Hacker News new | ask | show | jobs
by fowl2 3534 days ago
this... is certainly not my experience. However, they're a large organisation so they're most likely schizophrenic.
2 comments

It's certainly not a lot of people's experience. Youtuber boogie2988 (3.5m subscribers) had his accounts hacked and his channel deleted (his primary source of income) via a Verizon social engineering hack. The hack via Verizon gained the hackers access to his Twitter, YouTube/Google accounts, even his PayPal account.
Verizon may be quite serious about protecting Verizon and its infrastructure, while still indifferent to retail subscriber account takeovers.
Here are more details about that[1]. I'm still surprised how they could have gained access to his Youtube and Twitter just by using his phone number.

[1] https://www.reddit.com/r/boogie2988/comments/4psg4x/i_was_ha...

If you know someone's Gmail account used for YouTube and have access to their cell phone to receive text message verifications for account resets, you have full access.

Being able to verify a code sent to the mobile phone registered with the account is used as proof of identity for account recovery by basically everything online except banking.

k. But in boogie2988 case, did the hacker got access to his actual cell phone or just cell number? That's not clear.
A social engineer goes to the Verizon store and tells customer service that they have lost their cellphone. Customer service deactivates the owner's phone and gives the social engineer a brand new phone that's connected to the owner's account.
Weird! Don't the Verizon guys do an ID verification that the person requesting the new phone is really who he claims he is?
That's fair, I definitely don't have a global insight. Security teams are usually segmented in some way, rather than monolithic, with varying levels of competency among different teams.

They do periodically put out some interesting reading. If you want to look at it, their annual Data Breach Investigations Report are worth checking out:

http://www.verizonenterprise.com/verizon-insights-lab/dbir/

(prior year reports don't require registration and are still fairly applicable)

I once had verizon admit they'd oversold their capabilities for Incident Response and security consulting and were in dire need of support. Of course they wanted bottom barrel rates at $140 an hour.. seriously. Naturally we turned away from the opportunity as it wouldn't be profitable. I'm not convinced Verizon is anymore secure than Sony after that call ....