(googler, opinions are my own) This is one thing nice about Google Fi, Sim swap attacks aren't possible. Your phone number with Fi what is tied to your Google account, the only way to get a Fi phone number on a new phone is to sign into the Google account. So if you protect your account with good 2FA, your number is safer than any cell phone company (at least in the US).
Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
301–310 of 312 posts
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#302Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#303Earlier quoted context omitted.
There is no universally accepted second factor. * SMS (and automated voice call) are bad for people who live in areas with poor phone coverage, people with international phone numbers, and people who want good security. * TOTP is bad for people who don't have smartphones. * FIDO U2F is bad for people who don't have $20, safari/iOS users, and people whose devices don't have USB. * Vendor-specific apps are bad for peop…
> * SMS (and automated voice call) are bad for [...] people with international phone numbers Why is that? I'm maybe spoiled by my surroundings (Poland and Europe in general), but receiveing SMS text is free abroad. While using dataplan generally is not, so SMS is cheaper (free) as a second factor if you travel a lot.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#304Earlier quoted context omitted.
> There's an MVNO owned by the Canadian ISP tucows called Ting, I used them for my primary mobile service for some time (I would still but I wanted access to Verizon's 700 and 800 Mhz bands for better coverage at my residence so I switched). Anyhow last time I checked they've since added several awesome (and self configurable via their account dashboard) features like multi factor auth settings for # porting, compreh…
Tucows has been terrible in handling a client of mine's issues, their domain has no SPF or DKIM, and thus their email is unreliably making it to customer's inboxes. If anyone has pointers on how to get a domain & email address that are both bought & hosted with Tucows up to snuff with the email security standards of yesteryear (SPF & DKIM), I would really appreciate it!
Iirc tucows don't “directly” sell and host email to the general public. But offer reseller accounts or they are sold and hosted to the general public by their subsidiary Hover.
So just because its a "tucows domain" doesn't mean its actually tucows hosting your email services, anyways...
You might be able to get away without DKIM if the email is coming from “safe known ips” which hopefully your email provider has told the various big email providers.
SPF can be done completely from a DNS record. Google a SPF generator, fill in the details, and throw the result into your DNS records and done.
DKIM is a bit different as the outgoing mail server signs your outgoing email. The receiving party then check your DNS for the public key for the email.
Your mail provider might already be signing outgoing mail and you just need to put the public key on the DNS or you will need to contact your mail provider and ask them to turn it on for you. (If it’s is hover their customer support has always been good~ish to me. I think I’ve had one issue with them in the past, but it was a minor issue and I still have a few domains reg’ed with them. Anyways back on point.)
You can use something like https://www.appmaildev.com/en/dkim/ to check if you mail is already being signed and get the public key for it.
If your email provider is refusing to set up DKIM for you, you can try with just SPF and hope the reputation of the mail server itself is enough to fill in the blank of DKIM or moved to another provider either self hosted (cheaper, but more manual setup) or something like FastMail which does offer easy to configure DKIM (plus things like iOS Mail Push support) or an SMTP relay (depending on the volume of outgoing mail you might get away with using the free allowance from say sendgrid, sendpulse, mailgun or one of the many others out there.)
Obv trying to get your current provider up and running is the preferred option as then your client and any other mailboxes they have won’t need to chan he any of their mail client settings to get up and running.
EDIT: Also, having DKIM and SPF correctly configured doesn't always matter. Outlook for example may still reject your mail if it comes from an IP that they are not expecting. But you can ask them to add a mitigation for you via https://support.microsoft.com/en-us/supportrequestform/8ad56... (If they reply saying "Nope your not blocked..." just email them back politely asking them to check again as you are still having deliverability issues. I personally had this recently, but it was fixed with a follow up email so I'm not going to complain about it). Though as you are not the outgoing mail provider yourself you may not be able to answer all the questions (Are you sure you know all the ip ranges your mail provider use?). Gmail may get mad at you if you are doing a catch-all forward (including all the spam) from the domain to your clients personal gmail account.
But yeah, if you want to hit me up drop me a email and when I have a spare 30 mins I'll give it a once over and tell you your options. (Note: UK time here, dunno where you are, so if you email me while I'm asleep I'll get back you after coffee and I've done my morning tasks.)
GL;HF.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#305This could be stopped easily by making cell phone companies liable > Criminals have learned how to persuade mobile phone providers like T-Mobile and AT&T to switch a phone number to a new device that is under their control. > Hackers can get the codes by bribing phone company employees. How hard is it to insist on someone coming down to a store and submit several forms of identification to get a new SIM? And make mul…
But cell phone companies never opted into being used as security authenticators for other parties.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#306Earlier quoted context omitted.
Or do it like Turkey, and require central clearance with physical SIM replacement (this is required both for ownership and porting transfers). One of the few things we got right.
I feel like a time delay would help with this too. If it takes an extra 24 hours and you get notifications by SMS and email during that period with the chance to call "fraud" it stops most of these attacks which take control of e-mail and phone simultaneously. I get that makes life much more difficult when you are travelling and have your phone (and therefore SIM) stolen, but given the severity of the current issues…
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#307Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#308Earlier quoted context omitted.
Maybe it's time to reconsider phone numbers. Think about it. There's already a divide between phones on one side, and tablets/laptops/pcs etc on the other. You can only use whatsapp on a phone (or a laptop connected to a phone). You need a special phone contract to make phone calls. You can make voice calls via voip/whatsapp/whatever but you have to understand what network the person is on. Then there's this security…
> you just placed a voice call with someone else That "just" is doing a lot of legwork, though. How do you identify and find that someone else, so you can call them? Generally, you need some sort of unique identity. And how do you make sure that unique virtual identity connects to the correct physical person? Once you solve that, you can probably apply the solution to phone numbers.
So I'm really suggesting something like that. Assuming it was a standard and the company didn't want paying because they weren't doing the whole geographic number to voip identity thing - they were just allowing the creation of an account. We'd be moving away from traditional phone numbers - the number/id could be a guid or long hash or whatever; nobody's going to try and remember it - it would be stored in your contacts like "dave smith" or "mum" or whatever.
Dare I say it, you could have a blockchain for this. Just to store the identifier. Not associated with any other string, such as a name or email address; just a way to ensure that the identifier isn't taken (so there may be a rush for cool ones but like I said, no-one would actually need to remember them) - that you're the first person to claim it.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#309Earlier quoted context omitted.
Yes. Of course it works, if it was not possible for you to move your phone number to a different device then you'd be trapped and of course the mobile phone companies would take advantage of that to gouge you. The problem is your cell provider doesn't have a very good way to be sure it's Svip asking them to do this transfer. They are mostly going to rely on low paid call center or shop floor staff to decide. Fortunat…
There are still ways to make the system more secure. For example, you have to physically go to a store to port the number unless you have the old SIM. Then it's not done immediately - there's a 72 hour period in which multiple texts and calls are sent to the old SIM asking for confirmation. If you physically have the old SIM this is instant, but if you claim to have lost it you need to wait 72 hours and provide a sig…
People don't usually lose
their SIM card, so this
process wouldn't happen very
often.
People lose their entire phone all the time. In most cases, their SIM card is inside the missing phone.Unless, of course, they anticipated just such an emergency, and preemptively kept the phone and SIM separate because they care that much about faceless, global social media platforms.
Re: Hackers Hit Twitter CEO Jack Dorsey in a ‘SIM Swap’
#310Earlier quoted context omitted.
> you just placed a voice call with someone else That "just" is doing a lot of legwork, though. How do you identify and find that someone else, so you can call them? Generally, you need some sort of unique identity. And how do you make sure that unique virtual identity connects to the correct physical person? Once you solve that, you can probably apply the solution to phone numbers.
I briefly used a free UK voip service which allocated you a real, geographic phone number anywhere you wanted in the uk. 01234 567890 for examine. Anyone - you for example - could phone that number, and my phone would be configured to use that company's service via username/password such that I'd receive your call. You'd think it was a regular phone call, and being geographic it would be free, or taken from your minu…
If I press the button to call your unique ID, how does my softphone get yours to ring?