Tue 2025-07-01

Manty Ray Coffee Roasters
I had a baker's delight apple & walnut scroll for breakfast

Walked to manta ray for a morning coffee. It drizzled slightly on my walk home. I was a little late logging in 

My fingerbot successfully turned on my ducted heater (from bed) this morning, which was a good way to start the day

I had done wordle overnight at ~2am when i woke for a little time. Keith And The Girl podcast out me back to sleep. The guest was Mimi Cherry

DARKNET DIARIES
I've listened to some Darknet Diaries podcast episodes this week too. I am nearly up-to-date 

One episode was rather shocking. Thieves took over a phone number by doing a SIM-swap scam. They had targeted people who held a lot of crypto currency. Up to $2mm in the case of one victim

By stealing the victim's phone number the criminals could intercept the victim's Two-Factor Authentication (2FA) code. That allowed them to login to Gmail and other online accounts. They could reset the victim's other passwords (by entering the victim's 2FA code)

Worse: By logging in to a web-browser with the victim's Gmail, they could read passwords in PLAIN TEXT stored by Google from whenever it offered to "Save This Password?"

Even when users decline to Save This Password, google stores the website's address they visited – which means the criminals could see which crypto exchanges the victim uses (had used) and therefore where they store their crypto wallet

The moral of the story is that Google knows to much about a user. And telcos are easily tricked into a SIM-swap scam. The crooks would call 10 times, if they had to, to get a naive employee 

Comments

Popular posts from this blog

Fri 2025-05-09

Sat 2025-05-10

Thu 2025-05-15