<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIM Hacking by Social Engineering with PM in Get Support</title>
    <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418136#M308087</link>
    <description>&lt;P&gt;You can submit your phone number for authentication/etc. If you immediately&lt;SPAN&gt;&amp;nbsp;change it. And never advertise it anywhere online except in your PM Self-Serve page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This might be impossible in practice because google/Apple/etc will still collect everything they can from your contacts lists, calendars, browsing, email, and msg contents - once it's on the cloud it can be cached and copied forever.&amp;nbsp; Not to mention all the data (including your phone number) which can be harvested from your contact's phones.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think the best defense vs hacking is prevention, simply avoid being a juicy target. And only a fool would use a single master key to open everything he keeps secured.&amp;nbsp; Maybe Twitter only suffered from minor embarassment for a day because preemptive damage containment, or maybe they lost a billion dollars because they're dumb/lazy enough to deserve it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course PM/Telus coukd get hacked - Twitter CEO and AT&amp;amp;T got hacked, even google gets hacked.&lt;/P&gt;</description>
    <pubDate>Sun, 01 Sep 2019 09:31:09 GMT</pubDate>
    <dc:creator>Korth</dc:creator>
    <dc:date>2019-09-01T09:31:09Z</dc:date>
    <item>
      <title>SIM Hacking by Social Engineering with PM</title>
      <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/417964#M308082</link>
      <description>&lt;P&gt;The boss of Twitter was hacked today, the hacker transfered his phone mumber to a new number and SIM by social engineering.&amp;nbsp; &amp;nbsp; &amp;nbsp; Basicly they phoned his AT&amp;amp;T and had the number transfered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I right in thinking that this is impossible to do with PM as we control our own account online?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could a PM store or authorised dealer swap out our number or do they require our PIN?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 13:45:17 GMT</pubDate>
      <guid>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/417964#M308082</guid>
      <dc:creator>StewartMann</dc:creator>
      <dc:date>2022-01-05T13:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: SIM Hacking by Social Engineering with PM</title>
      <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/417977#M308083</link>
      <description>&lt;P&gt;&lt;a href="https://productioncommunity.publicmobile.ca/t5/user/viewprofilepage/user-id/61022"&gt;@StewartMann&lt;/a&gt;It is very easy to perform SIM jacking at Public Mobile, especially because the moderators takes a while to respond to crisis..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is a problem with the porting system between carriers.. You only need phone number, and a combination of the following Account # / PIN or IMEI. In order not to make porting system a long process, every carrier in Canada has to agree on a more secure method for porting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way to be secure (besides good internet hygiene?) ? Don't use your phone number as an authentication device, have a spare phone just in case.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2019 22:55:30 GMT</pubDate>
      <guid>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/417977#M308083</guid>
      <dc:creator>GinYVR</dc:creator>
      <dc:date>2019-08-31T22:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: SIM Hacking by Social Engineering with PM</title>
      <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/417985#M308084</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://productioncommunity.publicmobile.ca/t5/user/viewprofilepage/user-id/61022"&gt;@StewartMann&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;The boss of Twitter was hacked today, the hacker transfered his phone mumber to a new number and SIM by social engineering.&amp;nbsp; &amp;nbsp; &amp;nbsp; Basicly they phoned his AT&amp;amp;T and had the number transfered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I right in thinking that this is impossible to do with PM as we control our own account online?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could a PM store or authorised dealer swap out our number or do they require our PIN?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Doubtful. They aren't there for technical support so no reason for them to have access.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2019 23:01:17 GMT</pubDate>
      <guid>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/417985#M308084</guid>
      <dc:creator>cavemantoronto</dc:creator>
      <dc:date>2019-08-31T23:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: SIM Hacking by Social Engineering with PM</title>
      <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418023#M308085</link>
      <description>&lt;P&gt;&lt;a href="https://productioncommunity.publicmobile.ca/t5/user/viewprofilepage/user-id/61022"&gt;@StewartMann&lt;/a&gt;&amp;nbsp;since porting requires the name on account exatly, then make a slight&amp;nbsp; change in your name. This will help prevent people from porting your number, assuming they dont have access to selfserve.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2019 23:47:47 GMT</pubDate>
      <guid>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418023#M308085</guid>
      <dc:creator>mimmo</dc:creator>
      <dc:date>2019-08-31T23:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: SIM Hacking by Social Engineering with PM</title>
      <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418132#M308086</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://productioncommunity.publicmobile.ca/t5/user/viewprofilepage/user-id/12825"&gt;@mimmo&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://productioncommunity.publicmobile.ca/t5/user/viewprofilepage/user-id/61022"&gt;@StewartMann&lt;/a&gt;&amp;nbsp;since porting requires the name on account exatly, then make a slight&amp;nbsp; change in your name. This will help prevent people from porting your number, assuming they dont have access to selfserve.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;When done correctly, Public Mobile is probably safer than those with call centers because there's zero chance someone would be calling someone pretending to be you / use other social engineering techniques to trick a call center agent (which &lt;STRONG&gt;doesn't exist with PM&lt;/STRONG&gt;) into providing such information as account #'s and SIM details required for porting away as everything is done online on this forum instead. Public Mobile (and other prepaid services) also don't do credit checks, so feel free to make up any name you wanted. When done correctly, you'd be pretty safe from attacks of this sort with PM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recovering from one, may be difficult and slow due to the moderators' response time, I agree. Best thing to do is use authenticator apps vs SMS for protection.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2019 07:17:10 GMT</pubDate>
      <guid>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418132#M308086</guid>
      <dc:creator>Haiggy</dc:creator>
      <dc:date>2019-09-01T07:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: SIM Hacking by Social Engineering with PM</title>
      <link>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418136#M308087</link>
      <description>&lt;P&gt;You can submit your phone number for authentication/etc. If you immediately&lt;SPAN&gt;&amp;nbsp;change it. And never advertise it anywhere online except in your PM Self-Serve page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This might be impossible in practice because google/Apple/etc will still collect everything they can from your contacts lists, calendars, browsing, email, and msg contents - once it's on the cloud it can be cached and copied forever.&amp;nbsp; Not to mention all the data (including your phone number) which can be harvested from your contact's phones.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think the best defense vs hacking is prevention, simply avoid being a juicy target. And only a fool would use a single master key to open everything he keeps secured.&amp;nbsp; Maybe Twitter only suffered from minor embarassment for a day because preemptive damage containment, or maybe they lost a billion dollars because they're dumb/lazy enough to deserve it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course PM/Telus coukd get hacked - Twitter CEO and AT&amp;amp;T got hacked, even google gets hacked.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2019 09:31:09 GMT</pubDate>
      <guid>https://productioncommunity.publicmobile.ca/t5/Get-Support/SIM-Hacking-by-Social-Engineering-with-PM/m-p/418136#M308087</guid>
      <dc:creator>Korth</dc:creator>
      <dc:date>2019-09-01T09:31:09Z</dc:date>
    </item>
  </channel>
</rss>

