4 ms·
I worked in telecom for many years. Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surpri
by josh2600 3y ago
I worked in telecom for many years.
Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation.
The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard.
The good news is that they made it much much harder for retail employees to access your account without your consent. You almost universally need a pin or last 4 of a social to access a customer account now without a manager override.
This is a huge improvement from the time I worked entry-level retail at AT&T when I could see any customer’s full social or tax ID by typing their phone number into the point of sale!
Imagine being 18, poor as fuck, and able to see anyone’s financial information. I was moral, but I knew tons of people who just took out loans as if they were the customer committing massive fraud. It was very hard for AT&T to catch this kind of identity theft. I’m glad systems are becoming safer over time.
- hjerne 3y agoscammers are not allowed to stay here. @Josh Goldbard
- koolba 3y ago> You almost universally need a pin or last 4 of a social to access a customer account now without a manager override. Last four of a social is a terrible additional form of security. Even four random digit pins isn’t particularly secure if they don’t have proactive monitoring of attempts.
- slt2021 3y agolast 4 digits of SSN are regularly found in data leaks. what is worst is you CANNOT change it if your data is leaked from 3rd party site. conclusion: NEVER use phone number as 2FA, Always assume your cell number will be swapped, always use other more secure factor, especially if it has anything to do with money $$$
- pknomad 3y agoDo you mean never use your phone number as 2FA if other 2FA options are not available? Most major retail banks (BofA, Chase, Citi, etc) all offer mobile as the only, if not primary, 2FA option.
- neon5077 3y agoUnfortunately the vast majority of services only support SMS or email 2FA. I've set up a real 2FA app for every site I use that supports it, and that number is four: gitlab, github, discord, and my domain name provider. My bank, my utilities, my insurance, everything only supports SMS if they support 2FA at all. Most just don't.
- slt2021 3y agoemail is not bad option, at least you can harden your email to use normal 2FA instead of pathetic SMS
- elliottback 3y agoCompletely agree using last-4 SSN is terrible, but some light in the tunnel exists. It is possible to change it, although it is as you would expect, quite annoying: https://faq.ssa.gov/en-us/Topic/article/KA-02220 https://faq.ssa.gov/en-us/Topic/article/KA-02220