Earlier quoted context omitted.
> When signing up for a new Gmail, you don’t need to enter a phone number This is not true in general. It probably at least depends on the country you try to sign-up from probably other factors.
Gmail didn't mandate phone number the last time I created dummy account (~1 month ago). I don't have phone number linked even with my primary account.
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
231–240 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#232NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html
Is 2fa with SMS safer or less safe than no 2fa at all?
The problem is that nearly every single 2fa setup out there does something radically stupid such as use your 2fa method for password reset, or a combination of 2fa + email. This is horribly, horribly broken and worse than "no 2fa at all." All it takes is a SIM clone to steal your phone #, which you use to reset the email, and then email + phone/SMS can be used to reset nearly every single credential under the sun. The only exceptions are those that use proper 2FA such as one-time password apps -- but not Authy which just syncs your OTP/2fa credentials to the cloud and happily transfers to the cloned device :(
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#233Earlier quoted context omitted.
To be fair, you really don't own a domain. You still rely on the TLD honoring your purchase and not hand it over to someone else in the same way you rely on the phone company to treat your number as yours.
Some domain registrars are so completely incompetent (ie Dotster), I'm disappointed they're still in business. Literally clueless "customer support" staff that either don't auth (experienced that personally), or refuse to follow the written rules to everyone's detriment. Recent example: https://issues.apache.org/jira/browse/INFRA-13657 Note - Don't use Dotster (specifically) for your domains. If you're using them now…
https://www.google.com/amp/s/www.forbes.com/sites/theyec/201...
Not exactly an easy thing to do with a phone number.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#234Earlier quoted context omitted.
In Singapore they give us a physical token. We have to enter the 2Fa we receive into it to receive a third code to enter into the website. Well I guess it's 3Fa. It is a bit of a hassle but better safe than sorry.
Seriously, I don't understand why physical tokens are not the norm and standardized on all devices, still. It isn't a new concept at all.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#235Earlier quoted context omitted.
Authenticators are fine but u2f keys are better because they protect against phishing.
Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#236Why not just have all sites that require SMS 2FA (there are a lot, including tele co.s) be directed to a personal google voice number? And also remove the any SMS 2FA from this google and your personal? Wouldn't that solve the issue they are suggesting? Why do you need a third account?
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#237Earlier quoted context omitted.
Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.
Jeremy Clarkson made a similar argument and even published his bank details. Then this happened: http://news.bbc.co.uk/1/hi/7174760.stm
Many companies (and individuals) in Europe publish their account numbers on their letter head and website, it really isn't a big deal.
Anything else seems security by obscurity.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#238Great article -.-
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#239Earlier quoted context omitted.
>> If you have $250k stolen, it is bad but you are probably wealthy enough you won't go in deep trouble stress. Or it might be your entire life's savings and if you can't get it back you kill yourself from the stress of losing 40+ years of work. It's very dangerous to make assumptions about other people's money.
Do you usually have your life savings in a checking bank account and not in an IRA account? Shouldn't that has more red-flags for the bank. I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft.
>>I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft.
Absolutely not. Ignore the case when this 250k was your entire life savings (30-40 years of saving remainder of your salary every month and slowly building savings for retirement).
It could be mortgage money which you are about to buy a house with or it could be company money for payroll. Suddenly employees of a small business don't get paid. Those employees of course have to pay mortgage/rent/medical bills and suddenly paycheck they counted on doesn't come. This could affect many people in very negative ways.
I think $250k stolen should definitely get a priority to be investigated by agents over $2k stolen as it is more likely it will mess up lives of many people in a bad way.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#240So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…