Preventing the use of SIM farms for fraud: consultation
gov.uk
gov.uk
It would be just as easy to get SIMs that support roaming and text outside the UK, or better yet just use WiFi texting.
Local TOTP key as a second factor should be more standard.
Especially if I'm already paying for a service you shouldn't need SMS as a crappy veiled proxy for some human verification.
Supposed to pretend like this doesn't just force people to use more phones?
Immensely useful services like this without which for instance people would not be able to scrape social media services at scale.
> Whilst there are some potentially legitimate uses of the technology, these are limited and should not require using more than four SIM cards, based on the number of mobile operators in the UK. We have very limited evidence that there are any legitimate use cases for devices that allow the use of more than four SIM cards, and for all such cases alternative options exist.
The justification seems sound. What is the issue here?
Let's overlook the fact that such policies just make stolen id a lot more valuable than it is already.
Its also a stupid fucking policy.
A2P is also a US specific thing?
1. https://m.aliexpress.com/item/1005004866582019.html?spm=a2g0...
By “A2P fees” I’m referring to the fact that in most countries it costs more to send an SMS with Twilio than a 5000 message or unlimited message retail plan. I won’t deny that some SIM farms are used for scams but if you look at the countries that have banned them the reasoning is not because of fraud it’s because they have a monopoly phone provider and people effectively use these devices to convert international calls or SMS like verification code messages to domestic so that they don’t have to pay higher termination fees which costs the carrier some profits. They can also make tracing calls harder which is why India bans them. But given that there is VOIP I don’t see why banning this would prevent any fraud.
Your argument is that since this clearly sketchy service ran from Hong Kong that is dedicated to giving people the ability to automate signups on sites/apps and “earn money using our service” utilizes dozens of these devices, these devices are OK?
You might not make money using it and instead just use it to sign up for a single signal account, but you’re not really the target audience in that case.
And the use case they showcase involves mass creating Facebook pages. Come on. Are you really truly that naive?
It’s vaguely legitimate business that just happens to offer a service that’s super useful to a particular type of clientele. Just like bulletproof hosting.
Regardless, that was just a minor point about one potential use of SIM farms. The proposal says they intend to make possession a criminal offence and they don't even have data on whether these devices are used for fraud at scale in the UK.
However, it’s not. It’s got one clear use case and one clear market.
We started this discussion on sim farms and your very first point here (and in other places in this post) linked directly to the kind of thing that should, and hopefully will, be criminalised in the UK.
Because it’s quite obvious what it really is, even if you apparently can’t see it?
I find that quite hilarious.
Having recently looked at commercial SMS gateway pricing, I am inclined to the argument that these devices have a role in thwarting rent-seeking on the part of telcos.
You might use something like this to do bulk SMS, which could be spam or could be phone number confirmations (like it or not, it's a common activity). If voice works, it could be a backup outbound connection for an office PBX (although, unless you had fancy SIMs, you are going to get the sim's phone number as caller id which is undesirable).
Many countries have been making a2p messaging harder and harder; using a sim farm is a tempting way to opt-out of official restrictions, although it seems like a lot more operational work.
I am not an expert in modern mobile network technology so I’ll do something unusual for HN and refrain from suggesting a solution.
Most of the time when a spam number calls me, I can find it through spam reports on 3rd party websites by googling it.
Oh, you mean that you can identify the Caller ID number which the spammer chose to spoof at you?
But spoofing is also something that should be fixed. I know it's difficult because of VoIP and backwards-compatibility, but it's not impossible either.
Not government, but, forwarding spam texts to 7726 (SPAM) works for various carriers.
This is not about stopping fraud, this is about preventing "grey routes" that do arbitrage around tariffs and bypass carriers' outdated business model.
In my opinion, this is again just an excuse reason for a backdoor law to better control the population. 1984 style Ensuring that they can more easily control the lines that you have. Like that they can make mandatory the used of a registered phone number for online registrations like social accounts and be sure that you will not circumvent blocking by opening new lines.
Think about it, if you want to solve the problem that they pretend they want to solve: Each subscriber in UK is registered, so that if you open one or 50 lines, the will know you identity the same.
So, if you are a scammer or fraudster, they should already be able to arrest and jail you!
But take care, because here they only speak about sim, but it will also probably apply to virtual sims and require that you register all your foreign sim cards that did not use to be declared so far...
Avoiding saying no to telcos.
Turning me into a criminal for being the best at helping people with their mundane legitimate businesses.
That would require actual engineering skill and effort, not to mention reduce revenue as the spam messages still yield them money.
https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...
> The majority of national governments (around 160) require mandatory SIM-card registration, which means you need your real name and personal details to sign up for phone service. And just under 20 of these also require biometrics, e.g. your fingerprints or a facial scan, with eight more countries in the process of implementing such requirements.
The biometrics part is unnerving to be sure, but anonymous SIMs or DIDs are incompatible with fraud and spam fighting efforts. If you terminate bad actors, they’ll just keep spinning up more resources.
My current provider Orange even requires me to re-ID at their shop periodically now :(
I was pickpocketed a few years ago and I searched all the bins in the area and I came up with ID cards, medical cards, bank cards etc of 9 different people that had been robbed that night!
I think the thieves do this because if you point them out to the police they won't have any evidence on their possession. Because if they have someone's ID on them they will have some explaining to do. For some cash not so much, you can't prove it was yours.
Not that the police do anything anyway because the Spanish law lets them go free with a minor fine if they stole less than 400 euro, even if it was the 50th time this month. This is really why pickpocketing is so extremely rampant here, it's risk-free and the gangs are basically professional businesses.
Personally I think it would be quite a bit easier than the current mish-mash of identification documents for different purposes, everyone in practice carries some form of ID if only so they can show it when buying age restricted products on the odd occasion someone asks for verification.
Our current gov taking on these kind of moonshots makes you proud to be British.
Speculative questions:
Maybe there are some number switching, chip level protocol mitigations inherent to the standard?
Maybe carriers can push locks or there is remote attestation that could inhibit more than 4 registrations?
Will read up. I've never read the eSIM standards.
Though yes you are correct, if you're only thinking of a single chip (eSIM) instead of the system it usually goes in yes, you are be correct - those systems can currently exist.
iSIM, integrated eSIM with SOC (cpu, gpu, ram, wireless baseband, eSIM) will eventually be more common in phones.
Look up: "remote sim provisioning"
There are SIMs (either physical or eSIM) that do not have a phone number and/or has restrictions on what it can do. It's not the form itself that limits the functionality, it's the mobile network provider who decides what functionality each individual SIM has.
E.g. Mobile card payment devices may have a SIM that has no phone number and is data only with connection only permitted via a certain gateway to the payment provider.