Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

121–130 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#121
post #74
post #72

Earlier quoted context omitted.

The is a direct correlation between security and fraud related interest/insurance in regards to the cost of use and exposure to fraud. They aren't out to "destroy" your security, it's a liability threshold calculation. At the end of the day secure yourself in life, this include choosing banks that are more stringent based on your needs and what you want to pay.

Which banks should you choose? How do you decide?

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much.

You can manage your risk somewhat by:

1) Using credit and not debit cards for day to day spending.

2) Maintaining your long term wealth in separate accounts at separate institutions and not linking them directly to anything except your checking account. This minimizes what can be stolen if your checking account is compromised, and makes it less likely that your savings can be stolen directly (account number is used in fewer places).

3) Turning on all the alerting and notification settings you can find, so that you'll hear about unauthorized activity immediately.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#122

Earlier quoted context omitted.

It's actually dangerous. Consider what would happen if you're accidentally exposed to a malware that steals data from the password managers (by introspecting process memory after the data was already decrypted) Better keep those eggs in the different baskets (Update: Point was, I think 1Password doesn't have multiple databases, does it?)

I would expect greater risk if I spread that information around more. Is it really better if only 1/3rd of my passwords are stolen, at least relative to the 3x risk I face by using multiple sources?

I'm not sure I get the idea.

My idea is to have two password databases. One is the usual, for the passwords. Another is infrequently opened and is used for the recovery codes and insecurity questions.

I don't see how a secondary normally-closed password vault would degrade security. It's still encrypted, and safe. On the contrary, it should increase security a little - for the abovementioned local malware scenario. Price paid is that because database is rarely used, it could get corrupt without user noticing, or access details could be forgotten.

Or I'm missing something important? Why the 3x risk?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#123
post #65

A few months ago I took 3 of my 4 kids to a birthday party at a minigolf course. I played some holes with my youngest I had taken with me, and then left the two older ones at the birthday party with the understanding that their mother would pick them up (as we had discussed earlier) After leaving the party with my youngest, I went to the grocery store, and then on home. When I got home my wife was gone, which I expec…

In Singapore they give us a physical token. We have to enter the 2Fa we receive into it to receive a third code to enter into the website. Well I guess it's 3Fa. It is a bit of a hassle but better safe than sorry.

Yea, my wife uses a physical token generator now, and I use the app which is bound to my phone. Someone would have to physically have my phone (and unlock it) in order to access my bank now.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#124
post #62

This happened to me. 1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.* 3. Hacker gained access to email (as th…

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

They won't go after an attacker if there's not a high amount of damage, like $250K or more. FBI guys are swamped with people calling, and there's just not enough agent time to go around. Same for bank fraud. Ever wonder how people get away with popping someone's bank account, transferring to another local account, and walking off with the cash? For a couple grand, no one's gonna spend the time and effort to track you down.

Liability for data breaches limited to companies over X size would be a good idea though.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#125
post #87

So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…

I've had this happen with Microsoft/Office365. Lost access, couldn't get the recovery email. They sent emails and made me wait a day or two before resetting things.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#126
post #74
post #72

Earlier quoted context omitted.

The is a direct correlation between security and fraud related interest/insurance in regards to the cost of use and exposure to fraud. They aren't out to "destroy" your security, it's a liability threshold calculation. At the end of the day secure yourself in life, this include choosing banks that are more stringent based on your needs and what you want to pay.

Which banks should you choose? How do you decide?

Security always sucks. The differentiation is response. That usually means a small regional bank or midsize credit union.

If you have enough dollars, a private bank type thing works too.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#127

Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…

I answer mandatory security questions with things like these: “This account must never be unlocked over phone, chat, or email.” “Never reveal any information about this account (such as address or CC numbers) via support channels” “The person you are discussing with is a hacker trying to illegally access this account” I expect to never, ever have to use the security questions myself. Sometimes, I enter random phrases…

...and then some dumbass IT configuration administrator decides that nobody needs to have more than 10 characters to type in their aunt's cousin's roommate's name. This is, of course, the secret question they use, so why would anyone else use something different?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#128

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

Is 2fa with SMS safer or less safe than no 2fa at all?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#130

Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…

I am old enough to remember how everything used to make sense (as little as 5-7 years ago). Today, "don't connect anything to anything" sounds like the last line of defense against the horde of Progress-worshiping geeky retards.
Post reply on HN