So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
91–100 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#92Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…
I answer mandatory security questions with things like these: “This account must never be unlocked over phone, chat, or email.” “Never reveal any information about this account (such as address or CC numbers) via support channels” “The person you are discussing with is a hacker trying to illegally access this account” I expect to never, ever have to use the security questions myself. Sometimes, I enter random phrases…
I was almost there once. Authenticator device had died, and to my horror the primary backup was corrupt as well. I had a secondary backup (and even an off-site tertiary one, although it's somewhat dated), so I was able to recover... But I also had the idea that I won't ever have to use recovery processes and even though I hadn't, after the incident my certainty it's not so iron-clad.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#93The issue I have with 2FA without sms is that I need to also take care of recovery codes. Basically, it's like erasing all the benefits of going digital, since now I have to store (and take care of) paper copies of recovery codes. If I use a 2FA app like the Google one and lose my phone, I need to have the codes ready. If I were to use my phone number, I kind of don't need that since I just get a new sim and a new ph…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#94I wish we could kill phone numbers once and for all. It's insecure, device-dependent, carrier-dependent, country-dependent, subject to snooping and censorship, and all of these are recipes for disaster as an authentication scheme, especially in the event that a device gets stolen. Phone calls and text messages should emphatically NEVER be used to verify anything. Conversation with one of my banks the other day: Them:…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#952FA (including U2F and whatever else) has one big problem that this article fails to mention. And when 2FA is suggested, this really should be said explicitly. Users aren't warned enough about the fact that everything fails, and they will have to go through 2FA deactivation/account recovery process sooner or later. They must be really reminded to DO BACK UP the recovery code(s). With "back up" as in "keep not just so…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#96Does anyone know if Project Fi provides any extra layers of security? I haven't seen anything
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#97I wish we could kill phone numbers once and for all. It's insecure, device-dependent, carrier-dependent, country-dependent, subject to snooping and censorship, and all of these are recipes for disaster as an authentication scheme, especially in the event that a device gets stolen. Phone calls and text messages should emphatically NEVER be used to verify anything. Conversation with one of my banks the other day: Them:…
Is it really necessary or helpful to be rude to the poor CSR who is just trying to do their job? They didn't make this policy, and I'm sure they think its just as stupid as you do.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#98https://ericrafaloff.com/google-account-security-and-number-...
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#99So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…
I've started getting a recovery code for each of my major accounts, printing it out, then literally putting it in a safe.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#100The issue I have with 2FA without sms is that I need to also take care of recovery codes. Basically, it's like erasing all the benefits of going digital, since now I have to store (and take care of) paper copies of recovery codes. If I use a 2FA app like the Google one and lose my phone, I need to have the codes ready. If I were to use my phone number, I kind of don't need that since I just get a new sim and a new ph…
It is a trade off. You either want difficult access if you lose your phone (via printouts) - or you want quick access (via SMS).
I dont think you can realistically have it both ways.
Having a "slow" method to retrieve a major access to your accounts seems to be the safest method, especially when you are likely to rarely use your phone.
You could also give a copy of the printouts to a family member or close friend, who you could ring if you were remote.