Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

71–80 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#71

Earlier quoted context omitted.

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1] I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer. [1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them. I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a busine…

Or we could just have a modern ID card that already has a cert embedded in it, and skip the whole go to the post office step. Most big companies and the US Federal government have already figured this out for their own employees.

Keep the post office option for the folks that don't have an ID, but for most people, this would be the most straightforward option.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#72

Earlier quoted context omitted.

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1] I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer. [1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them. I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a busine…

Wouldn't people just get socially engineered into giving up their code signing certificate? Some ads along the lines of "give us your code signing certificate and be entered into a raffle for an iPhone" would probably work. Stand in line to get some document you'll never use, maybe win a gadget, and a few days later your name is being used to spread malware.

Basically, I don't think a natural person is enough protection against malice. Something like "stick 1 million dollars into escrow, and if someone uses your cert to spread malware, we keep it" is a much stronger incentive. (Not what's done, of course.)

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#74
post #29

Earlier quoted context omitted.

the USPS could be doing this and so much more for citizens. But lawmakers in this country are allergic to having the government manage anything

Here's my Senator on the subject of postal banking: > “You would have to work very hard to come up with a worse idea than having the government become a national bank executed through the post office,” [Sen. Pat Toomey, a Pennsylvania Republican] said. “Even if the U.S. Postal Service was the most competent, professional and best-run organization on the planet, they should not be in the business of banking. > “We hav…

What's even funnier is that we actually used to have Postal Banking back in the 20th century.

But like other things during the 'Regeanomics era', it was cut, along with forcing the USPS to pay pensions 10 years in advance. The context does help to explain the reason why our USPS Grumman vans are well over their service life, and no where near retirement yet.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#75

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

It is a good idea, that is why Australia Post have done just this: https://auspost.com.au/business/identity/voi-solutions-for-c...

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#76

Earlier quoted context omitted.

Canada Post, the equivalent of the USPS in Canada, offers exactly this service [1] I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer. [1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them. I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a busine…

Here in europe we have several countries with digital ID cards. You put your ID in a smartcard reader, you put in your pin, and you can get your identity verified in a web browser.

Belgium has an identity service based on this. Governmental OAuth. https://www.csam.be/en/about-csam.html | https://iamapps.belgium.be/sma/generalinfo

They publish their own eID reader (middleware) and browser extensions. https://eid.belgium.be/en

Even with an official Linux version. :) https://eid.belgium.be/en/linux-eid-software-installation

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#77
post #14

>Truglia is still being criminally prosecuted in Santa Clara, Calif., the home of the REACT task force, which pursues SIM-swapping cases nationwide. In November 2018, REACT investigators and New York authorities arrested Truglia on suspicion of using SIM swaps to steal approximately $1 million worth of cryptocurrencies from Robert Ross, a San Francisco father of two who later went on to found the victim advocacy webs…

Silicon Valley REACT task force?

In the end Truglia's bragging to gain /props/ for a /component/ of this crime, is what lead to the REACT task force getting their /hooks/ into his /lifecycle/.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#78

This is exactly why I gambled on Efani.

> efani enforces 11-layer propriety military-grade client layer authentication

I'm sure they're an upstanding company, but using the word 'propriety' instead of 'proprietary' is an instant turnoff for me. Security is a details-oriented endeavor, and everything from marketing to implementation needs to be squeaky clean. But, maybe that's just me!

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#79

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

What you describe does exist, but not via the post office. For example when I started a new job I had to go to a tiny store that does fax, copy, postal, notary and similar services and have them physically verify my employment eligibility documents. Several similar providers exist all over the city (including FedEx, UPS, banks and more).

This is such a high barrier to entry, however, that people will simply not do it for something that isn't absolutely critical. Online services compete with each other to be as frictionless as possible, whereas this is the exact opposite of that.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#80

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

New Zealand Post does this: https://www.realme.govt.nz/
Post reply on HN