Уровень 0 · материалов: 15
Документы должны касаться технических и организационных аспектов защиты мобильных устройств, SIM-карт и связанных с ними методов аутентификации, за исключением тем, посвященных исключительно борьбе со спамом.
Общие признаки: уязвимости SIM-карт и SMS-авторизации, защита персональных данных в смартфонах, риски использования номеров телефонов для идентификации, способы предотвращения мобильного мошенничества, двухфакторная аутентификация (TOTP)
Группа выше: Безопасность мобильной связи и критической инфраструктуры
Смысл: The main idea is that phone numbers are an unreliable and insecure method for identity verification and account protection due to low-cost SMS spoofing, technical vulnerabilities, and administrative loopholes.
Phone-based registration is an illusion of security that fails to stop spam and leaves users vulnerable to account theft and surveillance.
Смысл: The main idea is that tying digital identity to a mobile phone number creates a significant security vulnerability, allowing for easy doxxing and social engineering, and users should adopt compartmentalization strategies to protect their privacy.
Linking your identity to a mobile phone number enables easy tracking and scams, so users should use separate numbers for registrations and public life.
Смысл: The main idea is that relying on SMS for account security is dangerous in Russia due to state-sponsored interception via telecom operators (specifically MTS), and that even 2FA cannot prevent certain types of account destruction if the platform has vulnerabilities.
Russian security services are intercepting Telegram SMS codes via mobile operators, allowing attackers to delete accounts even when two-factor authentication is active.
Смысл: The main idea is that SMS and messenger-based 2FA are insecure and privacy-invasive; users should switch to TOTP (Time-based One-Time Passwords) using dedicated apps to significantly increase their digital security and privacy.
Stop using SMS for 2FA due to security flaws and switch to a TOTP app like Aegis for offline, private, and more secure account protection.
Смысл: The main idea is that while phone number spoofing is a systemic vulnerability of the SIP protocol used by fraudsters, a combination of new legislation and inter-operator technical verification systems is being implemented to mitigate the risk, although complete eradication of telephony fraud is unlikely.
The article explains how fraudsters spoof phone numbers using the SIP protocol and details the technical and legislative efforts by Russian operators to stop this practice.
Смысл: The main idea is that relying on single security measures like mobile phone linking or secret questions is insufficient, and that corporate recovery processes can be overly bureaucratic and impractical for victims of hacking.
An author shares their experience of having Mail.ru accounts stolen despite having a linked phone number, highlighting the weakness of secret questions and the difficulty of official account recovery.
Смысл: The main idea is to inform users that they can avoid using the MAX messenger and insecure SMS codes for Gosuslugi login by implementing the industry-standard TOTP authentication via the MULTIFACTOR app.
Learn how to use TOTP authentication via the MULTIFACTOR app to access Gosuslugi securely without relying on SMS or the MAX messenger.
Смысл: The main idea is that mobile operators may be unable or unwilling to prevent internal and external fraud involving SIM card duplication, necessitating that users implement their own strict security measures to protect their financial assets and personal data.
Due to the failure of mobile operators to prevent fraudulent SIM card duplication, users must adopt rigorous personal security protocols to protect their bank accounts.
Смысл: The main idea is that systemic failures in mobile operator security and rigid, unhelpful corporate policies of social media platforms leave users vulnerable and without recourse, making personal digital security measures and legal interventions the only viable protections.
Entrepreneur Alexey Mironov is suing VKontakte after the platform refused to restore his hacked account, which was compromised through a security flaw at MTS.
Смысл: The main idea is that purchasing SIM cards without official registration (where they remain in the seller's name) exposes the user to the risk of losing their number due to the seller's debts or actions.
Buying unregistered SIM cards can lead to permanent service blockage if the original registrant incurs debts with the mobile operator.
Смысл: The text aims to debunk the media's sensationalist portrayal of a mobile hacking scheme in Russia. It explains that the criminals used basic wireless vulnerabilities (Bluetooth/Wi-Fi) rather than hacking the cellular networks themselves, highlighting the importance of personal device security.
A reported 'network hack' in Russia was actually a simple exploitation of open Bluetooth and Wi-Fi connections used to steal small sums of money from unsuspecting users.
Смысл: The main idea is to highlight the risks of personal data exposure following phone theft and to evaluate Kaspersky Mobile Security 9 as a tool to mitigate these risks through remote management and privacy features.
A review of Kaspersky Mobile Security 9 focusing on its anti-theft and privacy tools to protect personal data after a phone is lost or stolen.
Смысл: The main idea is that users should proactively secure their smartphones using open-source software and restrictive network settings to protect their privacy against corporate and state surveillance, which the author believes will culminate in a social credit system.
A guide on enhancing Android privacy using F-Droid, ADB, and firewalls to protect personal data from being used for social rating and surveillance.
Смысл: The main idea is that technical security is insufficient if the service provider is dishonest or negligent; therefore, users must be equipped with specific legal knowledge and precedents to successfully sue mobile operators for damages resulting from unauthorized SIM swaps.
A guide on how to legally hold mobile operators like MTS accountable for financial losses caused by unauthorized SIM card replacements using specific Russian laws and court precedents.
Смысл: The main idea is that as smartphones become the primary computing tool, the lack of software and hardware freedom creates severe privacy and security risks, making the development of truly open Linux-based phones like Librephone an urgent necessity.
The Free Software Foundation's Librephone project aims to combat corporate surveillance and software lockdowns by creating a fully open-source smartphone.