Former telecom manager admits to doing SIM swaps for $1k
bleepingcomputer.com
bleepingcomputer.com
Retail employees would perform sim swaps at locations I worked at for about $250-300. This was circa 2006 so I’m not surprised that people do it for $1000 with inflation.
The reality is that cell phone employees are paid just above minimum wage, so asking them to protect a system that has the capacity for multiple millions of fraud by simply changing a sim is hard.
The good news is that they made it much much harder for retail employees to access your account without your consent. You almost universally need a pin or last 4 of a social to access a customer account now without a manager override.
This is a huge improvement from the time I worked entry-level retail at AT&T when I could see any customer’s full social or tax ID by typing their phone number into the point of sale!
Imagine being 18, poor as fuck, and able to see anyone’s financial information. I was moral, but I knew tons of people who just took out loans as if they were the customer committing massive fraud. It was very hard for AT&T to catch this kind of identity theft. I’m glad systems are becoming safer over time.
Last four of a social is a terrible additional form of security.
Even four random digit pins isn’t particularly secure if they don’t have proactive monitoring of attempts.
what is worst is you CANNOT change it if your data is leaked from 3rd party site.
conclusion: NEVER use phone number as 2FA, Always assume your cell number will be swapped, always use other more secure factor, especially if it has anything to do with money $$$
If you sync your secrets to some cloud service then yes, you are trusting that cloud service. And if you let your TOTP cloud service reset your account with an email then it probably isn't the most secure option.
But the important thing here is that the user is in control. They can memorize their secret if they want to an no one can take it from them. Or they can publish it online if they don't like security. With SMS 2FA you need to trust your telecom provider, I very much don't.
You may be confusing TOTP with proprietary app-based 2FA solutions which just send the token in a push notification or similar.
The system is designed to assume that the user doing the initializing that one time is the legitimate user.
(There's a bootstrapping problem for the authenticators, that the account provider needs to "trust once" that the user is legitimate. The best time to do that is as early as possible. Preferably when the account is set up, and before much value/dependence has been invested in the account.)
After that first initialization of an authenticator for an account, anyone trying to initialize another authenticator would have the burden of trying to prove to the account provider that they aren't just an illegitimate person trying to bypass the 2FA.
So, you probably can't just use email to do a "lost my authenticator lol", unless the account provider doesn't really care about 2FA, and has implemented it in a very weak way.
As such, no, it's not associated with anything from the source account. It is not challenge/response, and you can scan the QR code with 10 different phones and they will all produce the same codes at the same time.
There was a DND that talked about how sim swaps used to be a cakewalk over the phone social engineering exercise but were now kind of expensive to pull off and required a man in a physical location, with T-mobile remaining the easiest target. The black hat guy they were talking to said his first steps were finding a target worth swapping, usually some one that bragged a lot about bitcoin or some other crypto currency on twitter. And getting the phone number was usually really easy to do with a combination of OSINT and abusing the fact services will give you a partially masked phone number when you try to login.
Does not naming the company suggest that it's not considered liable?
> indicate five victims
Over what time period? Did the company detect and halt this quickly, and was conscientious about referring it to law enforcement?
I'm willing to agree a store/carrier/brand should be given a pass in a particular instance, but the bar for protecting against SIM-swapping has to be pretty high, considering what an attractive vulnerability that is.
With poor technology and poor regulation around some big-ticket authentication problems right now, one mechanism we do have is brand reputation.
For example, if people seem to keep hearing about SIM swaps involving carrier X or store Y, then some people are going to start thinking that brand is sketchy, and more likely to get your bank account emptied or computer accounts hacked. So then all the brands would have more incentive to be very diligent about internal controls, very cautious about partners and outsourcing, etc.
But if it's always just an unnamed phone store SIM-swapping for an unnamed carrier, or an unnamed carrier's support call center, then that brand reputation mechanism is defeated.
Also, once the log was audited it pointed to the individual that is facing sentencing in July, no?
If I were the Verizon Wireless CEO, I'd own it and pledge to resolve as best I can. And maybe they have, I haven't looked yet.
Edit: I had it backwards. Not AT&T, but rather Verizon. Changed. "Telecom in Georgia" would allude to AT&T. "Telecom in Kansas (or maybe Bellevue, WA now)" to T-Mobile, etc.
I wonder who thought it was a good idea in the first place. Maybe their real intent was to collect people's phone numbers instead of protecting their accounts.
Another benefit is that they can block duplicate accounts with the same phone number, this effectively adds a cost to account creation which can help to reduce spam.
And yes, some will then use it to spam or sell.
I don't think anyone ever thought that SMS 2FA was strong protection. It mostly benefits the service operators by reducing spam and stolen accounts.
Kinda like SSNs though, I think it's way past the point when a better designed system should have been developed. Sadly, that costs a lot of money.
On a more technical note, is there any safeguard against SIM swaps? Something like a fingerprint scan that's tied to your SIM. I'm not familiar with phone hardware at all but I'd love to hear if someone's working on this type of thing
The telco also needs a process to reclaim the number when you stop paying for it.
Often SIM swaps are done via porting the number to a different telco, and telcos are compelled to do ports in many jurisdictions.
If you're really worried about it, I guess you could look into what it takes to get a number block assigned to you as a competitive telco. That would likely be hard to get transfered out from under you, but the effort may not be worth it.
Also, if the price to get a sim swap is $1k (plus a % of ill gotten gains!), that's high enough to keep out untargetted attacks, IMHO, which isn't a terrible place to be.
You can be court ordered/forced to put your thumb on the home button.
You can’t be forced to remember a password you “forgot” ;)
We don't need to make shit worse.
Just to reiterate, I am personally a fan of maintaining anonymity, particularly online. I'm just concerned that our increasingly aging population won't be able to keep up with security best practices and we may need some braindead solutions to keep them safe.
So, a little more than $1k pp
The only solution is to refuse to use SMS for 2FA. If a service requires it, use a different service.
It's entirely possible some of the brighter ones have gotten their co-workers username/password combinations, and are using those when doing dodgy stuff.
There is. Some Russian banks detect when SIM identifier has changed and refuse to send SMS codes to a new SIM card.
Meanwhile, SIM swaps continue by malicious actors with seemingly nothing that can be done to stop them. So I can't swap my own SIM without waiting on hold for an hour or two, either by chat or on the phone, but the scammers can do it with apparent impunity. (I have tried messaging T-Mobile's help group on Twitter but they seem to be the only competent support available and thus are also incredibly backlogged.)
I get that providers have to cater to the lowest common denominator but I wish there was a MVNO or similar who would allow use of authenticator keys and maximum level self service, with the understanding that if I break or lose my authentication methods, I am out of luck. Right now, my current carrier seems the worst of both choices.
The trouble with compartmentalizing with a separate phone is that the company with your money probably also sold your secret phone number (that they only required for security) so it will probably also show up on that whitepages site.
There is also that some services don't accept foreign numbers for authentication. Nor virtual phone numbers.
But it adds a layer of protection, doesn't it? Your known public phone number is one, your verification phone is another one from another carrier.
Is that really an additional layer of protection, or the same layer, slightly obscured? But probably not obscured from the attacker that managed to get your password and just needs the SMS verification code to get into your account.
You have to give this phone number to a bunch of services that you use, i.e. all the ones that do sms confirmations. One data breach, and it isn't "secret" anymore.
Does knowing the employee did it make the company liable for damages?
Worst part? They send a text saying, in effect, “we’re chabeing your SIM in 15 minutes unless you call us”
This is AFTER their supposed security improvements, but then again so are the two other hacks where customer data was leaked.
Don’t use SMS 2FA and set the most obnoxious ringtone for your carrier’s short codes. Take the most defensive approach to being a cell customer because the carriers won’t save you.
Locking your SIM prevents someone from physically stealing the card and putting it in a different device - unless they know the PIN which protects it.
But that isn't the attack here.
The phone number does not belong to you - the network operator defines which SIM it points to. So a suitably authorised person at the telco can point the number to a new SIM card. That's helpful if you've lost your SIM but bad if an attacker wants to divert your number.
The best thing you can do is set a strong password on the account you have with the operator. You can also try ringing them and pretending to be you - see if they'll initiate a swap without proper authentication. If they do - move your number to a more reputable provider.
But there's nothing you as an individual can do to prevent a corrupt employee making the change without authorisation.
Sure, what this guy did was criminal. But not nearly as criminal as it should be for companies to unilaterally force customers into using snake oil authentication methods, just so they can check some new compliance boxes and pretend to be adding security.
You can’t receive shortcode or other SMSs for X hours after porting/doing a SIM replacement. Maybe just block everything with numbers in it, or “code” or “security” for this time.
Now if your phone goes dark, you get some notice to take action before your world falls apart.
the receipt of TOTP via SMS, regardless of telephony platform, however, is generally frowned upon by security heads.