That said, I wonder if Gemalto really had any other option than to say its keys weren't stolen. What might be the cost of replacing all affected SIM cards?
That said, I wonder if Gemalto really had any other option than to say its keys weren't stolen. What might be the cost of replacing all affected SIM cards?
No kidding, they've been bought, under more-than-suspicious circumstances, by [inQtel](https://www.iqt.org/) and [Texas Partner Group](https://tpg.com/), which officially are CIA proxies.
I don't think they had to resort to tailored access to perform their heist, I'd rather bet that they still have enough former colleagues inside Gemalto to get whatever they want by simply entering the correct password on the correct keyboard.
But that just means they don't need to officially own it anymore: Alex Mandl, Gemalto's current chairman, is among others a former board member of intQtel, which presents its mission on its web page as:
We identify, adapt, and deliver innovative technology solutions to support the missions of the Central Intelligence Agency and broader U.S. Intelligence Community.
So the news that nobody wants spread is: nobody cares about how much the NSA stole from Gemalto: whatever Gemalto has and NSA wants, the NSA is most likely to get by simply asking NSA affiliates installed at every interesting node in Gemalto's hierarchy.Incidentally, it's rather easy to find sources about this in French (Gemplus used to be a French company, before the fusion with Axalto which was forced by intQtel and TPG), but surprisingly hard to find in English.
This seems at odds with the leaked documents though. Why going to the trouble of compromising a company you've already social-engineered to the max?
The doctrine has been called "penetrating targets' defences" or PTD: that's also the name of their budget/office/department/contracting scheme which is broadly equivalent to NSA's Special Source Operations/Targeted Access Operations, only more aggressive and multi-pronged. It incorporates HUMINT as well as both R&D and operational deployment of advanced technical attacks.
You may see references in the Snowden documents of this (check the bottom), or in their tenders to BAE Detica for their modular botnet software, or elsewhere. Although much of the really juicy or operational stuff is STRAP3 and thus kept off the TS//STRAP2 wiki.gchq (which the NSA have shared access to via their ic.gov portal, and which Snowden dumped - and which, yes, runs a tweaked MediaWiki on PHP).
secondly soon news will be out (give it a couple more days ;-)) which is currently not on any news sites radar - on IMSI catchers (aka fake BTS) which will put the whole story into a new context.
The statement made is pretty much a text book declaration of damage control. Personally I'm not buying their claims, but only they can proof it happened and they never will as the market will loose complete faith in buying from them.
If you're based in the Netherlands, no such justification is necessary.
But it seems like that isn't really needed because the stolen keys were mostly replaced already anyway. Anyone who suspects they might be a person of interest can always just request a new one from their carrier.
I doubt SIMs are manufactured just-in-time for each individual customer; more likely, carriers order batches of hundreds/thousands/millions SIMs. Without a recall program, it will take years before you can be confident that your freshly-acquired SIM is not compromised.
I'd say it's safe to assume that from now on, any cellphone communication can be trivially intercepted by NSA/GCHQ. The most paranoid already assumed that, but now we have confirmation.