Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

41–50 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#41

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1] I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer. [1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them.

I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a business.

Imagine being able to get a code signing certificate in a single afternoon by signing up, taking your ID to Canada Post, and downloading your certificate after the identity verification is submitted. That would be quite the difference from the current awful experience where someone in a foreign country guesses and makes judgement calls based on the documentation you snail mail to them.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#42
I just posted this in another thread...

Also, don't let your mobile phone number expire and someone else get it.

I can log in to the previous owner's TikTok account with just his number.

I signed up for a food delivery service two days ago and it autofilled all the details with his full name and address for me.

How many other sites let you log in with just a phone number? Asking for a friend...

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#43

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

cough national id scheme, anyone? Thinking of E-Estonia here.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#44

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1] I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer. [1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

Here in Czech Republic the CzechPoint system kinda does that:

https://www.ceskaposta.cz/en/sluzby/egovernment/czechpoint

Its usually situated on post offices or local government offices and makes it possible to get verified electronic signature that you can then use to prove your identity electronically. It can also access various government registries, etc.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#45
post #39

SMS-based 2FA needs to be eliminated completely. Authenticator apps need to come preinstalled as an essential utility on every OS. There doesn't seem to be a whole lot of pressure to improve 2FA security.

I don't think it's too heavy handed to make the practice of implementing SMS 2FA straight-up illegal. If credit card processing requires PCI compliance why wouldn't we apply similar thought to 2FA?

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#46
post #39

SMS-based 2FA needs to be eliminated completely. Authenticator apps need to come preinstalled as an essential utility on every OS. There doesn't seem to be a whole lot of pressure to improve 2FA security.

Doesnt that force people to not only use smartphones, but "approved" smartphones (read Android/iOS) with locked bootloaders and no root access (or the bank authenticator app will refuse to run)?

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#47
post #33

Earlier quoted context omitted.

> one number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still). > reply Why not use a special phone number for 2FA? How do hackers know your phone number?

Hackers can easily get anyone’s phone number. Just Google phone number. There are so many data brokers out there happy to sell this information.

[deleted]

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#48
post #43

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

cough national id scheme, anyone? Thinking of E-Estonia here.

I lived in the Netherlands and admired how they offer a SSO service called DigiD for most—if not all—national and municipal services: personal tax, business tax, healthcare, pension, water, garbage, police and many other service portals. Yes, there is a nice online police portal where you can digitally file a police report, get a declaration for insurance, and ask questions.

You also get a digital inbox—Berichtenbox—to organize and centralize all communications from those agencies.

It is difficult to overstate how much life is made better when the government is well-organized and that organization is exposed to you through good UX. I'm now back in the US, it's been 2+ weeks since my renewed passport was supposed to have been mailed to me, and no one at the State Department knows anything.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#49

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

There are already standard ways of doing brick and mortar identity verification, and in somewhat surveillance-resisting ways even! The most common is "notarization" - a state-deputized "notary" verifies that you are who you say you are, and then endorses your signed document with a special stamp and a signature. Another common one used for financial transactions is a "medallion stamp", wherein not only do they verify…

Yes, but notarization feels like a much more cumbersome process, designed for more like "once in a lifetime" transactions (house purchase, will, etc). It also feels more like a proof, only needed if a transaction is disputed in court etc, it can be investigated back to the source.

I mean the every day kind of verification that fuels our daily transactions and benefits from instantaneous info being transmitted back and forth, to easily get a credit card approved for example.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#50
post #43

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

cough national id scheme, anyone? Thinking of E-Estonia here.

It's long, long overdue. That said a national ID scheme has long been opposed by a vocal part of the Christian population in the states. It's association with the new testament's prophesy of the mark of the beast prevents many lawmakers from pushing forward a proposal, especially since 65% of Americans in 2019 identified as having a belief in some variety of Christianity[0].

The obvious reality here is that in the wake of no proper national identification system, social security numbers have been used instead. It's not a question of whether or not we have a national ID, it's really just a question of whether we have a functional one or an inadequate one. Nonetheless politicians would likely be committing suicide with their constituents in some districts if they were to support a push towards a better system.

[0] https://en.wikipedia.org/wiki/Religion_in_the_United_States#....

Post reply on HN