this post was submitted on 23 Sep 2023
7 points (73.3% liked)

Cybersecurity

5742 readers
36 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

I know it's an odd question, but where I live phones get stolen often. My phone doesn't have the option for an eSim, which is a problem because 90% of the time when a thief steals a phone they take out the SIM card immediately, meaning I wouldn't be able to remotely lock or wipe my phone.

Should I consider glueing the SIM tray shut? Or are there alternative less permanent measures I can take to keep my device secure?

you are viewing a single comment's thread
view the rest of the comments
[–] InEnduringGrowStrong 16 points 1 year ago (1 children)

If I was stealing phones, I'd probably ditch the SIM first too.
Wouldn't want connectivity that will follow me around.
If removing the SIM fails, they'll either:

  • panic and scrap it on the spot / throw it as far as they can
  • calmly sigh and dump it in a metal can or mesh bag for later

Either way, you're probably never seeing this phone again after it gets stolen.
As such, I'm assuming the main focus is on protecting the data on it, more than the thing itself.

First thing to do is to encrypt it.
Remote lock? Your phone should already be locked if it's not in your hand.
Disable all the features that unlock your phone when at home and other shenanigans.

Encrypted and locked means someone who gets their hands on it is much less likely to log into everything and make your life hell.
A thief probably won't bother breaking encryption.
A lettered gov agency probably maybe might, but that's a whole different topic.
Remote wipe is never guaranteed anyway.
Faraday cages are utterly simple.

A phone thief wants money.
Your saved passwords, accounts, bank app, stuff like that are prime targets.
After that they could sell the phone or its parts.

There's honestly very little advantage to gluing your SIM tray and it's gonna suck for you when you change providers or they issue you a new SIM for some reason.

Don't leave your phone unlocked.
Don't leave your phone unattended.
Encrypt it.
Lock it.
Keep it updated.

I honestly wish traditional SIMs would die already, along with SMS-based and email-based 2FA.
TOTP 2FA is fine the others are mostly smoke and mirror.

[–] [email protected] 2 points 1 year ago (1 children)

Or just... turn it off until they can swap out the sim?

[–] InEnduringGrowStrong 2 points 1 year ago

Yea that too.
Aside from phones, there are enough airtags or similar trackers around these days, I'd imagine thieves might use signal blocking bags.

Either way, gluing your SIM slot is mostly useless.