Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

11–20 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#11

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

It doesn't stop incompetent dataroom operators either from forcing their users to give them their phone numbers for 2fa purposes.

And there is absolute gold in those datarooms if you know where to look.

Recent offender:

"iDeals proposes to protect your account with 2 factor authentication. It means that each time when you will be accessing the project/ changing your password/ accessing the protected versions of documents in the data room - an sms code will be sent to your cell phone. "

This after me pointing out that SMS for 2fa is not a good idea.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#12

Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

Only for 2-factor schemes that rely on your phone number. Those are horribly insecure, there's a reason NIST and pretty much all security experts recommend against using them.

SMS authentication was created as a cheap hack to get around needing SecurID tokens, and should have been abandoned when ToTP (Google Authenticator and the like) became possible.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#13
I owned a hosted PBX company from 2007-2011 and was amazed with how antiquated the port request system truly is.

The problem is that the phone company owns your phone number and you just get access as part of a service. Unlike a domain name where you own it.

If we change the law we'd bring more accountability.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#14
post #5

This has been the vector for Twitter hacks for many years. Get the 2nd factor

SMS is the 2nd factor. Actually it's worse than just a 2nd factor because a compromised phone number can usually be used for password recovery

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#15

Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

SMS/phone number are a security nightmare as 2nd factor. Using a key via an authenticator app as the 2nd factor is really good.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#16
post #2

"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.

The problem is that you can socially engineer the Telecom service desk. It's not that hard. I did it when I pretended to be my dad (at his request) to switch his phone plan.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#17
post #2

"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#18
post #2

"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.

Did you read the article? The victim who've had their phone number stolen weren't the ones that fell prey to social engineering - it's the customer service people at the phone provider who are persuaded to do a port of the phone number. Unless you operate your own phone carrier, it would be hard to avoid this attack.

It would be about as hard as it is to prevent DNS zone hijacking. That is, not very hard.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#19

Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

Only for 2-factor schemes that rely on your phone number. Those are horribly insecure, there's a reason NIST and pretty much all security experts recommend against using them. SMS authentication was created as a cheap hack to get around needing SecurID tokens, and should have been abandoned when ToTP (Google Authenticator and the like) became possible.

I agree with you completely that those are totally insecure. However, 2nd factor as a dictionary vernacular term has become synonymous in the press with a telephone number and some sort of texting scheme. Before this there was little incentive to hijack phone numbers. No longer is that the case.

Having a phone number is not secure in any way, proves nothing, and offloading security onto a totally insecure system such as the possession of phone numbers was a massive cop out and completely irresponsible.

Maybe as you say there are 2nd factor schemes that don't use phone numbers but it hardly matters since the term 2nd factor has unfortunately come to mean phone numbers in the vernacular.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#20

I owned a hosted PBX company from 2007-2011 and was amazed with how antiquated the port request system truly is. The problem is that the phone company owns your phone number and you just get access as part of a service. Unlike a domain name where you own it. If we change the law we'd bring more accountability.

To be fair, you really don't own a domain. You still rely on the TLD honoring your purchase and not hand it over to someone else in the same way you rely on the phone company to treat your number as yours.
Post reply on HN