Live data from Hacker News

Former telecom manager admits to doing SIM swaps for $1k

bleepingcomputer.com

31–40 of 87 posts

Re: Former telecom manager admits to doing SIM swaps for $1k

#31

And this is where paranoids have the upper hand. Have a secondary secret phone number from another carrier exclusively for sms confirmations, using a dumb phone, which must be turned off when not expecting an automated code. Preferably a prepaid sim bought anonymously. Extra points if bought in another country and has coverage in your area.

> secret phone number

You have to give this phone number to a bunch of services that you use, i.e. all the ones that do sms confirmations. One data breach, and it isn't "secret" anymore.

Re: Former telecom manager admits to doing SIM swaps for $1k

#32

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

ATT has account passcodes, but not sure how high up of an employee you have to be at ATT to do a SIM swap without a customer’s passcode.

Re: Former telecom manager admits to doing SIM swaps for $1k

#33
I worked in telecom for many years.

Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation.

The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard.

The good news is that they made it much much harder for retail employees to access your account without your consent. You almost universally need a pin or last 4 of a social to access a customer account now without a manager override.

This is a huge improvement from the time I worked entry-level retail at AT&T when I could see any customer’s full social or tax ID by typing their phone number into the point of sale!

Imagine being 18, poor as fuck, and able to see anyone’s financial information. I was moral, but I knew tons of people who just took out loans as if they were the customer committing massive fraud. It was very hard for AT&T to catch this kind of identity theft. I’m glad systems are becoming safer over time.

Re: Former telecom manager admits to doing SIM swaps for $1k

#35
The two factor authorization using a phone number isn't such a strong protection after all, is it.

I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.

Re: Former telecom manager admits to doing SIM swaps for $1k

#36
post #14

> while he was a manager for a telecom firm. [...] abused his managerial position and highly privileged account at a mobile telecommunications store Does not naming the company suggest that it's not considered liable? > indicate five victims Over what time period? Did the company detect and halt this quickly, and was conscientious about referring it to law enforcement? I'm willing to agree a store/carrier/brand shoul…

TFA identified the period as between may 10th and may 20th, 2021 when the sim swaps occurred.

Also, once the log was audited it pointed to the individual that is facing sentencing in July, no?

Re: Former telecom manager admits to doing SIM swaps for $1k

#37

The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.

Wasn’t it heavily pushed by tech giants for data harvesting purposes, then cargo cult copied by everyone else?

Re: Former telecom manager admits to doing SIM swaps for $1k

#38
post #8

This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.

If you have access to someone’s email account can’t you dl the totp authenticator and bypass this? Effectively that makes email the authenticator which isn’t better than a phone number and device

Re: Former telecom manager admits to doing SIM swaps for $1k

#39

Earlier quoted context omitted.

Biometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)

That makes sense - maybe something closer to a passphrase-protected SIM could work?

Passkeys.

Re: Former telecom manager admits to doing SIM swaps for $1k

#40

I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation. The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard. The good news is…

> You almost universally need a pin or last 4 of a social to access a customer account now without a manager override.

Last four of a social is a terrible additional form of security.

Even four random digit pins isn’t particularly secure if they don’t have proactive monitoring of attempts.

Post reply on HN