Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

51–60 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#51

This recently happened to a friend of mine. It was devastating. As mentioned, U2F is very scarcely supported today. The best way he came up with to secure services that insist on using SMS for 2FA (or credential reset) was to register the number of a pre-paid phone for those services. Inconvenient? YES. But a pre-paid phone number can not be ported by a negligent (or willfully criminal!) operator.

It's still very trivial to tell a customer rep that you lost your SIM card and have the rep send all new communication to the phone number to a separate SIM card with a pre paid phone.

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#52

Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…

I answer mandatory security questions with things like these:

  “This account must never be unlocked over phone, chat, or email.”

  “Never reveal any information about this account (such as address or CC numbers) via support channels”

  “The person you are discussing with is a hacker trying to illegally access this account”
I expect to never, ever have to use the security questions myself.

Sometimes, I enter random phrases.

Never anything that would actually be true.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#53

Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…

I never use real answers. I've had a bank teller ask "your mother had a number I get maiden name?" "Wait, you actually use real answers instead of passwords for security questions?"

I don't use real answers either because I'm paranoid about this stuff, but it always causes trouble when I have to interact with an institution.

Examples:

- I lost my health insurance for 6 months because I couldn't dig up my 'secret answer' in time to activate COBRA.

- My credit card expired while I was traveling and I couldn't reactivate it because I didn't know what answer I had given to 'mother's maiden name'. (In the end I convinced them I didn't need a secret answer to verify my identity, which in its own way is even worse).

- Some company had a form that stripped numbers from the secret answer and mine had numbers in it (hilarity ensues).

Instead of working around institutional nonsense, we should fire bad companies and hire / start good ones.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#54

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

U2F is ludicrously hard to implement. Adding TOTP 2FA to an existing webapp will take a competent developer a few hours, using only a 10-line code snippet and the standard library. Adding U2F means learning a ton of complicated concepts and either using a giant, poorly documented library provided by Yubico or writing a bunch of tricky crypto code from scratch. :(

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#55

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

so why do well-respected companies like Google and Stripe do it?

Because their target markets contain both people who'll gladly spend 50 quid on the latest account security dongle, as well as people who have a Pentium 4 desktop and a 50 quid feature phone. The latter get much more secure when apart from a password, probably on a post it stuck next to the screen, they are inconvenienced to also type in a few digits from SMS.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#56
This happened to me.

1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.* 3. Hacker gained access to email (as that email was also within the telco's site). At the beginning, the hacker did not reset the password. After I changed the email's password, hacker was still gaining access to our emails and he/she eventually reset the email blocking my access. (reason was all the text and calls was forwarding to his/her burn phone so he/she can reset the pass anytime) 5. Requested 2FA from bank. 6. Gained access to bank account.

This was over a course of 3 months. It was a nightmare to resolve and paranoia still remained. The hacker later on went opening several bank accounts. Fortunately, this was discovered early. The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared.

*I saw two numbers that were being used within my wireless account site to forward the calls.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#57

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

I don't have a phone number in any of my Google accounts, just Google Authenticator for 2-step verification.

I don't recall ever having a problem with this setup. Are there services that require a Google account to sign in, but don't work if you don't have a phone number?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#58
post #26

Earlier quoted context omitted.

There’s a far worse example: PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices. Support for TOTP? HOTP? Nope.

Paypal also couldn't walk you through a 2FA payment for eBay on mobile. At all. You had to use a desktop. This was about a year or two ago. One would think that a payment company would have better security, especially given they're owned by eBay.

They aren't owned by eBay anymore. They were spun off into an independent company in 2015.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#59

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

Something that is infuriating is that when you have 2FA enabled on Google, they insist that you add a backup phone number that a bot calls to give you a verification code, in case, you know, you lost your second factor. Which is nice and all, but now, you're back to having a second factor that is about as vulnerable as SMS.

You can remove the phone after you add another factor (ex: TOTP device).

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#60

Earlier quoted context omitted.

I never use real answers. I've had a bank teller ask "your mother had a number I get maiden name?" "Wait, you actually use real answers instead of passwords for security questions?"

I don't use real answers either because I'm paranoid about this stuff, but it always causes trouble when I have to interact with an institution. Examples: - I lost my health insurance for 6 months because I couldn't dig up my 'secret answer' in time to activate COBRA. - My credit card expired while I was traveling and I couldn't reactivate it because I didn't know what answer I had given to 'mother's maiden name'. (I…

I always, always store my bogus answers in 1Password. One of many reasons I love the tool.

Most security questions are either trivial for someone else to figure out with a little research or I don't know what my real answer would be. Name of my first pet? Well, I had several that could meet that definition, and I definitely don't remember the name of the first one.

Post reply on HN