-
Notifications
You must be signed in to change notification settings - Fork 683
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
sim swapping #103
Comments
Isn't that more of an OS/HW level issue than app/web app? |
I don't think so because the topic is cross cutting many technologies and also can involve social engineering. But for (web) app specifically it would at least be a good idea to advise against sending out plain passwords over sms. |
Fair enough |
Hi! Even though this is a very old issue, it would be great if you could assign it to me. I could create a sample guideline for preventing SIM Swapping based on similar references and provide a solution to this issue. It would be even better if you could tell me where this guideline would be inserted for the PR. |
A new control page would make sense if you plan for the content to be about prevention. https://github.com/OWASP/www-community/tree/master/pages/controls |
Okay. Then I will create the same. |
@kingthorin |
@kingthorin |
Yup as time permits, there's no need to ask. GitHub notifications work fine. |
Sorry sir, for being impatient. |
I read more and more articles about the dangers of sim swapping. Would be nice to have some guidelines on how to prevent such attacks.
Example article https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts
The text was updated successfully, but these errors were encountered: