Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sim swapping #103

Open
flip111 opened this issue Apr 6, 2020 · 11 comments
Open

sim swapping #103

flip111 opened this issue Apr 6, 2020 · 11 comments
Assignees
Labels
enhancement New feature or request related to the improvement of this project and its resources good first issue Good for newcomers

Comments

@flip111
Copy link

flip111 commented Apr 6, 2020

I read more and more articles about the dangers of sim swapping. Would be nice to have some guidelines on how to prevent such attacks.

Example article https://www.vice.com/en_us/article/pke9zk/paypal-and-venmo-are-letting-sim-swappers-hijack-accounts

@kingthorin
Copy link
Contributor

Isn't that more of an OS/HW level issue than app/web app?

@flip111
Copy link
Author

flip111 commented Apr 6, 2020

I don't think so because the topic is cross cutting many technologies and also can involve social engineering. But for (web) app specifically it would at least be a good idea to advise against sending out plain passwords over sms.

@kingthorin
Copy link
Contributor

Fair enough

@kingthorin kingthorin added enhancement New feature or request related to the improvement of this project and its resources good first issue Good for newcomers help wanted Extra attention is needed labels Apr 7, 2020
@Sudhanyo
Copy link

Hi! Even though this is a very old issue, it would be great if you could assign it to me.

I could create a sample guideline for preventing SIM Swapping based on similar references and provide a solution to this issue. It would be even better if you could tell me where this guideline would be inserted for the PR.

@kingthorin
Copy link
Contributor

A new control page would make sense if you plan for the content to be about prevention.

https://github.com/OWASP/www-community/tree/master/pages/controls

@Sudhanyo
Copy link

Sudhanyo commented Jan 20, 2023

Okay. Then I will create the same.

@kingthorin
Copy link
Contributor

@Sudhanyo ?

@Prakhar-Shankar
Copy link
Contributor

@kingthorin
This issue has been open from quite a long time now, can you please assign this issue to me.

@kingthorin kingthorin removed the help wanted Extra attention is needed label Aug 17, 2023
@Prakhar-Shankar
Copy link
Contributor

@kingthorin
Please review this PR.

@kingthorin
Copy link
Contributor

Yup as time permits, there's no need to ask. GitHub notifications work fine.

@Prakhar-Shankar
Copy link
Contributor

Yup as time permits, there's no need to ask. GitHub notifications work fine.

Sorry sir, for being impatient.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request related to the improvement of this project and its resources good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

4 participants