Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

71–80 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#71
post #28

Earlier quoted context omitted.

The comment in question was in poor taste by mocking victims of hacks for being stupid, and the premise of it was wrong anyway (not understanding that it's the telco customer service at fault more than the people who got hacked). That's about as unsubstantive/low quality as comments go, and really doesn't qualify as "polite rational debate and discussion". It makes sense for a mod to step in and say something.

I must disagree with this. Monsieur Lerie clearly and specifically objects to the use of the term "social engineering". This does in fact deal with situations where naïve persons can be fooled by con artists. This is a problem in the field. A problem we are all aware of. Denying that it is a problem is counterproductive. Denial does not address the core issues, of exploits that utilize and depend upon the naïvity of…

The part you are missing is that the mark is not the one being socially engineered. The attacker is getting a completely random telco to hijack the mark's phone number by socially engineering the telco. There is nothing 'the mark' can do to prevent this.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#72
post #62

This happened to me. 1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.* 3. Hacker gained access to email (as th…

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

The is a direct correlation between security and fraud related interest/insurance in regards to the cost of use and exposure to fraud.

They aren't out to "destroy" your security, it's a liability threshold calculation. At the end of the day secure yourself in life, this include choosing banks that are more stringent based on your needs and what you want to pay.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#73
post #26

Earlier quoted context omitted.

There’s a far worse example: PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices. Support for TOTP? HOTP? Nope.

Those proprietary 2FA devices are just TOTP with a weird provisioning system. You can use a tool such as https://github.com/dlenski/python-vipaccess to use google authenticator/freeotp etc. to access paypal. That said... I believe you still need a mobile number enrolled to enable a token.

Wow, that actually works. I had to go through many ancient web interfaces, but it works.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#74
post #72
post #62

Earlier quoted context omitted.

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

The is a direct correlation between security and fraud related interest/insurance in regards to the cost of use and exposure to fraud. They aren't out to "destroy" your security, it's a liability threshold calculation. At the end of the day secure yourself in life, this include choosing banks that are more stringent based on your needs and what you want to pay.

Which banks should you choose? How do you decide?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#75
I read a blog where someone got hacked through a simcard clone, and they went into the details of how easy it was to do. This prompted me to enable 2fa on everything I could, but the funny thing is, a lot of the backup options for 2fa is -- you guessed it -- your cell phone number. Some of them don't even allow you not to use your cell phone as a backup. I think Github and Slack are like this, but I may be wrong, it has been a while since I turned them on.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#76

Earlier quoted context omitted.

Something that is infuriating is that when you have 2FA enabled on Google, they insist that you add a backup phone number that a bot calls to give you a verification code, in case, you know, you lost your second factor. Which is nice and all, but now, you're back to having a second factor that is about as vulnerable as SMS.

You can remove the phone after you add another factor (ex: TOTP device).

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#77
I'm SHOCKED this wasn't a thing earlier. Spoofing a phone number is insanely easy. When I was in High School we figured out how to do it and used to prank call people from other peoples numbers. Eventually, we realized that if you call someone's cell from their own number it takes you directly into the voicemail admin menu. Fun times.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#78
post #69

I wish we could kill phone numbers once and for all. It's insecure, device-dependent, carrier-dependent, country-dependent, subject to snooping and censorship, and all of these are recipes for disaster as an authentication scheme, especially in the event that a device gets stolen. Phone calls and text messages should emphatically NEVER be used to verify anything. Conversation with one of my banks the other day: Them:…

Is it really necessary or helpful to be rude to the poor CSR who is just trying to do their job?

They didn't make this policy, and I'm sure they think its just as stupid as you do.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#79
post #72
post #62

Earlier quoted context omitted.

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

The is a direct correlation between security and fraud related interest/insurance in regards to the cost of use and exposure to fraud. They aren't out to "destroy" your security, it's a liability threshold calculation. At the end of the day secure yourself in life, this include choosing banks that are more stringent based on your needs and what you want to pay.

The real answer is to not use SMS as a 2FA. That was never ever a good idea.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#80
post #78
post #69

I wish we could kill phone numbers once and for all. It's insecure, device-dependent, carrier-dependent, country-dependent, subject to snooping and censorship, and all of these are recipes for disaster as an authentication scheme, especially in the event that a device gets stolen. Phone calls and text messages should emphatically NEVER be used to verify anything. Conversation with one of my banks the other day: Them:…

Is it really necessary or helpful to be rude to the poor CSR who is just trying to do their job? They didn't make this policy, and I'm sure they think its just as stupid as you do.

This isn't a literal transcript of the conversation, more like what was going on in my head vs. what they said ;) Of course I was nice to them in explaining that I have a ton of virtual phone numbers and really don't know which one I used, etc.
Post reply on HN