Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

231–240 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#231
post #222

Earlier quoted context omitted.

> When signing up for a new Gmail, you don’t need to enter a phone number This is not true in general. It probably at least depends on the country you try to sign-up from probably other factors.

Gmail didn't mandate phone number the last time I created dummy account (~1 month ago). I don't have phone number linked even with my primary account.

I don't doubt that. In my experience sometimes a phone number is required and sometimes not. When it prompted for a phone I didn't find a way to work around that.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#232

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

Is 2fa with SMS safer or less safe than no 2fa at all?

REAL 2fa with SMS is marginally safer (but not much more so), since it requires password and SMS to do anything.

The problem is that nearly every single 2fa setup out there does something radically stupid such as use your 2fa method for password reset, or a combination of 2fa + email. This is horribly, horribly broken and worse than "no 2fa at all." All it takes is a SIM clone to steal your phone #, which you use to reset the email, and then email + phone/SMS can be used to reset nearly every single credential under the sun. The only exceptions are those that use proper 2FA such as one-time password apps -- but not Authy which just syncs your OTP/2fa credentials to the cloud and happily transfers to the cloned device :(

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#233

Earlier quoted context omitted.

To be fair, you really don't own a domain. You still rely on the TLD honoring your purchase and not hand it over to someone else in the same way you rely on the phone company to treat your number as yours.

Some domain registrars are so completely incompetent (ie Dotster), I'm disappointed they're still in business. Literally clueless "customer support" staff that either don't auth (experienced that personally), or refuse to follow the written rules to everyone's detriment. Recent example: https://issues.apache.org/jira/browse/INFRA-13657 Note - Don't use Dotster (specifically) for your domains. If you're using them now…

At least you have a legal path:

https://www.google.com/amp/s/www.forbes.com/sites/theyec/201...

Not exactly an easy thing to do with a phone number.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#234

Earlier quoted context omitted.

In Singapore they give us a physical token. We have to enter the 2Fa we receive into it to receive a third code to enter into the website. Well I guess it's 3Fa. It is a bit of a hassle but better safe than sorry.

Seriously, I don't understand why physical tokens are not the norm and standardized on all devices, still. It isn't a new concept at all.

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#235
post #169

Earlier quoted context omitted.

Authenticators are fine but u2f keys are better because they protect against phishing.

Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.

Authy allows multiple devices (and encrypted backups) - that ensures fairly good security (if good password is chosen) and availability, doesn't it?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#236
"If you follow several of the steps I outline in this story (unless you go with Google Voice), you’ll end up with at least three email addresses: your current primary one, one just for your mobile carrier, and one that you use for other sensitive accounts such as online banking or Facebook or Dropbox."

Why not just have all sites that require SMS 2FA (there are a lot, including tele co.s) be directed to a personal google voice number? And also remove the any SMS 2FA from this google and your personal? Wouldn't that solve the issue they are suggesting? Why do you need a third account?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#237
post #198
post #172

Earlier quoted context omitted.

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

Jeremy Clarkson made a similar argument and even published his bank details. Then this happened: http://news.bbc.co.uk/1/hi/7174760.stm

For SEPA (Single European Payment Area) direct debits, you have 8 weeks to get a full and immediate refund. I'd assume that holds for the UK as well.

Many companies (and individuals) in Europe publish their account numbers on their letter head and website, it really isn't a big deal.

Anything else seems security by obscurity.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#239
post #217

Earlier quoted context omitted.

>> If you have $250k stolen, it is bad but you are probably wealthy enough you won't go in deep trouble stress. Or it might be your entire life's savings and if you can't get it back you kill yourself from the stress of losing 40+ years of work. It's very dangerous to make assumptions about other people's money.

Do you usually have your life savings in a checking bank account and not in an IRA account? Shouldn't that has more red-flags for the bank. I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft.

I have all my life savings in a checking account. So in my case if I got hacked and my money from that account stolen I would be in big trouble and have suicidal thoughts very likely.

>>I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft.

Absolutely not. Ignore the case when this 250k was your entire life savings (30-40 years of saving remainder of your salary every month and slowly building savings for retirement).

It could be mortgage money which you are about to buy a house with or it could be company money for payroll. Suddenly employees of a small business don't get paid. Those employees of course have to pay mortgage/rent/medical bills and suddenly paycheck they counted on doesn't come. This could affect many people in very negative ways.

I think $250k stolen should definitely get a priority to be investigated by agents over $2k stolen as it is more likely it will mess up lives of many people in a bad way.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#240

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

It seems Google Voice is US only, and a bit abandoned. From the UK, the website throws various errors, and searching for "Google Voice" in Apple's App Store just shows spam apps.
Post reply on HN