Comments on: Identity is an opportunity for mobile operators in an API world http://tomorrowstransactions.com/2013/01/identity-is-an-opportunity-for-mobile-operators-in-an-api-world/ Thought leadership from Consult Hyperion Sat, 19 Apr 2014 23:37:23 +0000 hourly 1 http://wordpress.org/?v=3.8.3 By: Mark Cross http://tomorrowstransactions.com/2013/01/identity-is-an-opportunity-for-mobile-operators-in-an-api-world/#comment-226 Sat, 09 Feb 2013 09:24:42 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/01/identity-is-an-opportunity-for-mobile-operators-in-an-api-world/#comment-226 Hi Dave,

The Achilles Heal of using mobiles in any part of this security chain is the ease of which it is possible obtain a PAC code. The number you need to port your mobile number to another network.

A few months ago a real estate agent found herself the victim of financial fraud based on the usual DOB and maiden name etc. One of her accounts got cleaned out by $19k, fortunately she could survive this while it got sorted out.
http://www.itnews.com.au/News/322059,home-buyer-funds-targeted-in-phone-porting-scam.aspx

A few weeks, I later I obtained the PAC code to my girlfriend’s number online via chat with what felt like ZERO security checking. I’m kicking myself I didn’t save the transcript…

An industry standard on issuing PAC codes is likely to be ZERO. UK or International.

There is a way of solving the issue using the same method of protection yourself against identity theft in the UK. EG “Write a notice of correction” – using your own fingerprints. http://www.redlinesecurity.co.uk/product_info.php?products_id=193

The same method could be used to protect the issue of a PAC code, the industry would hate it because of the cost and speed slow down. But don’t the consumers deserve a choice in their security? Or at least a half decent attempt to make something broken better, instead using sticky tape all the time.

The question I constantly find myself asking is the way that financial systems are basically signed-off. IS risk assessment and underwriting really the best way to go. I’m not an academically qualified person in network security, I’m just a middle aged Computer Science Grad, but I feel the whole way many industries that find themselves having to provide security on the Internet plain lame?

Enjoy the Bar Camp with Gordon R, he’s supposed to say hello for me!

]]>