5 ms·
Phone numbers are trivial to spoof or steal and there is currently no way to protect against that.
by macrolime 3y ago
Phone numbers are trivial to spoof or steal and there is currently no way to protect against that.
- YetAnotherNick 3y agoCare to explain how can I spoof other's phone number. Also phone is as hard to steal as any device where key is stored. In fact, people will remember their phone is stolen much before than the usb key or laptop or anything else.
- p_l 3y agoIf you can get S7 link with Telco, in most cases it's trivial to spoof Caller ID signals, as those are essentially forwarded from originating network. Getting direct S7 link isn't as hard as it sounds, it's IIRC common thing if yo want to run VOIP provider. Your telco's NOC can at best track what "port of entry" the call came from but can't force the Caller ID go be truthful.
- xur17 3y agoI imagine it has changed, but 10-ish years ago I recall having a cheap VoIP account that just let me enter whatever phone number I wanted as the caller ID.
- p_l 3y agoIt's very much a "honor system". If VoIP provider doesn't do due diligence, the other networks can't really check the value, especially since number porting became norm
- MichaelZuo 3y agoFor the first few dozen times sure, but after the hundredth or so report of a scam call associated with a spoofed number, the VoIP provider should be blocked by the telco. That is if they were allowed to do so.
- p_l 3y ago"should" is doing a lot of heavy lifting in that statement :)
- xorcist 3y agoThere is an authentication between your phone and your telco, but there is no authentication between your telco and others. Any telco in the world (and there are many) or someone who has bribed (or hacked) someone who works there can say "this phone is now roaming our network" and traffic gets routed there. These things are usually discovered but not before a call or sms goes through. There are also other possibilities such as diverting calls available to someone with the right access to the signalling network. Anything that's unauthenticated and unencrypted should be regarded as insecure, really.
- HeatrayEnjoyer 3y agoIf it's authenticated how can one telco sign a call with the key of another telco?
- wolfgang42 3y agoThere is (or was) no authentication within the core of the public switched telephone network, since it was designed at a time when that was impractical and physical infrastructure was assumed to be reasonably secure. So you don’t need to fake signing, you just say “Hey, +1-555-555-5555 roamed onto my network and is making a phone call” and the recipient takes this at face value. (“Blue boxing” to fake the phone system into giving you free long distance phone calls worked for similar reasons.) STIR/SHAKEN is supposed to fix this, though I don’t know how far along implementation has actually gotten.
- HeatrayEnjoyer 3y agoWhat happened that made it insecure? I've heard of stir shaken but I recall FCC ordered it mandatory multiples years ago. Did that not happen?
- xorcist 3y agoThey let untrusted people in on the trusted network, basically. Telcos are no longer considered national security. Privatization has given us a cheaper and better communication, but security hasn't always kept up. The authencation above is between the terminal and the location registry (simplified, there are several other components involved). Not internationally between the telcos.
- internet101010 3y agoFrom what I gather it depends on the carrier. T-Mobile is supposedly the easiest and Verizon the most difficult. The Darknet Diaries (link below) recently did an episode on how the sim swapping thing works and how expensive it is to get it done. https://www.youtube.com/watch?v=Cjy8-rVXO7o&t=2190s https://www.youtube.com/watch?v=Cjy8-rVXO7o&t=2190s
- Aloisius 3y agoExcept one can simply ask to call them back to verify.
- mmvasq 3y agoOnce you have lived through reporting to a telco you have been dealing with fraud - you learn the procedures are in a scripted loop, everywhere. The answer will probably be go to store get new sim and never reach conclusion it was swapped for people who do not investigate their situation. I haven’t dealt with sim swapping yet some pretty heinous organized crime now and the folks are nice yet you will never walk away knowing the cause or source of an incident.