Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

171–180 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#171

Two factor authentication is nothing more than a massive vulnerability. We've seen people somehow change our listed contact numbers through unknown exploits, then hijack ownership of properties using the new number to prove they are us. This wouldn't be possible if not for 2nd factor authorization schemes.

Not just that, it's a bad solution to the problem it's attempting to solve. (What if your password manager gets compromised?) To have that problem, someone must both have your password manager database and the master password and/or keys to unlock it. Since you need your password manager on your phone, the assumption that having your phone somehow provides an additional factor over having your password manager is just plain wrong from the beginning. 2FA as implemented isn't even a second factor.

And, as others have mentioned, it increases the likelihood of getting locked out of your accounts (if you don't have your phone with you or the battery died or whatever). Which encourages service providers to make account recovery easier (it needs to be easier if people are more likely to get locked out.) And making account recovery easier makes it easier for other people to 'recover' your account.

3rd-party authentication (other people vouching that you are who you say you are) might be better, but would have its own problems.

In the end, the real solution to the problem of 'what if your password manager gets compromised?' is to minimize that possibility by _not_ having it online, having really strong master password and/or keys, and avoiding malware. 2FA doesn't help with that at all. It just adds its own problems.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#172
post #74

Earlier quoted context omitted.

Which banks should you choose? How do you decide?

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there.

In US it seems #freemarket is putting externalities (security) on the customer.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#173

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

Or use a Google Voice number to setup 2FA on the same account. That way you can only ever login if you have a device on your person already logged in. If somehow you're away from technology long enough that all your devices are locked, use a printed backup code to unlock one.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#174
post #141
post #123

Earlier quoted context omitted.

Yea, my wife uses a physical token generator now, and I use the app which is bound to my phone. Someone would have to physically have my phone (and unlock it) in order to access my bank now.

Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.

Banks can always ask you to go into a branch for more important things like that. They do that in the UK. If you're not in the country, you can write a letter on paper and have the local police or lawyer confirm your identity. I've done that before. It's a nightmare but it eventually works.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#175
post #148

Earlier quoted context omitted.

Your story reminds me of when I ordered a $200 video card from Staples ship to store. I went to the cashier and told them they should have a video card I ordered. They asked for my name and gave it to me (inside the shipping box so they didn't even know the contents). It's not as bad as getting your phone number stolen but it opened my eyes how easy it would be to "steal" a package.

The problem with all these stories is that there is a physical interaction. Maybe there is a video or whatever, but for some reason people easily let their guard down when transaction is conducted in person.

That physical interaction is important. It means there's a human being in your country committing a crime on video. That same person could just pick up a product off the shelf and walk out with it too. Either way, they're putting themselves at risk of arrest.

When it's online, there's almost no risk because they're probably in Russia and leave no physical evidence.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#176
post #168

This kind of attacks could lead to total disasters in China where the standard is to login and register solely on a phone number using a confirmation text. In China your phone number is pretty much as valuable as all your password combined, all services are solely linked to it. Even though phone companies ask for id before issuing a SIM card, I'm pretty sure a tiny bribe is enough to get past most store clerks

ID isn't just for security, it's so the police can track you. So they'll be putting pressure on phone companies to do it thoroughly. They take a copy of my passport when I get a SIM card. Probably not going to bribe them into leave missing documentation on your file. They could easily be caught by their boss at any time in the future.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#177
5 or 6 years ago, my phone number got ported by someone else without my knowing. My phone suddenly didn't work anymore. I called into AT&T right the way to ask what's going on and they said someone has "took over billing" from my account and AT&T transferred the number over. WTF? I was adamant to get the number back since that's the number I give it out to people. They won't bungle saying it's out of their hand. Finally they said they could place the number into the free pool for re-allocation which would freeze it for 3 months before it could be used again. I was concerned it could be used as a vector against my bank accounts. It was a nightmare.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#178
post #172

Earlier quoted context omitted.

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

ACH is a service of the Federal Reserve, actually.

It also provides wire transfers, which are a little more secure because they're push only, but also less secure because they're instantaneous and irreversible. All banks charge at least ~$15 per transaction and they're really only used for high value, time sensitive deals.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#179
post #168

This kind of attacks could lead to total disasters in China where the standard is to login and register solely on a phone number using a confirmation text. In China your phone number is pretty much as valuable as all your password combined, all services are solely linked to it. Even though phone companies ask for id before issuing a SIM card, I'm pretty sure a tiny bribe is enough to get past most store clerks

Or do what I do every time I visit China - just buy a SIM from some dudes cart by the side of the road. He doesn't care who you are.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#180
Great. Now that we've succeeded in compiling a list of personal sad stories to one up one another, why not not discuss how we could encourage the banks / phone companies to make this situation impossible.

1) Ban SMS as a second factor for high risk targets like banks.

2) Telecom companies should require social security number or uniquely identifying information to provide account access.

3) ???

Post reply on HN