6 ms·
What steps do you think you'll be taking to never have to deal with this again?
by smhmd 4y ago
What steps do you think you'll be taking to never have to deal with this again?
- brightball 4y agoIdeally, Verizon should be able to give an “in person only” option for a SIM swap. And that’s the default.
- latchkey 4y agoWouldn't a 'plug' working in a store work around that?
- doctoboggan 4y agoI’ve “locked” my number and it requires a transfer PIN. I hope Verizon’s systems won’t allow a transfer without that pin even with a malicious employee, however I wouldn’t be surprised if they are able to override it. Apparently my attacker had a fake ID with my name and their photo. It’s possible a store employee could override the transfer lock if they are sufficiently convinced it’s really me.
- latchkey 4y agoI've heard many cases of transfer locks being broken. From what I understand, it is even possible to simjack at a higher level than the individual telco. Thus, I don't even bother with stuff like this, the only solution in my eyes is to not rely on SMS 2FA and if you absolutely have to, at least use a GV number. While GV isn't totally secure either, at least it is disconnected a tiny bit from my cell number and doesn't have humans backing it (we all know that Google never answers the support phone).
- igetspam 4y agoThere's also a "run in, punch a guy in the face and steal the tablet" method. Can't get around that either.
- adastra22 4y agoI have this setup with my carrier (not Verizon) and it didn’t stop me from being victim of a sim swap attack twice thereafter.
- doctoboggan 4y agoFirst I “locked” my phone number disabling transfers (although I suspect this is vulnerable to social engineering attacks). I have also frozen my credit with the three credit bureaus (the attacker also opened a new line of credit in my name) I am also closing the bank account that was compromised. They aren’t giving me any info but I suspect the attacker got my debit card via social engineering. It was a new account and I hadn’t even received my debit card yet. I have a subscription to a credit monitoring service as well which has proven its worth in this situation. Otherwise honestly I am not sure what to do. It sucks to know this person has my name, social, phone, and other info. I basically plan to keep my credit frozen indefinitely. I am also disabling text based 2FA for me and my wife wherever possible.
- ajhurliman 4y agoYou need to give your ssn to so many people over your lifetime and you’re essentially trusting that all of them will be trustworthy and secure with it. This could be easily solved with public key cryptography, but it would also confuse so many people it would be hard to implement. If there’s an upside to the crypto craze, maybe it’s teaching people about cryptography basics.
- Gigachad 4y agoWe will literally never teach the whole world to use current crypto tech safely. It needs better UI. At the root of the problem, people will forget passwords and lose physical tokens and will need some other way to restore access.
- ajhurliman 4y agoIf this were being used for SSNs, you'd have a central authority to restore access. If you lose your passport, they can issue you another one and mark the old one as lost/stolen. You can do the same thing for key pairs. The main problem it solves is giving a sketchy client your SSN on your I9 without allowing them to use it/leak it to scam groups to spin up a credit card on your behalf.
- e40 4y agoFreeze your credit at all three of the companies. It's free. It's not that painful to open it when you need it. Everyone should do this ASAP.