Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

21–30 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#21
post #13

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Going through some processes on DMV and USCIS recently I noticed both of them were using Id.me Seems like a private company providing services to these gov agencies on authentication. Seems like a better solution than showing up at the post office.

That’s actually fascinating, because this official login solution exists, and it seems very nice: login.gov. It’s from the GSA which seems to be doing some good work.

I wonder how id.me differs, and how we haven’t centralized on one solution yet

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#22

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1]

I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer.

[1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#23

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

> or at least substituting a voip service that can't be social engineered over the phone

unfortunately it's also very easy for somebody to submit falsified port documentation to port away your voip number to their own carrier.

In many cases even easier than doing a SIM swap, since the oldschool way to do a port is to literally print out one page of a bill with your name on it (Anybody could edit this by inspect element on a legit bill of their own and swap your name), print it, sign it in ink, scan it, and send it to the carrier requesting the port-in

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#24

Earlier quoted context omitted.

One thing I don't understand about the suggestion to remove my phone number from 2FA is that 1FA seems worse. I'd prefer something like Google authenticator, but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do?

> but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do? Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. If you really need to keep that account for reason X, move out all your assets to another bank and keep enough funds to fund X there.

[deleted]

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#25

Earlier quoted context omitted.

> but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do? Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. If you really need to keep that account for reason X, move out all your assets to another bank and keep enough funds to fund X there.

> Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. Have any suggestions for a bank that supports TOTP? I have yet to find a decent bank in the US that supports this.

First Tech Federal Credit Union and Fidelity both support time/token based auth although it's Entrust or Symantec VIP, not open TOTP

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#27
post #16

Earlier quoted context omitted.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One of the advantages of using Google Fi as your phone provider on a Google phone: there's no SIM, and you have to log in to the phone on your Google account in order to transfer phone/SMS service there. So an attacker can't use a SMS hijack to steal 2FA codes unless they've already compromised your Google account (which is hopefully a higher bar than convincing some random phone shop employee).

I have an iPhone with Google Fi and I have a SIM. The entire family does and they also have them.

However, the point of needing to login to your Google account is well taken. And I have 2FA on that.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#28

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

> one number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still).

> reply

Why not use a special phone number for 2FA? How do hackers know your phone number?

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#29

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

the USPS could be doing this and so much more for citizens.

But lawmakers in this country are allergic to having the government manage anything

Post reply on HN