Rooting SIM cards
srlabs.de
srlabs.de
First, in a proper network the mobile device and the network mutually authenticate themselves. So the cell can't be faked. Then it's very easy for the network to filter such management SMS and only allow them from their trusted server. It's a very basic security precaution. If done, you don't depend on the SIM crypto scheme for secure SMS, but here too using DES is a joke and 3DES / AES have been available for ages.
So I guess it's another sensationalistic report made to draw readers for most.
As for intelligence services, they already have access for domestic operators. This could only be for foreign and loosy operators maybe.
There's not much point in the intelligence services going after these keys, if they can just put a box in the operator's data center and capture unencrypted traffic
However, I would be very surprised if a phone bought in the last 5 years was susceptible to this attack. I used to work for one of the leading providers of SIM chips and almost all of our product was using 3DES or AES, and that was several years ago.
SIM vendor didn't want to install crypto keys for free, network operator didn't understand the importance...
1. Use a USB SIM card reader to see the contents of the standard files on your SIM to see if encryption is enabled.
2. Use a SIM-OTA system to send a command and see if it works. For example, overwrite your Service Provider Name (SPN) file with "Foobar", reboot your phone, and see if you now see this name instead of "AT&T" (or whatever).
3. Build your own SIM OTA system and do the above. This is easy. You just need a way to send SMS with the OTA bit set: e.g. a USB GSM modem on a network that allows it or an internet SMS gateway that allows it.
GSM 11.11 spec tells you what files are on the standard SIM card (including crypto settings): http://www.etsi.org/deliver/etsi_ts/101200_101299/101267/08....
GSM 03.48 spec tells you how to encode SMS-OTA messages: http://www.etsi.org/deliver/etsi_ts/101100_101199/101181/08....
I built a commercial SIM-OTA platform about 6-7 years ago that's sold by a big OEM. This was interesting: SIM card vendors really don't like the idea of network operators being able to independently do stuff with the SIMs they buy.