Live data from Hacker News

Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

arstechnica.com

131–140 of 225 posts

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#131
Another feather in the cap for a dedicated 2FA solution such as Google Authenticator etc. that doesn't use SMS?

Though having replaced two phones since using that solution - it can be a pain to have to re-set it up with each provider every time. I can see that if someone is prone to losing their phone, it will become a major issue.

I think the problem is that all the companies whom I use 2FA for have totally different methodologies for re-setting it up on a new device. Whilst some have an automated way of verifying my identity and resetting the new device almost instantly, I have had a couple that needed talking to a human support rep (inconvenient, but understandable) and one company that needed another employee in the company to do a full 2FA verification themselves, and then talk to a company support rep on my behalf to verify my request to reset my 2FA settings! (WTF).

Thus, each time I replace my phone, I find myself actually culling the number of services where I use 2FA purely because it was too much of a pain to go through the reset process, and it was actually easier to drop 2FA with them altogether (or in one case actually drop the service altogether).

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#133

Earlier quoted context omitted.

There are plenty of second-factor mobile apps as well: Duo, Authy, Google Authenticator, and Symantec VIP access, just to name a few.

And now I'm trapped in this multi-app universe where every entity uses a different app. My employer uses Symantec, my school uses Duo, my bank has its own app (as does Steam), and a handful of sites use TOTP. Argh.

At least TOTP (and U2F) are standards. All sites and organizations should be using them, not something they've created themselves.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#134
post #15

Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…

I have always been curious, do those devices work on linux?

I don't know about that particular implementation, but I can use my citizen card (also a smartcard) to login to government sites on Linux. The site uses a Java applet, which connects to libpcsclite to use the reader.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#135
post #35

SMS is not a secure 2nd factor. It is subject to not only technical attacks such as the one in the article, but also a wide variety of social engineering attacks. Getting cell phone reps to compromise an cell phone account is apparently not hard, and has been used many times to take over online accounts.

SMS as a 2nd factor represents an engineering trade-off. Prior to its introduction, the only people who had access to 2FA were people who got $60 tokens from RSA. It blocks against certain classes of attacks, but is vulnerable to others (like malicious or insecure carriers). Now, Apple users can use their fingerprint as a 2nd factor (e.g. for Apple Pay), but fingerprints have the unfortunate property of not being rot…

Well, people do have 10 fingerprints, but the bigger concern is how easy it is to find them and copy them. They're not secure. You'd actually be much more secure using toe prints as auth tokens, as gross and impractical as that sounds. Most biometrics are lame because they're so readily available. However, they are ridiculously useful because of how fast and conveniently they can authenticate you.

Honestly, this sounds like a much better technology: http://www.dailymail.co.uk/sciencetech/article-3220886/Forge... It transmits data through the human body. You could turn it on or off selectively, authenticate with anything you touch, and it would remain cryptographically secure.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#136

SMS is not a secure 2nd factor. It is subject to not only technical attacks such as the one in the article, but also a wide variety of social engineering attacks. Getting cell phone reps to compromise an cell phone account is apparently not hard, and has been used many times to take over online accounts.

Not just the phone company. Naive (ie old) people have been robbed by receiving a text saying "This is the bank, what's your password?" "Thanks. Now, what's the code we just sent you?"

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#137

Another feather in the cap for a dedicated 2FA solution such as Google Authenticator etc. that doesn't use SMS? Though having replaced two phones since using that solution - it can be a pain to have to re-set it up with each provider every time. I can see that if someone is prone to losing their phone, it will become a major issue. I think the problem is that all the companies whom I use 2FA for have totally differen…

There are some more friendly options than Google Authenticator if it's a hassle to keep setting up over and over.

I keep my 2FA in 1Password, and it works pretty well. I can access the codes from the desktop app without getting out my phone, or from my phone or tablet if I'm mobile.

The only scary issue is that all that information is encrypted in Dropbox. And I use 2FA on Dropbox! Hello cyclic dependencies! As a result, Dropbox is the only 2FA that I don't store in 1Password.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#138
Phreaking in 2017, interesting. The golden age of phreaking ended with SS7. SS5 was very insecure, people could just emit tones in certain frequencies and pull off tricks like calling for free. Maybe this is the beginning of a new era.

I think major websites should stop using SMS and ask for just an authenticator app or secure keys. SMS should be regarded as a bad security practice.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#139

Earlier quoted context omitted.

But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…

Typically, you are asked to print out backup codes when you enable 2FA. In addition, you could copy these backups codes into your password manager and sync your password file with multiple devices, so whenever one device is gone you can access all your passwords, including 2FA backup codes from other devices.

If these backup codes are in your password manager, you're effectively* back to 1FA. Same with putting the TOTP seed into it.

* Yes, technically you need the 1Password file as well. But someone who compromises your machine will get access to both. Or if you have it synced to your phone and both are unlocked with a fingerprint, all someone needs is your device and a little effort to fool the fingerprint sensor.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#140
post #44

Earlier quoted context omitted.

If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.

But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…

Not that I recommend SMS, but if thieves steal my phone I turn off its Google voice connection and it stops getting text that particular phone #, which I can still get just fine in Google Voice. More to the point I do tend to feel like N-factor auth is often a sort of Matryoshka doll thing on one end or another more than anything.
Post reply on HN