Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

131–140 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#131

Earlier quoted context omitted.

> yes, I could use Google Voice or some sort of VOIP number but that starts making things complicated. You should soldier through it. Google Voice is a decent free service domestically, unless paranoid. I use it in the reverse manner as I expect you would intend (if you'd intend to generate many virtual throw away numbers to forward back to your phone until the forwarding is manually severed). My actual phone number…

More and more places refuse to accept my Google voice number for verification. It started out with nearly all banks but has gotten ridiculous recently. Target outright refused for Target circle a couple years ago. Recently 7-11 had accepted my Google voice number to get points on in store purchases but now that I live somewhere where I need a car, the gas pump decided the number was invalid when I tried to get the di…

Good point, that is a problem, though I can't fathom why a bank wouldn't accept it, but I do recall having issues before with some site not accepting it (possibly Craigslist?). My solution is simple: if my GV number is not accepted, I take my business elsewhere.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#133

Earlier quoted context omitted.

> efani enforces 11-layer propriety military-grade client layer authentication I'm sure they're an upstanding company, but using the word 'propriety' instead of 'proprietary' is an instant turnoff for me. Security is a details-oriented endeavor, and everything from marketing to implementation needs to be squeaky clean. But, maybe that's just me!

Although “propriety” is a word and the sentence still makes sense with it.

Propriety is a noun

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#134

I don't think people appreciate just how big the crypto fraud problem is, and how much bigger it will get. Crypto is so big, to put it in perspective, the gambling sector worldwide was estimated to be worth roughly $265 billion U.S. dollars in 2019. That is just 2/3 the market cap of Ethereum alone. Crypto is bigger than pretty anything right now. Bigger than pro sports. bigger than the entertainment industry. Only t…

The market cap of Ethereum is a worthless estimate of value. Ethereum has no backstop for value, unlike a casino or a company. Microsoft trading at $300 will never go to $0.01, there are enough raw assets at play to keep Microsoft worth $1. But Ethereum can go to $.01 there are no fundamental reasons for it. So, the price is purely speculative, so you can in no way whatsoever compute the total value of Ethereum as ma…

no it is is not. there are $470 billion of eth out there. some if locked up, but a lot of it held by people and exchanges. hence efforts to steal it. The market for eth is huge and very liquids and deems it worth $3970. Whether or not the value is subjective is irreverent to the fact that there is a huge market.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#135

Earlier quoted context omitted.

It would be amazing to see the current trust / code-signing industry fail and for something that integrates services like the one you linked to replace them. I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a busine…

Here in europe we have several countries with digital ID cards. You put your ID in a smartcard reader, you put in your pin, and you can get your identity verified in a web browser. Belgium has an identity service based on this. Governmental OAuth. https://www.csam.be/en/about-csam.html | https://iamapps.belgium.be/sma/generalinfo They publish their own eID reader (middleware) and browser extensions. https://eid.belgi…

In Sweden we have "BankID" that could be card based, but almost everyone has it in their phone. It is issued by the banks (hence the name?) since they already has vetted your identity. BankID is used almost everywhere, from online banking to sign your employment contract or collect benefits when you're home to care for your sick child.

The post office used to issue normal identity cards, but today I only think it's the DMV equivalent and the police that does that.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#136

Earlier quoted context omitted.

The market cap of Ethereum is a worthless estimate of value. Ethereum has no backstop for value, unlike a casino or a company. Microsoft trading at $300 will never go to $0.01, there are enough raw assets at play to keep Microsoft worth $1. But Ethereum can go to $.01 there are no fundamental reasons for it. So, the price is purely speculative, so you can in no way whatsoever compute the total value of Ethereum as ma…

no it is is not. there are $470 billion of eth out there. some if locked up, but a lot of it held by people and exchanges. hence efforts to steal it. The market for eth is huge and very liquids and deems it worth $3970. Whether or not the value is subjective is irreverent to the fact that there is a huge market.

No, there are $470 billion if you make the huge mistake of assuming you can sell each one at the same price.

This is an issue for stocks also. If 100% of Amazon share holders tried to sell simultaneously the price would fall precipitously. But, Amazon is at least backed by assets, dividend potential, and IP.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#137
post #26

So is it recommended to remove your phone number from your Google account to ensure it's not used to ever reset the password?

They are currently trying to force me to add my mobile number to gmail. If I get logged out they are going to lock me out until I do.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#138

Earlier quoted context omitted.

no it is is not. there are $470 billion of eth out there. some if locked up, but a lot of it held by people and exchanges. hence efforts to steal it. The market for eth is huge and very liquids and deems it worth $3970. Whether or not the value is subjective is irreverent to the fact that there is a huge market.

No, there are $470 billion if you make the huge mistake of assuming you can sell each one at the same price. This is an issue for stocks also. If 100% of Amazon share holders tried to sell simultaneously the price would fall precipitously. But, Amazon is at least backed by assets, dividend potential, and IP.

from the perspective of the scammer, there is a huge and liquid market. way more liquid than the market for fenced goods. we're talking tens billions of dollars eth traded a day on many exchanges. that is like 1000x as much stolen by this one kid. the market is big enough to support a lot of criminals. plus, many of them are not going to be cashing out.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#139
post #115

Earlier quoted context omitted.

I don't know about other countries, but here in Australia post offices are open Monday-Friday, 9-5 (with the exception of some smaller ones being open until noon on a Saturday) and there are massive queues around lunchtime. And that's assuming there is a post office near you (or you have a car), and you're able-bodied enough to get there independently. I can say from personal experience that I have point blank refuse…

You may not like AusPost, but, the actually do offer the suggested service. [0] (As well as being somewhere you can apply for Police Checks and other identity services.) [0] https://auspost.com.au/business/identity/voi-solutions-for-c...

I mean sure, you can, but it's ridiculously inconvenient.

If an online service like eBay, Facebook or Uber required this level of verification, people would (rightly) tell them to piss off and use a competing service instead.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#140

Earlier quoted context omitted.

I don't understand why people think religion is the main reason to oppose this. The main reason to oppose this is that if you had a low friction government ID system, surveillance capitalism would then require you to present your ID to do anything whatsoever and all privacy would disappear forever.

But we already have that? If you pay with a credit card, have an address on file, or use a state-issued ID (drivers license), I don't see how that would be worse.

Credit cards are already a privacy catastrophe for anything where you have to pay money, but people will push back if you demand one for anything where you're not supposed to be paying anything because people are rightly wary of being charged when they ought not to be. Anyone who gives their credit card number for a "free trial" learns that the hard way and then becomes appropriately cynical.

A state-issued ID generally doesn't work over the internet, which is good. Some of them can be read electronically in person, which is already being abused to a limited extent and should be gotten rid of.

Which is the general response to your concern: "This is already a problem" means we need to go the other way and address that so that doesn't happen anymore, not intensify the problem and set it in concrete so it can never be fixed.

Centralized identity is a design flaw. Your bank needs to know if you're authorized to withdraw from your account, which is why you have a bank card. Your email provider needs to know if you're allowed to access your email account, which is why you have an email password. Your apartment building needs to know if you're authorized to enter, which is why you have an access card. What we don't need, and should not have, is a single primary key binding all of these things together so it can be correlated in a single database.

Post reply on HN