Live data from Hacker News

Two Charged in SIM Swapping, Vishing Scams

krebsonsecurity.com

61–70 of 71 posts

Re: Two Charged in SIM Swapping, Vishing Scams

#61
Shameless plug: my company has launched an alternative authentication modality that eliminates this issue, yet is also app-less and requires no download. It is also not limited in the ways FIDO authenticators are today, yet provides the same level of security because it can actually leverage FIDO authenticators if needed. Soft launch was last week. Email in my profile if this piques your interest and I can send more info directly.

Re: Two Charged in SIM Swapping, Vishing Scams

#62
post #55

Earlier quoted context omitted.

Yes, so much this. I want to be more secure but don't want the solution tied to my American phone number. I've even thought of getting a dual-sim phone just so I won't get locked out of my accounts when abroad and using a local sim.

Started to use Google Voice everywhere after telling my bank about it. They were OK, as long as they can call it from a landline. So I can slowly move away from SIMs. Virtual numbers from providers like Twilio, Plivo or Signalwire help too. They have 2FA mostly and couldn't be SIM-swapped (I hope). Google account security is quite good too.

I am afraid of google killing it eventually. I wonder if there's an alternative. Interestingly, Google Voice is now part of gcloud, so there might still be some hope for it.

Re: Two Charged in SIM Swapping, Vishing Scams

#64
post #50

Earlier quoted context omitted.

Even the US government uses it, such as for logging into your Social Security account.

I was shocked that login.gov even allows Yubikeys. Wish more banks would follow their lead.

And what happens if you lose your Yubikey?

Re: Two Charged in SIM Swapping, Vishing Scams

#65
post #15

It's insane to me that the only thing standing between me and having my life ruined is some minimum wage cell phone store employee. Text message based 2FA needs to die.

Seems the problem would be solved if someone would hold the phone companies accountable.

These problems seem easily solvable with MFA and a VPN, and if anyone should be an expert in networks, you would think it would be a telecom company.

This is gross negligence being passed off to the public as standard operating procedure.

Re: Two Charged in SIM Swapping, Vishing Scams

#66
post #57
post #56

Earlier quoted context omitted.

> minimum wage Seems unnecessary.

I think it’s relevant and it’s not a smear against the worker, but the job. If you’re making minimum wage, how much do you really care about your job in general? You’re probably regarded as disposable.

I understand that interpretation and I think it's valid. I also think that particular string "some minimum wage worker" has a long nose to look down and you shouldn't condescend or distrust lower compensated employees.

Re: Two Charged in SIM Swapping, Vishing Scams

#67
Does using Google Voice on a Google account that doesn’t forward via SMS and is used for nothing else provide any protection against SIM swapping? I would hope that Google has better security practices than the mobile carriers and that it’s a lot harder to steal a GV number.

Re: Two Charged in SIM Swapping, Vishing Scams

#68
post #50

Earlier quoted context omitted.

I was shocked that login.gov even allows Yubikeys. Wish more banks would follow their lead.

And what happens if you lose your Yubikey?

login.gov requires you to pick two second factors. So, either you had two Yubikeys (or I mention in a parallel sub-thread, any other type of FIDO Security Key or WebAuthn capable platform) or you had an entirely different second factor and that still works.

Re: Two Charged in SIM Swapping, Vishing Scams

#69
post #66
post #57

Earlier quoted context omitted.

I think it’s relevant and it’s not a smear against the worker, but the job. If you’re making minimum wage, how much do you really care about your job in general? You’re probably regarded as disposable.

I understand that interpretation and I think it's valid. I also think that particular string "some minimum wage worker" has a long nose to look down and you shouldn't condescend or distrust lower compensated employees.

I always interpretted "minimium wage" as "cheap to bribe and often effectively anonymous" in the objection in security contexts as that tends to matter more than lack of attention or aptitude. More of an argument to the opposite that the company should be either treating the access to the secure data/job better or promoting more loyalty. Plus any form of validation/licensing/training (say like bonded couriers for example) essentially requires both being paid for and the marginal cost encourages raising the rate so they don't change jobs as readily means it is no longer minimum wage even if it is still low on the worker totem pole.

Re: Two Charged in SIM Swapping, Vishing Scams

#70

I read these things and realize that statistically there must be 'non idiot' criminals out there. And I am guessing that they just profit day in and day out.

If you are smart, there are legal ways to make money without risking jail.

All that is needed is making even more money in illegal ways to tempt the smart but unethical. (Smart and "ethical" lawbreaking tends to be done for its own end.) an ideally structured system of law and market it is Not Worth It, usually for something that is in MMO terms "high aggro". Say operating a hitman for hire service or selling nuclear weapons it becomes very worth it to set up so that the majority of the small but very bad market is filled with FBI sting operations because almost all other operators are in jail.

In other less ideal situations especially with institutionalized corruption or shaky monopoly on violence such that it can not only pay better but effectively drag them into crime like to run an otherwise perfectly honest business you need goons to not be under someone's racket/pay bribes to operate and maintaining them becomes a slippery slope to collect protection money or forcing out competitors.

Post reply on HN