An IIPM Initiative
Thursday, October 8, 2026
 
 

Is China tuning into your cellphone?

 

Anil Pandey investigates how import of chinese SIMs can compromise national security and he finds the DoT not ignorant but wilfully negligent
WITH INPUTS FROM MAYANK SINGH | Issue Dated: May 30, 2010
Tags : |
 
Is China tuning into your cellphone? The technical terms used by Rajesh Kumar (name changed) were coming like bouncers. He read my mind and brought out two mobile handsets. He handed one to me and asked me to call my wife. After I finished talking to her, Rajesh asked me to call her once more. But this time, the voice on the other side was not that of my wife. It was Rajesh. Rajesh smiled and said, “Why don’t you send her a message?” After I sent it, Rajesh brought his handset forward and showed me. I was dumbfounded. How could the message land in his phone? Rajesh soon clarified, “We have put a spyware on the mobile. Not only we can eavesdrop on your conversations (by diverting your calls using SIM) but we can read your messages and send messages from your number. We can trace your location and we can block your phone.” The risk of spyware always exists in SIM (operating system or application) if the SIM is not produced in a secure environment under control. SIM is the most critical equipment in mobile telephony. It is not only instrumental in authenticating against the mobile network but also the unique identity of the subscriber. Rajesh is a technical expert of communication instruments.

I wondered if in my place, this spyware would be in the phone of a scientist at Indian Space Research Organisation or a senior Army officer or an officer of the ministry of finance or ministry of home? All important information could reach the enemy. That my thoughts were not fanciful was corroborated by the apprehensions expressed by the ministry of home (MHA) and various Intelligence agencies. The MHA has already communicated to the ministry concerned about the possibility of Chinese companies embedding spywares into instruments and software being sold to the Indian cellular operators which might be used to acquire important information. Even then, lakhs of SIM cards are reaching India every week. The Smart card Forum of India reveals that between January and March, 2010, 4.5 crore cards have reached India. Is China tuning into your cellphone? The Department of Telecommunication (DoT) of the ministry of communication and IT issued a circular to cellular operators on December 3, 2009. According to this circular, any operator buying any software or equipment will have to get a security clearance. It was on this basis that the government did not permit several cellular operators to use instruments of Huawei and other such Chinese companies. The circular says, “The Licensee shall apply to the Licensor for security clearance, along with the details of the equipment as well as detail of equipment suppliers and manufacturers including original equipment manufacturers (OEM), before placement of the final purchase order of procurement/ up gradation of equipment/ software for provisioning of telecommunications service under the licence.” It is clear that no cellular operator can buy any equipment without the government’s permission. But before we reveal that how officials at the ministry have their own interpretation of the circular, thereby jeopardizing the security of the nation, you should know that SIM cards made in China are security hazards. In the past, terrorists had used Chinese mobile handsets without IMEI numbers, prompting the government to ban those.

Actually, it is the SIM card which connects a customer with the service provider network. To enable this, a special programme is fed into the SIM along with some data. In technical language, this is called the personalisation of the SIM card. Every SIM card has a secure unique authentication key which is very important and is used for authentication against the mobile network. “If this key is known, it can even be cloned easily. It does not require any expert, it can be done by any student who is a plain Bachelor of electronics engineering,” reveals Rajesh.

Once the SIM card is cloned, one can easily trace your phone and location. Your conversations can be diverted, messages can be read and more than that it can even be used to call and send messages to others. This key is known to just two people, to your cellular operator and the other is the company which has personalised your SIM card. Now, 30 per cent of SIM cards used in India are personalised by Chinese companies in China. Is China tuning into your cellphone? Several Chinese and European companies sell SIM cards in India. Other than the Chinese companies, almost every other company has set up its personalisation centre in India. The fact that Chinese companies have not set their personalisation centre in India generates more suspicion. The two main Chinese companies, Watchdata and Eastcompeace, control more than 30 per cent of the Indian SIM card market. Data from Electronic Computer Software Promotion Council, Union ministry of commerce, reveal that during the last year (Between April 2008 and February 2009) around 11,68,17,092 SIM cards have come from China. These companies are selling SIM cards to Indian cellular companies since last three years. As per an estimate, more than 30 crore chinese SIM cards have reached the Indian market. The country head of Eastcompeace, Rajnish Giri told TSI, “We are the largest SIM card and Smart Card manufacturers of Asia. Our personalisation centre is completely safe and is SAS certified.” The SIM secure keys are kept with the Chinese bosses.

When TSI asked why Watchdata does not have its personalisation centre in India, Vijay Parthasarathy, country head, Watchdata Technologies (India), said, “Our personalisation centres are in Singapore and Japan. The whole issue of setting up a personalisation centre in India is ridiculous. I don’t think your question has an answer”.

It is an important question that how safe is our SIM card data in the hands of a country which has been accused of hacking and stealing data of other countries. India and China have a nervy relationship. Apart from the Tibet controversy and Chinese help to Pakistan, India has boundary disputes with China. Stealing important information of countries is part of the Chinese foreign policy. An advisor with the Institute for Defence Studies and Analysis, Brigadier (retd) Rumel Dahiya says, “Around 30,000 people are supposed to be involved in the task of hacking Cyber and communication networks. Also, a large number of people in China are doing it out of curiosity and nationalism.” There is an unofficial ban in America and European countries on import of mobile phone and communication service equipments from China. If china is viewed with suspicion by not just India but the whole world, there is solid reason behind it. Suvrokamal Dutt, an expert on international affairs, says, “Inquiries into hacking of computers of important organisations around the world has revealed that since the 80s, the source of nearly every hacking was in China. Right from Microsoft and NASA to White House and the British Parliament, all have had their servers and computers accessed by Chinese hackers. As Chinese companies are controlled by the government, they come under suspicion. Union home minister P. Chidambaram’s action is totally correct.” Is China tuning into your cellphone? The most recent attack on an Indian institution, known to the media, was on December 15, 2009, while India was signing defence agreements with some American companies. The then National Security Advisor K Narayan had admitted to the cyber attack by Chinese hackers. He had said, “This was not the first attempt by the Chinese to hack into the systems of important government offices.” His own office was targeted and the attack came in the form of an e-mail with a PDF attachment containing a ‘Trojan’ which allowed a hacker to access a computer remotely and download or delete files.

Keeping these issues in mind, the MHA asked the ministry of communication and IT to ban Chinese equipment and software pertaining to highly sensitive mobile services. China expert and professor at Jawaharlal Nehru University Srikanth Kondapalli says, “They are pushing for their companies but there is a difference between Indian and Chinese companies. Chinese companies have to have a member of the party committee in one top position where as in India no company generally has a member of a political party who will report to the Central committee or politburo of the party. Also, any Chinese citizen, who goes out of the country, first serves the country and then only gets his passport. So we can say there is some connection between the Chinese companies and the Communist Party in power.”

After the MHA raised the red flag, the government became active about mobile telephony equipment but it has not paid any attention to SIM cards. Its complete focus was on other equipment and software used in networking of the mobile services. It is to be noted here that the state-run BSNL considers SIM to be compliant with the same quality standard which is applicable to all other mobile equipments. Experts say that spyware planted in SIM cards can also be used to jam networks, causing chaos in the country. Senior Project manager of HCL technologies Sanjay Jauhari says, “Crores of SIM cards can be blocked by inserting spyware into them. Or, it can be used to listen in to conversations.” We can’t neglect the possibility of China already tracking the phones of important people? Former special director of Intelligence Bureau D.C.Nath says, “The problems of SIM cards are two-fold. They can infiltrate the communications of people who are directly or indirectly related to security and Intelligence establishments. The much bigger issue is that of economic espionage. The country’s economy can be crippled. The government should recall all foreign-origin SIM cards and cleanse the market of such SIM cards. Even the corporate world should be sensitive about it.” Is China tuning into your cellphone? It is not that the Indian Parliament is oblivious of the fact. Even parliamentarians are worried about this grave danger. BJP MP and member of the parliamentary committee on IT and communications Rajendra Aggarwal asks for a ban on SIM cards coming from China. He also seeks an audit check of the SIM cards which have already reached the country. He says, “The government should take immediate steps in this regard. The SIM cards which have come from China should be put to security audit. I am not against trade with China but the trade which puts our security in danger should be stopped.” The same apprehension is expressed by Prabhat Jha, MP and also a member of the same committee. He says, “Import of SIM cards from China is inviting danger.”

If the Chinese hackers hack the secure unique authentication key of the Indian SIM cards which are in china and pass it on to terrorists planning to spread violence in India, it can lead to a disaster. In countries like US, instances have been found where terrorists have cloned SIM cards and used them to not only talk to their handlers but also to trigger bomb blasts. The terrorists which attacked Indian Parliament also used a cloned phone. Now, when the government is strict about the verification of identity before issuing mobile connections, the possibility of using cloned phone increases. If the secure unique authentication key of a SIM is known, then any mobile number of the Indian network can be put on the Pakistani mobile network. A defence officer says, “We found a mobile with a terrorist and were stunned to find that the SIM of Indian network was working on Pakistan mobile network. It becomes very difficult for Intelligence agencies to trace such mobile numbers.”

Even then, DoT keeps its eyes closed. The way in which interests of Chinese companies are being safeguarded hints at a big scandal. TSI has in its possession the report of the committee under the chairmanship of the member technical of the DoT which was submitted on April 1, 2010. The committee was set up by the department of telecommunication to give security clearance to equipment and software bought by the cellular companies. This report has a few parameters for obtaining security clearance and the list of 15 equipment and software for which cellular operators will require the government’s permission. But the circular issued on December 3, 2009, asked the operators to take security clearance from the department if they bought any software or equipment. According to this circular, even SIM cards require security clearance. The sources informed TSI that while the list of the equipment and software which needed security clearance was being finalised, it had even SIM cards on it. But it was removed at the last moment. Why was this done? Was it the carelessness of the department or a planned omission? It will get clear only after an inquiry. Is China tuning into your cellphone? It’s not that India can’t manufacture SIM cards as per requirements. The secretary of Smart card Forum of India, Jagdish Raj Purohit, says, “The country has an annual demand for 60 crore SIM cards. Indian companies are capable of fulfilling this demand. Many companies are even exporting their SIM cards.” Yes, Chinese SIM cards are dirt cheap. R. Srinivasan, a senor defence expert, “Chinese equipment, especially SIM cards, supplied at cheap prices is a strategy to break into the internal security ring of the country at minimum cost. In my opinion, these SIMS are embedded with kinds of malwares, spywares, Trojan, hidden software etc.”

The eight parameters which were finalised by the committee included Data Confidentiality, Communication Security, Data Integrity, Privacy. If we pay attention to these four parameters, then SIM cards require security clearance. The interesting point is that when BSNL issued a tender on June 26, 2008, for the purchase of SIM cards, one of the conditions was that only companies having personalisation centres in India need apply. It is evident that even two years back, the government was aware of the dangers from Chinese SIM cards to internal security. When a few companies requested permission to buy Chinese SIM cards after the December 3, 2009, circular, they were denied security clearance. TSI has the copy of the letter no 10-8/2009/AS.III/Unitech sent by the department of telecommunication on February 18, 2010, to Unitech Wireless Private Limited which did not allow it to buy SIM cards personalised in China. Why is this double standard? We tried to speak to several DoT officers including DDG (security) Ram Narayan. But no officer spoke to us on the phone. Apart from this, we even asked for official information from corporate communication officers of Bharti Airtel, Reliance and Idea which buy SIM cards from Watchdata and Eastcompeace. But no one cared to respond to our queries.

The minister of state for communication and IT, Gurudas Kamat, while replying to a question, said in Parliament that “In the interest of the national security, the Government has directed BSNL in May, 2009, that resources should not be procured from Chinese vendors for deployment in the sensitive regions of Assam, Tripura, Sikkim, Nagaland, Arunachal Pradesh, Mizoram, Meghalaya, West Bengal, Gujarat, Rajasthan, Punjab, Jammu & Kashmir, Himachal Pradesh, Uttarakhand and Maharashtra.” When it is a matter of national security, then why is the direction given to just BSNL and not to the other private cellular companies which have more subscribers than their state-owned counterpart.

This problem goes bigger as India has no legal treaty with China. India has neither extradition nor any cyber treaty with China. In this situation, if anyone sitting in China commits a crime against India, he will never be brought to book. Further, our cyber laws are pretty weak. Well-known cyber law expert and Supreme Court lawyer Pavan Duggal says, “It is not just an issue of SIM cards as our cyber laws are silent on any type of data protection and privacy. Spyware is not even mentioned in Cyber Laws and IT Act-2000.”
Rate this article:
Bad Good    
Current Rating 2.3
Previous Story

Previous Story

 
 
Post CommentsPost Comments




Issue Dated: Feb 5, 2017