Earlier quoted context omitted.
Well, people do have 10 fingerprints, but the bigger concern is how easy it is to find them and copy them. They're not secure. You'd actually be much more secure using toe prints as auth tokens, as gross and impractical as that sounds. Most biometrics are lame because they're so readily available. However, they are ridiculously useful because of how fast and conveniently they can authenticate you. Honestly, this soun…
Fingerprints are on file in police records. Whenever you get an US visa, a passport with biometrics or stuff gets stolen from the office and the police is called to investigate, you get fingerprinted.
Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
201–210 of 225 posts
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#202The problem with SS7 is that trust is assumed. Mobile carriers that have roaming agreements will have either a direct link or via a hub. So what happened here was the network of the foreign roaming partner was used to redirect the SMS traffic on the victims carriers. Would not be surprised if it was an inside job. With ss7 you can do fun things like query the last location update/logged in base station for a mobile p…
@baybal2 you are shadowbanned. Only people with "showdead" on csn see your comments. You should probably make a new account.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#203Earlier quoted context omitted.
U2F security keys are a mutual authentication mechanism . The key authenticates the site as the site authenticates the key. Phone TOTP applications can't do that.
That still doesn't answer my question. If you read the guide that I am asking about, it advocates using security keys and also setting up phone TOTP as a backup. But I also don't need to know too badly, so I think I'll just move on.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#204Earlier quoted context omitted.
Because that would require them to have physical access to your unlocked mobile device. It's equivalent to saying "why can't a crook just steal your security key". The threat model this setup is protecting against is phishing. For that purpose, a security key is much better than TOTP (authenticator app).
You make this point frequently, but it really seems out of place here on HN where you have near 100% technically competent users who aren't going to get phished, at least not in any way that a security key is going to protect against. (Thinking of the recent Google Docs incident.) Security keys are great for journalists, activists, and high profile business people, but for your average geek it's an unnecessary amount…
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#205So SS7 is like BGP where you can just announce your number/IP block?
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#206Earlier quoted context omitted.
That still doesn't answer my question. If you read the guide that I am asking about, it advocates using security keys and also setting up phone TOTP as a backup. But I also don't need to know too badly, so I think I'll just move on.
If you don't need to know so badly, don't spew misinformation in a public thread.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#207Earlier quoted context omitted.
If you don't need to know so badly, don't spew misinformation in a public thread.
Excuse me? What misinformation did I spew? As far as I know, it's impossible to "spew misinformation" by asking questions.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#208Earlier quoted context omitted.
Excuse me? What misinformation did I spew? As far as I know, it's impossible to "spew misinformation" by asking questions.
Do you understand now why the recommendations are written they way they are? Maybe we can be done discussing now.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#209Earlier quoted context omitted.
Do you understand now why the recommendations are written they way they are? Maybe we can be done discussing now.
Yes, I am done with this thread. There is no respect here. And just for the record I have no beef with you tptacek. But idlewords stepped out of line.
If you know what you're talking about and have a serious concern about this kind of advice, by all means present your argument. But if you don't, find another way to learn.
Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol
#210Earlier quoted context omitted.
Yes, I am done with this thread. There is no respect here. And just for the record I have no beef with you tptacek. But idlewords stepped out of line.
I agree with Maciej here: the stock message board "I'm too smart to leave any advice unchallenged" attitudes on these threads are doing a lot of people who face serious risks a lot of harm. If you know what you're talking about and have a serious concern about this kind of advice, by all means present your argument. But if you don't, find another way to learn.