[HN Gopher] Preventing the use of SIM farms for fraud: consultation
___________________________________________________________________
Preventing the use of SIM farms for fraud: consultation
Author : azalemeth
Score : 44 points
Date : 2023-05-06 14:19 UTC (8 hours ago)
(HTM) web link (www.gov.uk)
(TXT) w3m dump (www.gov.uk)
| tjpnz wrote:
| What is this going to accomplish given that most scammers aren't
| operating on UK soil?
| whypretend wrote:
| [dead]
| whypretend wrote:
| What about the sim farm I use to delegate my SMS OTP codes to? No
| VOIP numbers don't work for everything, no using the same SIM
| card doesn't work, no I don't want to worry about running dozens
| of phones with batteries and no I'm not even sending messages.
|
| Local TOTP key as a second factor should be more standard.
|
| Especially if I'm already paying for a service you shouldn't need
| SMS as a crappy veiled proxy for some human verification.
|
| Supposed to pretend like this doesn't just force people to use
| more phones?
| CPLX wrote:
| Geniune question - what's the actual use case here? It can't be
| just you personally logging into various services right?
| whypretend wrote:
| Mitigating account lockout risk across lots of clients.
| Separate SIM for each client, having account lockouts are
| unacceptable. Yes, I've had problems with no recourse.
| costco wrote:
| https://smspva.com/
|
| Immensely useful services like this without which for
| instance people would not be able to scrape social media
| services at scale.
| whypretend wrote:
| [dead]
| DANmode wrote:
| If it was?
| whypretend wrote:
| [dead]
| ec109685 wrote:
| Why don't you want to use the same SIM card? Is it because you
| don't want services to be able to correlate usage across
| multiple services?
| whypretend wrote:
| I need a reliable way to manage OTP codes for many clients,
| having one SIM is just not good enough. Partially the same
| problem because I've run into limits - having a separate card
| is just less likely to be a problem.
| orf wrote:
| You say "no, no, no" as if it is obvious why you'd need to
| delegate SMS OTP codes to a sim farm.
| whypretend wrote:
| [dead]
| timthorn wrote:
| So please respond to the consultation. Q2 is literally asking
| for other uses of multiple SIMs that the policy wonks haven't
| thought about yet.
| whypretend wrote:
| [dead]
| jpalomaki wrote:
| Are operators doing spam filtering for outgoing SMS messages? The
| messaging patterns must be quite different from normal customers.
| Maybe you could also detect the suspicious amount of messages
| originating from certain location (cell).
| efitz wrote:
| Banning devices has not historically been a very effective way to
| prevent crime.
|
| I am not an expert in modern mobile network technology so I'll do
| something unusual for HN and refrain from suggesting a solution.
| ivanstojic wrote:
| What happens with eSIM devices?
| maratc wrote:
| eSIM device does not usually have a phone number, and it can't
| send (or receive) SMS.
| kiwijamo wrote:
| Incorrect, they can have an assigned phone number and can do
| anything a normal SIM can do.
|
| There are SIMs (either physical or eSIM) that do not have a
| phone number and/or has restrictions on what it can do. It's
| not the form itself that limits the functionality, it's the
| mobile network provider who decides what functionality each
| individual SIM has.
|
| E.g. Mobile card payment devices may have a SIM that has no
| phone number and is data only with connection only permitted
| via a certain gateway to the payment provider.
| jackweirdy wrote:
| Unless we are thinking of different technologies, you can use
| esims for all of that? Just last week I ordered a
| usmobile.com esim, installed it on my phone, received a +1
| 415 number and received and sent SMS with it
| whypretend wrote:
| [dead]
| whypretend wrote:
| [dead]
| orf wrote:
| > SIM farms are devices that can house hundreds of SIM cards,
| which can send out thousands of scam texts to defraud the UK
| public of millions of pounds. In addition to sending scam texts,
| these devices are used by criminals to run scam call campaigns
| and to post misleading, false or phishing messages on social
| media in bulk.
|
| > Whilst there are some potentially legitimate uses of the
| technology, these are limited and should not require using more
| than four SIM cards, based on the number of mobile operators in
| the UK. We have very limited evidence that there are any
| legitimate use cases for devices that allow the use of more than
| four SIM cards, and for all such cases alternative options exist.
|
| The justification seems sound. What is the issue here?
| nibbleshifter wrote:
| This is a backdoor way they are trying to introduce mandatory
| SIM registration.
| dazc wrote:
| Govt id is required to purchase a sim card in many EU
| countries. If the UK Govt decided to implement such a policy
| based on something like 'security' there wouldn't be a lot of
| push-back.
|
| Let's overlook the fact that such policies just make stolen
| id a lot more valuable than it is already.
| specproc wrote:
| I'm all for it continuing, but it always struck me as wild
| how you can just pick a UK SIM up at the airport from a
| vending machine. I don't know of many countries where this
| is possible.
| nibbleshifter wrote:
| I've found that policy trivial to circumvent in most EU
| countries I've visited (which is most of them).
|
| Its also a stupid fucking policy.
| [deleted]
| costco wrote:
| They propose a total ban that does not require fraudulent
| intent to criminalize possession, an unlimited fine, and ignore
| that most of the use is just bypassing rentseeking A2P SMS
| charges? Along with the fact that it's unclear who is even
| asking for it. UK similarly banned GSM gateways in the early
| 2000s but recent court rulings said the way it was banned was
| illegal and is in the appeals process.
| orf wrote:
| Most of the use case is spamming people. There are very few
| other uses for something like this[1].
|
| A2P is also a US specific thing?
|
| 1. https://m.aliexpress.com/item/1005004866582019.html?spm=a2
| g0...
| toast0 wrote:
| Something like that provides for programatic sms and maybe
| voice calling. Most likely, using consumer market sims, so
| tarriff arbitrage is likely a large component.
|
| You might use something like this to do bulk SMS, which
| could be spam or could be phone number confirmations (like
| it or not, it's a common activity). If voice works, it
| could be a backup outbound connection for an office PBX
| (although, unless you had fancy SIMs, you are going to get
| the sim's phone number as caller id which is undesirable).
|
| Many countries have been making a2p messaging harder and
| harder; using a sim farm is a tempting way to opt-out of
| official restrictions, although it seems like a lot more
| operational work.
| costco wrote:
| Sites like smspva.com would have dozens of those devices,
| should they be illegal? I can think of uses of these
| devices, yes most of them are "grey market" but they don't
| involve stealing from people.
|
| By "A2P fees" I'm referring to the fact that in most
| countries it costs more to send an SMS with Twilio than a
| 5000 message or unlimited message retail plan. I won't deny
| that some SIM farms are used for scams but if you look at
| the countries that have banned them the reasoning is not
| because of fraud it's because they have a monopoly phone
| provider and people effectively use these devices to
| convert international calls or SMS like verification code
| messages to domestic so that they don't have to pay higher
| termination fees which costs the carrier some profits. They
| can also make tracing calls harder which is why India bans
| them. But given that there is VOIP I don't see why banning
| this would prevent any fraud.
| orf wrote:
| > Sites like smspva.com would have dozens of those
| devices, should they be illegal?
|
| Your argument is that since this clearly sketchy service
| ran from Hong Kong that is dedicated to giving people the
| ability to automate signups on sites/apps and "earn money
| using our service" utilizes dozens of these devices,
| these devices are OK?
| costco wrote:
| Plenty of civic minded people find services like these
| useful for registering Signal accounts not tied to their
| own number. Or for scraping sites like LinkedIn. There
| are companies like this run from other countries if you
| don't trust Hong Kong. I don't think arguing that some
| unknowable fraction of fraud traffic flows through these
| devices is persuasive when the legislative conversation
| in the countries that banned these devices is almost
| entirely about carriers losing some termination fees and
| national security fears.
| incone123 wrote:
| In the UK we can still get anonymous SIM cards for cash,
| if you want an anonymous Signal account.
|
| Having recently looked at commercial SMS gateway pricing,
| I am inclined to the argument that these devices have a
| role in thwarting rent-seeking on the part of telcos.
| orf wrote:
| I mean it literally advertises itself as a service that
| enables people to make money by bypassing restrictions
| that require phone numbers.
|
| You might not make money using it and instead just use it
| to sign up for a single signal account, but you're not
| really the target audience in that case.
| costco wrote:
| The people making money from it wouldn't exist without
| people buying the verification codes. If you Google
| smspva or services like it and read forum posts about it
| the majority of discussion is about people using it to
| automate account registration.
| orf wrote:
| Yes, hello?? They often use those registered accounts for
| malicious purposes which generates income for them?
| costco wrote:
| Sorry, I misread your previous comment. The site doesn't
| advertise itself as a way to make money, its just
| incidental to how some people make money. Is scraping a
| malicious purpose? Maybe in some cases. Either way I
| don't see why this use of sim boxes shouldn't be a civil
| dispute between companies and needs to be something the
| government should criminalize. Fraud is already illegal.
| orf wrote:
| > The smspva website has been operating since 2013.
| During this time, we have gathered a large audience of
| users who trust us and earn money using our service
|
| And the use case they showcase involves mass creating
| Facebook pages. Come on. Are you really truly that naive?
|
| It's vaguely legitimate business that just happens to
| offer a service that's super useful to a particular type
| of clientele. Just like bulletproof hosting.
| costco wrote:
| Is that supposed to always be bad? Unless the pages are
| used to promote some kind of fraud I don't think that's
| illegal. It's "dual use" like any other kind of anonymity
| technology. Cloudflare says 90% of Tor traffic is
| malicious - does that mean hosting relays and using Tor
| should be criminalized?
|
| Regardless, that was just a minor point about one
| potential use of SIM farms. The proposal says they intend
| to make possession a criminal offence and they don't even
| have data on whether these devices are used for fraud at
| scale in the UK.
| orf wrote:
| If you go around selling micro sized mobile phones close
| to a prison then you can plead all you want that it's not
| fraudulent, it's just for people with tiny hands and it's
| ridiculous to imply that it's anything other than a
| legitimate business.
|
| However, it's not. It's got one clear use case and one
| clear market.
|
| We started this discussion on sim farms and your very
| first point here (and in other places in this post)
| linked directly to the kind of thing that should, and
| hopefully will, be criminalised in the UK.
|
| Because it's quite obvious what it really is, even if you
| apparently can't see it?
|
| I find that quite hilarious.
| asdadsdad wrote:
| how is scraping related to sim farms?
| costco wrote:
| Scraping services that require phone verified accounts
| but reject VOIP numbers. Someone (in house or a service
| like smspva) operating SIM farm would be required in
| order to do this economically.
| netik wrote:
| absolutely wrong approach. fix this at the carrier level and not
| client device level.
| Nextgrid wrote:
| You're forgetting that 1) carriers have near-zero engineering
| capability to fix this and 2) don't actually have an incentive
| to prevent spam/fraud because fraudulent traffic still pays
| them money.
|
| This is not about stopping fraud, this is about preventing
| "grey routes" that do arbitrage around tariffs and bypass
| carriers' outdated business model.
| petesergeant wrote:
| I think you might be right here, but what does that look like
| exactly? Stop companies distributing cheap SIMs? Force them to
| get ID from any customer?
| fathyb wrote:
| Maybe a standarized national system to report spam, or maybe
| even as part of the cellular protocol? I never heard of such
| a system deployed nationally, but I'm wondering if it could
| help.
|
| Most of the time when a spam number calls me, I can find it
| through spam reports on 3rd party websites by googling it.
| NoZebra120vClip wrote:
| > Most of the time when a spam number calls me, I can find
| it through spam reports on 3rd party websites by googling
| it.
|
| Oh, you mean that you can identify the Caller ID number
| which the spammer chose to spoof at you?
| fathyb wrote:
| No, it seems most spammers here use cheap SIMs without
| spoofing (which seems to be what OP is about). They even
| leave voicemail messages asking to call back.
|
| But spoofing is also something that should be fixed. I
| know it's difficult because of VoIP and backwards-
| compatibility, but it's not impossible either.
| DANmode wrote:
| > Maybe a standarized national system to report spam, or
| maybe even as part of the cellular protocol?
|
| Not government, but, forwarding spam texts to 7726 (SPAM)
| works for various carriers.
| petesergeant wrote:
| Given that gov.uk is already so surveillance happy, I'm surprised
| they haven't just mandated ID cards and then required SIMs to be
| linked to one of those or a passport
| justincormack wrote:
| Various governments tried at various times. There is historic
| resistance as ID cards were originally a wartime measure
| https://en.wikipedia.org/wiki/National_Registration_Act_1939
| and considered to be a symbol of war and so lack of freedom.
| You don't have to carry a driving license while driving, just
| present it later if asked. The latest elections required ID to
| vote and there is a lot of opposition to that, as it has never
| been a requirement.
| wkat4242 wrote:
| Yeah I'm surprised a surveillance country like the UK didn't do
| this yet. Here in Spain they do.
| toomuchtodo wrote:
| I see lots of griping in thread, but it seems business as
| usual in the countries where registration is required.
|
| https://www.comparitech.com/blog/vpn-privacy/sim-card-
| regist...
|
| > The majority of national governments (around 160) require
| mandatory SIM-card registration, which means you need your
| real name and personal details to sign up for phone service.
| And just under 20 of these also require biometrics, e.g. your
| fingerprints or a facial scan, with eight more countries in
| the process of implementing such requirements.
|
| The biometrics part is unnerving to be sure, but anonymous
| SIMs or DIDs are incompatible with fraud and spam fighting
| efforts. If you terminate bad actors, they'll just keep
| spinning up more resources.
| grantla wrote:
| From experience in other EU countries, registering SIM-card
| registration helps exactly nothing. The biometrics also
| won't help.
| wkat4242 wrote:
| Of course it doesn't. Especially with the low roaming
| costs inside Europe. Just grab one in another country and
| use that. It's purely theater. This is why it's so
| annoying.
|
| My current provider Orange even requires me to re-ID at
| their shop periodically now :(
| costco wrote:
| The interesting thing is despite the rules governments in
| countries like India or Ghana with strict registration laws
| will routinely find 3000 SIM cards on raids on simbox
| operators.
| toomuchtodo wrote:
| Who are these SIMs being registered to in these
| operations?
| costco wrote:
| Destitute people or a carrier employee is bribed to
| activate the SIM cards without registration.
|
| https://commsrisk.com/telco-corruption-fuels-simbox-
| frauds/
| dazc wrote:
| Stolen ID in Spain is rampant, it may be just a coincidence
| though?
| wkat4242 wrote:
| IDs are stolen yes but they are generally discarded.
| They're just a side catch for pickpockets and the moment
| they steal the wallet they will take the money and dump the
| IDs in a nearby bin.
|
| I was pickpocketed a few years ago and I searched all the
| bins in the area and I came up with ID cards, medical
| cards, bank cards etc of 9 different people that had been
| robbed that night!
|
| I think the thieves do this because if you point them out
| to the police they won't have any evidence on their
| possession. Because if they have someone's ID on them they
| will have some explaining to do. For some cash not so much,
| you can't prove it was yours.
|
| Not that the police do anything anyway because the Spanish
| law lets them go free with a minor fine if they stole less
| than 400 euro, even if it was the 50th time this month.
| This is really why pickpocketing is so extremely rampant
| here, it's risk-free and the gangs are basically
| professional businesses.
| jon-wood wrote:
| For reasons I've never really understood the UK (or at least
| the UK parliament) is wildly opposed to ID cards. There's been
| a few attempts to introduce them which got massive pushback and
| were eventually aborted.
|
| Personally I think it would be quite a bit easier than the
| current mish-mash of identification documents for different
| purposes, everyone in practice carries some form of ID if only
| so they can show it when buying age restricted products on the
| odd occasion someone asks for verification.
| bombcar wrote:
| Or just mandate warmup periods like we do with spam from IPs.
| danielfoster wrote:
| I don't see any evidence in the proposal that fraud is known to
| have originated from UK-based SIM farms. Maybe I missed this, but
| even so I can't imagine that banning these devices would have any
| impact on fraud.
|
| It would be just as easy to get SIMs that support roaming and
| text outside the UK, or better yet just use WiFi texting.
| incone123 wrote:
| Does WiFi texting not require the involvement of a mobile
| service provider somewhere along the line?
| danielfoster wrote:
| It does, but you can do it with a UK SIM card outside the UK.
| greatgib wrote:
| Banning "devices for more than four SIM cards"...
|
| In my opinion, this is again just an excuse reason for a backdoor
| law to better control the population. 1984 style Ensuring that
| they can more easily control the lines that you have. Like that
| they can make mandatory the used of a registered phone number for
| online registrations like social accounts and be sure that you
| will not circumvent blocking by opening new lines.
|
| Think about it, if you want to solve the problem that they
| pretend they want to solve: Each subscriber in UK is registered,
| so that if you open one or 50 lines, the will know you identity
| the same.
|
| So, if you are a scammer or fraudster, they should already be
| able to arrest and jail you!
|
| But take care, because here they only speak about sim, but it
| will also probably apply to virtual sims and require that you
| register all your foreign sim cards that did not use to be
| declared so far...
___________________________________________________________________
(page generated 2023-05-06 23:03 UTC)