That's Not How A SIM Swap Attack Works


A padlock engraved into a circuit board.

There's a disturbing article in The Guardian about a person who was on the receiving end of a successful cybersecurity attack. EE texted to say they had processed my sim activation request, and the new sim would be active in 24 hours. I was told to contact them if I hadn’t requested this. I hadn’t, so I did so immediately. Twenty-four hours later, my mobile stopped working and money was wit…

Continue reading →

There's nothing you can do to prevent a SIM-swap attack


Photo of a nano SIM card and its plastic housing.

It is tempting to think that users are to blame for their own misfortune. If only they'd had a stronger password! If only they didn't re-use credentials! If only they had perfect OpSec! If only...! Yes, users should probably take better care of their digital credentials and bury them in a digital vault. But there are some things which are simply impossible for a user to protect against. Take,…

Continue reading →

Cheapest Possible eSIM in the UK


Photo of a nano SIM card and its plastic housing.

After railing against eSIM-only phones for over a decade, I've finally succumbed. It appears impossible to buy a modern phone without them. Thankfully, most seem to be dual-SIM. So I can have a regular SIM card and an eSIM. I find dual-SIM phones handy. I have a disposable number which I give out to people who don't need my main number. And when I go abroad, it's useful to have a local SIM. …

Continue reading →

Using disposable phone numbers for better security


A pair of SIM cards.

Last night I received a call from my bank. They'd detected an unusual transaction and wanted to make sure that it was legitimate. Had I recently purchased £10,000 worth of crypto in the Maldives? What?!!? No! ARGH! I started to panic. All my apes money gone! No. Wait. The other thing. I knew it was a scam from the moment "James from your bank's fraud team" started his patter. You see, I have …

Continue reading →

Best Bulk Data PAYG SIMs in the UK


The Doctor on the phone.

I want to buy a big chunk of data and use it until it runs out. I'm not interested in a contract. I don't want a bundle of phone calls, SMS, or ringtones. Just give me DATA that lasts for as long as possible. Here's the best data deals that I could find. Stick them in your 2nd SIM slot, use them as broadband backup, or shove in a dongle and attach to a Raspberry Pi. Operator Cost Data …

Continue reading →

You need a SIM card in your phone to dial 999


Photo of a nano SIM card and its plastic housing.

I want to correct a common misconception. Many people think that you can dial the emergency services even if you do not have a SIM in your phone. I see this advice scattered around the web - often telling people to keep an old, SIMless phone for an emergency - and it is dangerously wrong. If you are in the UK, you must have an active SIM in your phone! Your SIM does not need to be in credit,…

Continue reading →

The SIM-less Phone Is Coming. And It Should Scare The Shit Out Of You


Photo of a nano SIM card and its plastic housing.

The argument over the nano-SIM is a distraction. It's a sleight of hand designed to catch the industry off guard and fool it into doing something really stupid. The SIM is designed to do a number of things; encryption, address storage, hold SMS, etc. Most importantly, it's designed to be swappable. With GSM, you can choose your phone and your network provider separately. Want the iPhone? Hate …

Continue reading →