Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

271–280 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#271
What's funny is... my Bank does not allow me to use any special characters and for the investor accounts numerical only. They do not have 2FA either.

CIBC Canada

Addendum also several of my purchases were flagged as hacked purchases by them and I had to call them three times so far this year. All purchases from same Amazon account, same IP too. So I do not think they have a good services team.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#272
post #232

Earlier quoted context omitted.

Is 2fa with SMS safer or less safe than no 2fa at all?

REAL 2fa with SMS is marginally safer (but not much more so), since it requires password and SMS to do anything. The problem is that nearly every single 2fa setup out there does something radically stupid such as use your 2fa method for password reset, or a combination of 2fa + email. This is horribly, horribly broken and worse than "no 2fa at all." All it takes is a SIM clone to steal your phone #, which you use to…

Could you elaborate on why Authy is not safe? In my setup,

1) after adding the devices I wanted to add, I've disabled multi-device (which keeps the existing devices, but prohibits adding new devices),

2) for new devices, it requires a backup password (once) to decrypt the credentials retrieved from the cloud, and

3) IIRC, it requires authorisation from one of the trusted devices to add a further device.

All in all, it seems much better (in terms of the security/availability trade-off) than Google Authenticator. But I've read opinions similar to yours a few times, and I wonder where they come from, whether they've been reasonable in the past, and whether they still are.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#273

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

It seems Google Voice is US only, and a bit abandoned. From the UK, the website throws various errors, and searching for "Google Voice" in Apple's App Store just shows spam apps.

Not abandoned - The past year Google has been pushing updates; including a new websites and mobile apps (finally)!

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#274
A few weeks ago I was vacationing in Big Bend National Park, which is in a remote corner of Texas. When trying to pay for our breakfast, my credit card was declined.

On the phone with them, they said the card had been flagged as being used in fraud because we were off in the middle of nowhere, away from our normal spending patterns. The ONLY way to reactivate the card is for the CC company to SMS text us with a code, which we have to read back to them. The thing is, the very reason they flagged us - that we were way off in the middle of nowhere - also meant that we had no cell phone service, and couldn't receive the SMS. And given the vast size of Big Bend (getting out of the park from the hotel is a 45 minute drive), it was questionable if I'd be able to drive to a location with cell service if I couldn't fill my gas tank first.

The hotel manager overheard me arguing on the payphone with the credit card company, and he drew me a map of some pockets of cell service within the park, so in the end I was able to get it taken care of.

One ironic part of this was that the card is in my wife's name. When they wouldn't listen to her, she gave them verbal authorization to talk to me in her stead. They were willing to believe her identity for this, but not for the re-activation of the card, which doesn't make sense.

I also asked their CSR why they flagged the card. They said that I should always notify them if I'm going away. I asked them what the criteria is for that, since this was an in-state trip (I live in Austin, and Big Bend is also in Texas). The CSR said that's odd, and he doesn't know why that would happen.

So good for them that they watch for fraud, but the failure mode for their heuristic is the most catastrophic possible. If the very reason they flag me also prevents me from fixing the problem, then it's a rather badly-designed system.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#275
post #265

Can anyone recommend a US based bank (or a bank that accepts US customers) that 1) has either a 2FA token for phone e.g. with Google Authenticator, a hardware token, or some kind of other token based factor; and 2) has strong security when calling? I generally don't need a physical presence. My current two banks don't have direct 2FA enabled. As far as I remember, the questions available to one of my banks (credit un…

I know that USAA offers TOTP 2FA. Not sure about calling though.

Yes, but it's this janky Symantec-only implementation. AFAIK I'm unable to use a generic TOTP authenticator like Duo or GA.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#276

Earlier quoted context omitted.

I have all my life savings in a checking account. So in my case if I got hacked and my money from that account stolen I would be in big trouble and have suicidal thoughts very likely. >>I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft. Absolutely not. Ignore the case when this 250k was your entire life savings (30-40 years of saving remainder of your salary eve…

Interesting. When two crimes both take similar effort to commit, and similar effort to investigate, I'm not sure if the higher dollar amount should be defacto prioritized. I am going away from SMS based 2FA where I can. For services where it is used, anyone have opinions on using 2FA via a SMS to VOIP number with a provider who has better account security/authentication tools than most telcos (e.g. google, etc)?

I was using google voice for this for a while but if you are worried that someone may have access to your computer / email, then they may effectively access to your google voice as well. voice.google.com

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#277
post #268

Earlier quoted context omitted.

I know that USAA offers TOTP 2FA. Not sure about calling though.

Sadly, USAA is only open to military service members and their kids. That would be my choice if I could use it.

Not true. They offer insurance only to military families. Banking is open to anyone. EDIT: This is no longer true as of 2013.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#279
post #169

Earlier quoted context omitted.

Authenticators are fine but u2f keys are better because they protect against phishing.

What is a good u2f key you'd recommend?

Feitian NFC-compatible is nice because you can set up your Google Account on an Android phone with it: https://www.amazon.com/gp/aw/d/B01M1R5LRD/

If you're into cryptocurrency, the Trezor will also act as a U2F device.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#280
post #265

Can anyone recommend a US based bank (or a bank that accepts US customers) that 1) has either a 2FA token for phone e.g. with Google Authenticator, a hardware token, or some kind of other token based factor; and 2) has strong security when calling? I generally don't need a physical presence. My current two banks don't have direct 2FA enabled. As far as I remember, the questions available to one of my banks (credit un…

There are a handful of smaller banks or credit unions listed as accepting proper 2FA here. [0] I have no experience with any of them.

[0]https://twofactorauth.org/#banking

Post reply on HN