How does shit like this happen
Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
111–120 of 225 posts
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#112Earlier quoted context omitted.
So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?
Isn't that what the backup codes they give you when you enable it are for?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#113Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…
In the US they have finally started rolling out chip-based cards. However, there's no PIN needed if you run the card as credit, defeating much of the security.
In many ways, this is better, since a skimmer can't grab my pin and credit cards have rules where they must immediately refund fraudulent purchases, while debit cards are often much more difficult to reverse.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#114SMS is not a secure 2nd factor. It is subject to not only technical attacks such as the one in the article, but also a wide variety of social engineering attacks. Getting cell phone reps to compromise an cell phone account is apparently not hard, and has been used many times to take over online accounts.
SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#115Earlier quoted context omitted.
If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.
But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…
You can then set the service up to forward received SMS messages to your regular SMS number—but, if your phone is compromised/stolen, you can go back to the account and immediately turn off this forwarding.
---
Sadly, this approach reduces the security back to single-factor, since you get into the SMS account with something you know, rather than something you have.
You can at least treat the VoIP account like a password-manager: give it a long, unforgiving "master password." (Or a random password that's stored in a password-manager, if you use one.)
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#116Is there a good technical explanation of how SS7 works, technical docs, etc?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#117Earlier quoted context omitted.
You dont even need to buy a $18 hardware token. You can use a software TOTP token (ie. google authenticator)
So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?
I own a yubikey but it's useless as a permanent device since it needs a fullsize USB port - something my phone (and the latest gen macbook) lack.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#118Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…
In the US they have finally started rolling out chip-based cards. However, there's no PIN needed if you run the card as credit, defeating much of the security.
I find this an especially entertaining juxtaposition with the transit systems. In Canada, you swipe on the bus and tap in the stores; in the US, swipe in store, tap on the bus.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#119Earlier quoted context omitted.
Except it's not because they are very small, cheap devices that everyone has, generally a couple of. I have one at home, one at work, one in my bag, and everyone I know has one I could borrow if I needed one. Essentially all security is a trade off against convinience, this is, in my eyes, a no-brainer. It's barely any more effort and much, much more secure.
What? I can't think of a single person who uses this and I have lived here ten years. I once got one for a corporate account and it was atrocious with required plug-ins for ie
Takes about 1 minute to do, and you don't need it for every action. E.g. you use it for adding a new account payee and for making a first (or very large) payment to a payee.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#120My bank's 2FA literally comes on a piece of paper. A set of numbered codes, and the banking app/site tells me which code to use for any given transfer.