Last Thursday, Snowden leaks revealed that the NSA and GCHQ had hacked into the networks of the largest SIM card manufacturer, Gemalto. Immediately after the NSA and GCHQ hack was revealed, the Dutch company lost €470 million as its share price plummeted.
Gemalto appeared surprised by the revelation that intelligence agencies had breached its systems, stealing encryption keys for millions of SIM cards used to encrypt phone calls around the world. Gemalto supplies SIM cards to 450 networks worldwide.
However, the event had immediate "side effects" as the Dutch company on Friday saw its share price fall eight points at the opening of the stock exchange before recovering slightly to minus 2.69 (3.70%) at its close.
The company issued a statement in which it promised a full recovery from the hack:
"At Gemalto we are extremely vigilant about malicious hackers, and we have been detecting, recording and blocking many types of attacks over the years. At this time we cannot prove the hacking reported yesterday.".
"We will take this publication very seriously and will dedicate all resources necessary to fully investigate and understand the scope of this advanced technique."
Security observers praised the company for its prompt and honest response, and of course many people were outraged by the latest revelations about mass surveillance by GCHQ and NSA without warrants.
The World Wide Web Foundation has called for urgent measures to be taken to secure private calls and electronic communication in general.
Chief Anne Jellema said any security weaknesses or backdoors in a cryptographic system could also be exploited by cybercriminals and called for an investigation into GCHQ, along with “a full and honest disclosure as to why a private company based in an allied country was hacked.”
Other security experts have warned that other intelligence agencies may be using the same tricks. Andrew Conway, research analyst at Cloudmark, said:
"The ease with which the NSA and GCHQ were able to hack into all mobile communications is shocking. But there are many other sophisticated hackers working for governments. In particular, the Chinese group Axiom has shown remarkable skills in penetrating Western targets."
Ultimately a complete redesign of mobile comm security may be required, Conway said.
“In the short term, companies that require secure voice communications may want to consider deploying mobile devices with additional layers of encryption, such as the Blackphone or Cryptophone. In the long term, we need to do a better job of end-to-end encryption of all mobile and fixed communications, not relying on a single master encryption key.”
Source: secnews.gr
