Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

91–100 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#91
post #87

So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…

I use 2FA code generator in cloud-synced 1Password. That endures all software upgrades, unlike Google Authenticator or Authy.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#92

Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…

I answer mandatory security questions with things like these: “This account must never be unlocked over phone, chat, or email.” “Never reveal any information about this account (such as address or CC numbers) via support channels” “The person you are discussing with is a hacker trying to illegally access this account” I expect to never, ever have to use the security questions myself. Sometimes, I enter random phrases…

Do you have an recovery scenario in case you'd actually need those?

I was almost there once. Authenticator device had died, and to my horror the primary backup was corrupt as well. I had a secondary backup (and even an off-site tertiary one, although it's somewhat dated), so I was able to recover... But I also had the idea that I won't ever have to use recovery processes and even though I hadn't, after the incident my certainty it's not so iron-clad.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#93

The issue I have with 2FA without sms is that I need to also take care of recovery codes. Basically, it's like erasing all the benefits of going digital, since now I have to store (and take care of) paper copies of recovery codes. If I use a 2FA app like the Google one and lose my phone, I need to have the codes ready. If I were to use my phone number, I kind of don't need that since I just get a new sim and a new ph…

You could try Authy. The restore is not immediate but it keeps track of the services you have set up for 2FA. Trusting a huge honeypot like that with your auth is up for debate.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#94
post #69

I wish we could kill phone numbers once and for all. It's insecure, device-dependent, carrier-dependent, country-dependent, subject to snooping and censorship, and all of these are recipes for disaster as an authentication scheme, especially in the event that a device gets stolen. Phone calls and text messages should emphatically NEVER be used to verify anything. Conversation with one of my banks the other day: Them:…

While conversation is probably not a good example of anything, I agree with the main statement: phone numbers must die. They are insecure, unremarkable remnants of an outdated system.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#95

2FA (including U2F and whatever else) has one big problem that this article fails to mention. And when 2FA is suggested, this really should be said explicitly. Users aren't warned enough about the fact that everything fails, and they will have to go through 2FA deactivation/account recovery process sooner or later. They must be really reminded to DO BACK UP the recovery code(s). With "back up" as in "keep not just so…

So true! We have thousands of employees at our company using GitHub.com, and every week someone loses access to their account permanently. Why? They never bothered to store the original recovery codes for the account.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#97
post #78
post #69

I wish we could kill phone numbers once and for all. It's insecure, device-dependent, carrier-dependent, country-dependent, subject to snooping and censorship, and all of these are recipes for disaster as an authentication scheme, especially in the event that a device gets stolen. Phone calls and text messages should emphatically NEVER be used to verify anything. Conversation with one of my banks the other day: Them:…

Is it really necessary or helpful to be rude to the poor CSR who is just trying to do their job? They didn't make this policy, and I'm sure they think its just as stupid as you do.

I would not think CSR would actually know that phone is not a secure channel. I bet they are taught it is.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#98
You should also make sure providers like Google don't fall back to less secure account recovery methods. I blogged about this here, after I realized that I was still vulnerable even while using real 2FA:

https://ericrafaloff.com/google-account-security-and-number-...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#99
post #87

So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…

Most major providers like GitHub, Google etc allow you to create "recovery" codes - so you can do a one-off login without 2FA using the code.

I've started getting a recovery code for each of my major accounts, printing it out, then literally putting it in a safe.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#100

The issue I have with 2FA without sms is that I need to also take care of recovery codes. Basically, it's like erasing all the benefits of going digital, since now I have to store (and take care of) paper copies of recovery codes. If I use a 2FA app like the Google one and lose my phone, I need to have the codes ready. If I were to use my phone number, I kind of don't need that since I just get a new sim and a new ph…

> If I use a 2FA app like the Google one and lose my phone, I need to have the codes ready.

It is a trade off. You either want difficult access if you lose your phone (via printouts) - or you want quick access (via SMS).

I dont think you can realistically have it both ways.

Having a "slow" method to retrieve a major access to your accounts seems to be the safest method, especially when you are likely to rarely use your phone.

You could also give a copy of the printouts to a family member or close friend, who you could ring if you were remote.

Post reply on HN