7 Tips To Avoid SIM Swap Attacks! What is SIM Swapping?

  Рет қаралды 101,489

Shannon Morse

Shannon Morse

4 жыл бұрын

SIM Swapping requires a savvy social engineer but also availability of personally identifying information. Learn how you can protect yourself from SIM swaps with these 7 tips!
#CyberSecurityAwarenessMonth
Special thanks to Crashplan for sponsoring this episode! Sign up for your own 1 month free trial at: www.anrdoezrs.net/click-918520...
Important links:
30 day security challenge: snubsie.com/30-day-security-c...
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤
FOLLOW THE SOCIALS THINGS:
Support ➜ / shannonmorse
Buy Me a Coffee ➜ www.buymeacoffee.com/snubs
Twitter ➜ / snubs
Instagram ➜ / snubs
KZbin ➜ kzbin.info?s...
Website ➜ www.shannonrmorse.com
Amazon Associates ➜ amzn.to/2pHgf8T
My Amazon Influencer Page ➜ www.amazon.com/shop/shannonmorse
Other shows I work on ➜ kzbin.info?sub_confi... and kzbin.info?s...
Mail ➜ please email for mailing address
Email ➜ shannon@shannonrmorse.com
❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤❤
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

Пікірлер: 233
@user-qg3zp5be7y
@user-qg3zp5be7y 3 жыл бұрын
If a scammer phones up a Telco and says "I have had my phone stolen and I want to swap my phone SIM", the Telco support staff should call the number of the "stolen phone" to see who answers it. If the phone has not been stolen then the true owner of the phone will now be speaking to the Telco support staff member. Problem solved.
@ShannonMorse
@ShannonMorse 3 жыл бұрын
If only telcos would do this before swapping the sims!
@aikafuwa7177
@aikafuwa7177 Жыл бұрын
That does not work for the paid bribed insider.
@Living_Dead_Girrl
@Living_Dead_Girrl Жыл бұрын
Plus due to the rampant data breaches, etc, nobody answers numbers they don't know anymore because they're usually scammers or robocallers. I'd say save the number for customer support in your contacts, but there's no knowing what number the actual dept or employee will call from. Then there's the fact that we sleep and do other activities where we have phone set to silent or can't be near our phone. That'd be a full time job just trying to catch that one call. Assuming they always use the "my phone was stolen" social engineering excuse, cell companies should require a police report first. Phones aren't cheap. For starters, best thing you can do use a service that limits it's SIM cards & doesn't do eSIM without getting their physical SIM first. Some service providers only sell their SIMs at one store chain, and that store won't sell them online. No matter what, you use this provider, someone's gotta go in person to buy the SIM where they'll be caught on surveillance cameras. It's a deterrent. There's also less data out their tying your identity to a pay as you go provider. They don't require SSNs or PID to activate a brand new SIM, and they do contact the prior service provider before they port that existing number. I recall it taking upwards of 3 hours dealing with CS when I switched to a pay as you go provider. I believe somebody tried to SIM swap me 2 days ago, because I got a text from customer service asking to rate their service or contact them if I need anything else. The text was legit, not phishing. So I immediately tried to login to my acct, but it kept giving an error that my acct was "invalid." Their site has become a nightmare, so it took a very long time to finally locate "forgot password" (it's not on login menu), which required me to 2FA from SMS several times to get there, and then again to select reset option. From there, they emailed a link to reset that expires in 10 min (wouldn't work with any DNS or browser ad/tracking blockers enabled), and yes, if your email's been hacked, this is extremely problematic, but they do continuously require SMS code authentication & I use an email proxy so no one can use that email address to login to the email itself. The site was buggy as hell, but I was finally able to change my password, pin, etc - and since I had to know my SIMs SN to activate, I saved it, and carrier showed my number's still on the same SIM. So, hacker waisted their time, and now my acct's on lockdown. In my case, I use a proxy email address that can't be used to login to the actual email acct. This "hidden" feature is avail free with free some email services, it's just not an advertised feature so you have to dig and it can't be an annoying process to set up. It's worth it given it helped me avoid a doomsday scenario when my extremely old email was compromised in multiple data breaches and there were tons of login attempts presumably to reset other acct passwords. I was able to keep the email without having to manually change email login on dozens of accts by creating a proxy email and swapping it to be primary, and then blocked logins from the compromised email address. For all important accts now, I use proxies for login and compartmentalize which email addresses I use for different security levels (i.e. banking, social media, cloud, personal, retailers, etc).
@gotdamnsoup2727
@gotdamnsoup2727 Жыл бұрын
@@ShannonMorse Message in a bottle..., Ive been social enginered, in sweden (didnt know they had customer support in swedish) I got hit by roaming mantis, cosmicstrand, both UEFI / lojax full control and a variant of xhelper. They have access over my gmail, and I cant do anything. Ive even tried installing linux with n external USB, but they have UEFI access so didnt succeed. Im alone here, so if someone see this. Please help me! they have control over my number with simcard jacking introduced after getting full access on one phone. Everything since rented out my appartment and they didnt pay rent so i cut internet, then I can see in the loggs (afterwards) tried to get free internet from me. That open the backdoor on my huw awei router and now my asus laptop, zenfone 9 , my girlfriends mac and her iphone. They have supershell access to this computer, and i dont even no if this comment will end up and your place shannon . But IF it do, please help me! i have lost everything and have nothing, i cant even pay my re nt. All accounts down. Im just a teacher and have been sick for 3 weeks now trying to solve this. But its not possible. If you help me I will be one of your paying subscriber forever. I worked with IT a long time ago (2011) I have done everything I know, but cant stop it. They just gaind more access, now having it all. THese 3 weeks of h ell making all my devices rooted with different malwares. DNS rerout, cookie poison, server cookie poison, everything. My m 4li is 1 a t u r ld o t1 with the last numbrs being the numbr equalent to letters. please somebody, help.
@gotdamnsoup2727
@gotdamnsoup2727 Жыл бұрын
Message in a bottle..., Ive been social enginered, in sweden (didnt know they had customer support in swedish) I got hit by roaming mantis, cosmicstrand, both UEFI / lojax full control and a variant of xhelper. They have access over my gmail, and I cant do anything. Ive even tried installing linux with n external USB, but they have UEFI access so didnt succeed. Im alone here, so if someone see this. Please help me! they have control over my number with simcard jacking introduced after getting full access on one phone. Everything since rented out my appartment and they didnt pay rent so i cut internet, then I can see in the loggs (afterwards) tried to get free internet from me. That open the backdoor on my huw awei router and now my asus laptop, zenfone 9 , my girlfriends mac and her iphone. They have supershell access to this computer, and i dont even no if this comment will end up and your place shannon . But IF it do, please help me! i have lost everything and have nothing, i cant even pay my re nt. All accounts down. Im just a teacher and have been sick for 3 weeks now trying to solve this. But its not possible. If you help me I will be one of your paying subscriber forever. I worked with IT a long time ago (2011) I have done everything I know, but cant stop it. They just gaind more access, now having it all. THese 3 weeks of h ell making all my devices rooted with different malwares. DNS rerout, cookie poison, server cookie poison, everything. My m 4li is 1 a t u r ld o t1 with the last numbrs being the numbr equalent to letters. please somebody, help.
@JohanlastZa
@JohanlastZa 4 жыл бұрын
Every time I think of security, I think of this: You are the weakest link. Humans should not be trusted with security of any kind because we are fallible and easily corruptible. SIM swap should not be allowed over the phone or email, only in person, face to face, complete a form and it must be signed by the customer, the agent and a higher up at the company. Companies should take responsibility for their failures in security. It astounds me on the lack of foresight when they hire people to work in an environment where they have access to personal information of people, yet they have ZERO security clearance.
@ShannonMorse
@ShannonMorse 4 жыл бұрын
Yes!!! This!!! I completely agree with you.
@JohanlastZa
@JohanlastZa 4 жыл бұрын
@@ShannonMorse With the increase in SIM swap fraud, people should also move away from OTP authentication and rather let them send the code request to a secure email. Another thing would be to use supplied security certificates on transactional devices which should remove the SIM swap problem.
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
More and more use prepaid phones. Your idea only works if you have a contract. Or if you can go into a store. Even then you have to have an 'account' most of the human race does not. I had a phone years ago. All I had to do was turn it on. I had a number.
@JohanlastZa
@JohanlastZa 4 жыл бұрын
@@jamesedwards3923 Where I am from, if you do not use the number for 3 months, it is gone. Secondly, all numbers in use must be on the "RICA" system. All numbers are connected to a SIM, a person and that person's address. Unfortuantely only one bank here requires physical presence when activating cellphone banking with a working and registered SIM and phone and during setup the client's phone setup, a form is signed and finger prints taken. A really secure setup. If client's phone or SIM changes, these steps will need to be repeated. Prepaid and contract are all registered.
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
@@JohanlastZa Wow, you are way more secure than most of us.
@SU-II
@SU-II Жыл бұрын
In Malaysia, SIM card replacement requires walk-in to nearest mobile center, inserting the national ID to a validator device, scanning a thumbprint to validate ID ownership before proceeding to print the SIM card. New SIM Card registration requires a national ID or Passport for foreigner. Liability falls on the registrant if the number is used for criminal activities. You can keep same phone number even if you switch carriers
@SU-II
@SU-II Жыл бұрын
@Faye Cushnie Seems like you are also still stuck in the 70s
@gertleroy
@gertleroy 3 жыл бұрын
great vid thanks for explaining !
@Blockxblock
@Blockxblock 7 ай бұрын
Just stumbled upon your channel since I've started to strengthen my security seriously. Great content. Thank you
@_pilly
@_pilly 4 жыл бұрын
Good list of tips! Ever since seeing the Threatwire video I’ve been worrying about this. Thanks for making this video!
@MB-hz7wm
@MB-hz7wm 3 жыл бұрын
This is truly valuable content ~ thanks for what you do!
@Planetgreenzen
@Planetgreenzen 3 жыл бұрын
Thank you for making this video. Much appreciated.
@0404brad
@0404brad 4 жыл бұрын
I feel like this is similar to why we need to stop using SSNs as a national ID number
@Nylspider
@Nylspider 3 жыл бұрын
Exactly SSN's aren't even secure
@Minecraft101ToonLink
@Minecraft101ToonLink 3 жыл бұрын
Even a credit card’s card number by itself is more secure than a SSN because it has more digits.
@camaroman101
@camaroman101 2 жыл бұрын
considering fingerprint scanners are in every phone, I feel like that would be much more secure
@amymaier2679
@amymaier2679 4 жыл бұрын
Your video is the best I've seen on this subject. Thank you💓🙏
@zulfphotography
@zulfphotography 3 жыл бұрын
Excellent advice, thanks
@AndrewK
@AndrewK 3 жыл бұрын
Thank you for the help 🙏
@keiththomson5256
@keiththomson5256 3 жыл бұрын
Excellent video. Well researched, thank you !
@somethingelse25
@somethingelse25 10 ай бұрын
This is good advice. I'm leaving my browser open on this video and I'll watch it again but I plan on implementing much if not all of this. Thanks!
@lanajantz2240
@lanajantz2240 2 жыл бұрын
Wow that is a lot if information. I will have to watch a few times and take notes! Thank you.
@nickinhb1
@nickinhb1 4 жыл бұрын
Shannon, Thank You
@MrSuperSnuiter
@MrSuperSnuiter 4 жыл бұрын
Awesome video 🔥
@joiab11
@joiab11 3 жыл бұрын
Hi from 2021! I have been planning, dreaming, learning about starting a KZbin channel but I'm a really private person and I have been so worried about safety. This video is really helpful, I took notes and I'm going to follow your advice. Thank you!
@user-uu5di9de2t
@user-uu5di9de2t 2 жыл бұрын
Thank you so much for this.
@Anna-jv8mn
@Anna-jv8mn 3 жыл бұрын
Thank you, please continue these videos!
@ShannonMorse
@ShannonMorse 3 жыл бұрын
You got it!
@Nylspider
@Nylspider 3 жыл бұрын
Came here from Roberto and I really needed to know about this. Thanks for these tips!
@IsThatOC
@IsThatOC 3 жыл бұрын
Opened my eyes!
@VeganGroceryLife
@VeganGroceryLife 3 жыл бұрын
I have a Google number that is tied to my phone so it’s time to get another Google number! Thank you for the info! I came here from Roberto’s channel.
@What2expectinthehospital
@What2expectinthehospital Жыл бұрын
Thanks!
@bethanyfleming4798
@bethanyfleming4798 4 жыл бұрын
Thank you Shannon for this much needed information. I am currently going through some troubles with every phone I get. For some reason I feel like I'm not doing something right from the time I turn the phone on until I break it or buy a new one. It's very frustrating. I just wanted to thank you for the work your doing and information you have made available.
@ShannonMorse
@ShannonMorse 4 жыл бұрын
Absolutely! Happy to help!
@hunterthejokethegamerandst5567
@hunterthejokethegamerandst5567 2 жыл бұрын
@@ShannonMorse does encrypting your phone help?
@jaisvikt
@jaisvikt 3 жыл бұрын
Sharp lady and great advice. Not technical myself, I notice you have great color for your nails, they are short enough to indicate you work for a living. Best
@ShannonMorse
@ShannonMorse 3 жыл бұрын
You can solder with long nails, FYI.
@jedimindtrickonyou3692
@jedimindtrickonyou3692 4 жыл бұрын
Hey Shannon, I hope you do more videos like this even after this mini series is over! Threatwire isn’t often enough for me to get my Shannon-Tech fix. It’s been hard on me since Tekthing ended. 😉Seriously though, you’re one of my favorites and I love all your content. A++
@ShannonMorse
@ShannonMorse 4 жыл бұрын
Thank you!! I'd love to do more security and privacy videos!
@jedimindtrickonyou3692
@jedimindtrickonyou3692 4 жыл бұрын
Yes, please! Your 30 day challenge you did a year or two ago sparked my interest in the subject. I view everything differently now and am in a much better position after implementing as much of the suggestions as possible. Thank you for that! 🙏🏻
@expchrist
@expchrist Жыл бұрын
Thank you for this!!!
@ShannonMorse
@ShannonMorse Жыл бұрын
No problem 😊
@shakura6476
@shakura6476 4 ай бұрын
I would love to transition to not having a cell phone at all, and I would love to hear from you or others about ways to transact with banks and businesses and the world without owning a cell phone.
@BlankHero
@BlankHero 3 жыл бұрын
Thanks for the Tips! Roberto sent me and I'm glad I listened
@dilshanmaduranga6669
@dilshanmaduranga6669 3 жыл бұрын
Me too
@nagamachiku8699
@nagamachiku8699 3 жыл бұрын
@@dilshanmaduranga6669 Me three...
@modelchickny
@modelchickny 3 жыл бұрын
Roberto Blake suggested your channel. Thanks for this information.
@sisteradmn
@sisteradmn 3 жыл бұрын
Thanks! good stuff
@ShannonMorse
@ShannonMorse 3 жыл бұрын
thank you!
@teddyamuma3240
@teddyamuma3240 4 жыл бұрын
Very helpful
@janokartal5690
@janokartal5690 4 жыл бұрын
Looks great
@jackiedecoma4637
@jackiedecoma4637 4 жыл бұрын
Thank you for tips. Sadly I still need this information broken down simplifer as I am not tech savvy. Can you recommend a book or something - thanks!
@junquindoy6417
@junquindoy6417 4 жыл бұрын
Very informative information indeed. Thanks for sharing. I will share this to my friends
@phylanselmo981
@phylanselmo981 2 жыл бұрын
You are a cute letting us know about this threats. I was hacked so many times. Last time I couldn't use my Facebook or WhatsApp sending OR receiving photos, videos or voice message. Thanks for your help. I am appreciating it.
@garynagle3093
@garynagle3093 4 жыл бұрын
Great tips. Now I’m nervous about someone stealing my phone number. 🤪
@ShannonMorse
@ShannonMorse 4 жыл бұрын
You're likely fine as long as you use some of these tips and good internet hygiene!
@garynagle3093
@garynagle3093 4 жыл бұрын
Shannon Morse, I need to investigate the google phone tip for sure, and my replacing my mother’s maiden name with my favorite song phrase
@Kas_Styles
@Kas_Styles 4 жыл бұрын
@@garynagle3093 you commenting that you should change it to your favorite song lyric is now info that someone could use. Another tip: never talk about what your Security answer is or what its about.
@gpwgpw555
@gpwgpw555 3 жыл бұрын
At over seventy years of age it becomes difficult to jump over these high mental fences. When asked to choose three out of eight security question, I only knew one. ( this is the first one of your videos I have seen).
@jenespaltero475
@jenespaltero475 3 жыл бұрын
Thank u..very helpful..
@ShannonMorse
@ShannonMorse 2 жыл бұрын
Happy to help
@jeffhirata
@jeffhirata 2 жыл бұрын
Thank you!!! If you stopped using SMS 2FA, wouldn't that completely eliminate the ability to SIM swap???
@yumeko9773
@yumeko9773 3 жыл бұрын
Thanks for this Ma'am :). Btw i really love your cute anime stuff at the back hehe.
@ShannonMorse
@ShannonMorse 3 жыл бұрын
Thanks!
@kaw1980q
@kaw1980q Жыл бұрын
a little late to the watching this video! lol! I work in fraud for a big communication company and the biggest thing a person can do to protect them self is protect your phone number and your email. You give real good advice!!
@KRIS47GAMER
@KRIS47GAMER 4 ай бұрын
I’m sure it’s happened to me mate
@BackcountryTripper
@BackcountryTripper 3 жыл бұрын
Roberto Blake sent me here, this video was fantastic thank you!!!
@MahfuzurRahman-fr8tk
@MahfuzurRahman-fr8tk 2 жыл бұрын
🤔many many thanks to you ...
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
Secret Questions are an excellent old fashioned tool for authentication. They are easy to change and easy to store in alternate locations. In an encrypted state of course.
@camaroman101
@camaroman101 2 жыл бұрын
also only you would know some of them. Unfortunately people seem to be phasing them out.
@jamesedwards3923
@jamesedwards3923 2 жыл бұрын
@@camaroman101 Unfortunately.
@therealtea9786
@therealtea9786 3 жыл бұрын
My hacker also listens to my sim calls live distorts the line & drops it just to be annoying is this still a sim swap attack or is he using some sort of Tower near where i live to intercept the line?
@tomng7677
@tomng7677 Жыл бұрын
Hi, Shannon. I have a question. Do I need each ubit key for one application or can I put multiple applications into 1 ubit key?
4 жыл бұрын
I dont how but in Turkey, Banks uses one time code and if sim card change new one they stop one time code until you call customer services or going to atm.
@beatweezl
@beatweezl 2 жыл бұрын
Here's my tip after getting SIM swapped weeks after I switched to a new carrier: Request upgraded security on your account. That means that the carrier will disable you from accessing your account on their website to make any account changes. Your 8 digit PIN code won't work. The only way you can make changes to your account is to go in to a corporate location and show them your ID or provide an alpha numeric password that you set up when requesting the security upgrade.
@aaronyeboah7824
@aaronyeboah7824 3 жыл бұрын
Is it advisable to use your channel email account to buy any video editing app or audio for your channel?
@SuperWishaniggawoods
@SuperWishaniggawoods 3 жыл бұрын
Miss mamas came thru with all this Information ℹ️! Great video Totally explains why I don’t get half of the text messages I used too. Lol 😂 silly rabbit 🐰
@gbass7328
@gbass7328 2 жыл бұрын
Hello - what is the liability for selling a SIM card not in use by your phone account anymore?
@drac124
@drac124 3 жыл бұрын
Its not clear to me that put a pin or passcode in the SIM card would avoid cloning the phone number. Because that PIN is for my physical SIM card, inside my phone. Does it sync to any SIM card created for that specific phone number?
@jambojim2910
@jambojim2910 4 жыл бұрын
AT&T wont make those changes without seeing your state DL. But the carrier should then be liable for not verifying the true identity of the customer!!! More law suits coming now doubt.
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
The problem is you may not always to be able to get to your provider. Life is problematic.
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
If you can find it in their: Public Bills. Contract. Customer Service Call. Etc. You have a law suite.
@jenjen3366
@jenjen3366 3 жыл бұрын
Oh yes much more lawsuits cali. NM. TX. Yep
@charlesmaou6375
@charlesmaou6375 2 жыл бұрын
Hi, just a thought here, how about having another phone or with a dual sim phone have another sim purely for all finances, ie banks, crypto exchanges ect ect and not used for anything else, ie phone calls messages ect. And furthermore, on this phone have a sim pin/passcode?
@samillien
@samillien 2 жыл бұрын
This information is great. Too bad that the way I found this video is because I was SIM swapped and over $11,000 was stolen from me. But going for are, I will use some of these tips.
@ebenezer357
@ebenezer357 3 жыл бұрын
Important question. To open up a new phone number for 2Auth they need my official name, which means that it will go to the white pages, and even if I never give my new number to anyone, a hacker could still find it on the white pages. Do you have a solution for that? Please help!
@therealtea9786
@therealtea9786 3 жыл бұрын
Will a Yubi Key still work if your hacker is a mind reader i am not joking & can the Yubi key be cloned?
@a.b.8606
@a.b.8606 3 жыл бұрын
You can also ask a family member to get you a sim. This way, the phone number/plan you are using is under their name and not yours!
@tomng7677
@tomng7677 Жыл бұрын
Hi, Can you make a video about SIM LOCK, this feature available in Android and iPhone. How is the sim lock work? Would it prevent SIM SWAP? AND further more about Esim. Would Esim prevent sim swap since it's not a physical sim card? Thanks
@xiloeteknowledgiesllc1973
@xiloeteknowledgiesllc1973 3 жыл бұрын
How about SimJacker where they just send you a hidden text message and take over your phone at the baseband level?
@PeaceChanel
@PeaceChanel 2 жыл бұрын
Thank You for All that you are doing for World Peace and for our Planet... Peace.. Shalom.. Salam.. Namaste .. 🙏🏻 😊 🌈 ✌🌷 ☮️ ❤️ 💐 🕊
@Cali_Girl1
@Cali_Girl1 Жыл бұрын
If I get a new SIM Card and Phone Number, will that stop 'Spam Calls' ?
@Kr33gola
@Kr33gola 7 ай бұрын
should I buy a second sim? or a thrid
@rvrss7192
@rvrss7192 Жыл бұрын
Ha-ha, so somewhere there in "advanced OmeriGa" one can call mobile provider and ask to switch SIM based on statement that the caller is a real owner of a "stolen" phone, even without presenting himself alive to the provider service center to prove the identity of a subject?
@ced468
@ced468 4 жыл бұрын
What about a private mail server with Google Authenticator?
@johnholme783
@johnholme783 2 жыл бұрын
A very comprehensive critique of sim swap security! Thank you!
@thelittleittybittypityshow6380
@thelittleittybittypityshow6380 3 жыл бұрын
I bought a ybi key over a year ago. Still don’t know how to use it
@amymaier2679
@amymaier2679 4 жыл бұрын
Domestic violence survivors are often victims. I have experienced every device I obtain hacked for many years and now sim swapped. Perpetrators work together and make it impossible for their victims to use technology without being hacked & cyberstalked. Sim swappers have turned off my phones. They also seem to enjoy having their victims use the victim phone while they watch and perpetrate all kinds of destructive acts against their victims. I tried only accessing my telecom account at their stores. Telecom employees copied my IDs many times. My service and accounts became even worse; with my identity seemingly stolen. How can a domestic violence and stalking survivor of extremely intelligent, high tech perpetrators possibly move forward??? 😓😓😓
@spaceiswater6539
@spaceiswater6539 4 жыл бұрын
Does the USB hardware key have a password as well to use it, for example if someone did steal it from you they would they still not be able to use the hardware usb key due to needing a password or is it just plug it in and it just does what it needs to do? Great video thank you so much.
@jedimindtrickonyou3692
@jedimindtrickonyou3692 4 жыл бұрын
I have a yubikey and you can enable a password for some of the key's features. You can actually store the same type of 2fa time based TOTP codes that authy uses on the yubikey and use yubico authenticator to view the codes. For that you can protect it with a password. For Fido U2F, which is the method you would use to register the key with your Google, Facebook, Twitter, etc account. For that, I don't think you can protect the yubikey with an additional password. But keep in mind it's a second factor, so they would need your login username + password + physical posession of your yubikey to gain access to your accounts and if they could get all 3 of those things from you, then they could probably steal that additional password too. If you're gonna buy a yubikey, you should ALWAYS buy two and register both of them with all the same accounts so that if you were to lose possession of one of them, you would still be able to access everything.
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
Look up the FIDO standard. Answers all your questions.
@plainsabertooth7828
@plainsabertooth7828 Жыл бұрын
So how do they get your social medias info?
@marcusboddington7554
@marcusboddington7554 4 жыл бұрын
You need to make longer videos. I like your videos, but I like longer ones.
@tyron4183
@tyron4183 2 жыл бұрын
if someone called up and gave the wrong birthday or mothers middle/ maiden name or something that could not be remembered wrong and the company doesn't or can't report that to authorities they are partially/ unintentionally allowing ID theifs to incentivise their efforts. Collecting statistics like that might at least give some insight on how rampant ID theft is in different areas
@amritasharma9840
@amritasharma9840 2 жыл бұрын
How can we know or confirm that our sim is cloned by someone or not?
@oldmovies799
@oldmovies799 3 жыл бұрын
What about enable a PIN on the Sim?
@doge1931
@doge1931 2 жыл бұрын
OMG .. I wonder how many people have changed there secret answer to " a scrub is a guy who can't get no love from me"
@masterbjohnson2
@masterbjohnson2 4 жыл бұрын
In Australia, you only need DOB, address and phone number to sim port. Once a telco has had the request to port your number, they must do it by law, even if the authorised account holder tells them not to. The only way to protect yourself is to move house or change your phone number, or lie about your DOB, which apparently is an offence under the act.
@leonmcgovern2804
@leonmcgovern2804 4 жыл бұрын
Great explanation and very useful tips; especially number 7. However, it seems like SIM swapping is not something hackers could get away with for a long time as I should almost immediately notice that my phone is no longer working. Or is there another more subtle way of getting away with this?
@uniquechannelnames
@uniquechannelnames 3 жыл бұрын
Its more like they can start attacking so fast oncce they have the number they hope you take at least 15-30 mins to recover. That way they can exploit your email's SMS recovery or bank SMS recovery and by then theyre into all the important accounts of yours. If they lose the phone number after that its not a big deal because they already got the access and have changed passwords etc... Especially if you have crypto coins somehow linked thru emails that get compromised. It can be devastating. It isnt meant to be a long con. It's more like "swap it, now exploit as much as possible as fast as possible"
@laurenblakley8069
@laurenblakley8069 4 жыл бұрын
Google Voice, sounds good but who can trust Google?
@solice8844
@solice8844 4 ай бұрын
Even if the scammers get the SIM card working on anew phone and they now have access to your apps, messages, emails, etc. how can they drain your bank accounts if they don’t know the usernames and passwords?
@ShannonMorse
@ShannonMorse 4 ай бұрын
If you have account resets or password resets tied to your phone number, that can be used to bypass the original password. Because they would receive your text messages.
@solice8844
@solice8844 4 ай бұрын
@@ShannonMorse okay, now I get it. Thanks.
@bana2s
@bana2s 4 жыл бұрын
I have Google Voice configured on an OBi200 VOIP phone connected to my wifi.
@bana2s
@bana2s 4 жыл бұрын
For extra coolness, it’s connected to a red auto-dial phone. My family has a hotline to my cellphone.
@blomegoog
@blomegoog 4 жыл бұрын
and how do you get SMS thru your OBI cordless I wonder
@gregh7457
@gregh7457 4 жыл бұрын
warning: i tried setting up a pin on my unlocked iphone6. I turned on sim lock and it asked to enter a pin code. Entered my new code twice and said that it could not lock the sim. I then tried to disable sim lock and it asked for a PUK code. I have no memory of ever locking the sim on this phone and had never heard of it before this video so its highly unlikely the sim was locked already. I had to call tmobile for a PUK code. what a pain!
@Flippeh
@Flippeh 3 жыл бұрын
The carrier has a default code. Google tells me that tmobile's default is 1234
@saifislam6971
@saifislam6971 2 жыл бұрын
Mam i have a question please respond if you see this. I just activated a sim against my identity. Please respond to my query i will explain more.
@CookingwithMsvee
@CookingwithMsvee 2 жыл бұрын
What to do after you got scammed, I lost over $1000.
@DexterRiverman
@DexterRiverman 4 жыл бұрын
About crashplan, what about privacy? Security?
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
Encrypt the files before you upload them. Problem more or less solved. VeraCrypt. PeaZip 7zip KeePass Password Safe
@jamesedwards3923
@jamesedwards3923 4 жыл бұрын
Which is why manual backups of data to the cloud is my preference. Whether you use a zero knowledge backup provider like spider oak. Or some other cloud service. If you encrypt the data with layers of encryption and multi factor efforts. The data should be reasonably secure. Encrypting a file in a simple encrypted file and then encrypting that file in another file. Is the easiest common sense approach. So even if an inside man compromises a cloud service and extract your encrypted file. They would have to attack all the layers of encryption. For example PeaZip allows for keyfile encryption. Typically most people do not use keyfiles for a zip file or a .7zip file. Which means a typical hacker will normally not account for that vector. Depending on the software applications. You can use key files or hardware keys. This is why you must actually sit and ponder how you are going to secure your data.
@arunaslasiunas6699
@arunaslasiunas6699 3 жыл бұрын
How to Avoid Getting hacked?
@tyrellmccurbin8045
@tyrellmccurbin8045 3 жыл бұрын
Roberto Blake sent me here
@BOOSTEDDUDE
@BOOSTEDDUDE 4 ай бұрын
But I don't get it. Wouldn't the persons phone they just called customer service to sim swap and activate their phone cause the persons phone that was swapped service to shut down? Thus, disabling the victims phone would suggest they wouldn't try to use any 2FA push and making any intercepts unlikely.
@ShannonMorse
@ShannonMorse 4 ай бұрын
When I switch my sim or esim to a new phone, my old phone never shuts down. The ONLY thing that happens is the little icon at the top changes from showing me 5g to showing me wifi only. If someone doesn't notice that they'd have no clue their phone number was swapped.
@BOOSTEDDUDE
@BOOSTEDDUDE 4 ай бұрын
Oh wow, That's hard to believe. Thanks the info@@ShannonMorse
@ShannonMorse
@ShannonMorse 4 ай бұрын
Why is it hard to believe? I review phones and swap my sims in between them at least once a month. I've also don't over 2500 videos about sec/priv (my OG channel is called Hak5). I think I know what I'm talking about.
@lorimast
@lorimast 3 жыл бұрын
Using Google voice for authentication is a great tip!
@runitback2back
@runitback2back 3 жыл бұрын
I had a pass code and they still have my chip away
@maniapannu927
@maniapannu927 3 жыл бұрын
Mam please tell me that a person from Orlando Florida is asking me to buy a new sim on my name and insert In a phone so that he could give me an iPhone as GIVEAWAY ? Help me mam
@TechExploresNYC
@TechExploresNYC 3 жыл бұрын
What's your favorite color? Banana, or Coffee, What's your mother's maiden name? Hillary Clinton, something like that.
@BorisBidjanSaberi11
@BorisBidjanSaberi11 2 жыл бұрын
Just happened to me… 2021
@george_anak_lihi
@george_anak_lihi 6 ай бұрын
0:07 😮😮😮
@0mkarMirkar
@0mkarMirkar 4 жыл бұрын
😆😆😆 first I was getting your video that it was about sim swapping later as it gone to social engineering well my dear, in India such attacks are too hectic for attacker because our telecom operator does not create an online account in India what will happen is customer care will try to verify you & at the end he/she will tell to carry all the necessary valid documents & physically visit the gallery for buying a new sim at ₹30/- per sim 🤣🤣🤣 and by valid document I MEAN PAN card, Aadhar card, driving licence, passport, electric city bill, etc. only government documents are allowed. One original for proof & one xerox for submission an attacker will have alot of hurdle to grab on it. With regards to privacy I keep three sim & three phone one for business & social use, one for family & friends only (shared only people with count on my finger tip) & one for validating my otps & all verification phone this phone is usually kept at home diverted on my phone 2. For social & business I use a 2g phone featureless phone with no gps no Bluetooth & no wifi it only has a call recorder an headset & memory & sim card slot just to stay off the grid. My friends & family phone & authenticator phone are my smart phones both on with fake GPS on so I leave in California on my fake gps while physically leaving in Mumbai & my tor vpn is always online 😜. Google Ads I receive are all California based so it verifies me that I have correctly spoofed location. Love to see your videos following u on insta.
@user-tv4ki7yc1k
@user-tv4ki7yc1k 2 ай бұрын
❤❤😊sorry about that but that all factual. The companies allowing this sort of behaviour is sad. When I see my folks getting a new phone only to notice it hacked. I can't even tell them. These companies are disgusting protected behaviour ❤
@Rise9192Against
@Rise9192Against 3 жыл бұрын
I think Authy requires you to use a phone number--which defeats the purpose of true 2FA.
@ShannonMorse
@ShannonMorse 3 жыл бұрын
It does, but luckily there are tons of alternatives (my favorite being hardware keys, of course.). I get why they do it - it makes Authy more user-friendly because you can put it on multiple devices or reinstall it if you lose your device... but yes, that does still open up your Authy account to potential vulnerabilities in security. You CAN turn off "Multi-device" in the settings and you CAN add PIN and fingerprint protection to the app so even if someone sim swapped you, they'd still be locked out without your PIN. That's what I'd do if I switched phones a lot and used Authy.
@inezsecurity3753
@inezsecurity3753 3 жыл бұрын
How does sim pin prevent sim swab ?
@uniquechannelnames
@uniquechannelnames 3 жыл бұрын
Ostensibly, if you have a PIN set up and someone calls to change your sim to another card, they will have to give the correct PIN. BUT do not put any faith in pins, because carrier agents have the power to go around PINs, if the criminal can give enough of your personal information to convince the agent, then theyll void the PIN and swap the sim over. Best course of action is to simply give no power to someone who gains your phone number. No reocvery sms, no sms 2FA, nothing for any important accounts.
@uniquechannelnames
@uniquechannelnames 3 жыл бұрын
Oh a SIM PIN. I thought you meant a PIN on your phone company account.
@aaronyeboah7824
@aaronyeboah7824 3 жыл бұрын
Hello Morse, Another thing is that can they still steal your account if they don't know your number? Is there any way they can do that?
Top 9 EASY Smartphone Security Tips For Android and iPhone!
12:15
Shannon Morse
Рет қаралды 29 М.
ТАМАЕВ vs ВЕНГАЛБИ. ФИНАЛЬНАЯ ГОНКА! BMW M5 против CLS
47:36
Phishing bank scam dupes Golden couple out of $137K
5:14
FOX31 Denver
Рет қаралды 462 М.
The Truth About SIM Card Cloning
13:04
Janus Cycle
Рет қаралды 1 МЛН
The $24 Million SIM-Swapping Hack
3:59
Bloomberg Originals
Рет қаралды 151 М.
Debunking 5 MYTHS About Yubikey
15:36
Shannon Morse
Рет қаралды 185 М.
Expert Explains How To Prevent Cell Phone SIM Card Swapping
5:36
News On 6/KOTV
Рет қаралды 133 М.
Why VPNs are a WASTE of Your Money (usually…)
14:40
Cyberspatial
Рет қаралды 1,4 МЛН
6 Must-Have Security Gadgets That Fit in Your Pocket
9:03
All Things Secured
Рет қаралды 1,8 МЛН
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,7 МЛН
What is a SIM Swap Scam?
12:33
Putnam County District Library
Рет қаралды 329 М.
How to protect yourself from phone SIM swapping
4:08
NBCLA
Рет қаралды 161 М.
Bluetooth Desert Eagle
0:27
ts blur
Рет қаралды 8 МЛН
Ждёшь обновление IOS 18? #ios #ios18 #айоэс #apple #iphone #айфон
0:57
i like you subscriber ♥️♥️ #trending #iphone #apple #iphonefold
0:14