Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

1–10 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#2
"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me.

If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess.

Maybe this is just a Forbes scare tactic.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#3
post #2

"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.

Would you please stop posting unsubstantive comments and rants to HN? We're trying for higher quality here.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#4
post #2

"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.

Did you read the article? The victim who've had their phone number stolen weren't the ones that fell prey to social engineering - it's the customer service people at the phone provider who are persuaded to do a port of the phone number.

Unless you operate your own phone carrier, it would be hard to avoid this attack.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#6
post #2

"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.

If a bad actor gets your data in a breach, the article posits that only person that has to fall victim to any level of social engineering is the customer service rep of your cell provider or some other service you use.

So while you might be above nigerian prices, free cruises, and the like - do you have the same faith in the as-cheap-as-possible customer service rep from your provider?

That's what the article is getting at.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#7
NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa.

[0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#8
Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#10

Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

The biggest issue today is password reuse, and 2FA does help mitigate the liabilities of that. Is it perfect? No. Does it introduce more attack surface? Yes. But for the average user, it almost certainly increases their opsec.
Post reply on HN