Live data from Hacker News

NY Man Pleads Guilty in $20M SIM Swap Theft

krebsonsecurity.com

11–20 of 176 posts

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#11

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

>We have Post Offices in nearly every corner of this country. How about turning them into a kind of value-added identity verification

When I opened a bank account (n26) in Germany this is how they verified my identity (along with a brief video call) as a foreigner so the idea has merit.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#12

Earlier quoted context omitted.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One thing I don't understand about the suggestion to remove my phone number from 2FA is that 1FA seems worse. I'd prefer something like Google authenticator, but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do?

> but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do?

Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. If you really need to keep that account for reason X, move out all your assets to another bank and keep enough funds to fund X there.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#13

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

Going through some processes on DMV and USCIS recently I noticed both of them were using Id.me

Seems like a private company providing services to these gov agencies on authentication. Seems like a better solution than showing up at the post office.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#14
>Truglia is still being criminally prosecuted in Santa Clara, Calif., the home of the REACT task force, which pursues SIM-swapping cases nationwide. In November 2018, REACT investigators and New York authorities arrested Truglia on suspicion of using SIM swaps to steal approximately $1 million worth of cryptocurrencies from Robert Ross, a San Francisco father of two who later went on to found the victim advocacy website stopsimcrime.org.

holy shit, no wonder people are going dark. yall better hide.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#15
post #5

Earlier quoted context omitted.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One of the few things I miss about giving up my landline a couple years ago is that I pretty much have to give out my cell phone number for anything that needs a valid phone number. (yes, I could use Google Voice or some sort of VOIP number but that starts making things complicated.) I used to be very selective at giving out my cell number.

> yes, I could use Google Voice or some sort of VOIP number but that starts making things complicated.

You should soldier through it. Google Voice is a decent free service domestically, unless paranoid. I use it in the reverse manner as I expect you would intend (if you'd intend to generate many virtual throw away numbers to forward back to your phone until the forwarding is manually severed). My actual phone number has changed many times over the years, but my GV number stays the same. Eventually, I got rid of my phone altogether. That was January 2014. But jobs will often require I carry the on-call cell (which I almost never need to use and just for work). Boy I sure miss those cell phone bills every month, not. I just realized GV has saved me at least $10K since I cancelled my cell contract.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#16

Tangentially, the FCC is forcing the hand of mobile carriers on this. T-Mobile just the other day has updated their policy so that two employees must be present and part of the process to swap a customer’s SIM. The perils of your phone number being your identity. Refreshing to see these active theft and wire fraud prosecutions.

That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary. Also,…

One of the advantages of using Google Fi as your phone provider on a Google phone: there's no SIM, and you have to log in to the phone on your Google account in order to transfer phone/SMS service there. So an attacker can't use a SMS hijack to steal 2FA codes unless they've already compromised your Google account (which is hopefully a higher bar than convincing some random phone shop employee).

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#17

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

There are already standard ways of doing brick and mortar identity verification, and in somewhat surveillance-resisting ways even! The most common is "notarization" - a state-deputized "notary" verifies that you are who you say you are, and then endorses your signed document with a special stamp and a signature. Another common one used for financial transactions is a "medallion stamp", wherein not only do they verify your identity, but the institution doing the medallion stamp also takes on the risk for a fraudulent transaction.

Both are generally available for free by being a customer of your local small bank or credit union. These could be easily adopted by web companies for password resets, account withdrawals above self-set limits, etc.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#18
1) The ability to reset account credentials or get into a service just by using a phone number is not real 2FA and is a huge security risk generally. SMS based 2FA is not real 2FA.

2) Social engineering mobile phone first-tier customer service reps into doing a SIM swap is not hard at all.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#19

Earlier quoted context omitted.

One thing I don't understand about the suggestion to remove my phone number from 2FA is that 1FA seems worse. I'd prefer something like Google authenticator, but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do?

> but none of my banks offer that. Did I misunderstand the suggestion? Is there something else I should do? Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. If you really need to keep that account for reason X, move out all your assets to another bank and keep enough funds to fund X there.

> Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there.

Have any suggestions for a bank that supports TOTP? I have yet to find a decent bank in the US that supports this.

Re: NY Man Pleads Guilty in $20M SIM Swap Theft

#20

I wonder if the following idea has occurred to anyone else? We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc. We have Post Offices in nearly every corner of this co…

There's a number of KYC services where you're basically asked to be filmed and a person in a call centre looks at it and decides whether it's really you. When I went looking at them they were boasting with using AI, and then in the meeting it turned out it was mostly farmed out to someone in India.

You misread. They're using Al, he's in Chennai and on call 24/7.
Post reply on HN