Live data from Hacker News

Former telecom manager admits to doing SIM swaps for $1k

bleepingcomputer.com

81–87 of 87 posts

Re: Former telecom manager admits to doing SIM swaps for $1k

#81
post #8

This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.

SMS MFA thwarts the vast vast vast majority of attacks that a typical user reality. Yes, you’re almost certainly a typical user. Considering usability issues related to TOTP, SMS MFA well and truly has its place. Computer nerds get so giddy about TOTP that they keep making these ‘perfect v good’ arguments. Be realistic here.

Re: Former telecom manager admits to doing SIM swaps for $1k

#82

The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.

Because SMS MFA is orders of magnitude more secure than no MFA, and there are barriers to entry for TOTP that there simply aren’t for SMS. This is an unsubstantiated conspiracy theory.

Re: Former telecom manager admits to doing SIM swaps for $1k

#83
post #13

Earlier quoted context omitted.

The telco is in charge of what SIM is mapped to a given number. There's not anything technical the customer can do there; access control is up to the telco. The telco also needs a process to reclaim the number when you stop paying for it. Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions. If you're really worried about it, I guess you coul…

Very informative - thanks for the explanation! I also forget that these attacks are usually very targeted (I guess I just imagine criminals swimming in money despite the old adage). I'll just have to do my best to be an unremarkable person.

I’m sure you’re doing this without trying, much like the vast majority of others.

Re: Former telecom manager admits to doing SIM swaps for $1k

#84

Earlier quoted context omitted.

Biometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)

Biometrics are never a good idea in general. You can be court ordered/forced to put your thumb on the home button. You can’t be forced to remember a password you “forgot” ;)

You can be jailed until you remember.

Re: Former telecom manager admits to doing SIM swaps for $1k

#85

Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…

> is there any safeguard against SIM swaps There is. Some Russian banks detect when SIM identifier has changed and refuse to send SMS codes to a new SIM card.

I just ported my number to a new carrier and had to re setup sms on two separate American banks.

Re: Former telecom manager admits to doing SIM swaps for $1k

#86

Earlier quoted context omitted.

Biometrics are never a good idea in general. You can be court ordered/forced to put your thumb on the home button. You can’t be forced to remember a password you “forgot” ;)

You can be jailed until you remember.

You’re missing the point. Even doing that, they still don’t have access.

Re: Former telecom manager admits to doing SIM swaps for $1k

#87

I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation. The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard. The good news is…

scammers are not allowed to stay here. @Josh Goldbard
Post reply on HN