[HN Gopher] Preventing the use of SIM farms for fraud: consultation
       ___________________________________________________________________
        
       Preventing the use of SIM farms for fraud: consultation
        
       Author : azalemeth
       Score  : 44 points
       Date   : 2023-05-06 14:19 UTC (8 hours ago)
        
 (HTM) web link (www.gov.uk)
 (TXT) w3m dump (www.gov.uk)
        
       | tjpnz wrote:
       | What is this going to accomplish given that most scammers aren't
       | operating on UK soil?
        
         | whypretend wrote:
         | [dead]
        
       | whypretend wrote:
       | What about the sim farm I use to delegate my SMS OTP codes to? No
       | VOIP numbers don't work for everything, no using the same SIM
       | card doesn't work, no I don't want to worry about running dozens
       | of phones with batteries and no I'm not even sending messages.
       | 
       | Local TOTP key as a second factor should be more standard.
       | 
       | Especially if I'm already paying for a service you shouldn't need
       | SMS as a crappy veiled proxy for some human verification.
       | 
       | Supposed to pretend like this doesn't just force people to use
       | more phones?
        
         | CPLX wrote:
         | Geniune question - what's the actual use case here? It can't be
         | just you personally logging into various services right?
        
           | whypretend wrote:
           | Mitigating account lockout risk across lots of clients.
           | Separate SIM for each client, having account lockouts are
           | unacceptable. Yes, I've had problems with no recourse.
        
           | costco wrote:
           | https://smspva.com/
           | 
           | Immensely useful services like this without which for
           | instance people would not be able to scrape social media
           | services at scale.
        
             | whypretend wrote:
             | [dead]
        
           | DANmode wrote:
           | If it was?
        
             | whypretend wrote:
             | [dead]
        
         | ec109685 wrote:
         | Why don't you want to use the same SIM card? Is it because you
         | don't want services to be able to correlate usage across
         | multiple services?
        
           | whypretend wrote:
           | I need a reliable way to manage OTP codes for many clients,
           | having one SIM is just not good enough. Partially the same
           | problem because I've run into limits - having a separate card
           | is just less likely to be a problem.
        
         | orf wrote:
         | You say "no, no, no" as if it is obvious why you'd need to
         | delegate SMS OTP codes to a sim farm.
        
           | whypretend wrote:
           | [dead]
        
         | timthorn wrote:
         | So please respond to the consultation. Q2 is literally asking
         | for other uses of multiple SIMs that the policy wonks haven't
         | thought about yet.
        
           | whypretend wrote:
           | [dead]
        
       | jpalomaki wrote:
       | Are operators doing spam filtering for outgoing SMS messages? The
       | messaging patterns must be quite different from normal customers.
       | Maybe you could also detect the suspicious amount of messages
       | originating from certain location (cell).
        
       | efitz wrote:
       | Banning devices has not historically been a very effective way to
       | prevent crime.
       | 
       | I am not an expert in modern mobile network technology so I'll do
       | something unusual for HN and refrain from suggesting a solution.
        
       | ivanstojic wrote:
       | What happens with eSIM devices?
        
         | maratc wrote:
         | eSIM device does not usually have a phone number, and it can't
         | send (or receive) SMS.
        
           | kiwijamo wrote:
           | Incorrect, they can have an assigned phone number and can do
           | anything a normal SIM can do.
           | 
           | There are SIMs (either physical or eSIM) that do not have a
           | phone number and/or has restrictions on what it can do. It's
           | not the form itself that limits the functionality, it's the
           | mobile network provider who decides what functionality each
           | individual SIM has.
           | 
           | E.g. Mobile card payment devices may have a SIM that has no
           | phone number and is data only with connection only permitted
           | via a certain gateway to the payment provider.
        
           | jackweirdy wrote:
           | Unless we are thinking of different technologies, you can use
           | esims for all of that? Just last week I ordered a
           | usmobile.com esim, installed it on my phone, received a +1
           | 415 number and received and sent SMS with it
        
           | whypretend wrote:
           | [dead]
        
         | whypretend wrote:
         | [dead]
        
       | orf wrote:
       | > SIM farms are devices that can house hundreds of SIM cards,
       | which can send out thousands of scam texts to defraud the UK
       | public of millions of pounds. In addition to sending scam texts,
       | these devices are used by criminals to run scam call campaigns
       | and to post misleading, false or phishing messages on social
       | media in bulk.
       | 
       | > Whilst there are some potentially legitimate uses of the
       | technology, these are limited and should not require using more
       | than four SIM cards, based on the number of mobile operators in
       | the UK. We have very limited evidence that there are any
       | legitimate use cases for devices that allow the use of more than
       | four SIM cards, and for all such cases alternative options exist.
       | 
       | The justification seems sound. What is the issue here?
        
         | nibbleshifter wrote:
         | This is a backdoor way they are trying to introduce mandatory
         | SIM registration.
        
           | dazc wrote:
           | Govt id is required to purchase a sim card in many EU
           | countries. If the UK Govt decided to implement such a policy
           | based on something like 'security' there wouldn't be a lot of
           | push-back.
           | 
           | Let's overlook the fact that such policies just make stolen
           | id a lot more valuable than it is already.
        
             | specproc wrote:
             | I'm all for it continuing, but it always struck me as wild
             | how you can just pick a UK SIM up at the airport from a
             | vending machine. I don't know of many countries where this
             | is possible.
        
             | nibbleshifter wrote:
             | I've found that policy trivial to circumvent in most EU
             | countries I've visited (which is most of them).
             | 
             | Its also a stupid fucking policy.
        
             | [deleted]
        
         | costco wrote:
         | They propose a total ban that does not require fraudulent
         | intent to criminalize possession, an unlimited fine, and ignore
         | that most of the use is just bypassing rentseeking A2P SMS
         | charges? Along with the fact that it's unclear who is even
         | asking for it. UK similarly banned GSM gateways in the early
         | 2000s but recent court rulings said the way it was banned was
         | illegal and is in the appeals process.
        
           | orf wrote:
           | Most of the use case is spamming people. There are very few
           | other uses for something like this[1].
           | 
           | A2P is also a US specific thing?
           | 
           | 1. https://m.aliexpress.com/item/1005004866582019.html?spm=a2
           | g0...
        
             | toast0 wrote:
             | Something like that provides for programatic sms and maybe
             | voice calling. Most likely, using consumer market sims, so
             | tarriff arbitrage is likely a large component.
             | 
             | You might use something like this to do bulk SMS, which
             | could be spam or could be phone number confirmations (like
             | it or not, it's a common activity). If voice works, it
             | could be a backup outbound connection for an office PBX
             | (although, unless you had fancy SIMs, you are going to get
             | the sim's phone number as caller id which is undesirable).
             | 
             | Many countries have been making a2p messaging harder and
             | harder; using a sim farm is a tempting way to opt-out of
             | official restrictions, although it seems like a lot more
             | operational work.
        
             | costco wrote:
             | Sites like smspva.com would have dozens of those devices,
             | should they be illegal? I can think of uses of these
             | devices, yes most of them are "grey market" but they don't
             | involve stealing from people.
             | 
             | By "A2P fees" I'm referring to the fact that in most
             | countries it costs more to send an SMS with Twilio than a
             | 5000 message or unlimited message retail plan. I won't deny
             | that some SIM farms are used for scams but if you look at
             | the countries that have banned them the reasoning is not
             | because of fraud it's because they have a monopoly phone
             | provider and people effectively use these devices to
             | convert international calls or SMS like verification code
             | messages to domestic so that they don't have to pay higher
             | termination fees which costs the carrier some profits. They
             | can also make tracing calls harder which is why India bans
             | them. But given that there is VOIP I don't see why banning
             | this would prevent any fraud.
        
               | orf wrote:
               | > Sites like smspva.com would have dozens of those
               | devices, should they be illegal?
               | 
               | Your argument is that since this clearly sketchy service
               | ran from Hong Kong that is dedicated to giving people the
               | ability to automate signups on sites/apps and "earn money
               | using our service" utilizes dozens of these devices,
               | these devices are OK?
        
               | costco wrote:
               | Plenty of civic minded people find services like these
               | useful for registering Signal accounts not tied to their
               | own number. Or for scraping sites like LinkedIn. There
               | are companies like this run from other countries if you
               | don't trust Hong Kong. I don't think arguing that some
               | unknowable fraction of fraud traffic flows through these
               | devices is persuasive when the legislative conversation
               | in the countries that banned these devices is almost
               | entirely about carriers losing some termination fees and
               | national security fears.
        
               | incone123 wrote:
               | In the UK we can still get anonymous SIM cards for cash,
               | if you want an anonymous Signal account.
               | 
               | Having recently looked at commercial SMS gateway pricing,
               | I am inclined to the argument that these devices have a
               | role in thwarting rent-seeking on the part of telcos.
        
               | orf wrote:
               | I mean it literally advertises itself as a service that
               | enables people to make money by bypassing restrictions
               | that require phone numbers.
               | 
               | You might not make money using it and instead just use it
               | to sign up for a single signal account, but you're not
               | really the target audience in that case.
        
               | costco wrote:
               | The people making money from it wouldn't exist without
               | people buying the verification codes. If you Google
               | smspva or services like it and read forum posts about it
               | the majority of discussion is about people using it to
               | automate account registration.
        
               | orf wrote:
               | Yes, hello?? They often use those registered accounts for
               | malicious purposes which generates income for them?
        
               | costco wrote:
               | Sorry, I misread your previous comment. The site doesn't
               | advertise itself as a way to make money, its just
               | incidental to how some people make money. Is scraping a
               | malicious purpose? Maybe in some cases. Either way I
               | don't see why this use of sim boxes shouldn't be a civil
               | dispute between companies and needs to be something the
               | government should criminalize. Fraud is already illegal.
        
               | orf wrote:
               | > The smspva website has been operating since 2013.
               | During this time, we have gathered a large audience of
               | users who trust us and earn money using our service
               | 
               | And the use case they showcase involves mass creating
               | Facebook pages. Come on. Are you really truly that naive?
               | 
               | It's vaguely legitimate business that just happens to
               | offer a service that's super useful to a particular type
               | of clientele. Just like bulletproof hosting.
        
               | costco wrote:
               | Is that supposed to always be bad? Unless the pages are
               | used to promote some kind of fraud I don't think that's
               | illegal. It's "dual use" like any other kind of anonymity
               | technology. Cloudflare says 90% of Tor traffic is
               | malicious - does that mean hosting relays and using Tor
               | should be criminalized?
               | 
               | Regardless, that was just a minor point about one
               | potential use of SIM farms. The proposal says they intend
               | to make possession a criminal offence and they don't even
               | have data on whether these devices are used for fraud at
               | scale in the UK.
        
               | orf wrote:
               | If you go around selling micro sized mobile phones close
               | to a prison then you can plead all you want that it's not
               | fraudulent, it's just for people with tiny hands and it's
               | ridiculous to imply that it's anything other than a
               | legitimate business.
               | 
               | However, it's not. It's got one clear use case and one
               | clear market.
               | 
               | We started this discussion on sim farms and your very
               | first point here (and in other places in this post)
               | linked directly to the kind of thing that should, and
               | hopefully will, be criminalised in the UK.
               | 
               | Because it's quite obvious what it really is, even if you
               | apparently can't see it?
               | 
               | I find that quite hilarious.
        
               | asdadsdad wrote:
               | how is scraping related to sim farms?
        
               | costco wrote:
               | Scraping services that require phone verified accounts
               | but reject VOIP numbers. Someone (in house or a service
               | like smspva) operating SIM farm would be required in
               | order to do this economically.
        
       | netik wrote:
       | absolutely wrong approach. fix this at the carrier level and not
       | client device level.
        
         | Nextgrid wrote:
         | You're forgetting that 1) carriers have near-zero engineering
         | capability to fix this and 2) don't actually have an incentive
         | to prevent spam/fraud because fraudulent traffic still pays
         | them money.
         | 
         | This is not about stopping fraud, this is about preventing
         | "grey routes" that do arbitrage around tariffs and bypass
         | carriers' outdated business model.
        
         | petesergeant wrote:
         | I think you might be right here, but what does that look like
         | exactly? Stop companies distributing cheap SIMs? Force them to
         | get ID from any customer?
        
           | fathyb wrote:
           | Maybe a standarized national system to report spam, or maybe
           | even as part of the cellular protocol? I never heard of such
           | a system deployed nationally, but I'm wondering if it could
           | help.
           | 
           | Most of the time when a spam number calls me, I can find it
           | through spam reports on 3rd party websites by googling it.
        
             | NoZebra120vClip wrote:
             | > Most of the time when a spam number calls me, I can find
             | it through spam reports on 3rd party websites by googling
             | it.
             | 
             | Oh, you mean that you can identify the Caller ID number
             | which the spammer chose to spoof at you?
        
               | fathyb wrote:
               | No, it seems most spammers here use cheap SIMs without
               | spoofing (which seems to be what OP is about). They even
               | leave voicemail messages asking to call back.
               | 
               | But spoofing is also something that should be fixed. I
               | know it's difficult because of VoIP and backwards-
               | compatibility, but it's not impossible either.
        
             | DANmode wrote:
             | > Maybe a standarized national system to report spam, or
             | maybe even as part of the cellular protocol?
             | 
             | Not government, but, forwarding spam texts to 7726 (SPAM)
             | works for various carriers.
        
       | petesergeant wrote:
       | Given that gov.uk is already so surveillance happy, I'm surprised
       | they haven't just mandated ID cards and then required SIMs to be
       | linked to one of those or a passport
        
         | justincormack wrote:
         | Various governments tried at various times. There is historic
         | resistance as ID cards were originally a wartime measure
         | https://en.wikipedia.org/wiki/National_Registration_Act_1939
         | and considered to be a symbol of war and so lack of freedom.
         | You don't have to carry a driving license while driving, just
         | present it later if asked. The latest elections required ID to
         | vote and there is a lot of opposition to that, as it has never
         | been a requirement.
        
         | wkat4242 wrote:
         | Yeah I'm surprised a surveillance country like the UK didn't do
         | this yet. Here in Spain they do.
        
           | toomuchtodo wrote:
           | I see lots of griping in thread, but it seems business as
           | usual in the countries where registration is required.
           | 
           | https://www.comparitech.com/blog/vpn-privacy/sim-card-
           | regist...
           | 
           | > The majority of national governments (around 160) require
           | mandatory SIM-card registration, which means you need your
           | real name and personal details to sign up for phone service.
           | And just under 20 of these also require biometrics, e.g. your
           | fingerprints or a facial scan, with eight more countries in
           | the process of implementing such requirements.
           | 
           | The biometrics part is unnerving to be sure, but anonymous
           | SIMs or DIDs are incompatible with fraud and spam fighting
           | efforts. If you terminate bad actors, they'll just keep
           | spinning up more resources.
        
             | grantla wrote:
             | From experience in other EU countries, registering SIM-card
             | registration helps exactly nothing. The biometrics also
             | won't help.
        
               | wkat4242 wrote:
               | Of course it doesn't. Especially with the low roaming
               | costs inside Europe. Just grab one in another country and
               | use that. It's purely theater. This is why it's so
               | annoying.
               | 
               | My current provider Orange even requires me to re-ID at
               | their shop periodically now :(
        
             | costco wrote:
             | The interesting thing is despite the rules governments in
             | countries like India or Ghana with strict registration laws
             | will routinely find 3000 SIM cards on raids on simbox
             | operators.
        
               | toomuchtodo wrote:
               | Who are these SIMs being registered to in these
               | operations?
        
               | costco wrote:
               | Destitute people or a carrier employee is bribed to
               | activate the SIM cards without registration.
               | 
               | https://commsrisk.com/telco-corruption-fuels-simbox-
               | frauds/
        
           | dazc wrote:
           | Stolen ID in Spain is rampant, it may be just a coincidence
           | though?
        
             | wkat4242 wrote:
             | IDs are stolen yes but they are generally discarded.
             | They're just a side catch for pickpockets and the moment
             | they steal the wallet they will take the money and dump the
             | IDs in a nearby bin.
             | 
             | I was pickpocketed a few years ago and I searched all the
             | bins in the area and I came up with ID cards, medical
             | cards, bank cards etc of 9 different people that had been
             | robbed that night!
             | 
             | I think the thieves do this because if you point them out
             | to the police they won't have any evidence on their
             | possession. Because if they have someone's ID on them they
             | will have some explaining to do. For some cash not so much,
             | you can't prove it was yours.
             | 
             | Not that the police do anything anyway because the Spanish
             | law lets them go free with a minor fine if they stole less
             | than 400 euro, even if it was the 50th time this month.
             | This is really why pickpocketing is so extremely rampant
             | here, it's risk-free and the gangs are basically
             | professional businesses.
        
         | jon-wood wrote:
         | For reasons I've never really understood the UK (or at least
         | the UK parliament) is wildly opposed to ID cards. There's been
         | a few attempts to introduce them which got massive pushback and
         | were eventually aborted.
         | 
         | Personally I think it would be quite a bit easier than the
         | current mish-mash of identification documents for different
         | purposes, everyone in practice carries some form of ID if only
         | so they can show it when buying age restricted products on the
         | odd occasion someone asks for verification.
        
         | bombcar wrote:
         | Or just mandate warmup periods like we do with spam from IPs.
        
       | danielfoster wrote:
       | I don't see any evidence in the proposal that fraud is known to
       | have originated from UK-based SIM farms. Maybe I missed this, but
       | even so I can't imagine that banning these devices would have any
       | impact on fraud.
       | 
       | It would be just as easy to get SIMs that support roaming and
       | text outside the UK, or better yet just use WiFi texting.
        
         | incone123 wrote:
         | Does WiFi texting not require the involvement of a mobile
         | service provider somewhere along the line?
        
           | danielfoster wrote:
           | It does, but you can do it with a UK SIM card outside the UK.
        
       | greatgib wrote:
       | Banning "devices for more than four SIM cards"...
       | 
       | In my opinion, this is again just an excuse reason for a backdoor
       | law to better control the population. 1984 style Ensuring that
       | they can more easily control the lines that you have. Like that
       | they can make mandatory the used of a registered phone number for
       | online registrations like social accounts and be sure that you
       | will not circumvent blocking by opening new lines.
       | 
       | Think about it, if you want to solve the problem that they
       | pretend they want to solve: Each subscriber in UK is registered,
       | so that if you open one or 50 lines, the will know you identity
       | the same.
       | 
       | So, if you are a scammer or fraudster, they should already be
       | able to arrest and jail you!
       | 
       | But take care, because here they only speak about sim, but it
       | will also probably apply to virtual sims and require that you
       | register all your foreign sim cards that did not use to be
       | declared so far...
        
       ___________________________________________________________________
       (page generated 2023-05-06 23:03 UTC)