@Bruce Schneier

Ross Anderson had a nice idea but what’s worrying is the use of “Overlay” SIM cards. Overlay SIM are simply a sticker containing a SIM chip and you paste the SIM sticker on top of a cellphone’s GSM SIM card and this has gotten GSMA very worried.

In fact, GSMA, in an effort to retain their powers, had wrote a letter to all Service Providers to take Overlay SIMs as possible problems to the GSM network.

To put it bluntly, the Powers That Be hates changes and prefers the old ways to retain their market control.

I see an avenue for camera phones with a modification to Ross Anderson’s method to use Overlay SIMs combined with cameras on phones to create a lightweight distributed payment with more security by exchanging asymmetric keypairs (i.e. Currve25519 or ECC P-256) instead of shared keys. Although Ross Anderson was correct that SIM chips are tamper resistant, the fact is that they still can be decapped and gotten hold of the shared keys. If keypairs are used, decapping a single Overlay SIM is useless as everyone would theoretically have a different keypair and this is where you use the camera of the phone comes in to do photo-based QR code verification and transmission of parties’ public keys just like how Signal and other security apps use QR codes to exchange public keys with camera phones.

The main thing is snapping the spine of GSMA controlled authentication and payment because GSMA will not sit idly to allow DigiTally the rampant adoption as GSMA and their Service Providers that makes profits over telco network services would see a drop in revenue since DigiTally does not provide payment over SMS and GSMA’s warning to telcos about the “dangers” of Overlay SIM.


“In fact, GSMA, in an effort to retain their powers, had wrote a letter to all Service Providers to take Overlay SIMs as possible problems to the GSM network.”

On the other hand, there are equally big powers that are very, very keen on expand mobile payments into the developing world. Access to banks, savings, and credit are one of the main obstacles of economic development in large parts of the world.

I expect the parties to come to some agreement to allow such a service in one way or another.

The reason GSMA wrote the letter is due to the fact that they have their own payment and financial APi over GSM network (linked below). All the GSMA APIs are behind NDAs, paywalls, contracts and so on.

Noting that major telcos in Africa have the M Pesa mobile payment initiatives and DigiTally seems to outperform M Pesa (froim the reports), what are the chances that the telcos who have their own lousier implementation would back down and admit that DigiTally is the better version and support it ? There is a chance the huge telcos may back down and adopt DigiTally or revamp their M Pesa to use DigiTally schemes but I guess their huge corporate egos may not allow it to happen ?

These are all my guesses though.


@ Wm,

In Africa, can it handle elephant’s tusk, crocodile teeth, and leopard skins?

Man, that is some serious bling you want to bring to that thing… 😉

If, by “economic development” you mean capturing the African financial system for the Blood Sucking Parasites, then I agree.
. .. . .. — ….

