One man lost his life savings in a SIM hack, you can try to protect yourself
cnn.com
cnn.com
You know what happens if someone tries this with your brokerage? It takes three days, not one hour, there's a name on the destination account (know your customer), it takes days (at least) to withdraw money from it, and there's a medallion signature on the transfer, so your brokerage is on the hook for it.
There's a reason fraudsters are targeting cryptocurrency exchanges: arguably less security, but more importantly, it's easy to quickly and irreversibly transfer the money.
I'm...not sure that's how it works. Yes, common sense suggests it's much more difficult with conventional financial assets, but is that signature guarantee or whatever you call it protecting you or the institution? In the sense that, if someone successfully forges one, what actually happens next?
> A medallion signature guarantee is a guarantee by the transferring financial institution that the signature is genuine and the financial institution accepts liability for any forgery.
[0] https://en.m.wikipedia.org/wiki/Medallion_signature_guarante...
Maybe I'm forgetting how this works...
...reading the wikipedia page, it sounds like the idea is to deal with forgeries of signatures provided to the guarantor. Not with forgeries of the guarantor's approval.
Then again, maybe you can't really forge a guarantee as long as it can be looked up or invalidated by their database.
Seems like the best answer is to not reuse passwords, use complex passwords and avoid giving "real" answers to security questions.
And if course, don't keep your life savings in an account that can be withdrawn entirely on a moments notice...
From a quick look at your website, it looks like you are offering prepaid services through different providers similar to H20 Wireless. You claim to offer protection but give no detail on it except that you use "military grade protection".
I get the fact that the real crook is the thief, but surely ATT is at least partly negligent. How much are they responsible?
And unlucky people are caught in the middle.
https://www.pindrop.com/blog/nist-explains-proposed-ban-on-s...
Why should we use outdated and vulnerable networks when social engineering is all you need to steal stuff?
This from 2012: https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking...
I encourage everyone to use a hard to guess email alias (foo+bar@gmail.com) for your LOGIN — not password. This thwarts many of these attacks!
“Sir, let’s reset your password. What is your email please?”
“foo@gmail.com”
“Sorry, we have no such user.”
“Really? But—“
“Really.”
I haven't used it. I want to, but haven't wanted to deal with changing my family plan. It does make me more interested in a dual-sim phone.
I want to know how it would’ve prevented this social engineering attack
Sure, you can make porting difficult. That doesn’t get you very far.
Can you defend against sim swap attacks if your MNO is compromised, how?
Where can I read more about your insurance policy? I can’t find any specific details on your website.
We do defend against SIM swap attacks because MNOs can't access our account
How does that work? Your contracts might stipulate this, but I don’t understand how this could work from a technical PoV.
They might be able to protect you against regular port-outs, but not SIM swap attacks performed by people who’ve compromised carrier infrastructure.
The language on the page is downright hilarious “11-Layer of Military Grade Authentication”.
Yeah, the problem here is that since you’re a MVNO the easiest angle of attack would might just be to go for the big MNOs that you resell (Verizon, ATT, Sprint,Tmo). You can’t really offer bounties for such attacks, and I can’t see how you could defend against them either.
The fact that you control the # might defend against port-outs, I don’t understand how that could prevent SIM swaps though.
> Hi, AT&T, I was at the bar last night and I lost my phone. I still have my old phone, though. Can you help me transfer it? Mother's maiden name? Why yes, it is on whitepages.com!
Sorry for the delay in answering, “Social Engineering” is not hacking. Manipulating the SS7 protocols for nefarious ends, could be considered hacking.
https://blog.securegroup.com/phone-hacking-through-ss7-is-fr...
(I’m on T-Mobile and this has happened to me 3 times)
It sounds like you are not aware of the existence of the term “Social Engineering”.
I invite you to read this Wiki page [1] which explains what the hack is about.
Social Engineering is, in fact, one of the most common techniques used by hack people, for example, by tricking someone into clicking a malicious link in a phishing email. There is also “Smishing” which is the same —tricking someone into reading and clicking a malicious text or link— but via SMS. In this specific case the hackers are using a technique commonly known as “Vishing” or “Voice Phishing” [2] which is a criminal practice of using social engineering over a telephone system to gain access to private personal and financial information from the public for the purpose of financial reward (verbatim from WikiPedia).
Have you heard stories of hacks where an employee plugged an infected USB, CD-ROM or floppy-disk into a computer connected to a secure facility? Well, this is another social engineering technique commonly known as “Baiting” used by hackers to attack systems that otherwise would be impossible to access from outside [3]. Stuxnet [4] is one of the most famous examples of a social engineering attack, among several other techniques.
As you can see, social engineering is the very beginning of many hacks.
[1] https://en.wikipedia.org/wiki/Social_engineering_%28security...
[2] https://en.wikipedia.org/wiki/Voice_phishing