NY Man Pleads Guilty in $20M SIM Swap Theft
krebsonsecurity.com
krebsonsecurity.com
We have more and more kinds of accounts, financial products, online services, etc. that would benefit from some kind of real in-person verification at points in the process (initial application, maintenance, changes to account) that are imperfectly done with credit checks, questions/answers, logins, etc.
We have Post Offices in nearly every corner of this country. How about turning them into a kind of value-added identity verification service where any company wanting/needing an identity verification could rely on the Post Office to accept someone in person to prove who they are (through fingerprint, document, etc) and be the 3rd party to make this proof easy?
Sure you would need to have normal fraud protections, etc. but I bet the act of having to come to a post office would make things very secure / reliable. And it would give the post office a new function. I heard of this being done in some other countries.
It seems like a way to avoid us all having to pay for fraud so frequently.
When I went looking at them they were boasting with using AI, and then in the meeting it turned out it was mostly farmed out to someone in India.
When I opened a bank account (n26) in Germany this is how they verified my identity (along with a brief video call) as a foreigner so the idea has merit.
Seems like a private company providing services to these gov agencies on authentication. Seems like a better solution than showing up at the post office.
I wonder how id.me differs, and how we haven’t centralized on one solution yet
Both are generally available for free by being a customer of your local small bank or credit union. These could be easily adopted by web companies for password resets, account withdrawals above self-set limits, etc.
I mean the every day kind of verification that fuels our daily transactions and benefits from instantaneous info being transmitted back and forth, to easily get a credit card approved for example.
Doing this instantaneously implies skipping the heavyweight process. Which I assume means doing something like a one time (or periodic) cumbersome in-person process, and then repeating a quicker online process. Any private company could create such a system right now, bootstrapping off the notarization framework to do the heavy lifting.
But credit cards and other traditional financial institutions don't actually care about identity in such a strong sense. The standard process for setting up online access for a new account at a brick and mortar bank involves leaving the bank, going to their website from home, and entering your not-particularly-private information to sign up. That could be easily modified to setting up initial access credentials right in the bank if they wanted to, but the traditional financial system is pretty forgiving for the most part.
So we're really talking about custodians of new bearer instruments (eg cryptocurrency), which are more like cash. Hence my reference to these new holding companies being the ones that should be integrating notarization into their exceptional account access methods. Of course they could also just insist on the use of real security tokens, require a second one for backup purposes, and simply not use SMS at all.
FWIW another more convenient way of doing brick and mortar verification is to snail mail out a letter with a code on it to the address of record. It obviously doesn't have super security properties (anyone can steal mail), but it's much better than electronic-only non-verification and much nicer than surveillance database verification.
Yes from what I know, you technically do not need to get a will notarized. But getting it notarized makes it a "self proving will", which will be easily accepted by a court. If you don't do the notarization at the time, your poor executor will likely need to hunt down the witnesses and get them to sign affidavits.
I've used it for Know-Your-Client type stuff with banks, but it is theoretically open to most if not all businesses. Every time I've needed to interact with it, it's been a straightforward process as a consumer.
[1]: https://www.canadapost-postescanada.ca/cpc/en/business/posta...
(Use your translation service of choice if desired.) https://www.sagawa-exp.co.jp/service/kakunin/
I've always thought that a code-signing certificate tied to a natural person should be more valuable than one tied to a faceless corporation, but the industry is (poorly) built around selling high priced certificates to anyone with enough money to start a business.
Imagine being able to get a code signing certificate in a single afternoon by signing up, taking your ID to Canada Post, and downloading your certificate after the identity verification is submitted. That would be quite the difference from the current awful experience where someone in a foreign country guesses and makes judgement calls based on the documentation you snail mail to them.
Keep the post office option for the folks that don't have an ID, but for most people, this would be the most straightforward option.
Basically, I don't think a natural person is enough protection against malice. Something like "stick 1 million dollars into escrow, and if someone uses your cert to spread malware, we keep it" is a much stronger incentive. (Not what's done, of course.)
Belgium has an identity service based on this. Governmental OAuth. https://www.csam.be/en/about-csam.html | https://iamapps.belgium.be/sma/generalinfo
They publish their own eID reader (middleware) and browser extensions. https://eid.belgium.be/en
Even with an official Linux version. :) https://eid.belgium.be/en/linux-eid-software-installation
The post office used to issue normal identity cards, but today I only think it's the DMV equivalent and the police that does that.
https://www.ceskaposta.cz/en/sluzby/egovernment/czechpoint
Its usually situated on post offices or local government offices and makes it possible to get verified electronic signature that you can then use to prove your identity electronically. It can also access various government registries, etc.
But lawmakers in this country are allergic to having the government manage anything
Making money while doing something actually useful? Not my government, not when there's a tiny sliver of profit to be funneled to wealthy special interests!
Congress has slowly been fucking the USPS to death at the behest of FedEx, UPS, et al lobbyists.
> “You would have to work very hard to come up with a worse idea than having the government become a national bank executed through the post office,” [Sen. Pat Toomey, a Pennsylvania Republican] said. “Even if the U.S. Postal Service was the most competent, professional and best-run organization on the planet, they should not be in the business of banking.
> “We have banks,” Toomey continued. “The idea that the government is going to do a better job is just laughable.”
What a moron.
https://www.oleantimesherald.com/news/gop-senators-oppose-id...
But like other things during the 'Regeanomics era', it was cut, along with forcing the USPS to pay pensions 10 years in advance. The context does help to explain the reason why our USPS Grumman vans are well over their service life, and no where near retirement yet.
This is false, as the factcheck.org reference posted above in this thread makes clear.
You also get a digital inbox—Berichtenbox—to organize and centralize all communications from those agencies.
It is difficult to overstate how much life is made better when the government is well-organized and that organization is exposed to you through good UX. I'm now back in the US, it's been 2+ weeks since my renewed passport was supposed to have been mailed to me, and no one at the State Department knows anything.
The obvious reality here is that in the wake of no proper national identification system, social security numbers have been used instead. It's not a question of whether or not we have a national ID, it's really just a question of whether we have a functional one or an inadequate one. Nonetheless politicians would likely be committing suicide with their constituents in some districts if they were to support a push towards a better system.
[0] https://en.wikipedia.org/wiki/Religion_in_the_United_States#....
Historically that was sort of the case. I'd argue today that we mostly rely on state-issued IDs (especially but not necessarily driver's licenses) which are now overlaid with RealID requirements.
As a practical matter it's probably indistinguishable from what a federally-issued ID would be and I'm mostly content with not adding any more layers of identity verification than are really necessary. I'd probably oppose a push for a broadly required federal ID--although I have a passport (and a global entry card).
This doesn't invalidate your point, but man it irritates me how many states have chosen to retain a noncompliant ID tier in order to avoid eating costs or raising fees. At least my state offers a full EDL so there's some added value, but it's absurd that the 'default' local ID isn't adequate for domestic air travel.
For people without a passport, it's extremely easy to have lost a birth certificate at some point over the years. And I honestly have no idea how easy or hard getting a new one issued is from some potentially far away city or town.
That's not why. States like California have dragged their feet for a decade with RealID compliance because they want to keep IDs for people in the US illegally indistinguishable from those for citizens, permanent residents, and others here legally.
Can you elaborate on this for us non-USA people?
The main reason to oppose this is that if you had a low friction government ID system, surveillance capitalism would then require you to present your ID to do anything whatsoever and all privacy would disappear forever.
A state-issued ID generally doesn't work over the internet, which is good. Some of them can be read electronically in person, which is already being abused to a limited extent and should be gotten rid of.
Which is the general response to your concern: "This is already a problem" means we need to go the other way and address that so that doesn't happen anymore, not intensify the problem and set it in concrete so it can never be fixed.
Centralized identity is a design flaw. Your bank needs to know if you're authorized to withdraw from your account, which is why you have a bank card. Your email provider needs to know if you're allowed to access your email account, which is why you have an email password. Your apartment building needs to know if you're authorized to enter, which is why you have an access card. What we don't need, and should not have, is a single primary key binding all of these things together so it can be correlated in a single database.
Since then the UK has imposed ID (technically "proof of right of residence", but that kind of has to be ID) on having a bank account, having a job, and both buying and renting houses. All without having a coherent ID scheme other than passport or driving license.
Privacy and anonymity are not the same; there are many domains where anonymity is reasonable and default, but also many domains where it is not; in those someone can respect privacy and at the same time refuse to deal with anonymous partners, and it's an entirely reasonable choice that they should be able to make not only in theory but in practice - having an effective, secure mechanism for a person to verify their identity to someone else.
Proper identities are a key basis for trust - without them you can do one-off immediate barters (perhaps many times), but prolonged relationships, various forms of credit and "credit-like-effects", accumulation of reputation are highly beneficial for society; and from the perspective of incentives it's worth noting that the harder it is to "get away with" betraying trust and start from zero, the less incentive there is to defect and more incentive to cooperate; there's a good reason why the game theory iterated Prisoner's dilemma (which relies on preserving identities) gets so much better average results for everyone than non-iterated or fully anonymized Prisoner's dilemma.
But I agree - NFC passports are already kinda doing that, but there isn’t enough services that support it.
While it's doubtless sometimes necessary, I'm generally a fan of not having to go into an office for money transfers and so forth. It's also worth remembering that this sort of thing may (normally) be pretty low overhead for a lot of us but isn't for e.g. people who aren't very mobile.
This is such a high barrier to entry, however, that people will simply not do it for something that isn't absolutely critical. Online services compete with each other to be as frictionless as possible, whereas this is the exact opposite of that.
Every state has its own requirements to become a notary(with one requirement being posting a $10k bond or purchasing insurance, so you have something to lose if you make an egregious mistake).
You can require counterparties notarize any documents you'd like, and reject anyone who declines. And you can do this without needing to change the law to increase the scope of responsibility of the USPS. It's illegal for the USPS to offer notary services, although they're often located near notaries: UPS Stores usually offer it.
But then we also have a notary public system, which is already in the business of verifying identification for official purposes. That could do it too.
Or, you know, it's hard to innovate when you're in organizational crisis mode trying to prefund 50 years of retirement while not being allowed to market-rate your core service...
If the political system stops public sector organisations innovating, they won't innovate. See, for example, BT in the UK, who were looking into investing in fibre optic rollout in the 80s and 90s until Thatcher snuffed that idea out and we're only now starting to get fibre to the premises rolled out in significant numbers.
https://www.techradar.com/uk/news/world-of-tech/how-the-uk-l...
That's because it has been a target of right-wing attack for decades starting with the republican-led 2006 bill that effectively bankrupted it overnight by requiring a massive 50 years of health benefits to be funded.[1]
So when you have a service (not a business) that is constantly being picked apart and hamstrung from completing its most basic functions, you can't possibly blame them for not innovating. Well you can, but it is not in good faith.
https://www.politifact.com/factchecks/2020/apr/15/afl-cio/wi...
And that's assuming there is a post office near you (or you have a car), and you're able-bodied enough to get there independently.
I can say from personal experience that I have point blank refused to pick up Signature on Delivery (ie, the sender instructed the postal service not to leave the package on the porch) items from the post office in the past and demanded a refund from the seller. I'd do the same if I was asked to go down there to verify an account for Uber or whatever.
[0] https://auspost.com.au/business/identity/voi-solutions-for-c...
If an online service like eBay, Facebook or Uber required this level of verification, people would (rightly) tell them to piss off and use a competing service instead.
Well, we'll see once the government forces through the "anti-troll" bill that does require a similar level of verification, next year.
[0] https://www.theregister.com/2021/11/29/australia_troll_bill/
I think there is a need for authentication, especially among people that are in and out of poverty.
The catch-22 is that you can't get a job without an address, and you can't get an address without a job, so you cannot be authenticated by means available to most people! Hard to bootstrap yourself when you can't prove you exist. Having some kind of authentication that doesn't require an easily lost-or-stolen asset (ID card, birth certificate) would be helpful, as long as it is voluntary!
Consider how you would like the Post Office to verify your identity and then ask why someone else, e.g. the person you're trying to prove your identity to, couldn't do the exact same thing.
One advantage of an ID is that it's a physical token, so they can't just guess your password, they'd need to physically have it. Unless they can forge one, so you'd really want to use some kind of cryptography. You've just reinvented a YubiKey.
The actual problem isn't that we don't know how to solve this. It's that people prefer insecurity to minor inconveniences. Especially when the liability is on someone else.
[1]: https://en.wikipedia.org/wiki/United_States_Postal_Savings_S...
[2]: https://federalnewsnetwork.com/agency-oversight/2021/10/usps...
Possible in some places!
In many European countries the post office also offers banking services.
Millions of American citizen will be forced to provide their info to this private company. Authentication involves you providing your cell phone number, then uploading a photograph of your drivers license or passport with that phone and then allowing ID.me to scan your face using the same phone camera.
You may think if the IRS and DMV are using this company it must be a serious identity service vetted by homeland security and what not. I did some digging around.
ID.me has a shopping site where you can shop for deals on sunglasses, sneakers and food kits [1] https://shop.id.me/. They use .me which is the top-level domain for Montenegro.
There is one hackernews thread about this company filled with clearly fake reviews made by accounts created the day the post appeared [2] https://news.ycombinator.com/item?id=13831921
What could go wrong ?
They’ve now used those groups as a stepping stone to verify the public. They want everyone.
Id.me’s Privacy Policy and Terms of Service state that they will not sell your data. Good, but they absolutely can and will sell your demographic cohort. With the buyers being their integration clients (brands) and data brokers.
Hopefully they use differential privacy techniques. Doubtful. It quickly has become a government mandated (irs.gov) Facebook style audience mining network. That’s why Google invested in them and had a seat on their board.
They were damn good to hook wink the IRS and VA on that one.
https://californiaglobe.com/articles/monetizing-data-the-edd...
Refreshing to see these active theft and wire fraud prosecutions.
Never did any myself, but have friends who have done well with these cases. They essentially allow the lawyers to share in the appreciation of crypto.
I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary.
Also, it's important where possible to use types of multi-factor that don't rely on your phone number. The tricky part is, so many sites will let you reset your password if you can receive a link via SMS at the phone number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still).
You should soldier through it. Google Voice is a decent free service domestically, unless paranoid. I use it in the reverse manner as I expect you would intend (if you'd intend to generate many virtual throw away numbers to forward back to your phone until the forwarding is manually severed). My actual phone number has changed many times over the years, but my GV number stays the same. Eventually, I got rid of my phone altogether. That was January 2014. But jobs will often require I carry the on-call cell (which I almost never need to use and just for work). Boy I sure miss those cell phone bills every month, not. I just realized GV has saved me at least $10K since I cancelled my cell contract.
Target outright refused for Target circle a couple years ago. Recently 7-11 had accepted my Google voice number to get points on in store purchases but now that I live somewhere where I need a car, the gas pump decided the number was invalid when I tried to get the discount on gas from the pump I'm worried since I basically never gave out my actual cell for over a decade now
Most SIM-swappers are retiring with their ill-gotten crypto, but the ones remaining are at the "bribing prosecutors" level now.
With crypto skyrocketing and the pitfalls of SMS becoming more apparent, I fully expect the jump to amateurs purchasing and leveraging state-level 0days against unwitting wallet holders.
The gap between profit and cost is getting larger, and more crypto-millionaires are going to get their Teamviewer 0dayed.
Yes there is: change your bank. If your bank is still using SMS based 2FA, get the hell out of there. If you really need to keep that account for reason X, move out all your assets to another bank and keep enough funds to fund X there.
Have any suggestions for a bank that supports TOTP? I have yet to find a decent bank in the US that supports this.
Charles Schwab and USAA use TOTP but aren't exactly main stream banks. Both use a Symantec client and don't officially support third party authenticator apps.
Not too many banks with physical locations in my area AND 2FA more secure than SMS.
However, the point of needing to login to your Google account is well taken. And I have 2FA on that.
unfortunately it's also very easy for somebody to submit falsified port documentation to port away your voip number to their own carrier.
In many cases even easier than doing a SIM swap, since the oldschool way to do a port is to literally print out one page of a bill with your name on it (Anybody could edit this by inspect element on a legit bill of their own and swap your name), print it, sign it in ink, scan it, and send it to the carrier requesting the port-in
> reply
Why not use a special phone number for 2FA? How do hackers know your phone number?
I gave up on that ten years ago when I worked at a biometric authentication company. Banks were soon to be regulated to use 2FA, and our system was easy to use, we're all gonna be rich!
Then the banks were allowed to use security questions as 2FA. Not only were the employees not "all gonna be rich", everyone else was going to get fucked when they accidentally post something on Facebook about how their mother (neé Mary $MAIDEN_NAME) used to do $SOMETHING on $STREET_I_GREW_UP_ON. So the continued use of SMS-base 2FA, despite its frequently-published flaws, isn't going anywhere until a new way to fuck up 2FA is found.
If I had a viable solution to it all, well, I'd be rich.
holy shit, no wonder people are going dark. yall better hide.
In the end Truglia's bragging to gain /props/ for a /component/ of this crime, is what lead to the REACT task force getting their /hooks/ into his /lifecycle/.
Also, don't let your mobile phone number expire and someone else get it.
I can log in to the previous owner's TikTok account with just his number.
I signed up for a food delivery service two days ago and it autofilled all the details with his full name and address for me.
How many other sites let you log in with just a phone number? Asking for a friend...
How would you do this, then? I believe old numbers are kept for a certain time (6 months?) and then put back into the public pool. If we had a more technical solution (think IPv6 addresses, but for phone numbers) this shouldn't be an issue in theory. Of course, having to remember something resembling an IPv6 address to contact somebody would be a pain. I would say we could use a username system, but I believe we've seen the downsides of that way too many times already.
You port your number to a super-cheap carrier and keep paying for their lowest subscription, even if you don't need it anymore.
I payed for 5 years $5 per month to keep a number alive, even if I wasn't living anymore in the country that issued it.
2) Social engineering mobile phone first-tier customer service reps into doing a SIM swap is not hard at all.
Request: can anyone help clarify why this needed to be civil and didn't qualify for criminal?
I'm sure they're an upstanding company, but using the word 'propriety' instead of 'proprietary' is an instant turnoff for me. Security is a details-oriented endeavor, and everything from marketing to implementation needs to be squeaky clean. But, maybe that's just me!
Horrible deterrent, because it isnt a deterrent
Unless…
> “On the surface, Pinsky is an ‘All American Boy,'” Terpin’s civil suit charges. “The son of privilege, he is active in extracurricular activities and lives a suburban life with a doting mother who is a prominent doctor.”
Crypto is so big, to put it in perspective, the gambling sector worldwide was estimated to be worth roughly $265 billion U.S. dollars in 2019. That is just 2/3 the market cap of Ethereum alone.
Crypto is bigger than pretty anything right now. Bigger than pro sports. bigger than the entertainment industry. Only the tech, real estate, retail, and finance industries are bigger. But those are composed of thousands of companies.
Crypto is big, but to be fair "just" Apple is bigger than crypto. Compared to the NYSE or Nasdaq, it's small, and when compared to forex (maybe a more apt comparison), it barely registers. Incidentally, I think this is why crypto's here to stay (probably forever): it's huge and growing, very popular, and the masses seem to like it. It's like the McDonalds of financial instruments. I don't think governments care to (or can) regulate it, so as long as we're paying taxes on gains, they will let it slide.
In fact you can
China has literally banned Bitcoin. Their approach is to roll out their own digicoin.
Governments have been very slow to figure out how to approach crypto, but the current Wild West of tax evasion, money laundering and virtual bank robberies won't go on forever. Just like counterfeiting and money laundering exists today, there will continue to be exploitation of the financial system, but it will be explicitly criminalized.
China "banning" cryptocurrency is a meme at this point (I think they've banned it 4 times now).
> Wild West of tax evasion
You literally cannot evade taxes, so I'm not even sure what this means. All US exchanges report everything to the IRS/SEC. And if the exchanges don't, your bank certainly will. Moving money in your bank account and not reporting it as income is a big no-no so good luck to anyone that tries to do this.
> Just like counterfeiting and money laundering exists today
This is kind of a faulty analogy, it's not like cash is banned, and most of those things are done with cash. People seem to like crypto markets as a speculative instrument. Is that good/bad? I don't know, but it's probably here to stay.
The idea of equating <insert anything> to crypto market cap needs to stop. $265B in actual real dollars is exchanged between two parties every year for gambling. That means a business pays a salary to someone and then that someone gives that money to someone else.
Crypto market caps doesn't necessarily mean that someones earned currency is transferred to another one and it doesn't representing an annual value. In other words `income != net worth` or `revenue != asset value`
Example of how this works: https://news.ycombinator.com/item?id=29471847
This is an issue for stocks also. If 100% of Amazon share holders tried to sell simultaneously the price would fall precipitously. But, Amazon is at least backed by assets, dividend potential, and IP.