Live data from Hacker News

Two Charged in SIM Swapping, Vishing Scams

krebsonsecurity.com

51–60 of 71 posts

Re: Two Charged in SIM Swapping, Vishing Scams

#51

Earlier quoted context omitted.

It’s the 21st century prisoners dilemma. You and your partner stole a bunch of Bitcoin via SIM swapping. If you split it, you each get half. If you don’t split it, the other one will SWAT you and you both go to jail.

Not to nitpick this brilliant comment, but it's more of an iterated prisoner's dilemma over multiple thefts. If one expected the charade to go on forever then the optimal strategy is indeed TFT ( https://en.wikipedia.org/wiki/Tit_for_tat ) but a criminal well-advised in game theory could calculate a threshold gain beyond which it is optimal to compete.

To be even more nitpicky, it isn’t really a prisoners dilemma; defecting is not rewarded at all since both people went to prison if anyone defects. The defector did not get charged with a lesser crime or anything.

Re: Two Charged in SIM Swapping, Vishing Scams

#53
post #15

It's insane to me that the only thing standing between me and having my life ruined is some minimum wage cell phone store employee. Text message based 2FA needs to die.

It also causes stupid trouble for those of us that travel alot, or split time between countries. SMS 2FA is my sworn enemy.

Yes, so much this. I want to be more secure but don't want the solution tied to my American phone number. I've even thought of getting a dual-sim phone just so I won't get locked out of my accounts when abroad and using a local sim.

Re: Two Charged in SIM Swapping, Vishing Scams

#54
post #50

Earlier quoted context omitted.

Even the US government uses it, such as for logging into your Social Security account.

I was shocked that login.gov even allows Yubikeys. Wish more banks would follow their lead.

Specifically login.gov implements WebAuthn.

So this should mean you can use the built-in biometric security of an iPhone or high end Android since those can also be used with WebAuthn in the built-in browser or with Firefox, or any security key, not just a Yubikey.

WebAuthn is easier (one tap login), it cannot be phished, it's privacy preserving, and yet somehow here we are in 2020 and most sites are like "Hmm, maybe we should add SMS 2FA?"

Re: Two Charged in SIM Swapping, Vishing Scams

#55

Earlier quoted context omitted.

It also causes stupid trouble for those of us that travel alot, or split time between countries. SMS 2FA is my sworn enemy.

Yes, so much this. I want to be more secure but don't want the solution tied to my American phone number. I've even thought of getting a dual-sim phone just so I won't get locked out of my accounts when abroad and using a local sim.

Started to use Google Voice everywhere after telling my bank about it. They were OK, as long as they can call it from a landline. So I can slowly move away from SIMs.

Virtual numbers from providers like Twilio, Plivo or Signalwire help too. They have 2FA mostly and couldn't be SIM-swapped (I hope). Google account security is quite good too.

Re: Two Charged in SIM Swapping, Vishing Scams

#57
post #56
post #15

It's insane to me that the only thing standing between me and having my life ruined is some minimum wage cell phone store employee. Text message based 2FA needs to die.

> minimum wage Seems unnecessary.

I think it’s relevant and it’s not a smear against the worker, but the job.

If you’re making minimum wage, how much do you really care about your job in general? You’re probably regarded as disposable.

Re: Two Charged in SIM Swapping, Vishing Scams

#58

It's crazy that companies are still using SMS for 2FA. TOTP solves this problem is a much more elegant way and is immune to such attacks.

You might have set up TOTP and removed SMS 2FA on Gmail but don't forget to remove your phone number as a recovery method as this can be equally devastating when exploited by SIM Swapping.

Ahh, this is a great tip. I’ll have to double check now.

Thanks.

Re: Two Charged in SIM Swapping, Vishing Scams

#59
post #8
post #4

I'm a blockchain pro and there was a couple month period in 2017 when tons of people I know got SIM swapped including me. The T-Mobile call person kept asking me "Are you sure you didn't go into a store in Detroit and ask for your phone to be changed? They showed an ID!" No, I didn't do that. Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key…

(Googler, opinions on my own) This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.

What happens if the SIM is damaged, lost, or stolen?
Post reply on HN