Is there a good technical explanation of how SS7 works, technical docs, etc?
Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
11–20 of 225 posts
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#12Who would have guessed?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#13Phreaking, the cutting edge way to commit computer fraud in 2017. Who would have guessed?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#14> We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#15It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's still pretty good. The readers are also cheap and standardised, so you can use any one of them for any account, which is useful.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#16Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#17Pretty unacceptable considering how important domain control is.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#18Isn't this the old "SMS is not 2FA, stop calling it that" argument?
Yep. Everyone has been saying SMS is not a secure channel for forever now, and this is only one of many possible attacks that can be used to trivially bypass SMS based auth. It's sad but true that in general banks have some of the weakest security on the internet, most online games do a better job protecting user accounts from unauthorized access.
Another bank of mine can't issue proper bank reference letters anymore which are required in many cases to open other accounts or form a company. The same bank also stopped the Visa support of their debit cards so they are practically useless apart from using at the ATM.
Another bank with a business account can't issue credit cards anymore. For many transfers they require tons of verification and paperwork, opening a new account gets harder and harder. I have to fill out a stupid W-8ben form even though I have nothing to do with the US. It goes on and on.
It seems in the past 5 or so years banks in general have gone into a slow but steady self-destruct mode - especially with all that speculation in the debt casino. Banking is becoming a more and more frustrating experience even though it's so core to our society.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#19This is really scary... can banks please start using something like Google Authenticator? I was assuming that 2FA over SMS was the most secure thing ever...apparently that's not the case.
As an aside, as someone who spends time between multiple different countries, SMS 2fa is a real pain to deal with.
0: https://www.wired.com/2016/06/hey-stop-using-texts-two-facto...
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#20Is there a good technical explanation of how SS7 works, technical docs, etc?