Live data from Hacker News

Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

arstechnica.com

11–20 of 225 posts

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#15
Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money.

It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's still pretty good. The readers are also cheap and standardised, so you can use any one of them for any account, which is useful.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#18
post #3
post #2

Isn't this the old "SMS is not 2FA, stop calling it that" argument?

Yep. Everyone has been saying SMS is not a secure channel for forever now, and this is only one of many possible attacks that can be used to trivially bypass SMS based auth. It's sad but true that in general banks have some of the weakest security on the internet, most online games do a better job protecting user accounts from unauthorized access.

It's sad but I have to agree. My local bank suddenly changed their Mastercard Securecode online verification scheme from a password to either SMS 2FA (for which they charge 9 cents per SMS and don't even support all numbers) or some really shitty mobile app which has a rating of 1.7 on the play store with tons and tons of people complaining that it just doesn't work and now renders their CC totally useless. I'm sure they are losing customers left and right. Mobile phones (especially Android) are incredibly insecure. Why not use these little token generators like in the past?

Another bank of mine can't issue proper bank reference letters anymore which are required in many cases to open other accounts or form a company. The same bank also stopped the Visa support of their debit cards so they are practically useless apart from using at the ATM.

Another bank with a business account can't issue credit cards anymore. For many transfers they require tons of verification and paperwork, opening a new account gets harder and harder. I have to fill out a stupid W-8ben form even though I have nothing to do with the US. It goes on and on.

It seems in the past 5 or so years banks in general have gone into a slow but steady self-destruct mode - especially with all that speculation in the debt casino. Banking is becoming a more and more frustrating experience even though it's so core to our society.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#19
post #10

This is really scary... can banks please start using something like Google Authenticator? I was assuming that 2FA over SMS was the most secure thing ever...apparently that's not the case.

Nah, it's not the case [0] and hasn't really ever been. It's only now, due to its ubiquity with banking and other high-value sites that the incentives are there to abuse it.

As an aside, as someone who spends time between multiple different countries, SMS 2fa is a real pain to deal with.

0: https://www.wired.com/2016/06/hey-stop-using-texts-two-facto...

Post reply on HN