Live data from Hacker News

Former telecom manager admits to doing SIM swaps for $1k

bleepingcomputer.com

61–70 of 87 posts

Re: Former telecom manager admits to doing SIM swaps for $1k

#61

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

> is there any safeguard against SIM swaps

There is. Some Russian banks detect when SIM identifier has changed and refuse to send SMS codes to a new SIM card.

Re: Former telecom manager admits to doing SIM swaps for $1k

#62

The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.

Still better than no second factor

Re: Former telecom manager admits to doing SIM swaps for $1k

#63

The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.

Wasn’t it heavily pushed by tech giants for data harvesting purposes, then cargo cult copied by everyone else?

If that is so, the same tech giants are now pushing for passkeys, which is actually close to the ideal solution.

Re: Former telecom manager admits to doing SIM swaps for $1k

#64

And this is where paranoids have the upper hand. Have a secondary secret phone number from another carrier exclusively for sms confirmations, using a dumb phone, which must be turned off when not expecting an automated code. Preferably a prepaid sim bought anonymously. Extra points if bought in another country and has coverage in your area.

Does that help against an attacker determined enough to hack you that he'll pay $1000 for a SIM swap? Surely he has channels to figure out your "secret" phone number since you registered it with the service he's trying to hack into.

It is more difficult to sim swap a foreign number from another company. Not impossible, of course.

There is also that some services don't accept foreign numbers for authentication. Nor virtual phone numbers.

But it adds a layer of protection, doesn't it? Your known public phone number is one, your verification phone is another one from another carrier.

Re: Former telecom manager admits to doing SIM swaps for $1k

#65

And this is where paranoids have the upper hand. Have a secondary secret phone number from another carrier exclusively for sms confirmations, using a dumb phone, which must be turned off when not expecting an automated code. Preferably a prepaid sim bought anonymously. Extra points if bought in another country and has coverage in your area.

Does that help against an attacker determined enough to hack you that he'll pay $1000 for a SIM swap? Surely he has channels to figure out your "secret" phone number since you registered it with the service he's trying to hack into.

You can probably figure out most people's default phone number by googling their name and going to one of those crappy white pages sites. Then try to login/do a password reset to their services and compare the masked phone number to the ones on the site. No advanced hacking or special channels required.

The trouble with compartmentalizing with a separate phone is that the company with your money probably also sold your secret phone number (that they only required for security) so it will probably also show up on that whitepages site.

Re: Former telecom manager admits to doing SIM swaps for $1k

#66
post #50

I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation. The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard. The good news is…

last 4 digits of SSN are regularly found in data leaks. what is worst is you CANNOT change it if your data is leaked from 3rd party site. conclusion: NEVER use phone number as 2FA, Always assume your cell number will be swapped, always use other more secure factor, especially if it has anything to do with money $$$

Do you mean never use your phone number as 2FA if other 2FA options are not available? Most major retail banks (BofA, Chase, Citi, etc) all offer mobile as the only, if not primary, 2FA option.

Re: Former telecom manager admits to doing SIM swaps for $1k

#67
post #8

This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.

I prefer TOTP for privacy and control reasons, but I think you're overselling the disadvantages of SMS here. If you have to find and pay an inside guy to do SIM swaps, they'll be limited in the number they can do before getting caught so it really will only be suitable to do targeted attacks on targets you're pretty sure have something worth stealing. There was a DND that talked about how sim swaps used to be a cakew…

I agree it's a threat that is not exactly easy to pull off. But my main issue with is is represents an attack vector that you can do exactly nothing to defend against yourself. If you use other forms of MFA, you are at least in charge. Sure you can lose your TOTP seed or something, but you have agency in how it is stored. SMS forces you to rely on companies that have log histories of failing to protect your phone number.

Re: Former telecom manager admits to doing SIM swaps for $1k

#68
post #50

I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation. The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard. The good news is…

last 4 digits of SSN are regularly found in data leaks. what is worst is you CANNOT change it if your data is leaked from 3rd party site. conclusion: NEVER use phone number as 2FA, Always assume your cell number will be swapped, always use other more secure factor, especially if it has anything to do with money $$$

Unfortunately the vast majority of services only support SMS or email 2FA. I've set up a real 2FA app for every site I use that supports it, and that number is four: gitlab, github, discord, and my domain name provider. My bank, my utilities, my insurance, everything only supports SMS if they support 2FA at all. Most just don't.

Re: Former telecom manager admits to doing SIM swaps for $1k

#69
Until carriers are hit with substantial penalties, this will continue. T-Mobile allowed a SIM swap at a retail store on my line, which I noticed in real-time. Corporate couldn’t have cared less, even though I had all the names and location and detail from the store after I investigated myself.

Worst part? They send a text saying, in effect, “we’re chabeing your SIM in 15 minutes unless you call us”

This is AFTER their supposed security improvements, but then again so are the two other hacks where customer data was leaked.

Don’t use SMS 2FA and set the most obnoxious ringtone for your carrier’s short codes. Take the most defensive approach to being a cell customer because the carriers won’t save you.

Re: Former telecom manager admits to doing SIM swaps for $1k

#70

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

Biometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)

Biometrics are never a good idea in general.

You can be court ordered/forced to put your thumb on the home button.

You can’t be forced to remember a password you “forgot” ;)

Post reply on HN