Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

281–290 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#281
post #96
post #84

Does anyone know if Project Fi provides any extra layers of security? I haven't seen anything

If anything the ability to get texts via the web makes it worse.

How so?

By which I mean... I think that doesn't make any sense but please elaborate.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#282
post #5

This has been the vector for Twitter hacks for many years. Get the 2nd factor

SMS is the 2nd factor. Actually it's worse than just a 2nd factor because a compromised phone number can usually be used for password recovery

You are confusing two different things.

The problem is one factor account recovery, because it means you have one factor auth.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#283

I am surprised no one here mentioned mooltipass https://www.themooltipass.com/

It's another gadget to carry arround, and if you lose it or forget it somewhere, you're SOL. Better have a KeePass2 database on your phone synced to a cloud storage. Even if the cloud account is compromised, without the KeePass password, your credentials should be safe. If you need, you can open the database using a webapp in any browser.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#285
post #265

Can anyone recommend a US based bank (or a bank that accepts US customers) that 1) has either a 2FA token for phone e.g. with Google Authenticator, a hardware token, or some kind of other token based factor; and 2) has strong security when calling? I generally don't need a physical presence. My current two banks don't have direct 2FA enabled. As far as I remember, the questions available to one of my banks (credit un…

Chase has 2FA with a token.

See: https://www.jpmorgan.com/tss/General/Improved_Security_and_1...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#286
post #277
post #268

Earlier quoted context omitted.

Sadly, USAA is only open to military service members and their kids. That would be my choice if I could use it.

Not true. They offer insurance only to military families. Banking is open to anyone. EDIT: This is no longer true as of 2013.

Are you sure? At the link listed below, it seems that it's only available for military.

https://www.usaa.com/join/start/?productId=bank-checking-cla...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#287
post #265

Can anyone recommend a US based bank (or a bank that accepts US customers) that 1) has either a 2FA token for phone e.g. with Google Authenticator, a hardware token, or some kind of other token based factor; and 2) has strong security when calling? I generally don't need a physical presence. My current two banks don't have direct 2FA enabled. As far as I remember, the questions available to one of my banks (credit un…

Chase has 2FA with a token. See: https://www.jpmorgan.com/tss/General/Improved_Security_and_1...

Is that for Chase, or J.P. Morgan? My understanding is that Chase doesn't offer a 2FA besides SMS and when I go into my account settings I don't see anything that lets me enable 2FA.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#288

A few weeks ago I was vacationing in Big Bend National Park, which is in a remote corner of Texas. When trying to pay for our breakfast, my credit card was declined. On the phone with them, they said the card had been flagged as being used in fraud because we were off in the middle of nowhere, away from our normal spending patterns. The ONLY way to reactivate the card is for the CC company to SMS text us with a code,…

This used to happen to me all the time with Lloyds "Worldwide Service". When I would travel, I would tell them ahead of time where and when, and inevitably the first time I used my card in another country it was declined and I'd need to call in to card security and clear it. Mind you this would cost a couple quid due to the overseas use of my phone. These weren't exotic locations either, it would happen in NYC.

Then one time to me it happened when I was exhausted after a very long flight, trying to check into a hotel. I got on the phone with them, sternly told them the history of events and the situation, and demanded to be compensated for the time and hassle otherwise I would switch banks. I pointed out their bank was misnamed "Worldwide Service". They put £100 in my account, and the problem seemed to go away after that point (I still needed to inform them ahead of time, but that did the trick).

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#290

Earlier quoted context omitted.

> Yeah, Identity theft is one of those crimes where the authorities don't really care. There is no such thing as "identity theft". You can't steal who someone is, that's bullshit. It's rather some party not making sure it's actually you they are talking to, and then claiming that you are responsible for it anyway because they fell for someone else's scam.

And piracy is an act of robbery on the high seas. When the name sticks, there's usually nothing we can do. Sad but true.

That example doesn't use word games to shift the loss to an uninvolved and innocent party.
Post reply on HN