Earlier quoted context omitted.
What is better? Authenticator apps/hardware devices?
Most Dutch banks (except for ING, which does still use SMS) use hardware devices that use the chip on your debit card to authenticate. You unlock the chip with your PIN, enter the challenge code supplied by the banking website for the transaction, and the device shows you a one time code you enter in the banking website. This is a decade old technology that works rather well.
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
251–260 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#252Great. Now that we've succeeded in compiling a list of personal sad stories to one up one another, why not not discuss how we could encourage the banks / phone companies to make this situation impossible. 1) Ban SMS as a second factor for high risk targets like banks. 2) Telecom companies should require social security number or uniquely identifying information to provide account access. 3) ???
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#253So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…
It seems Google Voice is US only, and a bit abandoned. From the UK, the website throws various errors, and searching for "Google Voice" in Apple's App Store just shows spam apps.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#254Earlier quoted context omitted.
Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.
Thats exactly why I copy and save every 2fa QR Code in my KeePass database, along with backup codes. Phone changed? No worries, install Google Auth, rescan those QRs, and voila, your 2fa system is back and running !! :)
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#255Earlier quoted context omitted.
Do you usually have your life savings in a checking bank account and not in an IRA account? Shouldn't that has more red-flags for the bank. I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft.
I have all my life savings in a checking account. So in my case if I got hacked and my money from that account stolen I would be in big trouble and have suicidal thoughts very likely. >>I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft. Absolutely not. Ignore the case when this 250k was your entire life savings (30-40 years of saving remainder of your salary eve…
I am going away from SMS based 2FA where I can. For services where it is used, anyone have opinions on using 2FA via a SMS to VOIP number with a provider who has better account security/authentication tools than most telcos (e.g. google, etc)?
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#256Earlier quoted context omitted.
I have all my life savings in a checking account. So in my case if I got hacked and my money from that account stolen I would be in big trouble and have suicidal thoughts very likely. >>I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft. Absolutely not. Ignore the case when this 250k was your entire life savings (30-40 years of saving remainder of your salary eve…
Interesting. When two crimes both take similar effort to commit, and similar effort to investigate, I'm not sure if the higher dollar amount should be defacto prioritized. I am going away from SMS based 2FA where I can. For services where it is used, anyone have opinions on using 2FA via a SMS to VOIP number with a provider who has better account security/authentication tools than most telcos (e.g. google, etc)?
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#257Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#258A few months ago I took 3 of my 4 kids to a birthday party at a minigolf course. I played some holes with my youngest I had taken with me, and then left the two older ones at the birthday party with the understanding that their mother would pick them up (as we had discussed earlier) After leaving the party with my youngest, I went to the grocery store, and then on home. When I got home my wife was gone, which I expec…
"Apparently after I had left, someone went into a T-Mobile store and somehow convinced the associate that my number was theirs." How that can happen? When I visit my cell provider's store, nobody is going to talk about any account details while you haven't provided a government issued ID to prove that you are an account holder. Sure, it's not 100% bulletproof method, but if somebody went a great lengths to counterfei…
The point is that by using an SMS as 2fa, is placing much of your security in underpaid cell phone store workers.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#259Could you convince a cell phone store rep that you are who you say you are without your drivers license?
Or, for a million bucks, could you make a cell phone store rep think you were someone else?
The answer is why SMS 2fa isn't such a great idea. Because your security checkpoint is owned by a (underpaid) store representative.