Live data from Hacker News

Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

arstechnica.com

91–100 of 225 posts

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#91
post #86

Earlier quoted context omitted.

> It's a much better system. Sure and much more inconvenient one, because you have to carry this device with you everywhere. Even much better system would be a living being at each ATM machine checking your credentials.

Except it's not because they are very small, cheap devices that everyone has, generally a couple of. I have one at home, one at work, one in my bag, and everyone I know has one I could borrow if I needed one. Essentially all security is a trade off against convinience, this is, in my eyes, a no-brainer. It's barely any more effort and much, much more secure.

What? I can't think of a single person who uses this and I have lived here ten years. I once got one for a corporate account and it was atrocious with required plug-ins for ie

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#92
post #80
post #43

Earlier quoted context omitted.

Hopefully we'll get to a world where people keep a U2F key on their keychain, and use it for all their important logins.

We have a long way to go. People need to understand: * How U2F works on their phone * What if the U2F key gets lost or stolen (revocation) * How to have a backup of the U2F key * Are multiple identities possible (home/work/whatever)

I think a lot of this is close enough to the way mechanical keys work that it's not a huge leap. You can have more than one house key, you change the lock if a key gets stolen, etc. It's a little different, but not really more complicated.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#93
post #35

SMS is not a secure 2nd factor. It is subject to not only technical attacks such as the one in the article, but also a wide variety of social engineering attacks. Getting cell phone reps to compromise an cell phone account is apparently not hard, and has been used many times to take over online accounts.

SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…

You can get a pre printed card for cheap for 2fa. No need for RSA token

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#94
post #44

Earlier quoted context omitted.

If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.

But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…

This doesn't help if the bank shows your linked phone number when logged in.

You could also buy a dual SIM phone and buy a throwaway sim card with a phone number you do not share.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#95

Namecheap only supports SMS 2FA. The have been suggesting they will support Authenticator for years now https://blog.namecheap.com/two-factor-authentication/ Pretty unacceptable considering how important domain control is.

+1. You find horror stories even on HN in the past how reckless Namecheap is. I personally had my domains on hold frozen without traffic being routed to my servers when my ex-gf chat with them gave my username (no password) and claimed it is her account because obviously she knew my full name and address where I live. While they didn't give her access to my account they sure froze my domain for about 5 days until eve…

Holy crap! I'll keep that in mind next time my registrations are up. This combined with their unwillingness to make proper 2FA a priority (a tweet told me they were 'setting up the infrastructure' 3 months ago) is a strong signal to look elsewhere.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#96
post #42
post #36

Earlier quoted context omitted.

You dont even need to buy a $18 hardware token. You can use a software TOTP token (ie. google authenticator)

So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?

You can authenticate more than one device. At least with Google accounts in the past. Meanwhile I use Titanium backup to backup authenticator and restore it on a different device.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#97
post #90
post #44

Earlier quoted context omitted.

If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.

Note that one time codes do not protect against phishing the same way U2F does (U2F is always bound to secure origin).

U2F is great but everything is better than SMS.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#98
post #15

Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…

Chip Authentication Programme (CAP) vulnerabilities

https://www.cl.cam.ac.uk/research/security/banking/emvcap/

http://sec.cs.ucl.ac.uk/users/smurdoch/papers/fc09optimised....

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#99
post #35

Earlier quoted context omitted.

SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…

The big problem that SMS solves that nothing else does is that you can be completely irresponsible/unlucky and it still works. You can lose your u2f key , lose any one time backup codes on paper, and so long as you can convince your phone company that you are you you're fine. I don't think most people are responsible enough to deal with more secure MFA. Most people don't know how to keep custody of stuff like that.

> so long as you can convince your phone company that you are you you're fine.

Well I think the problem starts when someone else convinces your phone company that they are you. As we've seen several times now it becomes easier and easier to pull this trick.

As for U2F add more than one to your account (2 is minimum) and you are safe. The same applies to any kind of physical key (home, car, etc.)

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#100
post #14

When I asked (via Twitter) if my credit union would provide a secure 2FA option, they told me: > We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.

As long as that means your funds are insured and will be replaced after they're stolen via SMS phreaking, I suppose that's not the worst answer they could have given you. Though I wonder how long it would take to get the replacement funds...

In addition to someone taking my money it is a privacy issue.
Post reply on HN