Live data from Hacker News

Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

arstechnica.com

21–30 of 225 posts

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#21

Where and how do these people get access to the PSTN?

Well, the article explained that in this instance, it was via a foreign run telco.

So, essentially, to get in you just need to find the weakest telco connected to the main SS7 network and own them, and use their infra as a staging point.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#23
post #15

Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…

> It's a much better system.

Sure and much more inconvenient one, because you have to carry this device with you everywhere. Even much better system would be a living being at each ATM machine checking your credentials.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#24
post #14

When I asked (via Twitter) if my credit union would provide a secure 2FA option, they told me: > We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.

As long as that means your funds are insured and will be replaced after they're stolen via SMS phreaking, I suppose that's not the worst answer they could have given you. Though I wonder how long it would take to get the replacement funds...

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#25

Namecheap only supports SMS 2FA. The have been suggesting they will support Authenticator for years now https://blog.namecheap.com/two-factor-authentication/ Pretty unacceptable considering how important domain control is.

+1. You find horror stories even on HN in the past how reckless Namecheap is.

I personally had my domains on hold frozen without traffic being routed to my servers when my ex-gf chat with them gave my username (no password) and claimed it is her account because obviously she knew my full name and address where I live. While they didn't give her access to my account they sure froze my domain for about 5 days until everything got solved.

Not long after I moved to NameSilo.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#26
The Sueddeutsche article claims that German customers were affected too. Most German banks I know of support TAN-generators[1] which are completely unhackable by any known methods. Insert your card, scan the barcode on your screen, confirm the target IBAN and amount, and you get a unique TAN that is calculated from your transaction parameters.

[1] https://www.amazon.de/ReinerSCT-Tanjack-chipTAN-SmartTAN-Tan...

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#27
post #26

The Sueddeutsche article claims that German customers were affected too. Most German banks I know of support TAN-generators[1] which are completely unhackable by any known methods. Insert your card, scan the barcode on your screen, confirm the target IBAN and amount, and you get a unique TAN that is calculated from your transaction parameters. [1] https://www.amazon.de/ReinerSCT-Tanjack-chipTAN-SmartTAN-Tan...

Yeah, here in the US you just tell the company billing you your account number and hope they don't abuse or leak it.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#28
post #3
post #2

Isn't this the old "SMS is not 2FA, stop calling it that" argument?

Yep. Everyone has been saying SMS is not a secure channel for forever now, and this is only one of many possible attacks that can be used to trivially bypass SMS based auth. It's sad but true that in general banks have some of the weakest security on the internet, most online games do a better job protecting user accounts from unauthorized access.

True but SMS was the only available 2fa for a long time. In fact, it's still largely the only available 2fa for most things (sadly). As bad as it is, it's better than just a straight password.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#29
The headline makes it sound as if abusing SS7 was all they needed to do but in fact they had to have the other factor as well so it really is not quite as scary as it at first appears. It also seems from the article that the thieves were able to log in to the accounts with just a password and only needed the SMS to sign transactions.

It's different here in Norway; the banks require two factor authentication to log in as well as signing transactions.

I don't claim it's perfect but at least no one can log in unless they control both factors.

Post reply on HN