Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

91–100 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#91

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

The term you're looking for is "Notary". There are plenty of them around, and they're required to execute high-dollar contracts like buying a house or wills.

Every state has its own requirements to become a notary(with one requirement being posting a $10k bond or purchasing insurance, so you have something to lose if you make an egregious mistake).

You can require counterparties notarize any documents you'd like, and reject anyone who declines. And you can do this without needing to change the law to increase the scope of responsibility of the USPS. It's illegal for the USPS to offer notary services, although they're often located near notaries: UPS Stores usually offer it.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#92
post #43

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

cough national id scheme, anyone? Thinking of E-Estonia here.

This is the US we are talking about. Must be against the constitution and government is bad. Better to live in perpetual fraud.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#93

He only got caught because he bragged about it? Horrible deterrent, because it isnt a deterrent

6 weeks Fear and Loathe and living like a king in Las Vegas is worth of 5 years of jail mate sex?

Unless…

> “On the surface, Pinsky is an ‘All American Boy,'” Terpin’s civil suit charges. “The son of privilege, he is active in extracurricular activities and lives a suburban life with a doting mother who is a prominent doctor.”

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#94
post #59

Earlier quoted context omitted.

SIM swapping has really nothing to do with crypto per se, people use it to steal identities/fiat all the time. Crypto is big, but to be fair "just" Apple is bigger than crypto. Compared to the NYSE or Nasdaq, it's small, and when compared to forex (maybe a more apt comparison), it barely registers. Incidentally, I think this is why crypto's here to stay (probably forever): it's huge and growing, very popular, and the…

crypto is money. So you got $2.2 trillion of money lying around. So of course criminals are going to go through any means to get some, including sim swaps, but soo much more. You cannot steal stock or real estate in the same way you can steal crypto. Crypto by definition is irreversible and unbreakable. SO even way more attractive to criminals just for that property.

> You cannot steal stock or real estate in the same way you can steal crypto.

In fact you can

https://www.bbc.com/news/uk-england-essex-59069662

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#95
post #71

Earlier quoted context omitted.

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them. I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a busine…

Or we could just have a modern ID card that already has a cert embedded in it, and skip the whole go to the post office step. Most big companies and the US Federal government have already figured this out for their own employees. Keep the post office option for the folks that don't have an ID, but for most people, this would be the most straightforward option.

This does work for certain things, but for some things you don’t just want proof of possession of a particular person’s ID card, you want to see that a particular person matches the document they are presenting in addition to verifying that the doc is real.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#96

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

It's a good idea. The flaw is in thinking USPS is even slightly interested in innovating. They're not.

But then we also have a notary public system, which is already in the business of verifying identification for official purposes. That could do it too.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#97
post #25

Earlier quoted context omitted.

> Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. Have any suggestions for a bank that supports TOTP? I have yet to find a decent bank in the US that supports this.

First Tech Federal Credit Union and Fidelity both support time/token based auth although it's Entrust or Symantec VIP, not open TOTP

Phone support at Fidelity will turn off VIP for you as long as you can answer at the account phone number.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#98
post #96

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

It's a good idea. The flaw is in thinking USPS is even slightly interested in innovating. They're not. But then we also have a notary public system, which is already in the business of verifying identification for official purposes. That could do it too.

>thinking USPS is even slightly interested in innovating

Or, you know, it's hard to innovate when you're in organizational crisis mode trying to prefund 50 years of retirement while not being allowed to market-rate your core service...

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#99
post #43

Earlier quoted context omitted.

cough national id scheme, anyone? Thinking of E-Estonia here.

This is the US we are talking about. Must be against the constitution and government is bad. Better to live in perpetual fraud.

People will always live in perpetual fraud, it's only a matter of degree.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#100

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

I don't know about other countries, but here in Australia post offices are open Monday-Friday, 9-5 (with the exception of some smaller ones being open until noon on a Saturday) and there are massive queues around lunchtime.

And that's assuming there is a post office near you (or you have a car), and you're able-bodied enough to get there independently.

I can say from personal experience that I have point blank refused to pick up Signature on Delivery (ie, the sender instructed the postal service not to leave the package on the porch) items from the post office in the past and demanded a refund from the seller. I'd do the same if I was asked to go down there to verify an account for Uber or whatever.

Post reply on HN