Live data from Hacker News

Two Charged in SIM Swapping, Vishing Scams

krebsonsecurity.com

41–50 of 71 posts

Re: Two Charged in SIM Swapping, Vishing Scams

#41

I read these things and realize that statistically there must be 'non idiot' criminals out there. And I am guessing that they just profit day in and day out.

There are. But it only takes one mistake and you're caught. I think most of the guys that do this for a living probably live in countries like Russia where the government doesn't cooperate with US authorities and they are basically free to do whatever they want as long as it doesn't screw over their home country.

Re: Two Charged in SIM Swapping, Vishing Scams

#42
post #31

Earlier quoted context omitted.

> What really needs to die is giving privileged access to underpaid monkeys. This in uncalled for.

You might reconsider this opinion once you or someone you know loses money and/or time because of some CS idiot. I’ve had my fair share of such incidents (so much that I’m paying 10x more for an enterprise-grade leased line just to not have to talk to them ever) and I no longer have any sympathy for those people.

I was a "CS monkey" for two years at Google. A job I was overqualified for but it was the only thing that got me into a major tech company.

(Nobody at big tech companies ever bothered to even phone screen me for SWE roles)

Also your enterprise account managers often are clueless and just ask the support team - certainly what happened in my experience.

Re: Two Charged in SIM Swapping, Vishing Scams

#43
post #8

Earlier quoted context omitted.

(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

Unfortunately Google Fi has its own set of issues that make it unpalatable as a primary mobile phone service: https://onemileatatime.com/google-fi-review/

I believe this is around when Google Fi expanded to support iOS? I think there were some admitted growing pains around that time, and they've worked to improve it since then. Hard to say.

Re: Two Charged in SIM Swapping, Vishing Scams

#44
post #36

It’s crazy that critical infrastructure providers (cell carriers) aren’t even using U2F internally, where they can mandate the rollout. Public utilities in the US need an overhaul.

Is there anywhere to read about cell carriers or other infrastructure providers in other nations implementing U2F? That sounds very interesting.

Re: Two Charged in SIM Swapping, Vishing Scams

#45

Using phone numbers for verification is just stupid. I've switched phones a few times over the years and just got a new number rather than keeping my old one and i got locked out of my accounts because i didn't have access to the old number anymore. Stuff like Authy and Google Authenticator exist, I think it's time companies started using them.

Even the US government uses it, such as for logging into your Social Security account.

Re: Two Charged in SIM Swapping, Vishing Scams

#46
post #18
post #6

Earlier quoted context omitted.

Why are the phone companies not responsible for swapping the number over? In a similar vein, I've known people who had unsigned checks stolen and their signature forged very poorly. The banks are supposed to check the signature, so why aren't the banks liable?

The phone company is giving you a phone number, it doesn't want to be responsible for providing security for your financial and private life.

Yes, it's really quite amazing to watch all companies including the US government pretty much task the mobile networks with providing plausible deniability that they verified your identity. They get to point to the mobile networks (or you) if there's a problem, and the mobile networks get to say, legally, it's not their problem...because it isn't.

Re: Two Charged in SIM Swapping, Vishing Scams

#47
post #31

Earlier quoted context omitted.

> What really needs to die is giving privileged access to underpaid monkeys. This in uncalled for.

You might reconsider this opinion once you or someone you know loses money and/or time because of some CS idiot. I’ve had my fair share of such incidents (so much that I’m paying 10x more for an enterprise-grade leased line just to not have to talk to them ever) and I no longer have any sympathy for those people.

People is keyword here, monkeys is not.

Re: Two Charged in SIM Swapping, Vishing Scams

#48
post #15

It's insane to me that the only thing standing between me and having my life ruined is some minimum wage cell phone store employee. Text message based 2FA needs to die.

It also causes stupid trouble for those of us that travel alot, or split time between countries. SMS 2FA is my sworn enemy.

Re: Two Charged in SIM Swapping, Vishing Scams

#50

Using phone numbers for verification is just stupid. I've switched phones a few times over the years and just got a new number rather than keeping my old one and i got locked out of my accounts because i didn't have access to the old number anymore. Stuff like Authy and Google Authenticator exist, I think it's time companies started using them.

Even the US government uses it, such as for logging into your Social Security account.

I was shocked that login.gov even allows Yubikeys. Wish more banks would follow their lead.
Post reply on HN