3 ms·
Given the diligence with which the attacker worked on Sony via social engineering to gain access to the account, what on earth makes you think the same techniqu
by venantius 8y ago
Given the diligence with which the attacker worked on Sony via social engineering to gain access to the account, what on earth makes you think the same technique wouldn't work just as well for a telecom company? You don't need to "hack" the network, just the customer service rep. Just say you lost your phone :)
- Illniyar 8y agoThe telecom company has identifying information about you that hackers are unlikely to be able to fake - such as an home address to where they send your new sim card, or physical locations where it's much harder to work these kind of social engineering. The telecom company also have more regulation and the stakes are higher for letting someone basically steal your number - it usually means they have a much stricter protocol to giving someone a new sim card - they'll require a physical presence, they can actually call your phone to verify you aren't a fake, they'll require confirmation of card ownership or an ID for states/countries that have them.
- venantius 8y agoI am going to refer to this thread, which shows exactly how easy it is and how difficult it is to defend yourself against: https://news.ycombinator.com/item?id=18194701 https://news.ycombinator.com/item?id=18194701
- Illniyar 8y agoFrom the thread: "T-Mobile has put in place some protections to prevent unauthorized transfers of your account to new SIM cards, I just had to deal with them last night - actually. Swapping SIM cards for a line must either be done in-store where your photo ID can be verified, or over the phone but only after confirmation of a OTP sent to account managers via SMS. I know T-Mobile actually had some issues with this in the past, so even though I miss the convenience of going to t-mobile.com/sim to swap a card out I feel it's a much better solution security-wise." Obviously it differs from provider to provider and time, but it'll start moving towards better security. 2FA has only recently gotten popular