Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

181–190 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#181
post #137

Earlier quoted context omitted.

It's certainly safer than only using a password if you use the same password on lots of sites, since the odds of any password database being hacked are higher than the odds of your phone being targeted.

Thanks. This thread was giving me the impression that adding 2fa with SMS to a system would make it more vulnerable somehow.

It does if the provider uses the phone number to reset the password.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#182
post #104

Last year when I upgraded my phone I was amused — but mostly horrified — by how easily one could get a SIM card for my own phone number with less than a modicum of information on me. As I required to upgrade my Micro SIM to a Nano SIM, I went to one of my provider's shops and asked for a Nano SIM for phone number X. I was then asked to verbally confirm my name and address — and that's it. No ID card confirmation, no…

Recently my dad entered his SIM PIN incorrectly three times and it locked him out. Turns out his mobile operator has an IVR service which hands out the PUK to any phone number you enter! No authentication whatsoever, just the phone number. How common is this?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#183
post #136

It's insane how much easier it is to transfer a phone number than a domain name. I also find it odd Facebook, and other sites will let you signup solely with a phone number. There's prepaid cell phone providers that recycle phone numbers, etc. Just seems so stupid to rely on a phone number for authentication alone, but two factor I'm okay with since you still need to know the password. Twitter has a developer product…

I can't speak for whether or not Facebook is doing it, but the carrier of the number is usually a determining factor on whether or not an arbitrary line is allowed for registration.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#184
Anyone here happen to know how hard it is to steal a Twilio number as compared to a number issued by eg T-Mobile or Verizon? Is the only way to do so, by accessing the Twilio account that controls the number (whether directly or by API)?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#185
post #180

Great. Now that we've succeeded in compiling a list of personal sad stories to one up one another, why not not discuss how we could encourage the banks / phone companies to make this situation impossible. 1) Ban SMS as a second factor for high risk targets like banks. 2) Telecom companies should require social security number or uniquely identifying information to provide account access. 3) ???

> 1) Ban SMS as a second factor for high risk targets like banks.

As others have pointed out, if it were just a second factor they would also need your password. SMS is being used for full account recovery, so as a single factor.

> 2) Telecom companies should require social security number

This is exactly what we should not be doing. I would like it to be harder to steal my identity than getting a 9-digit number, which can never be rotated, and which I am required to provide in plaintext to many different people in many different situations (renting an apartment, opening a credit card, etc.).

To make matters even worse, up to the first 5 digits of an SSN can be easily guessed if you know the person's age and birthplace, and the last 4 digits are used even more haphazardly than the entire number is (e.g. sometimes the last 4 are displayed in plaintext on a website while the first 5 are starred out).

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#186

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

Or use a Google Voice number to setup 2FA on the same account. That way you can only ever login if you have a device on your person already logged in. If somehow you're away from technology long enough that all your devices are locked, use a printed backup code to unlock one.

But, if you use Google Voice number on your other Gmail account, they say it's not recommended because you can get locked out of both.

I think you can use Google Voice number on everything other than your main Gmail account.

So, to be extra safe, after you've set up your 2FA for gmail, make sure to change your recovery phone # to something other than your main telco or google voice number.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#187
post #180

Great. Now that we've succeeded in compiling a list of personal sad stories to one up one another, why not not discuss how we could encourage the banks / phone companies to make this situation impossible. 1) Ban SMS as a second factor for high risk targets like banks. 2) Telecom companies should require social security number or uniquely identifying information to provide account access. 3) ???

Some kind of cryptographic challenge-response system might be a good solution but I don't know how to get your average computer user and customer support rep to use a system like that. All the ones I can think of are designed for computers to talk to each other so they aren't very user friendly. Is there something like Kerberos but for humans?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#188
A few months back I lost my phone, so I went to my operator with passport to get new sim with my old number (in Thailand) . She said the sim isn't actually in my name but my ex-girlfriend's, and I told I remember I took the sim with her id as I didn't carry my passport with me, so I guess there's nothing I can do.

She just replied well we could change the sim to your name, didn't even check with the original owner and 5 minutes later I was on my way with new sim.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#189
post #62

Earlier quoted context omitted.

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

They won't go after an attacker if there's not a high amount of damage, like $250K or more. FBI guys are swamped with people calling, and there's just not enough agent time to go around. Same for bank fraud. Ever wonder how people get away with popping someone's bank account, transferring to another local account, and walking off with the cash? For a couple grand, no one's gonna spend the time and effort to track you…

Maybe we should increase the number of agents investigating this stuff, then? Fraud affects many more people than terrorism, but nobody gives the "there's just not enough agents" excuse for that.

Also, only investigating fraud when there's lots of money involved means we're only helping rich people, who need the least help. Losing less money doesn't mean less impact on someone's life if that's all they have.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#190
post #169

Earlier quoted context omitted.

What is better? Authenticator apps/hardware devices?

Authenticators are fine but u2f keys are better because they protect against phishing.

Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.
Post reply on HN