Live data from Hacker News

Two Charged in SIM Swapping, Vishing Scams

krebsonsecurity.com

21–30 of 71 posts

Re: Two Charged in SIM Swapping, Vishing Scams

#21
post #8
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

Having unempowered customer support agents may mean customer support agents can't take over your account, and can't be social engineered into taking over your account. But it also means people who only have a phone and lose it with the sim and also don't remember their password (perhaps because it's never prompted for) are going to have a hell of a time getting their account back.

Re: Two Charged in SIM Swapping, Vishing Scams

#22
post #8

Earlier quoted context omitted.

(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

What happens when Google spontaneously bans your account for no reason?

What do you think happens?

Re: Two Charged in SIM Swapping, Vishing Scams

#23
post #15

It's insane to me that the only thing standing between me and having my life ruined is some minimum wage cell phone store employee. Text message based 2FA needs to die.

There are plenty of ways to ruin someone’s life with access to their phone number beyond compromising their accounts with 2FA.

What really needs to die is giving privileged access to underpaid monkeys.

Re: Two Charged in SIM Swapping, Vishing Scams

#24
post #6
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

Why are the phone companies not responsible for swapping the number over? In a similar vein, I've known people who had unsigned checks stolen and their signature forged very poorly. The banks are supposed to check the signature, so why aren't the banks liable?

> The banks are supposed to check the signature,

Actually no, not anymore after the "Check 21" act. They're not responsible for verifying any aspect of the check. Kind of a crock.

Re: Two Charged in SIM Swapping, Vishing Scams

#25
post #5
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

I was also the victim of a T-Mobile SIM swap back in February. My assumption is that the attackers target individuals that have a high likelihood of owning bitcoin or other digital currency. This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address, and anything else that would help…

> This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address

... and this is why you should never use your identity for these things.

KYC is a security liability.

Re: Two Charged in SIM Swapping, Vishing Scams

#26
post #5
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

I was also the victim of a T-Mobile SIM swap back in February. My assumption is that the attackers target individuals that have a high likelihood of owning bitcoin or other digital currency. This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address, and anything else that would help…

Happened to one of my friends who was also on T-mobile and had some bitcoins at some point. They got into his email and coinbase account, but he was holding any bitcoin so they tried to buy some which was declined by the credit card.

Re: Two Charged in SIM Swapping, Vishing Scams

#27
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

I know of a number of oil companies who had tens, if not hundreds of millions of dollars stolen in 2016. Their accountants were spear phished and their outboxes were closely monitored. When an outbound invoice was sent the email was caught and then altered to show the fraudsters bank and routing numbers. Oil companies are notoriously slow to pay (and frequently take lots of nudging to get a payment out) so the paymen…

OK, time to write an article and submit here. That sounds way too interesting for just a comment!

Re: Two Charged in SIM Swapping, Vishing Scams

#28
post #20
post #8

Earlier quoted context omitted.

(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

Is there a guarantee that Google won't add this feature in the future? What if people lost their phones etc.? I think the risk is too big. Use U2F, or something similar.

If you lose your phone you simply contact customer support to mail you a new SIM card (Not sure how it works with eSIM, but I assume something similar)

Re: Two Charged in SIM Swapping, Vishing Scams

#30

It's crazy that companies are still using SMS for 2FA. TOTP solves this problem is a much more elegant way and is immune to such attacks.

You might have set up TOTP and removed SMS 2FA on Gmail but don't forget to remove your phone number as a recovery method as this can be equally devastating when exploited by SIM Swapping.
Post reply on HN