Earlier quoted context omitted.
The eSIM is going to be more expensive than a regular SIM since no MVNO I'm aware of in the US supports eSIMs
I'm also not aware of any but that's less about whether they're actually available and almost entirely because like 7.6 billion other people, I don't live in the US.
From email to phone number, a new OSINT approach (2019)
41–50 of 127 posts
Re: From email to phone number, a new OSINT approach (2019)
#42Earlier quoted context omitted.
I'm also not aware of any but that's less about whether they're actually available and almost entirely because like 7.6 billion other people, I don't live in the US.
Considering how we were talking about how dual-SIM phones are niche in the US , I think my comment was rather relevant.
But regardless: using your existing 5 year old iPhone with an eSIM that isn't "cheap" is still going to be cheaper than buying a new dual-sim phone.
Re: From email to phone number, a new OSINT approach (2019)
#43Earlier quoted context omitted.
> For the second SIM option, that requires a dual-SIM device Or a device that supports an eSIM, which is every iPhone since 2018, for starters.
The eSIM is going to be more expensive than a regular SIM since no MVNO I'm aware of in the US supports eSIMs
Re: From email to phone number, a new OSINT approach (2019)
#44One thing I've always wondered is how security researchers feel justified in releasing tools like the one in this blog post to the public. I can almost certainly say that the number of bad or creepy uses for an automated email to phone number generating tool massively outweighs the good reasons for having one. Does he get a pass because he's doing this for "research" and it's a grey area anyways? Does he feel better…
I think the idea is to highlight the bad security practices that allow this in hopes that these companies patch these holes (in this case reduce leaked data in the password reset process). A GREAT example of this was when Firesheep forced Facebook (and countless other sites) into embracing https. Firesheep was a firefox plugin that anyone could run on a public wifi (e.g. coffee shop) and instantly start getting the p…
Re: From email to phone number, a new OSINT approach (2019)
#45Re: From email to phone number, a new OSINT approach (2019)
#46lol > Paypal, which displays five digits including area code to anyone knowing the email address (but only three if the attacker knows the target’s password), decided this is working as designed and will not take action. Wild. Does anyone know how scammers are getting numbers off of LinkedIn? Or correlating them to numbers from elsewhere? I know a company whose employees are constantly getting fake CEO texts.
I just realized this is from 2019 and confirmed this literally still works on PayPal. SMH
I once called PayPal to report an "your account is suspended" phishing email and they angrily told me to follow the directions in the email.
Re: From email to phone number, a new OSINT approach (2019)
#47> If it is a requirement, consider using a virtual number like Google Voice or even a dedicated SIM that you only use for this purpose and never give the number away. For the second SIM option, that requires a dual-SIM device, which are still fairly niche in the US. When it comes to VOIP numbers, unfortunately, many sites look up phone numbers and block VOIP providers, which sucks because Android still has no good wa…
> For the second SIM option, that requires a dual-SIM device Or a device that supports an eSIM, which is every iPhone since 2018, for starters.
Re: From email to phone number, a new OSINT approach (2019)
#48Earlier quoted context omitted.
Hell a lot of people have a last 4 digit that is literally just their mothers birth year.
Last four of their SSN? That makes no sense, those digits are sequentially assigned at the issuing office.
Re: From email to phone number, a new OSINT approach (2019)
#49There's one missing piece in that article, and it's the CNAM database (US only). CNAM is the database that carriers use to give you alphanumeric caller ID ("SMITH JOHN" instead of "+1 (555) 123-4567"). Many carriers don't display this data as far as I believe, but most of them make it available. Querying that database isn't free, but you could probably find a way to do it for a few hundred numbers relatively cheaply.…
Why is this not tied to a person's SSN (if possible)?
The point of that database is to display a recognizable name to the people you call, so that they know it's you. A recognizable name isn't always the one on your birth certificate (particularly in the US). There are also businesses, who want their business name there.
Re: From email to phone number, a new OSINT approach (2019)
#50Earlier quoted context omitted.
> For the second SIM option, that requires a dual-SIM device Or a device that supports an eSIM, which is every iPhone since 2018, for starters.
I guess dual SIM is different from having eSIM+physical SIM. Dual SIM typically allows both SIMs/phone-numbers to be active and when you receive a call, you will know which number is being called. With eSIM+physical SIM card, only one can be active at a time. The other has to be disabled. At least, this is what I found few years back.