Earlier quoted context omitted.
It's certainly safer than only using a password if you use the same password on lots of sites, since the odds of any password database being hacked are higher than the odds of your phone being targeted.
Thanks. This thread was giving me the impression that adding 2fa with SMS to a system would make it more vulnerable somehow.
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
181–190 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#182Last year when I upgraded my phone I was amused — but mostly horrified — by how easily one could get a SIM card for my own phone number with less than a modicum of information on me. As I required to upgrade my Micro SIM to a Nano SIM, I went to one of my provider's shops and asked for a Nano SIM for phone number X. I was then asked to verbally confirm my name and address — and that's it. No ID card confirmation, no…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#183It's insane how much easier it is to transfer a phone number than a domain name. I also find it odd Facebook, and other sites will let you signup solely with a phone number. There's prepaid cell phone providers that recycle phone numbers, etc. Just seems so stupid to rely on a phone number for authentication alone, but two factor I'm okay with since you still need to know the password. Twitter has a developer product…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#184Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#185Great. Now that we've succeeded in compiling a list of personal sad stories to one up one another, why not not discuss how we could encourage the banks / phone companies to make this situation impossible. 1) Ban SMS as a second factor for high risk targets like banks. 2) Telecom companies should require social security number or uniquely identifying information to provide account access. 3) ???
As others have pointed out, if it were just a second factor they would also need your password. SMS is being used for full account recovery, so as a single factor.
> 2) Telecom companies should require social security number
This is exactly what we should not be doing. I would like it to be harder to steal my identity than getting a 9-digit number, which can never be rotated, and which I am required to provide in plaintext to many different people in many different situations (renting an apartment, opening a credit card, etc.).
To make matters even worse, up to the first 5 digits of an SSN can be easily guessed if you know the person's age and birthplace, and the last 4 digits are used even more haphazardly than the entire number is (e.g. sometimes the last 4 are displayed in plaintext on a website while the first 5 are starred out).
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#186So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…
Or use a Google Voice number to setup 2FA on the same account. That way you can only ever login if you have a device on your person already logged in. If somehow you're away from technology long enough that all your devices are locked, use a printed backup code to unlock one.
I think you can use Google Voice number on everything other than your main Gmail account.
So, to be extra safe, after you've set up your 2FA for gmail, make sure to change your recovery phone # to something other than your main telco or google voice number.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#187Great. Now that we've succeeded in compiling a list of personal sad stories to one up one another, why not not discuss how we could encourage the banks / phone companies to make this situation impossible. 1) Ban SMS as a second factor for high risk targets like banks. 2) Telecom companies should require social security number or uniquely identifying information to provide account access. 3) ???
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#188She just replied well we could change the sim to your name, didn't even check with the original owner and 5 minutes later I was on my way with new sim.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#189Earlier quoted context omitted.
> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".
They won't go after an attacker if there's not a high amount of damage, like $250K or more. FBI guys are swamped with people calling, and there's just not enough agent time to go around. Same for bank fraud. Ever wonder how people get away with popping someone's bank account, transferring to another local account, and walking off with the cash? For a couple grand, no one's gonna spend the time and effort to track you…
Also, only investigating fraud when there's lots of money involved means we're only helping rich people, who need the least help. Losing less money doesn't mean less impact on someone's life if that's all they have.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#190Earlier quoted context omitted.
What is better? Authenticator apps/hardware devices?
Authenticators are fine but u2f keys are better because they protect against phishing.