Hacker News new | ask | show | jobs
by ryanlol 2280 days ago
>Happy to give you a bounty if you're able to break into the system.

Yeah, the problem here is that since you’re a MVNO the easiest angle of attack would might just be to go for the big MNOs that you resell (Verizon, ATT, Sprint,Tmo). You can’t really offer bounties for such attacks, and I can’t see how you could defend against them either.

1 comments

We can because due to our relationship, we control the # and they don't. We've a slightly different arrangement. Think of that you've ATT and you're roaming in Canada on Rogers network. Rogers employee can't port you out or do funny things to your account. Similarly, we're using their network but they can't access your account
You control the #, sure. But what specific technical measure prevents the carrier from associating that customer line with another sim card?

The fact that you control the # might defend against port-outs, I don’t understand how that could prevent SIM swaps though.

Carriers don't have access to the customer account. They don't even know who the customer is and our SIMs have a different serial number