Even given that, since it relies upon human choice and behavior, and does nothing versus attackers with assets within the phone company, it seems a bad idea to have 2FA via SMS.
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
21–30 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#22I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F.
As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient, isn't vulnerable against the kind of attack SMS-based 2FA is, and protects against phishing. But almost nobody outside Google supports it, and OS/Application support is rather incomplete or requires additional setup.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#23"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.
Did you read the article? The victim who've had their phone number stolen weren't the ones that fell prey to social engineering - it's the customer service people at the phone provider who are persuaded to do a port of the phone number. Unless you operate your own phone carrier, it would be hard to avoid this attack.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#24"Social engineering", a term reserved for those who willingly buy into the Nigerian scams. Now these same people are somehow losing their phone numbers, it's laughable to me. If you "lose" your phone number to "social engineering", you don't deserve a cell phone, please purchase a wall mounted, cord entangling mess. Maybe this is just a Forbes scare tactic.
Would you please stop posting unsubstantive comments and rants to HN? We're trying for higher quality here.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#25What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#26NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html
It doesn't stop incompetent dataroom operators either from forcing their users to give them their phone numbers for 2fa purposes. And there is absolute gold in those datarooms if you know where to look. Recent offender: "iDeals proposes to protect your account with 2 factor authentication. It means that each time when you will be accessing the project/ changing your password/ accessing the protected versions of docum…
PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices.
Support for TOTP? HOTP? Nope.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#27Yes, it's a problem that security questions turn hacking into a simple public records search.
BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later.
Why isn't the answer 'consumers have the power -- punish services that don't support FIDO by not using them'.
At best this article is saying 'don't connect anything to anything'.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#28Earlier quoted context omitted.
Would you please stop posting unsubstantive comments and rants to HN? We're trying for higher quality here.
I don't agree with his post. However it was clearly a reasonable position and not "unsubstantive comments and rants" as you are claiming. That is not a reasonable claim at all. Your post is unwarranted and is highly abusive. Just stop. Bullying valid minority viewpoints is not cool and does not contribute to the quality of polite rational debate and discussion.
That's about as unsubstantive/low quality as comments go, and really doesn't qualify as "polite rational debate and discussion". It makes sense for a mod to step in and say something.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#29What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#30I owned a hosted PBX company from 2007-2011 and was amazed with how antiquated the port request system truly is. The problem is that the phone company owns your phone number and you just get access as part of a service. Unlike a domain name where you own it. If we change the law we'd bring more accountability.
To be fair, you really don't own a domain. You still rely on the TLD honoring your purchase and not hand it over to someone else in the same way you rely on the phone company to treat your number as yours.