Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




203 posts

Master Geek


#195434 20-Apr-2016 10:07
Send private message

Hey guys,

 

So I recently upgraded from a Nexus 5 to a 5X. This necessitated moving from my older micro SIM to a nano SIM.

 

I headed down to my local Spark store to get this sorted. Let me be clear upfront; I was served in a professional and friendly manner by the staff, so no qualms with them personally.

 

In saying this, I am pretty gobsmacked by the total lack of any sort of identity verification, particularly in todays age where a lot of services use SMS as a second authentication factor, or account reset mechanism.

 

Here's a simplified version of how our conversation played out:

 

Me: I've just got a new phone, can I please move over to a new nano SIM?

 

Spark: Sure, what's your number?

 

Me: 027 xxxxxxx

 

*some fiddling at the PC, hands over new SIM packet*

 

Spark: Cool, all done. That'll be $5.

 

Sure enough, an hour or two later, the new SIM was up and running, and the old one was no more.

 

There was no check against any of my details, or even that I did in fact have the original SIM at all. I could've said any number under the sun, or less maliciously, the number may have been keyed incorrectly.

 

Now I am on prepaid so perhaps there would be a more robust check for an on account customer/number (they did ask if I was prepaid or account, to be fair), however I still feel some basic level of verification is definitely needed here. I've had my number for over 10 years so I'm not sure what specific details Spark will have on file, but it seems all too easy to go in and hijack some unsuspecting victims number (at least if they are a prepaid customer!).

 

I can understand perhaps the 'burner' nature of short term prepaid users, however with the semi-recent (and very attractive) monthly prepaid packs, I'm sure I'm not the only one who has stuck with prepaid for years.

 

Historically, at worst this would 'just' be grabbing someones phone number; today, we're potentially talking bank account access, and all manner of online accounts.

 

Has anyone else experienced this? Is this the standard Spark procedure for this sort of request?

 

 


Create new topic

xpd

Covid-19 Free
10647 posts

Uber Geek

Mod Emeritus
Trusted
Lifetime subscriber

  #1536318 20-Apr-2016 10:12
Send private message

I've had it with Vodafone and 2D - sometimes you get asked for ID/verification, but more often than not, nothing asked.

 

 





XPD^ / DemiseNZ

 

Blog         Free Games        Twitter

 

My TradeMe Goodies

 

Disclaimer - It wasn't me, the dog ate my keyboard, my account was hacked, I was drunk, ALIENS.


1100 posts

Uber Geek

Lifetime subscriber

  #1536325 20-Apr-2016 10:16
Send private message

I don't think that is the usual process. 

 

I recently had done this for someone and they have asked a Photo Identification and the person said the only acceptable photo identification is a Drivers License or a Passport. 

 

 

 

So, my guess is the person doing the swap was not aware of the process or missed it somehow. 

 

 


 
 
 
 


1558 posts

Uber Geek

Trusted

  #1536327 20-Apr-2016 10:18
Send private message

Had same experience at 2degrees store also.


16203 posts

Uber Geek

Trusted
Subscriber

  #1536340 20-Apr-2016 10:26
Send private message

Anyone know the name and phone number of the Spark CEO?


4771 posts

Uber Geek


  #1536391 20-Apr-2016 10:48
Send private message

timmmay:

 

Anyone know the name and phone number of the Spark CEO?

 

 

No idea,

 

but Details for people like the Head of Corporate Comms are in places like this

 

https://nzx.com/companies/SPK/announcements/280837


23456 posts

Uber Geek

Trusted
Subscriber

  #1536431 20-Apr-2016 11:47
Send private message

Yup, totally absurd how easy it is to move over to a new sim.

 

A phone bill has all the details you need to initiate a port to another provider on them, so if instore fails and you can get hold of someones account number then just get a $5 2 degrees sim, log in, and port to that, then you can 2 factor to your hearts content as someone else.

 

That is why I dont really trust SMS 2 factor as a second factor. So more like 1.5 factor.





Richard rich.ms

160 posts

Master Geek


  #1536509 20-Apr-2016 12:36
Send private message

Had the same with vodafone :) Even more, dude make some mistake and I've got somebody's else number. I didn't notice until strange people started calling me and ask for some Bob :) Then checked and yeap - I had different than my number, and looks like unlucky Bob sim was unregistered.


 
 
 
 


3154 posts

Uber Geek

Trusted
Lifetime subscriber

  #1536779 20-Apr-2016 15:48
Send private message

It different between prepaid and postpaid.

Prepaid there is no easy way to validate apart from pulling the sim.

With postpaid you should have been asked for your name and probably address. As that's what I was asked for last time I did a sim swap.




and


Create new topic




News »

Freeview On Demand app launches on Sony Android TVs
Posted 6-Aug-2020 13:35


UFB hits more than one million connections
Posted 6-Aug-2020 09:42


D-Link A/NZ extends COVR Wi-Fi EasyMesh System series with new three-pack
Posted 4-Aug-2020 15:01


New Zealand software Rfider tracks coffee from Colombia all the way to New Zealand businesses
Posted 3-Aug-2020 10:35


Logitech G launches Pro X Wireless gaming headset
Posted 3-Aug-2020 10:21


Sony Alpha 7S III provides supreme imaging performance
Posted 3-Aug-2020 10:11


Sony introduces first CFexpress Type A memory card
Posted 3-Aug-2020 10:05


Marsello acquires Goody consolidating online and in-store marketing position
Posted 30-Jul-2020 16:26


Fonterra first major customer for Microsoft's New Zealand datacentre
Posted 30-Jul-2020 08:07


Everything we learnt at the IBM Cloud Forum 2020
Posted 29-Jul-2020 14:45


Dropbox launches native HelloSign workflow and data residency in Australia
Posted 29-Jul-2020 12:48


Spark launches 5G in Palmerston North
Posted 29-Jul-2020 09:50


Lenovo brings speed and smarter features to new 5G mobile gaming phone
Posted 28-Jul-2020 22:00


Withings raises $60 million to enable bridge between patients and healthcare
Posted 28-Jul-2020 21:51


QNAP integrates Catalyst Cloud Object Storage into Hybrid Backup solution
Posted 28-Jul-2020 21:40



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.