Ontario police warn of SIM swapping fraud
cbc.ca
cbc.ca
What's even more weird - if you happen not own a phone - there's no digital service/website where you can call 911 (or local equivalent). You can't even text 911 in most countries.
(This was also back when, “Our system doesn’t let us do that” wasn’t an economically or socially acceptable response from someone representing a business or agency.)
Now we deal with machines for good and for bad.
Here I am 6 years without a phone number and probably make 3 calls a year.
Only thing I have is an Android tablet with a data plan and an old iPhone SE, only a data plan.
And we're generally lagging behind when it comes to digital solutions, so I would expect other countries to be ahead of the curve and no longer using SMS for anything important.
ID cards that support cryptographic functions (such as Estonia's National ID [2], or in the US, DoD CACs [3]) would go a long way to fixing these problems.
[1] https://en.wikipedia.org/wiki/Medallion_signature_guarantee
The ID card technically comes with a PIN and there were supposed to be special readers that could be used with a handful of authorized online services to verify your identity but as far as I can tell not much came from that as end users would have needed to buy special hardware and services interested in using that would have required special licensing or something.
That said, SMS is less secure than e-mail, so this seems like an odd choice these days (much like magnetic stripes rather than chip and pin).
Since BankID (identity verification) became a norm, this has essentially stopped.
Either the journalist has misinterpreted information given to them or the Ontario police are at least a decade behind current scams. SIM swapping or port-fraud is at least a decade old problem.
So if an attacker knows you’re making a day trip to go to one of the malls that dot the border, they can pounce and you won’t know until damage is done.
Meanwhile, T-Mobile plans include so much Canadian roaming that your plan is better than local Canadians’.
Truth. I know a guy who works for NORAD and his (US-based) data plan is 60/month and includes unlimited data anywhere in Mexico, Canada, or the US. No roaming, no nothing.
How the Canadian telcos haven't been prosecuted for price-fixing is beyond me.
Would cost a few dollars a month, but can’t receive SMS to it.
E.g. retail shops, clinics, utilities, etc.
Some local friends may be paying 20cpm to call her.
I once had a small telecom refuse to accept my 1-800 number...
Because they - and the Canadian banks and a whole bunch of other entities - are monopolists with a wink. Their competitors only exist for them to be able to claim they are not a monopoly.
There is also the LCBO, which is an outright state operated monopoly.
https://en.wikipedia.org/wiki/Liquor_Control_Board_of_Ontari...
Canadians pay way too much for many services and goods compared to those South of the border because of these quasi monopolies and the associated lack of competition.
Do you think that neo-bank Revolut will make it? I remembered ING direct managed to come to Canada a decade ago, but was brought back by Scotia Bank right after (now named Tangerine) - as you said - to façade competition.
Aside from "don't link your phone to these accounts" which isn't always possible as many banks in Canada only recently added SMS based 2FA.
Some ideas:
- separate phone for 2FA. This seems quite annoying in practice.
- a daily twilio script that SMS's your number as an indication that you've still got it. Easy to implement, but also easy to ignore and would only indicate after the fact that you lost your account.
I really miss that feature, and wish more online services supported something like it.
Your second scenario is like a dead man's switch. It's interesting, as it could prompt you with a daily challenge that only you can answer. But I don't see how it could be implemented in a normal person's life?
With the second scenario I was just thinking that, if I personally didn't receive the text on a given morning, I would know that my number has been ported and I would begin to freak out and try to race the attacker.
It's odd that Canada don't have this?
Also, in Lithuania (and many other countries) 2FA is hardware locked to your SIM card - can't really get new one without showing your Id in a shop (the shop doesn't really use the chip on Id tho).
Same for SIM swapping here in Sweden, they check your ID very superficially
Atleast Scotiabank didn't limit it to 6 characters.
I don't know about Canada but I feel like if you tried to implement this in Australia there'd be a lot of paranoia over a system like BankID with regards to privacy or gatekeeping
This episode of Reply All involves one of the hosts pissing off a group of SIM swappers, and him trying to go through the process of making himself safe. TL;DR -- It's really hard to do successfully.
In an ideal world you could trust the cell phone operators to diligently protect your number and you could rely on this to help Google/Chase/GoDaddy identify your account. The problem is this makes it complicated for the cell phone operators and why should they be the ones to have to enforce your identity protection to benefit FANGs/Banks/etc? It always seemed a bit dumb to me that you need a phone number for most accounts in this internet age.
Maybe they could offer a service for a fee where they will be stricter and you have to show a passport to the office to get a new sim issue.
In the meantime I'm sure they've figured out its more benefical in the long term that they just sell cell phone plans that are flexible and we need a better solution to identify people and their accounts.
The latter may be harder to undo given that it cancels your account. And providers always claim it’s impossible to give people their old plans back.
1) Consumers are largely at the mercy of platforms (Google, Apple, FB, etc) and they don't _really_ control their data. 2) Phone companies don't care enough to perform adequate due diligence, and regulation hasn't caught up. The phone companies lean toward making changes easy to prevent customer backlash.
Issue 1 can be improved slightly by not placing your entire digital life in the hands of one or two companies. Additionally, don't link your phone with these accounts if possible (although many, if not all, now require a phone number). Even better, store your data on your own computers instead of "the cloud" (which just means giving your data to someone else).
Issue 2, I suspect, can only be resolved if there's a change in regulation. Phone companies aren't going to go out of their way unless it starts to hurt them in their pocket books, which it would if they were fined when this happens.
Yes, I encounter a lot of services that put way too much weight on phone number (maybe because phone number has some legal status) but not the big platforms. For Google, at least, they go well beyond making other methods available - they really seem to encourage/push users to use better second factors.
In my experience the big platforms are the least guilty. My Google account/data is by far the most secure account I have online or off.
I'm not prominent at all, so I don't expect to be individually targeted. I store 2FA tokens in my password manager (1Password) so that I could recover from my phone being stolen or damaged. However, I don't have a printout of my 1Password backup code stored under my mattress (or in my desk) because I don't completely trust my roommates.
If I had my phone and laptop with me and was mugged, or if both were damaged at the same time, I would be locked out of everything if I didn't have phone-based 2FA. With it I could get a replacement SIM card, regain access to my Google account, and then use that to bootstrap password resets to everything else.
(For the same reason, my only duplicate passwords are memorized randomly generated passwords for phone, primary Google account, and laptop (and there is some duplication between them))
If controlling a phone number was not how platforms authenticated users, the impact of SIM swapping would end in someone else being able to run up a cell phone bill.
I’m practice, authentication of web platforms is based on the authentication and security protocols of the weakest cell phone provider (because cell phone numbers can be transferred from provider to another provider).
We have no comprehensive authentication system, so our security is held hostage to the weakest link in a chain of (email provider, cell provider, platform OAuth provider, commodity web system)