangoon, Burma, June 24, 2013.
A woman holds up a SIM card, which she won in a June lottery, in Rangoon, Burma, June 24, 2013.
A woman holds up a SIM card, which she won in a June lottery, in Rangoon, Burma, June 24, 2013.
A United Nations group that advises nations on cybersecurity plans to send out an alert about significant vulnerabilities in mobile phone technology that could potentially enable hackers to remotely attack at least half a billion phones.

The bug, discovered by German firm, allows hackers to remotely gain control of and also clone certain mobile SIM cards.

Hackers could use compromised SIMs to commit financial crimes or engage in electronic espionage, according to Berlin's Security Research Labs, which will describe the vulnerabilities at the Black Hat hacking conference that opens in Las Vegas on July 31.

The U.N.'s Geneva-based International Telecommunications Union, which has reviewed the research, described it as "hugely significant."

"These findings show us where we could be heading in terms of cybersecurity risks," ITU Secretary General Hamadoun Touré told Reuters.

He said the agency would notify telecommunications regulators and other government agencies in nearly 200 countries about the potential threat and also reach out to hundreds of mobile companies, academics and other industry experts.

A spokeswoman for the GSMA, which represents nearly 800 mobile operators worldwide, said it also reviewed the research.

"We have been able to consider the implications and provide guidance to those network operators and SIM vendors that may be impacted," said GSMA spokeswoman Claire Cranton.

Nicole Smith, a spokeswoman for Gemalto NV, the world's biggest maker of SIM cards, said her company supported GSMA's response.

"Our policy is to refrain from commenting on details relating to our customers' operations," she said.

Becoming the SIM

Cracking SIM cards has long been the Holy Grail of hackers because the tiny devices are located in phones and allow operators to identify and authenticate subscribers as they use networks.

Karsten Nohl, the chief scientist who led the research team and will reveal the details at Black Hat, said the hacking only works on SIMs that use an old encryption technology known as DES. The technology is still used on at least one out of eight SIMs, or a minimum of 500 million phones, according to Nohl.

The ITU estimates some 6 billion mobile phones are in use worldwide. It plans to work with the industry to identify how to protect vulnerable devices from attack, Touré said.

Once a hacker copies a SIM, it can be used to make calls and send text messages impersonating the owner of the phone, said Nohl, who has a doctorate in computer engineering from the University of Virginia.

"We become the SIM card. We can do anything the normal phone users can do," Nohl said in a phone interview. "If you have a MasterCard number or PayPal data on the phone, we get that too."

IPhone, Android, BlackBerry

The mobile industry has spent several decades defining common identification and security standards for SIMs to protect data for mobile payment systems and credit card numbers. SIMs are also capable of running apps.

Nohl said Security Research Labs found mobile operators in many countries whose phones were vulnerable, but declined to identify them. He said mobile phone users in Africa could be among the most vulnerable because banking is widely done via mobile payment systems with credentials stored on SIMs.

All types of phones are vulnerable, including iPhones from Apple Inc, phones that run Google Inc's Android software and BlackBerry Ltd smartphones, he said.

BlackBerry's director of security response and threat analysis, Adrian Stone, said in a statement that his company proposed new SIM card standards last year to protect against the types of attacks described by Nohl, which the GSMA has adopted and advised members to implement.

Apple and Google declined comment.

CTIA, a U.S. mobile industry trade group based in Washington, D.C., said the new research likely posed no immediate threat.

"We understand the vulnerability and are working on it," said CTIA Vice President John Marinho. "This is not what hackers are focused on. This does not seem to be something they are exploiting."

You May Like

Video Egyptian Journalists Call for Press Freedom

Despite release of al-Jazeera journalists and others, Egyptian Journalist Syndicate says some remain imprisoned More

Turkey Survey Indicates Traditional Distrusts, Shift to the West

Comprehensive public opinion survey also found a large majority of those interviewed distrust all countries other than country’s neighbor, Azerbaijan More

Pakistan Court Upholds Death Sentence in Blasphemy Killing

Highest court upholds sentence of Mumtaz Qadri convicted of 2011 killing a provincial governor for criticizing country’s controversial blasphemy law More

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Making a Minti
October 07, 2015 4:17 AM
While apples, corn, and cranberries top the list of fall produce in the US, it’s also the time to harvest gum, candy, and toothpaste—or at least the oil that makes them minty fresh. Erika Celeste reports from South Bend, Indiana on the mint harvest.

Video Making a Mint

While apples, corn, and cranberries top the list of fall produce in the US, it’s also the time to harvest gum, candy, and toothpaste—or at least the oil that makes them minty fresh. Erika Celeste reports from South Bend, Indiana on the mint harvest.

Video Activists Decry Lagos Slum Demolition

Acting on a court order, authorities in Nigeria demolished a slum last month in the commercial capital, Lagos. But human rights activists say the order was illegal, and the community was razed to make way for a government housing project. Chris Stein has more from Lagos.

Video Self-Driving Cars Getting Closer

We are at the dawn of the robotic car age and should start getting used to seeing self-driving cars, at least on highways. Car and truck manufacturers are now running a tight race to see who will be the first to hit the street, while some taxicab companies are already planning to upgrade their fleets. VOA’s George Putic has more.

Video TPP Agreed, But Faces Stiff Opposition

President Barack Obama promoted the Trans-Pacific Partnership on Tuesday, one day after 12 Pacific Rim nations reached the free trade deal in Atlanta. The controversial pact that would involve about 40 percent of global trade still needs approval by lawmakers in respective countries. Zlatica Hoke reports Obama is facing strong opposition to the deal, including from members of his own party.

Video Clinton Seeks to Boost Image Before Upcoming Debate

The five announced Democratic party presidential contenders meet in their first debate next Tuesday in Las Vegas, Nevada. Former secretary of state Hillary Clinton continues to lead the Democratic field, but she is getting a stronger-than-expected challenge from Vermont Senator Bernie Sanders. VOA National correspondent Jim Malone has more from Washington.

Video Ukranian Artist Portrays Putin in an Unusual Way

As Russian President Vladimir Putin was addressing the United Nations in New York last month, he was also being featured in an art exhibition in Washington. It’s not a flattering exhibit. It’s done by a Ukrainian artist in a unique medium. And its creator says it’s not only a work of art - it’s a political statement. VOA’s Tetiana Kharchenko has more.

Video South Carolina Reels Under Worst-ever Flooding

South Carolina is reeling from the worst flooding in recorded history that forced residents from their homes and left thousands without drinking water and electricity. Parts of the state, including the capital, Columbia, received about 60 centimeters of rain in just a couple of days. Authorities warn that the end of rain does not mean the end of danger, as it will take days for the water to recede. Zlatica Hoke reports.

Video Russia’s Syria Involvement Raising Concerns in Europe

European nations are joining the United States in demanding that Russia stop targeting opposition groups other than the Islamic State militants as Russian warplanes continue to conduct raids in Syria. The demand came in a statement from Britain, France, Germany, Qatar, Saudi Arabia, Turkey and the United States Friday. VOA Europe correspondent Luis Ramirez reports.

Video Nano-tech Filter Cleans Dirty Water

Access to clean water is a problem for hundreds of millions of people around the world. Now, a scientist and chemical engineer in Tanzania (in East Africa) is working to change that by creating an innovative water filter that makes dirty water safe. VOA’s Deborah Block has the story.

Video Demand Rising for Organic Produce in Cambodia

In Cambodia, where rice has long been the main cash crop, farmers are being encouraged to turn to vegetables to satisfy the growing demand for locally produced organic farm products. Daniel de Carteret has more from Phnom Penh.

Video Botanists Grow Furniture, with Pruning Shears

For something a bit out of the ordinary to furnish your home, why not consider wooden chairs, crafted by nature, with a little help from some British botanists with an eye for design. VOA’s Jessica Berman reports.

VOA Blogs