Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

31–40 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#31
post #13

Earlier quoted context omitted.

Going through some processes on DMV and USCIS recently I noticed both of them were using Id.me Seems like a private company providing services to these gov agencies on authentication. Seems like a better solution than showing up at the post office.

That’s actually fascinating, because this official login solution exists, and it seems very nice: login.gov. It’s from the GSA which seems to be doing some good work. I wonder how id.me differs, and how we haven’t centralized on one solution yet

Over 200 federal agency web properties have adopted login.gov. Social Security Administration recently adopted them as their primary identity provider (and appears to be phasing out id.me but I’m waiting on some ground truth to confirm that). Something is up with IRS as to why they went with with id.me, and someone has submitted FOIA requests to get more context.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#32

Earlier quoted context omitted.

> but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do? Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. If you really need to keep that account for reason X, move out all your assets to another bank and keep enough funds to fund X there.

> Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. Have any suggestions for a bank that supports TOTP? I have yet to find a decent bank in the US that supports this.

I am not in the US but I'm sure fellow HNers can help you out.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#33

Earlier quoted context omitted.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

> one number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still). > reply Why not use a special phone number for 2FA? How do hackers know your phone number?

Hackers can easily get anyone’s phone number. Just Google phone number. There are so many data brokers out there happy to sell this information.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#34

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

You must have to pay more than double to bribe two people simultaneously -- since each one then has to rely on an extra person to cover up the corruption.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#35

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1] I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer. [1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

Sagawa (a private courier in Japan) provides a similar service but at your doorstep. Basically the sender registers your info with them (mainly DoB) and upon delivery you have to provide an ID, which the driver checks that it matches with what's written on the envelope, then enters your DoB and other info and your ID number into a portable wireless POS device. Only if they match, you receive the package, and then I believe the info entered into the device gets relayed to the sender.

(Use your translation service of choice if desired.) https://www.sagawa-exp.co.jp/service/kakunin/

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#36
post #5

Earlier quoted context omitted.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One of the few things I miss about giving up my landline a couple years ago is that I pretty much have to give out my cell phone number for anything that needs a valid phone number. (yes, I could use Google Voice or some sort of VOIP number but that starts making things complicated.) I used to be very selective at giving out my cell number.

What about a second cell phone? Depending on whether ~20/month is worth it.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#37
post #29

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

the USPS could be doing this and so much more for citizens. But lawmakers in this country are allergic to having the government manage anything

Meanwhile the USPS instead funds itself by being an open channel for wasteful junk mail.

Making money while doing something actually useful? Not my government, not when there's a tiny sliver of profit to be funneled to wealthy special interests!

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#38

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

I'm all for it if they execute it well enough to make a profit.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#40
post #29

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

the USPS could be doing this and so much more for citizens. But lawmakers in this country are allergic to having the government manage anything

> But lawmakers in this country are allergic to having the government manage anything

Congress has slowly been fucking the USPS to death at the behest of FedEx, UPS, et al lobbyists.

Post reply on HN