Live data from Hacker News

Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

arstechnica.com

111–120 of 225 posts

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#112
post #42

Earlier quoted context omitted.

So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?

Isn't that what the backup codes they give you when you enable it are for?

Yes, not to mention that you can enroll more than one TOTP authenticator. There are legit complaints about Google Authenticator (foremost among them that it's a nightmare when you have more than 4-5 accounts), but "no backups" isn't one of them. Don't back up TOTP secrets.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#113
post #63
post #15

Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…

In the US they have finally started rolling out chip-based cards. However, there's no PIN needed if you run the card as credit, defeating much of the security.

>defeating much of the security.

In many ways, this is better, since a skimmer can't grab my pin and credit cards have rules where they must immediately refund fraudulent purchases, while debit cards are often much more difficult to reverse.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#114
post #35

SMS is not a secure 2nd factor. It is subject to not only technical attacks such as the one in the article, but also a wide variety of social engineering attacks. Getting cell phone reps to compromise an cell phone account is apparently not hard, and has been used many times to take over online accounts.

SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…

Security token devices for online banking is quite old now and came long before the trend of 2fa using sms, and they did not cost 60$. I have owned several by now and the first one one I owned was given as part of a gratis student package by the bank.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#115
post #44

Earlier quoted context omitted.

If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.

But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…

Easier: register with an SMS-enabled VoIP provider, like Twilio or voip.ms, and use said virtual SMS number as your 2FA. Rather hard to steal.

You can then set the service up to forward received SMS messages to your regular SMS number—but, if your phone is compromised/stolen, you can go back to the account and immediately turn off this forwarding.

---

Sadly, this approach reduces the security back to single-factor, since you get into the SMS account with something you know, rather than something you have.

You can at least treat the VoIP account like a password-manager: give it a long, unforgiving "master password." (Or a random password that's stored in a password-manager, if you use one.)

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#117
post #42
post #36

Earlier quoted context omitted.

You dont even need to buy a $18 hardware token. You can use a software TOTP token (ie. google authenticator)

So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?

I use google authenticator along with a printed list of recovery codes. Half are stored in my safe and half in another location offsite.

I own a yubikey but it's useless as a permanent device since it needs a fullsize USB port - something my phone (and the latest gen macbook) lack.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#118
post #63
post #15

Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…

In the US they have finally started rolling out chip-based cards. However, there's no PIN needed if you run the card as credit, defeating much of the security.

I just moved to the States from Canada. Surprised me how far behind payment technologies are here. Swiping is at least as common as the chip readers. I have been to two places that accepted tap and it blew the employee's mind both times that I had a card capable of doing that.

I find this an especially entertaining juxtaposition with the transit systems. In Canada, you swipe on the bus and tap in the stores; in the US, swipe in store, tap on the bus.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#119
post #91
post #86

Earlier quoted context omitted.

Except it's not because they are very small, cheap devices that everyone has, generally a couple of. I have one at home, one at work, one in my bag, and everyone I know has one I could borrow if I needed one. Essentially all security is a trade off against convinience, this is, in my eyes, a no-brainer. It's barely any more effort and much, much more secure.

What? I can't think of a single person who uses this and I have lived here ten years. I once got one for a corporate account and it was atrocious with required plug-ins for ie

You must be thinking of something else. This is just a card reader that you type a number into that your bank tells you to type, and that in combination with typing your PIN in (and having your card inserted) spits out a number on a little screen, which you type back into your bank's website.

Takes about 1 minute to do, and you don't need it for every action. E.g. you use it for adding a new account payee and for making a first (or very large) payment to a payee.

Post reply on HN