3 ms·
>Number porting is a huge and easily performed attack vector, it requires very, very little information Does it need to be? Seems most of it could be avoided i
by puzzlingcaptcha 7y ago
>Number porting is a huge and easily performed attack vector, it requires very, very little information
Does it need to be? Seems most of it could be avoided if the cellular service required a visit at the store with an ID card to clone a SIM card.
- PeterisP 7y ago... which is how it actually works in many countries. In USA "something you know" is enough to impersonate you, elsewhere you'd actually show up with a good quality forgery of passport or gov't ID card, which would cost you more than you might steal from a random person. Since USA has this "root of trust" problem, it's also unreasonably easy to obtain fake USA IDs since you (again) can impersonate people simply with "something you know" even for the purposes of obtaining legitimate IDs. It's not so easy elsewhere (e.g. if you claim you're me and have lost all ID, they'd just check biometrics before reissuing ID). Proper checks of IDs (+ verification of lost&stolen IDs databases) can ensure that identity theft cases are very rare. The identity theft epidemic isn't general worldwide, it's mostly a regional issue specific to USA and some similar countries.