Everyone is griping about the keys (i.e. triplets and session keys derived from that).I think someone needs to be very specific about the security threat involved here and both players aren’t revealing much.IMHO, there are at least 3 areas where security threats can emerge:1) Normally EAP-SIM would be used to authenticate the client/phone vs. the telco server (Safaricom in this case).The valuable information in this case would be the SIM triplets (and derived session key). Hence, this baseline EAP-SIM needs to be protected (Safaricom knows how this is done).If it isn’t, then we already have a problem that’s not due to thin-siim.2) For the thin-sim, another EAP-SIM negotiation between the client/phone vs. the overlay sever (Equity in this case).The valuable information again would be the thin-SIM triplets (and derived session key). Hence this overlay EAP-SIM needs to be protected in a manner that Safaricom can’t even see it… this is totally in the domain of how Equity has designed their network and their provisioning. (e.g. by encrypted negotiation & tunnelling directly between the client/phone and the Equity server).3) For the handsets, they would have to make sure that the telco applications can’t snoop or inject traffic/data into each other’s walled garden - there are 2 walled gardens in this case. The walled garden includes the sim triplets (and derived session key) along with each telco network routes, policies, arp-cache and tcp/ip connections. There exists a possibility of threats due to backwards incompatibility (with phones that can’t fully manage these walled gardens). Perhaps this is what Safaricom is complaining about?On Jul 21, 2015, at 2:20 PM, Mwendwa Kivuva via Security <security@lists.my.co.ke> wrote:> @mwendwa,
>
> Its possible for the owner of the network of the thin sim to be privy to information that only the host network sim should be having. It all comes back to someone internal at Equitel having the proper technical skills and motivation to use the sameStephen,
Then we have a major problem right there. I would not like Safaricom to disown any responsibility on their part when my security is compromised because I used thin sim. Therefore any security conscious users would not dare jeopardize their transactions by using thin sim. The question then is, how many of us care about their transaction security?>>
_______________________________________________
>> On Tue, Jul 21, 2015 at 1:52 PM, Mwendwa Kivuva via skunkworks <skunkworks@lists.my.co.ke> wrote:
>>>
>>> Then the trending issue of the day. Equitel. Safaricom had taken Equity to court and sounded a big warning on the use of thin sim. http://www.businessdailyafrica.com/Corporate-News/Safaricom-sounds-warning-to-users-of-Equity-s-thin-SIM/-/539550/2462110/-/cqwoby/-/index.html
>>>
>>> London-based GSMA, the global association of telecoms operators using the GSM technology, wrote to the Kenyan authorities warning of the risks that use of the slim SIM cards pose to the integrity of the mobile telecommunications platforms.The GSMA said the overlay SIM (which is embedded between a normal SIM card and the device) has the potential of harvesting and revealing sensitive data passing the system.
>>>
>>> Of course we all know Safaricom failed miserably in stopping Equity from progressing with its plans.
>>>
>>> Now the thin sim is here, and Equitel has said it will encrypt all data to and from the thin sim. Can experts in this area assure us that the use of thin sims will not affect the integrity of M-Pesa transactions?
>>>
>>> Regards
>>>
>>>
>>> _______________________________________________
>>> skunkworks mailing list
>>> skunkworks@lists.my.co.ke
>>> ------------
>>> List info, subscribe/unsubscribe
>>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
>>> ------------
>>>
>>> Skunkworks Rules
>>> http://my.co.ke/phpbb/viewtopic.php?f=24&t=94
>>> ------------
>>> Other services @ http://my.co.ke
>>
>>
>>
>>
>> --
>>
>> Best Regards,
>> Stephen Munguti.
>>
>> +254720425104
>
>
>
>
> --
>
> Best Regards,
> Stephen Munguti.
>
> +254720425104
Security mailing list
Security@lists.my.co.ke
http://lists.my.co.ke/cgi-bin/mailman/listinfo/security