Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

191–200 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#191
post #169

Earlier quoted context omitted.

What is better? Authenticator apps/hardware devices?

Authenticators are fine but u2f keys are better because they protect against phishing.

What is a good u2f key you'd recommend?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#192
post #55

Earlier quoted context omitted.

so why do well-respected companies like Google and Stripe do it?

Because their target markets contain both people who'll gladly spend 50 quid on the latest account security dongle, as well as people who have a Pentium 4 desktop and a 50 quid feature phone. The latter get much more secure when apart from a password, probably on a post it stuck next to the screen, they are inconvenienced to also type in a few digits from SMS.

You are 100% correct. But I'm genuinely curious why institutions such as banks/telcos couldn't spare the resources to offer both SMS 2FA and more secure options for those who do care. I can't imagine it's a matter of technical resources as it wouldn't take much. Is it institutional inertia? technical debt?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#193
post #189

Earlier quoted context omitted.

They won't go after an attacker if there's not a high amount of damage, like $250K or more. FBI guys are swamped with people calling, and there's just not enough agent time to go around. Same for bank fraud. Ever wonder how people get away with popping someone's bank account, transferring to another local account, and walking off with the cash? For a couple grand, no one's gonna spend the time and effort to track you…

Maybe we should increase the number of agents investigating this stuff, then? Fraud affects many more people than terrorism, but nobody gives the "there's just not enough agents" excuse for that. Also, only investigating fraud when there's lots of money involved means we're only helping rich people, who need the least help. Losing less money doesn't mean less impact on someone's life if that's all they have.

Because people are more terrified about a random bomb hitting a random place once in a while more than their accounts getting hacked and then finding themselves in a big trouble?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#194

I owned a hosted PBX company from 2007-2011 and was amazed with how antiquated the port request system truly is. The problem is that the phone company owns your phone number and you just get access as part of a service. Unlike a domain name where you own it. If we change the law we'd bring more accountability.

To be fair, you really don't own a domain. You still rely on the TLD honoring your purchase and not hand it over to someone else in the same way you rely on the phone company to treat your number as yours.

This needs to change as well. We nee to do away with the concept of a select few TLDs, indeed we need to scrap payed for subdomains/domains in general.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#195
post #62

Earlier quoted context omitted.

> The entire situation was communicated to the FBI, local police, and bank institutions, but I do not think anyone cared. Why would they care? It happens dozens of times a day, and the criminals are out of their jurisdiction. If only the police, FBI, politicians, etc. could go after the banks and telcos to improve their security. But no... they see it as their job to destroy security, in order to make you "safe".

They won't go after an attacker if there's not a high amount of damage, like $250K or more. FBI guys are swamped with people calling, and there's just not enough agent time to go around. Same for bank fraud. Ever wonder how people get away with popping someone's bank account, transferring to another local account, and walking off with the cash? For a couple grand, no one's gonna spend the time and effort to track you…

Which is interesting because it should be the other way around. If you have $250k stolen, it is bad but you are probably wealthy enough you won't go in deep trouble stress.

If your whole account is $2k it might be a different world for you and you might relying on these to pay rent, medical expenses which is more serious than an investor not having access to his $250k.

Not meaning it is fine to steal $250k from wealthy people but that poor ones being affected (at $2k) is more urgent from a humanitarian perspective.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#196
post #65

A few months ago I took 3 of my 4 kids to a birthday party at a minigolf course. I played some holes with my youngest I had taken with me, and then left the two older ones at the birthday party with the understanding that their mother would pick them up (as we had discussed earlier) After leaving the party with my youngest, I went to the grocery store, and then on home. When I got home my wife was gone, which I expec…

> someone went into a T-Mobile store and somehow convinced the associate that my number was theirs.

The fact that the T-Mobile employees can get hold of your mobile phone number is disturbing and a red flag for using your phone number for sensitive stuff (such as money). You should always assume malice from unknown actors.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#197
post #169

Earlier quoted context omitted.

Authenticators are fine but u2f keys are better because they protect against phishing.

Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.

Thats exactly why I copy and save every 2fa QR Code in my KeePass database, along with backup codes. Phone changed? No worries, install Google Auth, rescan those QRs, and voila, your 2fa system is back and running !! :)

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#198
post #172

Earlier quoted context omitted.

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

Jeremy Clarkson made a similar argument and even published his bank details. Then this happened: http://news.bbc.co.uk/1/hi/7174760.stm

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#199
post #172

Earlier quoted context omitted.

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#200
post #141
post #123

Earlier quoted context omitted.

Yea, my wife uses a physical token generator now, and I use the app which is bound to my phone. Someone would have to physically have my phone (and unlock it) in order to access my bank now.

Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.

Banks over here only reset those tokens with instructions sent to your known address. You can only change that address with a working token or showing government issued ID (which everyone around here has and is also required to open an account in the first place). At worst you need to send a copy by mail but going to a branch or post office or a video chat are more common.
Post reply on HN