Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

141–150 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#141
post #123

Earlier quoted context omitted.

In Singapore they give us a physical token. We have to enter the 2Fa we receive into it to receive a third code to enter into the website. Well I guess it's 3Fa. It is a bit of a hassle but better safe than sorry.

Yea, my wife uses a physical token generator now, and I use the app which is bound to my phone. Someone would have to physically have my phone (and unlock it) in order to access my bank now.

Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#142
post #91
post #87

So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…

I use 2FA code generator in cloud-synced 1Password. That endures all software upgrades, unlike Google Authenticator or Authy.

If you use an Android phone that's rooted, you can use Titanium Backup to copy your Google Authenticator app data between devices. It's up to you to copy that data somewhere else, but it is a very low level alternative to storing everything in 1Password or similar.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#144
post #62

This happened to me. 1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.* 3. Hacker gained access to email (as th…

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

> Why would they care?

Because it is their job.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#145

I highly suggest having at least 2 phone numbers, one that is your main number that you use and give out. The others are kept private and never for calls or texts, but only for 2FA.

I did this with TMobile when they had get 3 lines and get 4th free. I use the 4th free line as my 2FA. The 2FA line is an old android phone and is always plugged in & on in my basement. I have a little script on the phone that reports any SMS messages a db running on my home server (RPi) and I access it with in my network (or via VPN).

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#146

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

Go to: https://myaccount.google.com/signinoptions/two-step-verifica...

And remove SMS from the listing. I currently have 3 2FA mechanisms listed: Security-Key/Yubikey (default), Authenticator App (set on two devices), and Backup codes which I downloaded (and at some point will print and place in a safe deposit box).

Losing access to my two gmail accounts would be a complete nightmare---more so than my bank/brokerage accounts. Some brokerages like TD Ameritrade do not even offer 2FA. In my case, paranoia mode for email accounts is completely warranted.

I really wish U2F becomes the standard across all web services. It seems insane that, in some scenarios, the only barrier against financial ruin is the gullibility of your cell-phone provider's customer service rep.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#148
post #140
post #104

Last year when I upgraded my phone I was amused — but mostly horrified — by how easily one could get a SIM card for my own phone number with less than a modicum of information on me. As I required to upgrade my Micro SIM to a Nano SIM, I went to one of my provider's shops and asked for a Nano SIM for phone number X. I was then asked to verbally confirm my name and address — and that's it. No ID card confirmation, no…

Last week I walked into a T-Mobile store and asked for a new SIM card to replace one I lost. I gave them the phone number and apparently an invalid pin (the sales rep verified that I gave him the wrong PIN). I asked if I should do something else to verify it was my account and nothing. They didn't ask for name, ID, or anything else, and they didn't charge me for the SIM card. I went home and popped it in and my accou…

Your story reminds me of when I ordered a $200 video card from Staples ship to store. I went to the cashier and told them they should have a video card I ordered. They asked for my name and gave it to me (inside the shipping box so they didn't even know the contents). It's not as bad as getting your phone number stolen but it opened my eyes how easy it would be to "steal" a package.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#150
post #74

Earlier quoted context omitted.

Which banks should you choose? How do you decide?

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

I read somewhere that companies that do a lot of ACH payments use different accounts for receiving and sending payments. The receiving account is locked so that it can't send and the sending account is supposed to stay secret. I don't know if that actually works in practice, though.
Post reply on HN