3 ms·
Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks. The lack of a physical SIM does not give mo
by buildbuildbuild 3y ago
Be careful, I trace cryptocurrency for scam and hack victims and have personally seen GV transfers used in attacks.
The lack of a physical SIM does not give more safety. "SIM Swap" means "convincing a system or human to transfer a phone number." A GV number is just as easy to transfer as any other phone number.
- lxgr 3y agoI’d call that a number porting attack. A SIM swap to me is convincing the current provider to provision a new SIM for an existing line, which the attacker can then use to receive texts addressed to the victim. Porting attacks are definitely possible against Google Voice, but these require confirming the port in the target account first, no? And the Google Voice equivalent to a SIM swap would just be a compromise of the Google account itself. Definitely not impossible, and I know I’m tying my availability to a company not exactly known for being the best custodian for that – but I’ll take my chances with them over any phone provider.
- buildbuildbuild 3y agoGoogle will not share how threat actors are pulling it off but it definitely is happening. (see the Terpin v. AT&T lawsuit for why they might not be disclosing the vector) There are "fingerprint" cookie marketplaces that sell tokens from malware-compromised computers and allow you to make HTTP requests from a victim's connection, this could be one approach. There are also scammer call centers that will call unsuspecting people pretending to be Google, Coinbase, AT&T, or whomever, and have them click buttons in user interfaces. I've seen entire Google accounts deleted with no recourse due to this "suspicious activity" that victims had no control over. Computer says no, and it's near-impossible to get in touch with a human at Google. (I agree with you on terminology but media reports tend to group number porting attacks in with "SIM swaps")
- Obscurity4340 3y agoIs there a reason that would-be hackers are not preempted by requiring a specific device, pins, etc with no kill-switch or social engineering available (like, you lose your credentials, there's nothing we can do, its gone)? It sometimes feels like the system is deliberately designed so certain "legitimate" actors have a backdoor into any given system...
- theolivenbaum 3y agoThe only time where Google's absolute lack of customer service for end users might pay off
- joecool1029 3y ago> A GV number is just as easy to transfer as any other phone number. There is nobody to social engineer (it's Google, they hate customer service) and the system rejects all port-out requests until you unlock the number by paying a few dollars which requires breaking into the Google Account to begin with. It is absolutely not the same as compromising an employee of a carrier. To be clear I'm describing Google Voice which is purely a VOIP service, not Google Fi which is a MVNO.