Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

171–176 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#171

Earlier quoted context omitted.

I don't understand why people think religion is the main reason to oppose this. The main reason to oppose this is that if you had a low friction government ID system, surveillance capitalism would then require you to present your ID to do anything whatsoever and all privacy would disappear forever.

IMHO the difference is that the status quo (a high friction non-universal government ID system + almost universal private "ID"/tracking systems) has all the same disadvantages anyway, but simply fails to realize the possible benefits.

What possible benefits actually are there, compared to non-centralized identity systems we already have? The only thing you get from a centralized identity system is the bad thing -- it allows surveillance bureaucracies to correlate separate authentication tokens with each other.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#172

Earlier quoted context omitted.

Yes, but notarization feels like a much more cumbersome process, designed for more like "once in a lifetime" transactions (house purchase, will, etc). It also feels more like a proof, only needed if a transaction is disputed in court etc, it can be investigated back to the source. I mean the every day kind of verification that fuels our daily transactions and benefits from instantaneous info being transmitted back an…

The cumbersome part of notarization is having to physically go to the bank, which would be the same for the post office. The performance of showing up in person, and showing a physical hard-to-forge ID, is exactly what drastically raises the bar for an attacker. Doing this instantaneously implies skipping the heavyweight process. Which I assume means doing something like a one time (or periodic) cumbersome in-person…

@hellbannedguy:

Yes from what I know, you technically do not need to get a will notarized. But getting it notarized makes it a "self proving will", which will be easily accepted by a court. If you don't do the notarization at the time, your poor executor will likely need to hunt down the witnesses and get them to sign affidavits.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#173

Earlier quoted context omitted.

IMHO the difference is that the status quo (a high friction non-universal government ID system + almost universal private "ID"/tracking systems) has all the same disadvantages anyway, but simply fails to realize the possible benefits.

What possible benefits actually are there, compared to non-centralized identity systems we already have? The only thing you get from a centralized identity system is the bad thing -- it allows surveillance bureaucracies to correlate separate authentication tokens with each other.

This means that each and every institution has to verify identities "from scratch" which they are not really capable of. Bootstrapping trustworthy verification of identity that is useful for commerce (e.g. where you can practically collect debts/credit and prevent creating fake identities so that you know who you're dealing with, can reach them for contract enforcement if needed, and can ban people you don't want to deal with) is really hard, so everyone is essentially delegating it to someone else - webstores to credit card issuers, all kinds of institutions to social security numbers, some to phone numbers, and everyone is doing that poorly and failing at making it secure since there is no solid foundation for any of it, resulting in the extremely costly identity theft problem (in USA it's like $50bn per year?) and in cases like this, where companies have to rely on "phone numbers" and ridiculous "security" questions like mother's maiden name - because they don't have anything better to use.

Privacy and anonymity are not the same; there are many domains where anonymity is reasonable and default, but also many domains where it is not; in those someone can respect privacy and at the same time refuse to deal with anonymous partners, and it's an entirely reasonable choice that they should be able to make not only in theory but in practice - having an effective, secure mechanism for a person to verify their identity to someone else.

Proper identities are a key basis for trust - without them you can do one-off immediate barters (perhaps many times), but prolonged relationships, various forms of credit and "credit-like-effects", accumulation of reputation are highly beneficial for society; and from the perspective of incentives it's worth noting that the harder it is to "get away with" betraying trust and start from zero, the less incentive there is to defect and more incentive to cooperate; there's a good reason why the game theory iterated Prisoner's dilemma (which relies on preserving identities) gets so much better average results for everyone than non-iterated or fully anonymized Prisoner's dilemma.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#174
post #146

Earlier quoted context omitted.

I mean sure, you can, but it's ridiculously inconvenient. If an online service like eBay, Facebook or Uber required this level of verification, people would (rightly) tell them to piss off and use a competing service instead.

> If an online service like eBay, Facebook or Uber required this level of verification, people would (rightly) tell them to piss off and use a competing service instead. Well, we'll see once the government forces through the "anti-troll" bill that does require a similar level of verification, next year. [0] https://www.theregister.com/2021/11/29/australia_troll_bill/

Interesting. Could kill two birds with one stone.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#175
post #46
post #39

SMS-based 2FA needs to be eliminated completely. Authenticator apps need to come preinstalled as an essential utility on every OS. There doesn't seem to be a whole lot of pressure to improve 2FA security.

Doesnt that force people to not only use smartphones, but "approved" smartphones (read Android/iOS) with locked bootloaders and no root access (or the bank authenticator app will refuse to run)?

A dedicated 2FA token (yubikey, or many other brands) is also a reasonable option, and many systems support these standards (U2F/FIDO2).
Post reply on HN