Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

141–150 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#141
post #11

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

>We have Post Offices in nearly every corner of this country. How about turning them into a kind of value-added identity verification When I opened a bank account (n26) in Germany this is how they verified my identity (along with a brief video call) as a foreigner so the idea has merit.

It's called PostIdent, it'd a wonderful service.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#142
post #25

Earlier quoted context omitted.

First Tech Federal Credit Union and Fidelity both support time/token based auth although it's Entrust or Symantec VIP, not open TOTP

Phone support at Fidelity will turn off VIP for you as long as you can answer at the account phone number.

this and they are not alone, it's horrible

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#143

> Following the theft, Terpin filed a civil lawsuit against Truglia with the Los Angeles Superior court Request: can anyone help clarify why this needed to be civil and didn't qualify for criminal?

because the criminal has much higher burden of proof , requires charges to be pressed .

It would seem like a failure of the justice system if they didn't consider that this met the criteria of a criminal case. Could have also helped set a lot of precedents to deter such crimes in future.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#144

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

https://old.reddit.com/r/tifu/comments/muc3ze/tifu_by_accide...

Possible in some places!

In many European countries the post office also offers banking services.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#145

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Italy: spid. In person id verification at any post office, use the app thereafter.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#146
post #115

Earlier quoted context omitted.

You may not like AusPost, but, the actually do offer the suggested service. [0] (As well as being somewhere you can apply for Police Checks and other identity services.) [0] https://auspost.com.au/business/identity/voi-solutions-for-c...

I mean sure, you can, but it's ridiculously inconvenient. If an online service like eBay, Facebook or Uber required this level of verification, people would (rightly) tell them to piss off and use a competing service instead.

> If an online service like eBay, Facebook or Uber required this level of verification, people would (rightly) tell them to piss off and use a competing service instead.

Well, we'll see once the government forces through the "anti-troll" bill that does require a similar level of verification, next year.

[0] https://www.theregister.com/2021/11/29/australia_troll_bill/

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#147

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Unfortunately, the U.S. gov has gone in the direction of using a shady private company ID.me [0] to provide this service. Starting 2022, the IRS is using ID.me to authenticate login to the irs.gov website. Same with California DMV. [0] https://en.wikipedia.org/wiki/ID.me.

Millions of American citizen will be forced to provide their info to this private company. Authentication involves you providing your cell phone number, then uploading a photograph of your drivers license or passport with that phone and then allowing ID.me to scan your face using the same phone camera.

You may think if the IRS and DMV are using this company it must be a serious identity service vetted by homeland security and what not. I did some digging around.

ID.me has a shopping site where you can shop for deals on sunglasses, sneakers and food kits [1] https://shop.id.me/. They use .me which is the top-level domain for Montenegro.

There is one hackernews thread about this company filled with clearly fake reviews made by accounts created the day the post appeared [2] https://news.ycombinator.com/item?id=13831921

What could go wrong ?

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#148
post #53

Earlier quoted context omitted.

>social security numbers have been used instead Historically that was sort of the case. I'd argue today that we mostly rely on state-issued IDs (especially but not necessarily driver's licenses) which are now overlaid with RealID requirements. As a practical matter it's probably indistinguishable from what a federally-issued ID would be and I'm mostly content with not adding any more layers of identity verification t…

>RealID requirements This doesn't invalidate your point, but man it irritates me how many states have chosen to retain a noncompliant ID tier in order to avoid eating costs or raising fees. At least my state offers a full EDL so there's some added value, but it's absurd that the 'default' local ID isn't adequate for domestic air travel.

There's a surprising number of people who do not possess a birth certificate document. Their parents lost it, it got thrown out during an eviction, etc, etc. I've witnessed people at DMV stations who brought in their original birth certificates, but the embossed notary stamp had flattened over the years. It takes time and money to get a replacement. If the non-enhanced IDs didn't exist, these people couldn't get a state id card.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#149

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Unfortunately, the U.S. gov has gone in the direction of using a shady private company ID.me [0] to provide this service. Starting 2022, the IRS is using ID.me to authenticate login to the irs.gov website. Same with California DMV. [0] https://en.wikipedia.org/wiki/ID.me . Millions of American citizen will be forced to provide their info to this private company. Authentication involves you providing your cell phone n…

It’s worse than that. Id.me originally started by providing verification for group discounts. Fair enough needs to verify to provide a discount and facilitate commerce.

They’ve now used those groups as a stepping stone to verify the public. They want everyone.

Id.me’s Privacy Policy and Terms of Service state that they will not sell your data. Good, but they absolutely can and will sell your demographic cohort. With the buyers being their integration clients (brands) and data brokers.

Hopefully they use differential privacy techniques. Doubtful. It quickly has become a government mandated (irs.gov) Facebook style audience mining network. That’s why Google invested in them and had a seat on their board.

They were damn good to hook wink the IRS and VA on that one.

https://californiaglobe.com/articles/monetizing-data-the-edd...

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#150
post #96

Earlier quoted context omitted.

It's a good idea. The flaw is in thinking USPS is even slightly interested in innovating. They're not. But then we also have a notary public system, which is already in the business of verifying identification for official purposes. That could do it too.

> It's a good idea. The flaw is in thinking USPS is even slightly interested in innovating. They're not. That's because it has been a target of right-wing attack for decades starting with the republican-led 2006 bill that effectively bankrupted it overnight by requiring a massive 50 years of health benefits to be funded.[1] So when you have a service (not a business ) that is constantly being picked apart and hamstru…

Democrats have had opportunities to "rectify" this, including complete control of the Presidency and Congress the very next terms (2007-11 Congress and 2009-17 Presidency) as well as at present. Ask yourself why they didn't... and don't.
Post reply on HN