Earlier quoted context omitted.
Telecom in New Jersey is code for Verizon Wireless[1]. If I were the Verizon Wireless CEO, I'd own it and pledge to resolve as best I can. And maybe they have, I haven't looked yet. Edit: I had it backwards. Not AT&T, but rather Verizon. Changed. "Telecom in Georgia" would allude to AT&T. "Telecom in Kansas (or maybe Bellevue, WA now)" to T-Mobile, etc. 1. https://en.wikipedia.org/wiki/Verizon_(mobile_network)
AT&T is headquartered in Dallas, TX. Verizon Wireless headquarters is in New Jersey.
Former telecom manager admits to doing SIM swaps for $1k
41–50 of 87 posts
Re: Former telecom manager admits to doing SIM swaps for $1k
#42Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…
> On a more technical note, is there any safeguard against SIM swaps? The only solution is to refuse to use SMS for 2FA. If a service requires it, use a different service.
Re: Former telecom manager admits to doing SIM swaps for $1k
#43Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…
It's entirely possible some of the brighter ones have gotten their co-workers username/password combinations, and are using those when doing dodgy stuff.
Re: Former telecom manager admits to doing SIM swaps for $1k
#44This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.
If you have access to someone’s email account can’t you dl the totp authenticator and bypass this? Effectively that makes email the authenticator which isn’t better than a phone number and device
If you sync your secrets to some cloud service then yes, you are trusting that cloud service. And if you let your TOTP cloud service reset your account with an email then it probably isn't the most secure option.
But the important thing here is that the user is in control. They can memorize their secret if they want to an no one can take it from them. Or they can publish it online if they don't like security. With SMS 2FA you need to trust your telecom provider, I very much don't.
Re: Former telecom manager admits to doing SIM swaps for $1k
#45Meanwhile, SIM swaps continue by malicious actors with seemingly nothing that can be done to stop them. So I can't swap my own SIM without waiting on hold for an hour or two, either by chat or on the phone, but the scammers can do it with apparent impunity. (I have tried messaging T-Mobile's help group on Twitter but they seem to be the only competent support available and thus are also incredibly backlogged.)
I get that providers have to cater to the lowest common denominator but I wish there was a MVNO or similar who would allow use of authenticator keys and maximum level self service, with the understanding that if I break or lose my authentication methods, I am out of luck. Right now, my current carrier seems the worst of both choices.
Re: Former telecom manager admits to doing SIM swaps for $1k
#46The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.
Another benefit is that they can block duplicate accounts with the same phone number, this effectively adds a cost to account creation which can help to reduce spam.
And yes, some will then use it to spam or sell.
I don't think anyone ever thought that SMS 2FA was strong protection. It mostly benefits the service operators by reducing spam and stolen accounts.
Re: Former telecom manager admits to doing SIM swaps for $1k
#47This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.
Re: Former telecom manager admits to doing SIM swaps for $1k
#48The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.
Kinda like SSNs though, I think it's way past the point when a better designed system should have been developed. Sadly, that costs a lot of money.
Re: Former telecom manager admits to doing SIM swaps for $1k
#49Earlier quoted context omitted.
If you have access to someone’s email account can’t you dl the totp authenticator and bypass this? Effectively that makes email the authenticator which isn’t better than a phone number and device
What do you mean by "dl the totp authenticator"? But the answer is no. Without the TOTP secret no one else can generate valid codes. If you sync your secrets to some cloud service then yes, you are trusting that cloud service. And if you let your TOTP cloud service reset your account with an email then it probably isn't the most secure option. But the important thing here is that the user is in control. They can memo…
Re: Former telecom manager admits to doing SIM swaps for $1k
#50I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation. The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard. The good news is…
what is worst is you CANNOT change it if your data is leaked from 3rd party site.
conclusion: NEVER use phone number as 2FA, Always assume your cell number will be swapped, always use other more secure factor, especially if it has anything to do with money $$$