Two Charged in SIM Swapping, Vishing Scams
krebsonsecurity.com
krebsonsecurity.com
Text message based 2FA needs to die.
What really needs to die is giving privileged access to underpaid monkeys.
This in uncalled for.
I started my tech career in a call center. Were there people there that shouldn't have had that job? Sure. Do those people deserved to be belittled by calling them monkeys? No fucking way. Show some damn respect for your fellow man.
(Nobody at big tech companies ever bothered to even phone screen me for SWE roles)
Also your enterprise account managers often are clueless and just ask the support team - certainly what happened in my experience.
This was demonstrated by the two fat binders filled with procedures for EVERYTHING that were supposed to followed to the letter.
Virtual numbers from providers like Twilio, Plivo or Signalwire help too. They have 2FA mostly and couldn't be SIM-swapped (I hope). Google account security is quite good too.
Seems unnecessary.
If you’re making minimum wage, how much do you really care about your job in general? You’re probably regarded as disposable.
I also trust fast food employees to effectively sanitize, even if their position does not command a wage increase.
I stand by my initial argument with the wording and I'd rather not tangent down ethics, policy, hypotheticals.
I am just expressing a bad taste, that is all.
These problems seem easily solvable with MFA and a VPN, and if anyone should be an expert in networks, you would think it would be a telecom company.
This is gross negligence being passed off to the public as standard operating procedure.
You and your partner stole a bunch of Bitcoin via SIM swapping. If you split it, you each get half. If you don’t split it, the other one will SWAT you and you both go to jail.
Thanks.
Luckily I had 2-factor for everything, but I know some people who lost a lot. SMS is totally broken, use 2FA and hardware key if you can.
The craziest one was two people at another firm were sending each other a lot of money, and sent the address over Telegram. The hacker manipulated the address in the message - they checked after the (failed) transaction and the address sent was different than the address in the message received! I think the most likely cause was that the receiver's computer was rooted and the application itself was manipulated on the device, rather than the message contents changed en-route. This is why I recommend both visual and audio confirmation when sending large amounts.
My assumption is that the attackers target individuals that have a high likelihood of owning bitcoin or other digital currency. This can be easily determined by looking at data breaches, and targeting emails that are found both on a cryptocurrency breach and a personal information breach with phone number, name, address, and anything else that would help impersonate the victim.
They accessed my insecure email with SMS authentication, but everything else was locked down more securely. Also, since that day I have been getting 20 times more spam calls and texts, I'm guessing they added my number to some other targeted list.
How many people can do this? See those mom and pop "authorized resellers" at the mall? Yeah.
AT&T still let them order 4 new lines on a new account even though I already had an account with 2 lines.
... and this is why you should never use your identity for these things.
KYC is a security liability.
In a similar vein, I've known people who had unsigned checks stolen and their signature forged very poorly. The banks are supposed to check the signature, so why aren't the banks liable?
Actually no, not anymore after the "Check 21" act. They're not responsible for verifying any aspect of the check. Kind of a crock.
It was all kept hush hush to prevent copycat attacks. It took intervention from the FBI and a big netsec firm to even figure out how it had happened.
This is a nice benefit of Google Fi. Since swap attacks are not possible with it, as customers support agents aren't able to do sim swaps. Sims for Google Fi are fully tied to your Google account, and you must have access to that account to be able to register or unregister a phone.
I think the risk is too big. Use U2F, or something similar.
Are you sure that this is the case? According to https://support.google.com/fi/thread/761170 there was at least one case where support agents moved a Fi number from a locked account to a newly reopened account, without the user being able to access the locked account:
> I call Google Support and the amazing Google Support rep I spoke to (The only good one I’ve talked to so far during this whole process) stayed with me for over an hour and worked with tier 2 support in getting my Project Fi number transferred to Account 2.
A SIM swap with Fi might be harder to accomplish than with a regular provider, but it looks like there's still the risk that someone manages to convince a support agent to move the number to a different account.
So this should mean you can use the built-in biometric security of an iPhone or high end Android since those can also be used with WebAuthn in the built-in browser or with Firefox, or any security key, not just a Yubikey.
WebAuthn is easier (one tap login), it cannot be phished, it's privacy preserving, and yet somehow here we are in 2020 and most sites are like "Hmm, maybe we should add SMS 2FA?"
In other less ideal situations especially with institutionalized corruption or shaky monopoly on violence such that it can not only pay better but effectively drag them into crime like to run an otherwise perfectly honest business you need goons to not be under someone's racket/pay bribes to operate and maintaining them becomes a slippery slope to collect protection money or forcing out competitors.
Public utilities in the US need an overhaul.