U

Visitor

 • 

3 Messages

Tuesday, August 24th, 2021 7:00 PM

Closed

Security to prevent unauthorized SIM swaps?

Does Xfinity Mobile provide solid security options to prevent Port-out fraud/unauthorized SIM swaps? This is particularly worrisome to those who trade/own cryptocurrency as your mobile phone is often (unfortunately) a single point of failure, with many well-reported attacks via SIM swaps. Passwords and 2FA are OK but each have issues. For example, Xfinity uses text messaging vs authenticator apps (Google, Microsoft) that are typically rated stronger and not subject to man-in-the-middle attacks. Also in searches on Xfinity site I see nothing about a PIN/passcode/security Q to approve an account change. I would like to see a link to an article that deals with this issue and how Xfinity does/will secure the account (per FCC recommendations). Does this exist? 

Regular Visitor

 • 

12 Messages

4 years ago

I would like to know the same.  

Retired Employee

 • 

1.4K Messages

4 years ago

@user_240386, for ways to help protect your account, we recommend reaching out directly to Xfinity Mobile. You can reach them by phone or text at 1 (888) 936-4968 and they would love to assist you. They will better be able to identify ways to secure your account as well as the different security measures we have. We would love to hear about the recommendations you received in this thread.

Visitor

 • 

2 Messages

@XfinityTony Thanks for your response and as former Time Warner Cable Tier 2 Tech Support Lead your company is very behind when it comes to the latest security threats.

A customer service agent must know what exactly what a unauthorized sim swap actually is before they can help a customer. It seems apparent that there is no current policy on sim swapping fraud for reps to follow as the results of my many chat sessions and phone call that I experienced. 

I suggest adding a Administrative Lock (Verizon) or similar to Xfinity account website. 

Visitor

 • 

3 Messages

@XfinityTony 

Agree with user_f5473d. After talking to Xfinity Mobile transfer out team member, the security model for port outs does not have a process that allows the customer to have some modicum of control over verification of identity/user controlled authentication methods. This is a significant gap in security compared to your competitors. See https://www.verizon.com/support/port-out-faqs/#:~:text=%5BSolution%5D%20How%20to%20Set%20Up%20a%20Number%20Lock,You%20will%20need%20to%20turn%20...%20See%20More.

Can someone from Xfinity Mobile security reply to this thread to explain any gaps in our knowledge and/or a roadmap to improve the process?

(edited)

Visitor

 • 

1 Message

4 years ago

I was wiped out through Sim Swap fraud on August 25, 2021.. Have to fill out a report.

Visitor

 • 

2 Messages

3 years ago

Thank you for your post:)

I tried last month to find out what security measures they had and was unsuccessful after 2 chat sessions, nobody knew what sim swapping fraud was.

I also tried via a phone call and after being on the call over 40 minutes still no one had a solution and wanted to transfer to a 3rd dept, at this point I hung up. Xfinity Mobile clearly does not have any policies to safeguard against sim swapping fraud which in today's climate of data breaches is just ridiculous.

All other major carriers have options like Port freeze & Administrative Lock which does not allow a port change without calling you to verify or prevents phone number from being ported out to another carrier , so I'm just going back to one of them.

Visitor

 • 

3 Messages

3 years ago

user_f5473d

 I too had tried previously and got the runaround. Your message spurred me to try again just now. After 4 TXFRs I did get an explanation of the process.

Step 1: They verify your identity: name, address, last 4 digits of current ccard. Step 2: A security PIN is generated by their TXFR OUT team and send via SMS to your phone to facilitate the TXFR with new carrier. They say that code cannot be copied internally and is not known to other Xfinity systems. But no ability to set a "Number Lock" like VZN where there is a PIN/PW that only the current account owner knows.

Step 1 is not hard to get through. Your ccard info has likely been leaked/hacked by some merchant who doesn't encrypt sensitive data. Step 2 is not great but as long as you have possession of your phone, only you would have the generated PIN to complete the TXFR out. Of course malware on your device, MitM attack, etc and the fact that SMS is not encrypted are potential issues. At minimum, it would be some advance warning and you could call and intervene. My preference, like yours,  is a PIN/PW that only the user knows to initiate the process and create additional layer of security.

I did have a note put on my account that TXFR outs must be done in person in an Xfinity office by a "manager" on the Xfinity account with photo ID. I don't change carriers very often so not a burden. Of course, that assumes a TXFR Out cust svc rep will read and abide by that. 

I save $$ with Xfinity Mobile and I like the daily control over the billing rate. I did send an email to customer service recommending they match VZN security model. Maybe some day. 

(edited)

forum icon

New to the Community?

Start Here