This is a good example of why SMS 2-factor is far less secure than TOTP or other methods. You do what everyone tells you, add 2-factor to your account, and then some rando at the local T-Mobile store enables SIM swapping for peanuts, and your whole digital life goes up in smoke.
Former telecom manager admits to doing SIM swaps for $1k
81–87 of 87 posts
Re: Former telecom manager admits to doing SIM swaps for $1k
#82The two factor authorization using a phone number isn't such a strong protection after all, is it. I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.
Re: Former telecom manager admits to doing SIM swaps for $1k
#83Earlier quoted context omitted.
The telco is in charge of what SIM is mapped to a given number. There's not anything technical the customer can do there; access control is up to the telco. The telco also needs a process to reclaim the number when you stop paying for it. Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions. If you're really worried about it, I guess you coul…
Very informative - thanks for the explanation! I also forget that these attacks are usually very targeted (I guess I just imagine criminals swimming in money despite the old adage). I'll just have to do my best to be an unremarkable person.
Re: Former telecom manager admits to doing SIM swaps for $1k
#84Earlier quoted context omitted.
Biometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)
Biometrics are never a good idea in general. You can be court ordered/forced to put your thumb on the home button. You can’t be forced to remember a password you “forgot” ;)
Re: Former telecom manager admits to doing SIM swaps for $1k
#85Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that. On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on thi…
> is there any safeguard against SIM swaps There is. Some Russian banks detect when SIM identifier has changed and refuse to send SMS codes to a new SIM card.
Re: Former telecom manager admits to doing SIM swaps for $1k
#86Earlier quoted context omitted.
Biometrics are never a good idea in general. You can be court ordered/forced to put your thumb on the home button. You can’t be forced to remember a password you “forgot” ;)
You can be jailed until you remember.
Re: Former telecom manager admits to doing SIM swaps for $1k
#87I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation. The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard. The good news is…