Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

31–40 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#31

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

so why do well-respected companies like Google and Stripe do it?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#32

Earlier quoted context omitted.

Only for 2-factor schemes that rely on your phone number. Those are horribly insecure, there's a reason NIST and pretty much all security experts recommend against using them. SMS authentication was created as a cheap hack to get around needing SecurID tokens, and should have been abandoned when ToTP (Google Authenticator and the like) became possible.

I agree with you completely that those are totally insecure. However, 2nd factor as a dictionary vernacular term has become synonymous in the press with a telephone number and some sort of texting scheme. Before this there was little incentive to hijack phone numbers. No longer is that the case. Having a phone number is not secure in any way, proves nothing, and offloading security onto a totally insecure system such…

> 2nd factor as a dictionary vernacular term has become synonymous in the press with a telephone number and some sort of texting scheme

I don't think that's true. Both my bank issues hardware tokens for challenge response type authentications, these are widely in use and understood to be 2fa, the same goes for many other services.

It's a typical case of all cows are animals but not all animals are cows, I've yet to see the press categorically making that kind of mistake for 2fa, though I'm sure there will be some offenders on the whole people - and the press - seem to know the difference. And it's up to us to correct these things where and when we see them so if you do spot an article that incorrectly labels SMS as the one true 2fa then you should mail the author or the editor to get them to correct the record pointing out that they are perpetrating a fallacy that could cause their readers to be at risk.

This is not as far as I can see a lost battle - yet.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#33
post #28

Earlier quoted context omitted.

I don't agree with his post. However it was clearly a reasonable position and not "unsubstantive comments and rants" as you are claiming. That is not a reasonable claim at all. Your post is unwarranted and is highly abusive. Just stop. Bullying valid minority viewpoints is not cool and does not contribute to the quality of polite rational debate and discussion.

The comment in question was in poor taste by mocking victims of hacks for being stupid, and the premise of it was wrong anyway (not understanding that it's the telco customer service at fault more than the people who got hacked). That's about as unsubstantive/low quality as comments go, and really doesn't qualify as "polite rational debate and discussion". It makes sense for a mod to step in and say something.

I must disagree with this. Monsieur Lerie clearly and specifically objects to the use of the term "social engineering". This does in fact deal with situations where naïve persons can be fooled by con artists. This is a problem in the field. A problem we are all aware of.

Denying that it is a problem is counterproductive. Denial does not address the core issues, of exploits that utilize and depend upon the naïvity of the mark.

I do not agree with him that a solution is to prevent the technologically naïve from having access to phones. Nonetheless, this is still an issue that must be addressed. Security schemes intended to protect the general market of customers must not rely upon the customer's sophistication in defense against social engineering scams. Many customers, quite reasonably, are technically naïve in some aspect or another. In is completely improper as a security protocol for mass market products to rely upon customers having enlightened opsec.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#34

I owned a hosted PBX company from 2007-2011 and was amazed with how antiquated the port request system truly is. The problem is that the phone company owns your phone number and you just get access as part of a service. Unlike a domain name where you own it. If we change the law we'd bring more accountability.

"was amazed with how antiquated the port request system truly is"

Absolutely. In the UK, I could easily port someone or many someone's landline number and slap a trunk on it. Sadly though I would also end up paying the bill for it. However its much easier to simply fake your outbound CLID to show the call centre you are the mark.

I have no numbers for this but I'll bet that CLID is used by banks etc as part of the security checks for your identity.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#35
post #3

Earlier quoted context omitted.

Would you please stop posting unsubstantive comments and rants to HN? We're trying for higher quality here.

I don't agree with his post. However it was clearly a reasonable position and not "unsubstantive comments and rants" as you are claiming. That is not a reasonable claim at all. Your post is unwarranted and is highly abusive. Just stop. Bullying valid minority viewpoints is not cool and does not contribute to the quality of polite rational debate and discussion.

No, you totally, utterly fail to understand the interaction here and it is you that should stop. If you want to second guess the moderation here you're on very thin ice, this is a pretty clear cut case of someone purposefully ignoring the meat of an article to stir the pot.

Note that the victims here are not party to the exchange, contrary to what is claimed in that comment, it is the call center employees of the phone company that are being social engineered into making an unauthorized change to a subscribers record.

If you want to limit the use of the words 'social engineering' to the cases where the victims are the ones being social engineered you're ignoring about 3 decades worth of use of the term to apply to any situation where through clever exchanges an elevated level of access was achieved to some resource or other, and those exchanges do not have to be directly with the victim.

Typical example: call the secretary from the 'IT department' to gain access to the system of the boss.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#36

Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

Only for 2-factor schemes that rely on your phone number. Those are horribly insecure, there's a reason NIST and pretty much all security experts recommend against using them. SMS authentication was created as a cheap hack to get around needing SecurID tokens, and should have been abandoned when ToTP (Google Authenticator and the like) became possible.

SecurID tokens do ToTP just fine.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#38
post #26

Earlier quoted context omitted.

It doesn't stop incompetent dataroom operators either from forcing their users to give them their phone numbers for 2fa purposes. And there is absolute gold in those datarooms if you know where to look. Recent offender: "iDeals proposes to protect your account with 2 factor authentication. It means that each time when you will be accessing the project/ changing your password/ accessing the protected versions of docum…

There’s a far worse example: PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices. Support for TOTP? HOTP? Nope.

I think that your average dataroom holds stuff with value well in excess of what the average paypal account holds.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#39
post #26

Earlier quoted context omitted.

It doesn't stop incompetent dataroom operators either from forcing their users to give them their phone numbers for 2fa purposes. And there is absolute gold in those datarooms if you know where to look. Recent offender: "iDeals proposes to protect your account with 2 factor authentication. It means that each time when you will be accessing the project/ changing your password/ accessing the protected versions of docum…

There’s a far worse example: PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices. Support for TOTP? HOTP? Nope.

Paypal also couldn't walk you through a 2FA payment for eBay on mobile. At all. You had to use a desktop. This was about a year or two ago. One would think that a payment company would have better security, especially given they're owned by eBay.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#40

Earlier quoted context omitted.

Did you read the article? The victim who've had their phone number stolen weren't the ones that fell prey to social engineering - it's the customer service people at the phone provider who are persuaded to do a port of the phone number. Unless you operate your own phone carrier, it would be hard to avoid this attack.

It would be about as hard as it is to prevent DNS zone hijacking. That is, not very hard.

How, exactly, would you prevent someone in a call center on the other side of the world from being convinced to port your number away?

Outgoing port "blocks" are nothing more than a note in your file - what's to say that the attacker couldn't just make up a story? "I know I called a while back and asked you to prevent porting, but I really want to switch to X carrier to get their exclusive new handset. Can you remove the block request, my mothers maiden name is..."

Pretending like you could prevent this sort of attack is laughable, which is why it's so dangerous.

Post reply on HN