Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

81–90 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#81
post #13

Earlier quoted context omitted.

Going through some processes on DMV and USCIS recently I noticed both of them were using Id.me Seems like a private company providing services to these gov agencies on authentication. Seems like a better solution than showing up at the post office.

That’s actually fascinating, because this official login solution exists, and it seems very nice: login.gov. It’s from the GSA which seems to be doing some good work. I wonder how id.me differs, and how we haven’t centralized on one solution yet

login.gov is simply a user login mechanism. id.me does identity verification in many different ways.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#82

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Sounds like a Notary service.

"What is the meaning of notary service?

A notary is a publicly commissioned official who serves as an impartial witness to the signing of a legal document. Document signings where the services of a notary are likely include real estate deeds, affidavits, wills, trusts, and powers of attorney. The main reason a notary is used is to deter fraud."

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#83

Earlier quoted context omitted.

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them. I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a busine…

Wouldn't people just get socially engineered into giving up their code signing certificate? Some ads along the lines of "give us your code signing certificate and be entered into a raffle for an iPhone" would probably work. Stand in line to get some document you'll never use, maybe win a gadget, and a few days later your name is being used to spread malware. Basically, I don't think a natural person is enough protect…

You need to cater for those people, they will be the bulk of your clients and also need the most support. So make resetting it possible but not easy.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#84
post #53
post #50

Earlier quoted context omitted.

It's long, long overdue. That said a national ID scheme has long been opposed by a vocal part of the Christian population in the states. It's association with the new testament's prophesy of the mark of the beast prevents many lawmakers from pushing forward a proposal, especially since 65% of Americans in 2019 identified as having a belief in some variety of Christianity[0]. The obvious reality here is that in the wa…

>social security numbers have been used instead Historically that was sort of the case. I'd argue today that we mostly rely on state-issued IDs (especially but not necessarily driver's licenses) which are now overlaid with RealID requirements. As a practical matter it's probably indistinguishable from what a federally-issued ID would be and I'm mostly content with not adding any more layers of identity verification t…

Some states allow use of SSNs for drivers license numbers.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#85

> Following the theft, Terpin filed a civil lawsuit against Truglia with the Los Angeles Superior court Request: can anyone help clarify why this needed to be civil and didn't qualify for criminal?

It may have qualified as a criminal case, but you as a citizen can't really do much to get the police, AG or a federal agency to devote their resources to it. Suing someone in a civil court is a pretty straightforward thing to do.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#86
post #39

SMS-based 2FA needs to be eliminated completely. Authenticator apps need to come preinstalled as an essential utility on every OS. There doesn't seem to be a whole lot of pressure to improve 2FA security.

Apps just embolden employers to shirk on providing secure TOTPs or work phones. You should not be forced to use your personal property to conduct job duties.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#87
post #39

SMS-based 2FA needs to be eliminated completely. Authenticator apps need to come preinstalled as an essential utility on every OS. There doesn't seem to be a whole lot of pressure to improve 2FA security.

There doesn't seem to be a whole lot of pressure to improve 2FA security.

I gave up on that ten years ago when I worked at a biometric authentication company. Banks were soon to be regulated to use 2FA, and our system was easy to use, we're all gonna be rich!

Then the banks were allowed to use security questions as 2FA. Not only were the employees not "all gonna be rich", everyone else was going to get fucked when they accidentally post something on Facebook about how their mother (neé Mary $MAIDEN_NAME) used to do $SOMETHING on $STREET_I_GREW_UP_ON. So the continued use of SMS-base 2FA, despite its frequently-published flaws, isn't going anywhere until a new way to fuck up 2FA is found.

If I had a viable solution to it all, well, I'd be rich.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#88

This is exactly why I gambled on Efani.

> efani enforces 11-layer propriety military-grade client layer authentication I'm sure they're an upstanding company, but using the word 'propriety' instead of 'proprietary' is an instant turnoff for me. Security is a details-oriented endeavor, and everything from marketing to implementation needs to be squeaky clean. But, maybe that's just me!

The phrase "military-grade" is used, and a typo is what sets you off? :-)

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#89

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Taking this a step further, I'd love for them to be able to issue some sort of smart card that I could then utilize when signing up for other accounts that still wanted verification, but were okay with a slightly lower assurance.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#90

This is exactly why I gambled on Efani.

> efani enforces 11-layer propriety military-grade client layer authentication I'm sure they're an upstanding company, but using the word 'propriety' instead of 'proprietary' is an instant turnoff for me. Security is a details-oriented endeavor, and everything from marketing to implementation needs to be squeaky clean. But, maybe that's just me!

The grammar checker is layer 12. The first 11 are nested ROT13. Ultra secure.
Post reply on HN