The SIM Swap
TL;DRA 20-year-old named Nick allegedly stole $24M via SIM swapping—tricking carriers into redirecting victims' phone numbers to steal cryptocurrency. A friend named Chris recorded him and wrote a sworn affidavit detailing the scheme.
Jordan Bloemen & Scott Francis Winder discuss SIM Swap attacks.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: The following is based on a sworn affidavit, but it starts with some tweets. Here are just a few. Stole 24,000,000. Still a failure in the eyes of the world. Stole 24,000,000, can't stop stealing. Stole 24,000,000, but can't stay away from drugs. Stole 24,000,000, but still can't keep a friend. We are in the AT and T flagship store in Times Square, and two guys walk in. One younger, one older. The first guy, Nick, the younger of the two, is maybe 20, short black hair, gaunt face, goes up to a clerk named Spencer. Nick explains that there has been a mistake, and he needs to add his name to an account. He's got the info, the account number, the PIN, he shows his passport, and the employee, Spencer, goes to add Nick to the cell phone account. But, there's an outstanding bill, and the employee says that Nick has to pay it before he can add himself to the account. Nick says forget it, and he and his friend walk out. You see, the employee Spencer was this close to making just a huge mistake. Because you see, if Spencer had let Nick add his name to that account, well, let me take you through what would have happened. First, Nick would have used his new found presence on the phone account to redirect all incoming traffic to the number to him. This includes texts. Then, he would have used that number to get past the two factor authentication, protecting the original number holders cryptocurrency wallet. The kind of thing where you're texted a pin when you try and log into an account. Which is all to say that 20 year old Nick would have pretty quickly had complete and total access to an online wallet worth millions. And he would have stolen every cent were it not for Spencer. Which begs the the question, who was the guy who walked in with him? The other guy is Chris, author of the affidavit on which this story is based. Chris is a private jet rental salesman, who met Nick in the gym of a luxury apartment, played video games with him, became his friend, partied with him, figured out how Nick made all of his money, got terrified, started recording Nick, and wrote that. That story is based on his claims. There hasn't been a trial. We can't verify that. It's speculation. So what scam exactly, according to Chris, was this kid, who wrote those tweets that opened the episode, running? How exactly does a 20 year old steal $24,000,000? This is the sim swap, on this episode of Hacked. We're still here. We are. We didn't go anywhere.
Speaker 2: We didn't go anywhere. We've still been sitting in these seats
Speaker 1: Waiting.
Speaker 2: Waiting for a month to pass to release another episode.
Speaker 1: Weeks. See if we can record the next episode. That's how excited we've been.
Speaker 2: Yeah. No. It's been great. I, I gotta say that I've just been enamored by the great response to the podcast coming back, all the support, especially the patrons. And this episode shout out goes to Megan Star Trek. Thanks for your support. Thanks for being a $5 hire donor, and we really appreciate it.
Speaker 1: It means a whole heck of a lot to us and to everyone who's supporting us on Patreon, patreon.com/hackedpodcast. Just about the best way you can support the show. It's been a lot of fun being back and getting to make this thing that, has people who are actually enthusiastically listening to it. Every message we get, it's a treat. It's a treat every single time. And it makes it exciting for us to come down and sit in here and record one of these things.
Speaker 2: You make our day brighter. Each and every one of you. You're out
Speaker 3: to meet a man who lost a million dollars.
Speaker 4: If you have a mobile phone, you are a potential target in the SIM swap scale. The SIM is the small card that contains your phone number. The hackers got Rob's carrier to swap his number off his SIM and put it on their phones.
Speaker 1: AT and T said there had been a SIM swap request. What is a SIM card?
Speaker 2: A SIM card is a a relatively recent addition to the cell phone. It was only how in GSM rolled out. You might not be old enough to remember that, but I sure do. Yeah. The anyway, the SIM card is the, subscriber identity module, which is, you know, a beautiful tech name for something so basic. But essentially, it's a way that the cellular network identifies your device.
Speaker 1: Kinda like a name tag.
Speaker 2: Yeah. Essentially. Back in the day, the there there wasn't actually a card. It was just hard coded into the phone. So you would literally go to a a cell shop, get a phone and they would punch in your, like, subscriber ID right into your phone. And then eventually when GSM came out, they said, hey, you know, people are keeping their phone numbers and are changing phones. Wouldn't it be great if we put this onto a tiny little card that they could slide in and out of different devices?
Speaker 1: Right. So the reason you wanna have a little card that can be taken out of the phone is it so that people can easily swap phone numbers between phones and phones between phone numbers?
Speaker 2: Yeah. Essentially. It's probably where it came from. Interesting. And to promote the upgrade cycle of cell phones that we all now live and die in.
Speaker 1: At what point did a SIM card go from being a way to tie a phone number to a phone and become a tool for security?
Speaker 2: Well, that's, I don't think it ever has. I I think a bunch of companies have made it that way. You know, phones have never been identification documents. It's not my passport. You know? It's not something that I, like, have to go to the government and get issued to me. It's just a phone number. And the fact that we've all become so addicted to our cell phones and they never leave our side, they've started using them as such. I actually spent, you know, five minutes before we shot this episode and rolled through my cell phone or through my text messages to see what recent services had used my phone as such a thing, and the list was ridiculously long. And it was all major, companies too. It was like my bank. It was Facebook. It was Google. It was PayPal, and it was, like, my Internet provider at home. They all had texted me codes, kind of as a two factor authentication or, like, a cheap form of a two factor authentication.
Speaker 1: Your bank texting you a PIN code that you then type into their website, How does that turn your phone into an identification document? What is that trying to achieve?
Speaker 2: They're just essentially saying, hey, you have the password or, you know, you are trying to reset a password sometimes. They just wanna verify that the person making that request is the person who should be, and they're cheating the system by using, you know, your cell number essentially as a as a form of identification.
Speaker 1: When you say cheating, how's that a cheat?
Speaker 2: It's a cheat in the sense that it's not, you know, truly something that defines who you are and is part of your identity. It's just a your phone number. You know?
Speaker 1: Right. It's not blood. It's not a fingerprint.
Speaker 2: It's not a photo. No. It's just literally a text message.
Speaker 1: So the whole big idea behind this is I'm Google. I'm Facebook. I'm your bank. Someone has tried to log in to your Scott Winder's account. Mhmm. And the bank is gone. Okay. They had all the information that we would normally expect from them. Right? They they have your username and they have your password. But, we want to take this one last step. We want to someone else might have those things. We would just want to confirm that this is actually you. And, one other thing we know about you is that you have this phone. This Physical device that this hacker probably doesn't have. So we're gonna text that number and if you get that code you can confirm that you got texted. That's the basic kind of mechanism behind this. Right?
Speaker 2: Yeah. Yeah. The the beauty of it is is that it is actually better than not doing it but the catch is that some services, especially the cryptocurrency, brokerage that was in the intro story, was using the cell number as, like, true second validation of identity. So, like, instead of just being, like, I'm logging in. Here's my username and password. It was more like, I've lost my password. I need to reset it. And they would say, okay. We'll send you a link to your text message. You know? Same as when we talked about emails in a previous episode, It becomes a bit of the key chain. So if you can get access to someone's emails, you can get access to resetting their passwords. This is what the intro story was about was the fact that now, you know, some services are using text messages like that. So now getting access to the text message gets you access to reset their password.
Speaker 1: It's the service trusting that the phone number that they have on file is going to the person they think it is so thoroughly that they let you use that number as kind of a like a side door to allow a person to get into their account even if they forgot their password.
Speaker 2: Yeah. So imagine, you know, to go back to email, all of us have lost an a password to a service at some point and had to hit the forgot password button and it sends you a nice email with a little link that when you click on allows you to set a new password. The difference is that there's really no easy way to redirect email. You know, it requires you know, MX DNS records and all kinds of, you know, complicated infrastructure that most people would need to, you know, spend lots of time attaining access to versus a SIM or a cell phone, which you can easily kind of get access to.
Speaker 1: I wanna dwell on that. You can easily get access to someone else's incoming SMS traffic, like, the you can get the texts that are being sent to them sent to you.
Speaker 2: Yeah. There's a number of ways to do that. You know, one is just yeah. I've personally lost a phone. My phone is very locked down. Like, I have an iPhone. I probably shouldn't tell everybody that in the world, but I have an iPhone. Anyway, it's very encrypted. You know? There's a huge digit combo to get into it. Losing the device and somebody getting access to the device is really tough, but I can pop the SIM out of a device and slide it into another device. And most people don't have passcodes on their SIMs, so it immediately accesses the network as me, and my text message traffic begins. So that's one way. It's just simply having the physical copy of my SIM card.
Speaker 1: But that's like you said that's physical. You have to actually get access to that physical SIM card which if I'm Google, your bank, or Facebook seems like pretty good security. Right? We can trust that as long as someone hasn't physically taken that SIM card that it's still locked down. Are there ways for someone who wants access to that that text message traffic to get access to it without physically having the SIM card?
Speaker 2: Yeah. There's a there's a whole history of that in hacking. Like, one of the most famous hackers in the world, Kevin Mitnick, used to famously clone, sys numbers inside of old cell phones so that he could location stumble and they could never triangulate where he was. So he was on the run for years, and he would access the cell networks by essentially cloning other devices. You know? And that was in the nineties, like, eighties, nineties. You know? And and that kind of progresses right up to the intro story that we just heard, which is me getting access to your account, accessing the account on the cell network provider, convincing them to put that number onto a different SIM card. And then I take that SIM card and put it into a new device or a different device that I own, and now I'm you. Okay.
Speaker 1: So, I wanna be you in that that metaphor that we're talking about here and right now all of the traffic that goes to your phone number is being sent to the SIM card that's physically in your phone. So, what you're talking about is I just have to convince the phone carrier to redirect that traffic to this SIM card that I have over here.
Speaker 2: Correct.
Speaker 1: And all the stuff from from Scott's number to this new SIM card that
Speaker 2: I that I have. Totally. How? Yeah. It's it's it's definitely not the easiest thing, but it's not the hardest thing. Like, social engineering is probably the easiest way to attain all that information, and that's just literally, like, manipulation. And, you know, that's been going on for thousands of years, and, you know, some people are really good at it. And, you know, the the gentleman from the intro story had essentially done that. He'd socially manipulated or socially engineered somebody into giving him all the information that allowed him to access his account. And to think that, like, he stopped short because of, like, a little unpaid bill is is wild.
Speaker 1: So it really just comes down to can the person do a reasonable impression of you Yeah. Over the phone.
Speaker 2: Yeah. Like, my mother's maiden name is something that you probably know because we've worked together for a few years, and that is such a a, you know, a institutional stalwart of security, and that is barely confidential information, if at all, could be considered confidential information.
Speaker 1: So I've decided on a person that whose SIM I want to clone, basically.
Speaker 2: Sure. Me, hopefully. It's you. No.
Speaker 1: I start doing my research I start thinking I start figuring out all the stuff about you that a person might ask me to confirm that I am you
Speaker 2: well better than that you probably have an account with a cell company you could pretty easily figure out what questions they're gonna ask Right.
Speaker 1: You call them up and say that you need to do this for your own account. You figure out all the questions they're gonna ask you. Now you have basically a laundry list. This is the information about this person that I have to go get in order to be able to pull off this hack.
Speaker 2: Yeah. Correct.
Speaker 1: That seems like a giant vulnerability.
Speaker 2: It's like the the oldest vulnerability, and it continues to pay out.
Speaker 1: Okay. So I've decided I wanna go after your SIM card. I do my research. I figure out what I need to figure out about you, and then I just go hunting. And let's say I stitch together all of this information, what's the next step? Where does it go from there?
Speaker 2: Once you have all of my details and you just literally can walk into a cell phone shop for the company that I'm with and verify your identity, say that you forgot you have your ID. In some of these higher level cases, they often have what you call, like, you know, an inside person who who works at the cell company who can provide you with some of the details and bypass some of the security restrictions for you, which, you know, facilitates your access. So that, you know, that is some cases where there are multiple people, but in other cases, I don't know the last time you made serious changes to an account like this, but it's not a very rigorous verification process.
Speaker 1: So one thing I'm I'm noticing here is like when we talk about a lot of these hacks, they feel like they're shotgun approach. One's literally called phishing and it's like you're putting out all of these things into the world and you're seeing what comes back. This feels different than that. This feels like the amount of work necessary to get one person's traffic sent to this one device, like, there's research involved. You have to impersonate the person. There's there's real vulnerabilities in this process. Why would I want to put in all that work?
Speaker 2: Yeah. Quality over quantity. You know, the to go back to, like, online street crime and some of the previous episodes, you know, ransomware is a is a quantity business where this is a selective. This is a real hack. This is like, you know, Jordan is a Bitcoin trader, and I know that the brokerage he uses uses, SMS to do password resets. I think he has $20,000,000 in his in his Bitcoin account. Hypothetically. That makes you a great target. You know, we're talking about essentially a a quote unquote untraceable currency that I'm gonna potentially take from you with a a little bit of social engineering and a little bit of, like, cell phone cloning. And the other thing is is like maybe the first cell shop I go to, they wanna see my physical ID, and I haven't faked that yet. But, you know, there's probably 300 other cell stores, and eventually I'm gonna get a lazy person who's just gonna let me have the information and make the changes for me.
Speaker 1: So you get that information. You make that change. All of my texts are going to you.
Speaker 2: I steal your Bitcoin, and I leave the country. Thanks, Jordan. Starting
Speaker 1: something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world. I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 5: Where is Daredevil?
Speaker 6: Online. Don't miss the return of Marvel Television's Daredevil Born Again.
Speaker 1: So what's next? I feel liberated.
Speaker 6: We're gonna take this city back.
Speaker 1: Over Medicaid.
Speaker 6: In an all new season now streaming only on Disney plus.
Speaker 3: They're hunting us. It's time we started hunting them.
Speaker 6: I can work with that.
Speaker 2: This should be tons of fun.
Speaker 6: Marvel Television's Daredevil and Born Again now streaming only on Disney plus.
Speaker 1: How do Sims actually work?
Speaker 2: Yeah. So consider them to essentially be a small computer sitting inside of your phone. They have their own programs, they have their own data reserves, they have all this other functionality, which can be communicated to wirelessly, but we'll get into that later. When your phone tries to log on to the cell network, there's really two big pieces of information that are critical to that process. The IMSI number, which is the international mobile subscriber identity number, and then the KI, which is the key identification. So consider these kind of like the username and password, and they're often, you know, kind of coded into the SIM card. So these username and password kind of, have an encryption algorithm that they kind of vibe with the network, and that grants your phone access to the network. So that's kinda how they work. We could get into the encryption side of it, but probably don't need to. There's different versions of SIM cards over the last, you know, twenty years, and the first ones were very easily cloneable. The encryption algorithm was really basic, and you could actually brute force, kind of figure out what the key identification of the KI number was. That's been mostly fixed in the newer ones. So in, like, the version two and version three of the, like, SIM standards, it's much different. So they're much more secure than they used to be.
Speaker 1: Sure. So there's really no reason for a hacker to try and figure out what that IMSI and that KI number are because it's just gonna be too difficult. You need to just get the traffic redirected to a whole new SIM card with a whole new IMSI and KI number. That's gonna be simpler than trying to work through these impossible numbers.
Speaker 2: Yeah. Often. The to go back to the, you know, quote, unquote inside person, if you have true access into the cell network information, you can actually grab data tables of all of this information and just kind of make your own SIMs. So that's a different a different way to solve this problem.
Speaker 1: So instead of trying to trick someone to redirect the traffic, you just get access to the, like, the tool for redirection, basically, and redirect it yourself?
Speaker 2: Yeah. Essentially, you could just code your own Sims.
Speaker 1: That seems like you would that's like God mode.
Speaker 2: It seems like you would Yeah.
Speaker 1: God mode. Insane damage if you got into that back end.
Speaker 2: You get a special badge for that one. Yeah. And then actually in, there's a rumor in 2010 that Gemalto, one of the major SIM manufacturers, was actually hacked by the NSA. And I it's kind of a complicated story, but, you know, they never proved it was the NSA, then NSA never took credit for it, but essentially it looks like they hacked Gemalto to verify whether the entire global cell network was at risk because Gemalto had most of this information. So kind of accessing the ultimate god mode where you're not just in the cell network, but you're actually at the highest level getting, like, 7,200,000,000 SIM cards worth of data.
Speaker 1: And theoretically, if you were in there, you could redirect the traffic from any of them?
Speaker 2: Well, you would have enough data you would have enough data that you could really cause a havoc. You wouldn't be able to redirect the traffic as much as you would be able to start making your own SIM cards. So you'd be making clones of the username and password to log on to any cell network you wanted to.
Speaker 1: There's definitely, like, a certain, like, kinda elegance to this the whole solution that makes a lot of sense to me, in spite of that kind of human vulnerability we've been talking about. Is there a version of this that removes that? Is there a version of this that works better?
Speaker 2: Yeah. Well, it's it's actually coming. So, like, I have an Apple Watch on, which, again, I probably shouldn't tell people. But that watch has what's called an e SIM. So they've essentially gotten rid of the physical devices. So a lot of new phones now, you don't actually slide a SIM card into. They have a, you know, virtual SIM, so there's a separate security profile on my phone that downloads from the cell network my SIM card, but then it can also be taken off of my, like, off of my watch, and the same thing will happen. So they they they've definitely made large strides to solve this problem, and I think it's gonna go away. So we're gonna go less from now we started where we used to code in our IP addresses. You know, we would sit tell our phone what our SIMs were, what our our subscriber ID was, and then we went to this chip that kind of told the phone what our subscriber ID was. And now we're gonna go back, but it's gonna be prescriptive. So the the cell network will prescribe our device a subscriber ID, and then it will be able to recall and control that.
Speaker 1: I might be misunderstanding this, though. If the cell phone carrier has the ability to recall that profile and move that profile to say, oh, I got a new iPhone. And this whole hack is based on tricking the cell phone provider into thinking that you're someone you're not. Haven't we just ended up right where we started?
Speaker 2: Humans are always the vulnerable link, Jordan.
Speaker 5: When you finally find your thing, you want the whole world to know about that thing. So you use a thing called Canva to make it an even bigger and better thing. Whether you want to create flyers for that thing, make presentations for that thing, or design merch for that thing, you can do anything. So people can see your thing, feel your thing, love your thing. The next thing you know, it's a thing. Canva, the thing that makes anything a thing.
Speaker 7: You thought this was your run club era. Turns out, it was more of a thinking about run club era. The good news? Someone's marathon training is about to start. Sell your workout gear on Depop. Just snap a few photos, and we'll take care of the rest. They get their race day fit, and you get a payout for trying. Someone on Depop wants what you've got. Start selling now. Depop, where taste recognizes taste.
Speaker 1: I guess I'm curious, like, is there a way to do this without tricking people? Like, I I I like that this feels like a real hack. Right? Like, it feels like an actual like, it feels like heisty. Right?
Speaker 2: Yeah. This is a real heist.
Speaker 1: There's a grift. Like, you gotta trick people. You gotta have an inside man. It's really cool. But I feel like there is someone out there who at once wants access to one of these accounts, but doesn't have the ability or the the desire to go about it in that kind of social engineering, grifty way. Is there, like, a hard way through? Is there a way to get this traffic? Is there a way to clone someone's SIM without tricking a cell phone company? Is there a way to math your way through this thing?
Speaker 2: Yes. It's much harder now. I touched on it a bit ago that they've modified the SIM algorithms, so the encryption algorithms. So the first version of it, yes, used to be able to properly easily clone people's SIM cards. Now it's tougher. Even getting access to the actual physical card, you can't really easily scan off the IMSI and KI number, so it's much much more complicated. Getting raw access to the cell records inside the cell provider would probably be your easiest way. You can program your own SIMs. They are little microchips with computers and data. You can write stuff into that data, but you still need these pieces of critical information. And unless you can get those critical pieces of information, it's much more complicated. It's much easier to have the cell network do it for you than to try and do it yourself.
Speaker 1: We've been talking about the value of that cell phone traffic in the context of two factor authentication. I get texted this PIN. Great. I can now log in its account, and I can recall kinds of havoc. Does the information that's getting piped into your SIM card have any other value?
Speaker 2: Yeah. Of course. You know, when we talk about social engineering and social manipulation, if I have access to all of your private data, I'm gonna know a lot more about you and a lot more about what makes you tick. I'm gonna know about, you know, social vulnerabilities you have, you know, if you've been texting or DMing somebody that you shouldn't be, you know, any of that information is very valuable if I'm going to try and manipulate you. So, it depends on what your end goal of this hack is, you know. The the intro story was, hey, I wanna steal your Bitcoin and that's a great thing, but maybe it's not. Maybe it's in, you know, a different actor trying to get access to your work environment and maybe they clone your sim and they have been reading your text messages between you and somebody you shouldn't be texting and they're going to hold that over you unless you put this USB key into a computer at work. You know? So, you never really know what the outcome is gonna be or what the goal of the people doing the hack is, but, you know, any kind of valuable social information is always going to pay out if if you're kind of involved in a larger scale hack.
Speaker 1: It kind of paints this picture of a person who gets robbed through one of these hacks and then can't do anything or say anything about it because the person knows all this stuff about them.
Speaker 2: Yeah. Right. It's like the classic movie scene of, you know, the person who doesn't report the crime and is now a part of it.
Speaker 1: Looking at this hack from, you know, 10,000 feet up, what does the bleeding edge of this look like? Does it kind of live and die by social engineering, or is your phone vulnerable in some entirely different way?
Speaker 2: No. I think your phone's eternally vulnerable. You know, they've done a really good job encrypting the the local files and and things like that. So they've done a a pretty secure job. They've been in big fights with the FBI and the NSA about, you know, kind of preventing them from having a backdoor into it. But there there actually was, recently some interesting news that had come out. I think it was at the end of last year, you know, September, October. There's kind of a control protocol, so your phone SIM card being kind of like a little microchip and then kind of having its own programs needs to be communicated to via the cell network occasionally. And, it turns out that that's as simple as sending, you know, binary encoded text messages to your phone. They'll never pop up on your phone. You'll never know that it's happening, but it's happening in the background. It turns out that, you know, between well, known between 2015 and 2019, this was pretty common. So this security company was analyzing traffic and SMS data going across many networks, but often, some Mexican telcos. And it turns out that some third party actor was essentially pinging cell phones, getting location data via the the chip. So the chip or the the SIM card will return its cell ID and kind of its home tower and the tower that it's currently on, and they can use that to essentially kind of pinpoint where the phone is within a relative proximity. It kind of went on for years, and it still could be going on. There were some emergency kind of security protocols released in in 2019 to kind of tell cell companies to make some security mods to their their platforms to prevent it from happening, but, you know, who knows if those have actually been done.
Speaker 1: You're saying that cell phone carriers have the ability to, on the platform that text messages get sent on
Speaker 2: SMS.
Speaker 1: Send some piece of information to your phone that tells your phone to ping back with some piece of information about it, who you are and where your phone is kinda thing.
Speaker 2: Well, that is a few of the commands. It can actually send a plethora of commands as far as, like, open browser and download this. Yeah. Exactly. Jordan's face, you can't see right now, but it's exceptional.
Speaker 1: How the heck did someone figure out how to do that?
Speaker 2: It's all public API docs. You can literally pull up the technical docs to talk about it. It's very technical and you need to be very competent to do it, which is probably the best security that it has now is that you require a proper real IT tech hacker to do it, but it's very viable.
Speaker 1: That's the version of this we were talking about that sits somewhere outside of either physically getting the SIM card or tricking a person. So there is a way. There's this sort of math. You can math your way through this thing.
Speaker 2: You can you can program your way through it for sure. The it's not it's not gonna be easy. It's gonna be very hard, very complicated, but they suspect there's not a lot of public discussion about it because it is such a global security problem. So it's probably very locked down. But there's been rumors and discussion about it being as vulnerable as they can tell your phone to download a Trojan horse or download a virus, and your phone will go do it. So there's not a lot that verifies that. There's a few, like, Defcon articles and Defcon presentations about it. And it's not like the SMS networks and this this kind of, SIM toolkit SDK commands. It's kind of the the thing that I'm talking about. It's not like there aren't security protocols. It's just that when lots of these cell companies set them up, they didn't turn them on. So they don't require authentication. They don't require anything. They just the phones receive, you know, this kind of encoded message, and the phones execute the instructions in that message. You know, so many vulnerabilities that exist in the world today are because of improper setup.
Speaker 1: Whether it's someone figuring out that if they impersonate you, they might be able to get traffic redirected to a new SIM, whether it's someone figuring out how to send these weird phantom text messages that make your phone do stuff. The vulnerability on the cell phone carrier side, do you think that's born of ignorance or apathy? Do they know that this is a vulnerability, but they think no one's ever gonna figure it out? Or do they not know about it until somebody exploits it?
Speaker 2: Yeah. I think that's the case. I don't think anybody's, you know, willfully, negligent. I think that many of these hacks of opportunity that come up and, like, lots of the if you go through, like, the CVID, like, the security logs of, you know, insecurities that are found in the resolutions. You know, they're all kind of just accidental, whether they're set up, whether it's a user case that's no unprogrammed for, so you read reach an exception that doesn't have a catch. It's things like that that cause these problems. It's not, you know, somebody willfully being negligent.
Speaker 1: You kinda come back to that thing. We've talked about this before, but it's this idea of, like, you can point all this money and all this time and all this energy and all these resources and the smartest people you can conceivably hire for the most money at solving a problem, but you're never gonna be able to outsmart just the hive
Speaker 2: mind, basically. Well, and the reality is to that is that usually the problem you've tasked these people with isn't security. You're saying, hey, let's build this application that does this. Security is the afterthought. So, you know, all these smart people put their heads down and they build you this great piece of software, this huge cell network, all of these wonderful things that we use, but security is still the afterthought. They haven't spent all that time focused just on how do we make this the most secure platform ever. And that's where the securities come in and where a lot of, you know, today's infosec, kind of companies and service providers, what they do.
Speaker 1: Last question. Thinking about these systems, the ones that, you know, they've been improved and reiterated on, but were at their core invented decades ago. When the people who were designing those systems were designing them, were they thinking about security or were they just trying to make it work?
Speaker 2: I think like this is just my personal track record. I think over the last twenty five years, a lot more people think about it. You know, especially when you've got Technology has gone from being something that we use you know, a computer on a desk not connected to a network to being, you know, a small computer that's driving my Tesla. And, you know, when we talk about security or the impact of insecurity, that's a huge difference. You know, I'm not gonna lose my word document with my resume in it. I'm gonna lose my life.
Speaker 1: Welcome to the hacked after episode question hour. Hacked after dark, where we answer listener questions from previous episodes or just just about anything about life and love and finding your way in this crazy world. Our question this week is from our last episode, DDoS for Hire, and they wanted, Scott, they wanted you to dig a little deeper into how a DDoS attack actually takes a network down, the mechanic by which they take down a network.
Speaker 2: Yes. Thanks, Jordan. And I apologize. So a DDoS attack taking down a network. So let's go back to, one of the ways, Datapype. So say we have x bandwidth. Let's say that x bandwidth is 15 megabits per second. If enough people are attacking me sending data traffic packets of data into my pipe, the pipe essentially fills up and that means no other data can get into it. So if I'm trying to go to Google, there's no traffic inside of that pipe left to let me out to get to Google. So that's one way that it knocks you down. That's the most common recreational way that it knocks you down. The major other way is that when you overload a network so much with so much traffic that it'll actually overheat and shut down the physical electronic boxes that move packets around networks. So if you're sending so much traffic through that the capacity on all of the network routers and switches is capped out, eventually, they might overheat, shut down, melt. So those are the two probably main ways that DDoS attacks affect and disconnect things from the Internet.
Speaker 1: I have nothing to say to that. You can melt someone's computer?
Speaker 2: Oh, you wouldn't melt the computer. You'd melt their, like, you know, modem or router. But it wouldn't actually melt. It could. If it overheats enough, it could fry the chips. That's like a real thing.
Speaker 8: If you've got an insurance question, you could talk to the butcher at your local grocery store. He'd probably talk about trimming the fat, but it'd be about your brisket, not your insurance policies. Or you could talk to your local GEICO agent. They offer offer personalized assistance in finding the choicest cuts of coverage for all your insurance needs, which means more money for filet mignon. Or if you're a vegetarian, tofu lei mignon. To find a GEICO agent near you, visit geico.com/local.
Speaker 3: This episode is brought to you by Nespresso. Being the best version of yourself is an everyday journey, and it begins in the morning by taking a moment to ground yourself. With the new Nespresso Vertuo Up coffee machine, morning routines become rituals. Just one gentle press. And coffee brews, unfolding into whatever you need today. Bold or delicate, iced or hot, familiar or new. Press to explore. Every coffee, a new world. New Vertuo Up. Shop now at nespresso.com.
Speaker 9: The right window treatments change everything. Your sleep, your privacy, the way every room looks and feels. At blinds.com, we've spent thirty years making it surprisingly simple to get exactly what your home needs. Needs. We've covered over 25,000,000 windows and have 50,005 star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real design professionals, free samples, zero pressure. Right now, get up to 45% off-site wide, plus get a free professional measure at blinds.com. Rules and restrictions apply.