Live data from Hacker News

Nine Charged in Alleged SIM Swapping Ring

krebsonsecurity.com

11–20 of 41 posts

Re: Nine Charged in Alleged SIM Swapping Ring

#11
> a form of fraud in which scammers bribe or trick employees at mobile phone stores into seizing control of the target’s phone number and diverting all texts and phone calls to the attacker’s mobile device.

why bother to do that? in australia, you just need to know the person's DOB, address and his mobile account number to get full control of his/her mobile number.

Re: Nine Charged in Alleged SIM Swapping Ring

#12

This is the result when companies follow each other. We need to see more innovation in authentication and leadership in best practices. Hijacking of phone numbers is not new and devs need to stop shifting liability to phone carriers when authenticating users to every little thing. Phone carriers have no incentive to secure users data or make the user authentication process more stringent. This results in the consumer…

The phone carrier has no incentive which is why liability needs to be shifted to them.

The broader telecommunication industry has gotten a free ride long enough. They provide a blatantly insecure and mediocre service, profit from it and tell the world it's not their problem when it fails.

Re: Nine Charged in Alleged SIM Swapping Ring

#13
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

This is why I hate Apple’s new policy of requiring 2FA with a mobile number for new accounts.

Luckily I created my account before it was official policy, but I’m afraid their going to force it on me someday.

And if you turn on 2FA, you only have 2 weeks to turn it off.

Re: Nine Charged in Alleged SIM Swapping Ring

#14
post #4
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

Or, phrased another way: we are NOT in possession of a phone number any more than we are in possession of an IP address. Both are transiently assigned to us to the computer with a cellular modem in our pockets

Not really. For all intents and purposes you do "own" the number. You can take it to any carrier you want (local number portability), and carriers can't expropriate it. Try doing that with a /32 you got from your ISP, even a static one.

Re: Nine Charged in Alleged SIM Swapping Ring

#16
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

This is why I hate Apple’s new policy of requiring 2FA with a mobile number for new accounts. Luckily I created my account before it was official policy, but I’m afraid their going to force it on me someday. And if you turn on 2FA, you only have 2 weeks to turn it off.

> What if I can't access a trusted device or didn't receive a verification code?

> If you're signing in and don’t have a trusted device handy that can display verification codes, you can have a code sent to your trusted phone number via text message or an automated phone call instead. Click Didn't Get a Code on the sign in screen and choose to send a code to your trusted phone number. You can also get a code directly from Settings on a trusted device.

I thought that by now Apple's engineers had closed the sms loophole. But apparently it is still eminently there.

Re: Nine Charged in Alleged SIM Swapping Ring

#17
post #9
post #7

Earlier quoted context omitted.

What is, though?

A private key with an associated public key signed by one or more entitities that have verified the owner of the private key.

And how many people have those? With appropriate knowledge of how to generate, store, sign, backup, and secure the keys? On the front page of HN at the moment we have "we lost millions of dollars of Oracle DB due to key management issues". Key management is hard. Every few months a crypto exchange discovers this by either leaking or entirely losing their keys.

It's basically just people with Estonian e-identity cards and a handful of people with organisational PKI.

Re: Nine Charged in Alleged SIM Swapping Ring

#18
Several sites that I use, even some that support TOTP, still require a phone number.

I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft (assuming you protect your GV account of course) and relatively safe to use.

https://support.google.com/voice/answer/1065667#xferout

Re: Nine Charged in Alleged SIM Swapping Ring

#19
post #4
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

Or, phrased another way: we are NOT in possession of a phone number any more than we are in possession of an IP address. Both are transiently assigned to us to the computer with a cellular modem in our pockets

Better analogy would be a MAC address instead of an IP address.

Re: Nine Charged in Alleged SIM Swapping Ring

#20
post #14
post #4

Earlier quoted context omitted.

Or, phrased another way: we are NOT in possession of a phone number any more than we are in possession of an IP address. Both are transiently assigned to us to the computer with a cellular modem in our pockets

Not really. For all intents and purposes you do "own" the number. You can take it to any carrier you want (local number portability), and carriers can't expropriate it. Try doing that with a /32 you got from your ISP, even a static one.

True, but it's important to note phone numbers have the amount of security as e-mail/SMTP for self-identification. That's why it's so easy to spoof phone numbers and how robo-callers work.

Only this year, telecos are finally adding signature verification to caller-ID/reverse lookups. Once every teleco in a given country supports and is required to implement phone number verification, there will be a higher degree of assurance a phone number on your caller ID really is the person calling, but it's not there yet.

Post reply on HN