Live data from Hacker News

Former telecom manager admits to doing SIM swaps for $1k

bleepingcomputer.com

11–20 of 87 posts

Re: Former telecom manager admits to doing SIM swaps for $1k

#11
And this is where paranoids have the upper hand. Have a secondary secret phone number from another carrier exclusively for sms confirmations, using a dumb phone, which must be turned off when not expecting an automated code. Preferably a prepaid sim bought anonymously. Extra points if bought in another country and has coverage in your area.

Re: Former telecom manager admits to doing SIM swaps for $1k

#12

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

So you want to give your biometric info to a telecom? Are you nuts? We already have enough problems getting people to understand "IP's/SIM's/MAC's identify devices, not users".

We don't need to make shit worse.

Re: Former telecom manager admits to doing SIM swaps for $1k

#13

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

The telco is in charge of what SIM is mapped to a given number. There's not anything technical the customer can do there; access control is up to the telco.

The telco also needs a process to reclaim the number when you stop paying for it.

Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions.

If you're really worried about it, I guess you could look into what it takes to get a number block assigned to you as a competitive telco. That would likely be hard to get transfered out from under you, but the effort may not be worth it.

Also, if the price to get a sim swap is $1k (plus a % of ill gotten gains!), that's high enough to keep out untargetted attacks, IMHO, which isn't a terrible place to be.

Re: Former telecom manager admits to doing SIM swaps for $1k

#14
> while he was a manager for a telecom firm. [...] abused his managerial position and highly privileged account at a mobile telecommunications store

Does not naming the company suggest that it's not considered liable?

> indicate five victims

Over what time period? Did the company detect and halt this quickly, and was conscientious about referring it to law enforcement?

I'm willing to agree a store/carrier/brand should be given a pass in a particular instance, but the bar for protecting against SIM-swapping has to be pretty high, considering what an attractive vulnerability that is.

With poor technology and poor regulation around some big-ticket authentication problems right now, one mechanism we do have is brand reputation.

For example, if people seem to keep hearing about SIM swaps involving carrier X or store Y, then some people are going to start thinking that brand is sketchy, and more likely to get your bank account emptied or computer accounts hacked. So then all the brands would have more incentive to be very diligent about internal controls, very cautious about partners and outsourcing, etc.

But if it's always just an unnamed phone store SIM-swapping for an unnamed carrier, or an unnamed carrier's support call center, then that brand reputation mechanism is defeated.

Re: Former telecom manager admits to doing SIM swaps for $1k

#15
post #14

> while he was a manager for a telecom firm. [...] abused his managerial position and highly privileged account at a mobile telecommunications store Does not naming the company suggest that it's not considered liable? > indicate five victims Over what time period? Did the company detect and halt this quickly, and was conscientious about referring it to law enforcement? I'm willing to agree a store/carrier/brand shoul…

Telecom in New Jersey is code for Verizon Wireless[1].

If I were the Verizon Wireless CEO, I'd own it and pledge to resolve as best I can. And maybe they have, I haven't looked yet.

Edit: I had it backwards. Not AT&T, but rather Verizon. Changed. "Telecom in Georgia" would allude to AT&T. "Telecom in Kansas (or maybe Bellevue, WA now)" to T-Mobile, etc.

1. https://en.wikipedia.org/wiki/Verizon_(mobile_network)

Re: Former telecom manager admits to doing SIM swaps for $1k

#16
post #5

Why aren’t they naming the “telecommunications store”? Does knowing the employee did it make the company liable for damages?

The court documents don’t name the store, so the reporters may not know the store. The company may have turned in the employee with the understanding they would just be “Company 1” in all court documents.

Re: Former telecom manager admits to doing SIM swaps for $1k

#17
post #6

This is a timely post. I was going to do an "ask HN" on the best way to prevent a sim swap. I had heard about locking the SIM but then I heard this does not give much protection. What are your thought on best protection methods??

I've worked for two UK telcos. There is no technical measure which you can apply.

Locking your SIM prevents someone from physically stealing the card and putting it in a different device - unless they know the PIN which protects it.

But that isn't the attack here.

The phone number does not belong to you - the network operator defines which SIM it points to. So a suitably authorised person at the telco can point the number to a new SIM card. That's helpful if you've lost your SIM but bad if an attacker wants to divert your number.

The best thing you can do is set a strong password on the account you have with the operator. You can also try ringing them and pretending to be you - see if they'll initiate a swap without proper authentication. If they do - move your number to a more reputable provider.

But there's nothing you as an individual can do to prevent a corrupt employee making the change without authorisation.

Re: Former telecom manager admits to doing SIM swaps for $1k

#18

And this is where paranoids have the upper hand. Have a secondary secret phone number from another carrier exclusively for sms confirmations, using a dumb phone, which must be turned off when not expecting an automated code. Preferably a prepaid sim bought anonymously. Extra points if bought in another country and has coverage in your area.

Does that help against an attacker determined enough to hack you that he'll pay $1000 for a SIM swap? Surely he has channels to figure out your "secret" phone number since you registered it with the service he's trying to hack into.

Re: Former telecom manager admits to doing SIM swaps for $1k

#19
post #15
post #14

> while he was a manager for a telecom firm. [...] abused his managerial position and highly privileged account at a mobile telecommunications store Does not naming the company suggest that it's not considered liable? > indicate five victims Over what time period? Did the company detect and halt this quickly, and was conscientious about referring it to law enforcement? I'm willing to agree a store/carrier/brand shoul…

Telecom in New Jersey is code for Verizon Wireless[1]. If I were the Verizon Wireless CEO, I'd own it and pledge to resolve as best I can. And maybe they have, I haven't looked yet. Edit: I had it backwards. Not AT&T, but rather Verizon. Changed. "Telecom in Georgia" would allude to AT&T. "Telecom in Kansas (or maybe Bellevue, WA now)" to T-Mobile, etc. 1. https://en.wikipedia.org/wiki/Verizon_(mobile_network)

AT&T is headquartered in Dallas, TX. Verizon Wireless headquarters is in New Jersey.

Re: Former telecom manager admits to doing SIM swaps for $1k

#20
post #13

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

The telco is in charge of what SIM is mapped to a given number. There's not anything technical the customer can do there; access control is up to the telco. The telco also needs a process to reclaim the number when you stop paying for it. Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions. If you're really worried about it, I guess you coul…

This is why we have DNS {shudder in disgust}.
Post reply on HN