Some phones can be pwned by sending two SMS messages to them


The term “responsible disclosure” jumped at me. Could it have something to do with this?:
“Mr. Nohl said he was not planning to disclose the identities of the operators whose SIM cards had performed poorly in his study…”

I keep seeing ‘SMS’ and thinking of the Sega Master System, for some reason.

Actually a pretty gruesome vulnerability: The attack is on the SIM card’s embedded processor, so it is handset agnostic, and the attack reveals the IMSI and Ki, allowing a clone SIM to be generated remotely…

Game over man, game over!

So now Reese and Finch won’t even have to get within bluetooth range to force-pair phones on Person of Interest.

