Earlier quoted context omitted.
> It's a much better system. Sure and much more inconvenient one, because you have to carry this device with you everywhere. Even much better system would be a living being at each ATM machine checking your credentials.
Except it's not because they are very small, cheap devices that everyone has, generally a couple of. I have one at home, one at work, one in my bag, and everyone I know has one I could borrow if I needed one. Essentially all security is a trade off against convinience, this is, in my eyes, a no-brainer. It's barely any more effort and much, much more secure.
Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
91–100 of 225 posts
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#92Earlier quoted context omitted.
Hopefully we'll get to a world where people keep a U2F key on their keychain, and use it for all their important logins.
We have a long way to go. People need to understand: * How U2F works on their phone * What if the U2F key gets lost or stolen (revocation) * How to have a backup of the U2F key * Are multiple identities possible (home/work/whatever)
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#93SMS is not a secure 2nd factor. It is subject to not only technical attacks such as the one in the article, but also a wide variety of social engineering attacks. Getting cell phone reps to compromise an cell phone account is apparently not hard, and has been used many times to take over online accounts.
SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#94Earlier quoted context omitted.
If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.
But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…
You could also buy a dual SIM phone and buy a throwaway sim card with a phone number you do not share.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#95Namecheap only supports SMS 2FA. The have been suggesting they will support Authenticator for years now https://blog.namecheap.com/two-factor-authentication/ Pretty unacceptable considering how important domain control is.
+1. You find horror stories even on HN in the past how reckless Namecheap is. I personally had my domains on hold frozen without traffic being routed to my servers when my ex-gf chat with them gave my username (no password) and claimed it is her account because obviously she knew my full name and address where I live. While they didn't give her access to my account they sure froze my domain for about 5 days until eve…
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#96Earlier quoted context omitted.
You dont even need to buy a $18 hardware token. You can use a software TOTP token (ie. google authenticator)
So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#97Earlier quoted context omitted.
If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.
Note that one time codes do not protect against phishing the same way U2F does (U2F is always bound to secure origin).
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#98Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…
https://www.cl.cam.ac.uk/research/security/banking/emvcap/
http://sec.cs.ucl.ac.uk/users/smurdoch/papers/fc09optimised....
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#99Earlier quoted context omitted.
SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…
The big problem that SMS solves that nothing else does is that you can be completely irresponsible/unlucky and it still works. You can lose your u2f key , lose any one time backup codes on paper, and so long as you can convince your phone company that you are you you're fine. I don't think most people are responsible enough to deal with more secure MFA. Most people don't know how to keep custody of stuff like that.
Well I think the problem starts when someone else convinces your phone company that they are you. As we've seen several times now it becomes easier and easier to pull this trick.
As for U2F add more than one to your account (2 is minimum) and you are safe. The same applies to any kind of physical key (home, car, etc.)
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#100When I asked (via Twitter) if my credit union would provide a secure 2FA option, they told me: > We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.
As long as that means your funds are insured and will be replaced after they're stolen via SMS phreaking, I suppose that's not the worst answer they could have given you. Though I wonder how long it would take to get the replacement funds...