Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

201–210 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#201

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

Or use a Google Voice number to setup 2FA on the same account. That way you can only ever login if you have a device on your person already logged in. If somehow you're away from technology long enough that all your devices are locked, use a printed backup code to unlock one.

Somewhere on YouTube somebody got locked from his google account while streaming live because of similar setup as your suggestion, Google 2fa codes to Google voice, and the look on the face when he realised it was hilarious. Not sure, but maybe he sorted it out somehow.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#202

This happened to me. 1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.* 3. Hacker gained access to email (as th…

> 1. I believe it began with the hacker getting DOB/SSN

We [the US] dramatically over-rely on SSN. At least one upside to ubiquitous biometrics will be that we can start layering more authentication measures in an effective and consumer friendly way.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#203

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

> When signing up for a new Gmail, you don’t need to enter a phone number

This is not true in general. It probably at least depends on the country you try to sign-up from probably other factors.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#204
post #65

A few months ago I took 3 of my 4 kids to a birthday party at a minigolf course. I played some holes with my youngest I had taken with me, and then left the two older ones at the birthday party with the understanding that their mother would pick them up (as we had discussed earlier) After leaving the party with my youngest, I went to the grocery store, and then on home. When I got home my wife was gone, which I expec…

In Singapore they give us a physical token. We have to enter the 2Fa we receive into it to receive a third code to enter into the website. Well I guess it's 3Fa. It is a bit of a hassle but better safe than sorry.

I think it's worth noting that while physical token is needed for adding new payees and changing transaction limits, it is not necessary for online purchases, which only requires sms verification (at least for DBS).

I think it's a fine approach balancing security and convenience.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#205
post #142
post #91

Earlier quoted context omitted.

I use 2FA code generator in cloud-synced 1Password. That endures all software upgrades, unlike Google Authenticator or Authy.

If you use an Android phone that's rooted, you can use Titanium Backup to copy your Google Authenticator app data between devices. It's up to you to copy that data somewhere else, but it is a very low level alternative to storing everything in 1Password or similar.

Even without rooting, just do that that next time when you register for 2FA, save that QR image, or screenshot it, and/or save that 16+ chars string somewhere safe, same as where you save passwords. Phone died/changed/lost? Install Google Auth, rescan that QR/Screenshot.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#206

Earlier quoted context omitted.

The problem with all these stories is that there is a physical interaction. Maybe there is a video or whatever, but for some reason people easily let their guard down when transaction is conducted in person.

That physical interaction is important. It means there's a human being in your country committing a crime on video. That same person could just pick up a product off the shelf and walk out with it too. Either way, they're putting themselves at risk of arrest. When it's online, there's almost no risk because they're probably in Russia and leave no physical evidence.

Never mind the video, you know for a fact they are carrying a tracking device.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#207

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

I asked the same at https://security.stackexchange.com/questions/151675/how-to-s...

Basically, the safest is, add Google Auth via App to your account, then remove all the phone numbers from Google. If any phone number is linked to your account, no matter what your account recovery options are, Google will always give you option to "recover" it by SMS.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#208

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

Go to: https://myaccount.google.com/signinoptions/two-step-verifica... And remove SMS from the listing. I currently have 3 2FA mechanisms listed: Security-Key/Yubikey (default), Authenticator App (set on two devices), and Backup codes which I downloaded (and at some point will print and place in a safe deposit box). Losing access to my two gmail accounts would be a complete nightmare---more so than my bank/brokerage…

I might be wrong, tried long ago, but maybe it is that even if you don't list SMS as your backup code delivery option, clicking forgot password (need only your username), and then going to Other Options, and choosing to gey identified by providing a phone number (Google shows type your number * * * * * * -1234), hijacking its SMS, can provide access to your account.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#209
post #198
post #172

Earlier quoted context omitted.

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

Jeremy Clarkson made a similar argument and even published his bank details. Then this happened: http://news.bbc.co.uk/1/hi/7174760.stm

Not sure about UK but in Poland direct debit is something you need to manually enable and pay small fee for it.

And even if you enable it someone needs to forge your signature under direct debit order to allow someone to charge you.

So still no.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#210
post #79

Earlier quoted context omitted.

The real answer is to not use SMS as a 2FA. That was never ever a good idea.

What is better? Authenticator apps/hardware devices?

"What is better? Authenticator apps/hardware devices?"

Mobile signature (SIM-based)(0) is the most secure method as far as I've seen in banks. Citing wiki: "supporting the authentication on the Internet with a parallel closed network like mobile/GSM and a digital signature enabled SIM card is the most secure method today against the man in the middle attack."

0. https://en.wikipedia.org/wiki/Mobile_signature

Post reply on HN