7 ms·
Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line wo
by the-chitmonger 3y ago
Man... on top of the obvious moral issue with enabling this hack, I'm astounded that someone would do this for $1k per person. Putting my freedom on the line would be so much more expensive than that.
On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on this type of thing
- salawat 3y agoSo you want to give your biometric info to a telecom? Are you nuts? We already have enough problems getting people to understand "IP's/SIM's/MAC's identify devices, not users". We don't need to make shit worse.
- the-chitmonger 3y agoI'm not saying it's ideal, it was just an example of something that I thought could address the issue. I agree that we should limit PII being given to companies, but I'm conflicted on how the average Joe can maintain some semblance of security as hackers get better at finding holes. If the software can identify you based on something that only you have, then that's a tall barrier to cross for hackers that also doesn't require a steep learning curve for most. Just to reiterate, I am personally a fan of maintaining anonymity, particularly online. I'm just concerned that our increasingly aging population won't be able to keep up with security best practices and we may need some braindead solutions to keep them safe.
- toast0 3y agoThe telco is in charge of what SIM is mapped to a given number. There's not anything technical the customer can do there; access control is up to the telco. The telco also needs a process to reclaim the number when you stop paying for it. Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions. If you're really worried about it, I guess you could look into what it takes to get a number block assigned to you as a competitive telco. That would likely be hard to get transfered out from under you, but the effort may not be worth it. Also, if the price to get a sim swap is $1k (plus a % of ill gotten gains!), that's high enough to keep out untargetted attacks, IMHO, which isn't a terrible place to be.
- pyuser583 3y agoThis is why we have DNS {shudder in disgust}.
- the-chitmonger 3y agoVery informative - thanks for the explanation! I also forget that these attacks are usually very targeted (I guess I just imagine criminals swimming in money despite the old adage). I'll just have to do my best to be an unremarkable person.
- cqqxo4zV46cp 3y agoI’m sure you’re doing this without trying, much like the vast majority of others.
- ikekkdcjkfke 3y agoJust treat sms and call as insecure
- durazabu 3y agoBiometrics like fingerprint scans can only be used as a username, not a password. Reusing passwords is a bad practice and having 200 different biometrics for 200 different services is not realistic. As soon as your fingerprint that you registered on your lost phone is leaked you will be in a world of trouble if you use it for other services. (Also biometrics can change with time)
- the-chitmonger 3y agoThat makes sense - maybe something closer to a passphrase-protected SIM could work?
- toomuchtodo 3y agoPasskeys.
- wutwutwat 3y agoBiometrics are never a good idea in general. You can be court ordered/forced to put your thumb on the home button. You can’t be forced to remember a password you “forgot” ;)
- peddling-brink 3y agoYou can be jailed until you remember.
- wutwutwat 3y agoYou’re missing the point. Even doing that, they still don’t have access.
- cjrp 3y ago> On a more technical note, is there any safeguard against SIM swaps? The only solution is to refuse to use SMS for 2FA. If a service requires it, use a different service.
- ryandrake 3y agoThis works if you know about SIM swapping on day one of your life on the Internet, and refuse from day one. I probably have hundreds of Internet accounts, and no straightforward way to know which ones use SMS for 2-factor without trying to log in to them all. Further, many don’t use SMS for login but they do use it for password resets. So my only hope, if I want to clean house, is to sit down and try resetting my password on 400+ accounts one by one.
- MichaelZuo 3y agoThat still sounds like much less pain and effort then if the worst case scenario happens?
- arusahni 3y ago> For carrying the unauthorized number porting, Katz received $1,000 in Bitcoin per SIM swap (total of $5,000), plus an (unspecified) percentage of the profits earned from the illicit access to the victims' devices. So, a little more than $1k pp
- the-chitmonger 3y agoFair point, I guess shame(?) on him for not being smarter with the proceeds
- lotsofpulp 3y agoATT has account passcodes, but not sure how high up of an employee you have to be at ATT to do a SIM swap without a customer’s passcode.
- justinclift 3y ago> ... I'm astounded that someone would do this for $1k per person. It's entirely possible some of the brighter ones have gotten their co-workers username/password combinations, and are using those when doing dodgy stuff.
- codedokode 3y ago> is there any safeguard against SIM swaps There is. Some Russian banks detect when SIM identifier has changed and refuse to send SMS codes to a new SIM card.
- peddling-brink 3y agoI just ported my number to a new carrier and had to re setup sms on two separate American banks.