Live data from Hacker News

Former telecom manager admits to doing SIM swaps for $1k

bleepingcomputer.com

21–30 of 87 posts

Re: Former telecom manager admits to doing SIM swaps for $1k

#21

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

Just treat sms and call as insecure

Re: Former telecom manager admits to doing SIM swaps for $1k

#22

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

Biometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)

Re: Former telecom manager admits to doing SIM swaps for $1k

#23

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

> On a more technical note, is there any safeguard against SIM swaps?

The only solution is to refuse to use SMS for 2FA. If a service requires it, use a different service.

Re: Former telecom manager admits to doing SIM swaps for $1k

#24
post #12

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

So you want to give your biometric info to a telecom? Are you nuts? We already have enough problems getting people to understand "IP's/SIM's/MAC's identify devices, not users ". We don't need to make shit worse.

I'm not saying it's ideal, it was just an example of something that I thought could address the issue. I agree that we should limit PII being given to companies, but I'm conflicted on how the average Joe can maintain some semblance of security as hackers get better at finding holes. If the software can identify you based on something that only you have, then that's a tall barrier to cross for hackers that also doesn't require a steep learning curve for most.

Just to reiterate, I am personally a fan of maintaining anonymity, particularly online. I'm just concerned that our increasingly aging population won't be able to keep up with security best practices and we may need some braindead solutions to keep them safe.

Re: Former telecom manager admits to doing SIM swaps for $1k

#25

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

> For carrying the unauthorized number porting, Katz received $1,000 in Bitcoin per SIM swap (total of $5,000), plus an (unspecified) percentage of the profits earned from the illicit access to the victims' devices.

So, a little more than $1k pp

Re: Former telecom manager admits to doing SIM swaps for $1k

#26

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

Biometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)

That makes sense - maybe something closer to a passphrase-protected SIM could work?

Re: Former telecom manager admits to doing SIM swaps for $1k

#27
post #13

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

The telco is in charge of what SIM is mapped to a given number. There's not anything technical the customer can do there; access control is up to the telco. The telco also needs a process to reclaim the number when you stop paying for it. Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions. If you're really worried about it, I guess you coul…

Very informative - thanks for the explanation! I also forget that these attacks are usually very targeted (I guess I just imagine criminals swimming in money despite the old adage). I'll just have to do my best to be an unremarkable person.

Re: Former telecom manager admits to doing SIM swaps for $1k

#29
post #6

This is a timely post. I was going to do an "ask HN" on the best way to prevent a sim swap. I had heard about locking the SIM but then I heard this does not give much protection. What are your thought on best protection methods??

The best way to prevent a SIM swap is to not let your phone number be used as a trusted piece of authentication.

Sure, what this guy did was criminal. But not nearly as criminal as it should be for companies to unilaterally force customers into using snake oil authentication methods, just so they can check some new compliance boxes and pretend to be adding security.

Re: Former telecom manager admits to doing SIM swaps for $1k

#30
post #17
post #6

This is a timely post. I was going to do an "ask HN" on the best way to prevent a sim swap. I had heard about locking the SIM but then I heard this does not give much protection. What are your thought on best protection methods??

I've worked for two UK telcos. There is no technical measure which you can apply. Locking your SIM prevents someone from physically stealing the card and putting it in a different device - unless they know the PIN which protects it. But that isn't the attack here. The phone number does not belong to you - the network operator defines which SIM it points to. So a suitably authorised person at the telco can point the n…

I never thought about pentesting my service providers - sounds fun and useful! I'll try this the next time I have a moment.
Post reply on HN