5 ms·
From the examples I've seen, the attackers essentially become the customer. They've either socially engineered the customer or done research to gain access to e
by batch12 3y ago
From the examples I've seen, the attackers essentially become the customer. They've either socially engineered the customer or done research to gain access to enough information to validate themselves as the customer. Come up with a solution and sell it. You'll make some money.
- batch12 3y agoWell that got me thinking. You could stand up a third party verification service and sell the offering to companies that don't want to be bothered with authenticating the user. Something like Okta (I know, bad example when talking infosec at the moment) for real life.
- wahnfrieden 3y agoThey won't pay for it
- batch12 3y agoWith the right legal language, I think they would.
- batch12 3y agoI just realized this does exist (kinda) in the US with identogo. Could be an easy service offering for them or a partner for another company focused on the mfa issue.
- dcow 3y agoThere are numerous ID-proofing services out there.
- lxgr 3y agoSomebody already pays for it. Once regulations ensure that it's the companies skimping on KYC themselves, most will happily outsource that task to the cheapest (compliant) provider.
- dcow 3y agoThey pay for Twilio.
- PeterisP 3y agoThat's kind of the point, US Telcos don't really validate customer identity - probably because they can't, due to the general limitations of USA documents leading to relatively easy identity theft where merely having enough information is sufficient to impersonate someone. (A simple test - is your verification process likely to stop someone's parent, spouse or sibling from impersonating them? If no, you're not really verifying identities.) It's not something where a private entity can sell a solution, you need a more solid root of trust for verifying actual identities, like many other countries do, but that's not going to happen in USA any time soon.