shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

264
active users

#simswapping

0 posts0 participants0 posts today
Replied in thread

@stman @Sempf @LaF0rge yes.

Because physical SIMs, like any "cryptographic chipcard" (i.e. @nitrokey ) did all that fancy public/private crypto on silicon and unless that was compromizeable (which AFAICT always necessistated physical access to the #SIM, espechally in pre-#OMAPI devices) the SIM wasn't 'cloneable' and the weakest link always had been the #MNO /.#MVNO issueing (may it be through #SocialHacking employees into #SimSwapping or LEAs showng up with a warrant and demanding "#LawfulInterception"):

Add to that the regression in flexibility:

Unlike a #SimCard which was designed as a vendor-independent, #MultiVendor, #MultiProvider, device agnostic unit to facilitate the the #authentification and #encryption in #GSM (and successor standards), #eSIMs act to restrict #DeviceFreedom and #ConsumerChoice, which with shit like #KYC per #IMEI (i.e. #Turkey demands it after 90 days of roaming per year) und #lMEI-based #Allowlisting (see #Australia's shitty #VoLTE + #2G & #3G shutdown!) are just acts to clamp down on #privacy and #security.

  • And with #EID being unique per #eSIM (like the #IMEI on top!) there's nothing stopping #cyberfacist regimes like "P.R." #China, #Russia, #Iran, ... from banning "#eSIMcards" (#eSIM in SIM card form factor) or entire device prefixes (i.e. all phones that are supported by @GrapheneOS ), as M(V)NOs see the EID used to deploy/activate a profile (obviously they don't want people to activate eSIMs more than once, unless explicitly allowed otherwise.

"[…] [Technologies] must always be evaluated for their ability to oppress. […]

  • Dan Olson

And now you know why I consider a #smartphone with eSIM instead of two SIM slots not as a real #DualSIM device because it restricts my ability to freely move devices.

  • And whilst German Courts reaffirmed §77 TKG (Telco Law)'s mandate to letting people choose their devices freely, (by declarong #fees for reissue of eSIMs illegal) that is only enforceable towards M(V)NOs who are in #Germany, so 'good luck' trying to enforce that against some overseas roaming provider.

Thus #Impersonation attacks in GSM-based networks are easier than ever before which in the age of more skilled than ever #Cybercriminals and #Cyberterrorists (i.e. #NSA & #Roskomnadnozr) puts espechally the average #TechIlliterate User at risk.

  • I mean, anyone else remember the #Kiddies that fucked around with #CIA director #Brennan? Those were just using their "weapons-grade #boredom", not being effective, for-profit cyber criminals!

And then think about those who don't have privilegued access to protection by their government, but rather "privilegued access" to prosecution by the state because their very existance is criminalized...

The only advantage eSIMs broight in contrast is 'logistical' convenience because it's mostly a #QRcode and that's just a way to avoid typos on a cryptic #LocalProfileAgent link.

$38,000… GONE while he was sleeping.

That’s how fast SIM-swapping can destroy your financial life.

In just 3 hours, a hacker took over Justin Chan’s phone number, intercepted his two-factor codes, and emptied his bank and trading accounts. No alarms. No notifications. Just silent access and drained funds.

It didn’t happen because he was careless.
It happened because the attacker exploited a broken system:

- His mobile carrier transferred his number to a new device without proper checks
- His 2FA codes were sent to that new device
- His bank and investment apps trusted that number

This is the $38,000 mistake most people never see coming. Because by the time you realize something is wrong — it’s already too late.

The worst part? Getting the money back was harder than the hack itself.
It took media pressure, endless follow-ups, and months of stress just to get refunded.

Mobile numbers are the new master key — and most people are handing them out unlocked.

If your 2FA is tied to your phone number, it's time to change that.
If your carrier doesn’t lock down your SIM by default, it’s time to upgrade.
And if your bank’s idea of protection is a form letter and a closed case, don’t wait for a wake-up call at 3AM.

Psycho Bunny To The Rescue

After gaining control of her phone, hackers ripped off Avery Hartmans for $10,000.

Even worse, her credit card company didn’t believe the charges were fraudulent. Three weeks shy of her wedding, she was saddled with $9,778.24 in debt.

This interactive retelling of her ordeal is an awesome way to introduce people to the reality of organized crime attacking ordinary consumers through SIM swapping and physical theft of credit cards.

You don’t have to be “somebody special” to wind up on the receiving end of digital fraud.

And half of all victims of identity theft wind up being victimized again.

This is a great read, and the interactive pieces make the story more engaging.

businessinsider.com/credit-car

#InfoSec
#SIMSwapping
#PsychoBunny

Psycho Bunny To The Rescue

After gaining control of her phone, hackers ripped off Avery Hartmans for $10,000.

Even worse, her credit card company didn’t believe the charges were fraudulent. Three weeks shy of her wedding, she was saddled with $9,778.24 in debt.

This interactive retelling of her ordeal is an awesome way to introduce people to the reality of organized crime attacking ordinary consumers through SIM swapping and physical theft of credit cards.

You don’t have to be “somebody special” to wind up on the receiving end of digital fraud.

And half of all victims of identity theft wind up being victimized again.

This is a great read, and the interactive pieces make the story more engaging.

businessinsider.com/credit-car

#InfoSec
#SIMSwapping

> 400M Twitter accounts data is on sale, among which the most critical are username, mobile numbers & email. Hacker was able to provide a sample list of 1000 usernames, and our founder Haseeb Awan was able to verify many of them.

There are some serious concerns with the #databreach

1 - Identities of many pseudo accounts will be public
2 - With a phone number, it's super easy to find anyone's address and banking information.
3 - Multiple phishing attempts via cellphone, physical, or email
4 - #simswapping attacks to take over your bank account, social media, or confidential information

Preventative tips:

1 - Ensure that your MFA/non-sms 2FA is turned ON for every account that you use via #Authy #GoogleAuthenticator
2 - Switch to @Efani (irrespective of biasness, we have a 100% track record of securing your phone number, and no one provided any insurance)
3 - Use a #passwordmanager. Keeper Security Enterprise password Manager is ideal, but #DYOR.
4 - Call your bank and tell them to put a limit on withdrawals above
5 - Use a hardware wallet. #NGRAVE which is ideal, but #DYOR.
6 - Get Optery, getagency.com, or BLACK CLOAK for digital security