Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I thought they require ID for buying SIMs in Australia, surely they also require ID for switching your number to a new SIM?


That requirement is there for new or ported-in services.

But when you Sim swap, it's tied to the same account. So if you can convince the minimum wage hourly wage contract employee at a franchisee that you're the account holder, no worries.

Worse, most of those stores are using generic accounts and/or passwords.

Telstra years ago had a policy along the lines that store accounts could be not tied to a specific employee, so long as the store manager/team leader rotated the passwords and kept records. in reality it's something stupidly guessable that rotates only when required and all the staff know them.

Optus effectively has the same thing - I had an issue getting a SIM established and sat with an employee for about an hour as they re-rolled the account about 10 times. By the end I knew the passwords for all the accounts in the store, plus other identifiers and numbers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: