Earlier quoted context omitted.
Yes, ID check is easily circumvented. People are the weakest link. The store reps are not government officials or police officers, nor do they scan ids. They may be convinced not to check your if, accept an id that isn't your drivers license, or anything else. The point is that by using an SMS as 2fa, is placing much of your security in underpaid cell phone store workers.
"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
291–300 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#292Earlier quoted context omitted.
I would expect greater risk if I spread that information around more. Is it really better if only 1/3rd of my passwords are stolen, at least relative to the 3x risk I face by using multiple sources?
I'm not sure I get the idea. My idea is to have two password databases. One is the usual, for the passwords. Another is infrequently opened and is used for the recovery codes and insecurity questions. I don't see how a secondary normally-closed password vault would degrade security. It's still encrypted, and safe. On the contrary, it should increase security a little - for the abovementioned local malware scenario. P…
1/3rd / 3x was based on the idea of splitting my passwords across 3 databases. Let's take your idea instead.
My concern was that if there is a risk of compromise, by using two different software solutions you've doubled the odds that a vulnerability will expose your data. (I once consulted for a company that had two data centers for high availability, but they had split their production services across the data centers, effectively doubling the odds of an outage instead of reducing their exposure.)
If instead you use the same software and two different data stores, I can see a benefit in having a store that you rarely open, but I'm not sure it outweighs the extra work, at least for me. If someone grabs my password store, having the security questions and answers protected would only help for a few accounts (admittedly, my bank being an important one) and the protection would only last as long as it took an attacker to social engineer their way past it.
I admit, now that you've raised the issue I'm going to at least think about moving my bank q&a info, but I doubt I'll go to the trouble; I suspect I'd either end up forgetting how to get to the credentials or leaving them somewhere someone could get at them.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#293Earlier quoted context omitted.
Not true. They offer insurance only to military families. Banking is open to anyone. EDIT: This is no longer true as of 2013.
Are you sure? At the link listed below, it seems that it's only available for military. https://www.usaa.com/join/start/?productId=bank-checking-cla...
They've grandfathered in existing members who wouldn't qualify today.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#294Earlier quoted context omitted.
Sadly, USAA is only open to military service members and their kids. That would be my choice if I could use it.
Not true. They offer insurance only to military families. Banking is open to anyone. EDIT: This is no longer true as of 2013.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#295Earlier quoted context omitted.
I have all my life savings in a checking account. So in my case if I got hacked and my money from that account stolen I would be in big trouble and have suicidal thoughts very likely. >>I'm not saying that investigating the $250k is not important; but just not more urgent than the $2k theft. Absolutely not. Ignore the case when this 250k was your entire life savings (30-40 years of saving remainder of your salary eve…
Interesting. When two crimes both take similar effort to commit, and similar effort to investigate, I'm not sure if the higher dollar amount should be defacto prioritized. I am going away from SMS based 2FA where I can. For services where it is used, anyone have opinions on using 2FA via a SMS to VOIP number with a provider who has better account security/authentication tools than most telcos (e.g. google, etc)?
Why not? Higher net worth equates to higher taxes paid - the 250k victim has been paying the investigators a more substantial sum, and should receive a more substantial response from them. "Size matters" sums it up to me.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#296Earlier quoted context omitted.
REAL 2fa with SMS is marginally safer (but not much more so), since it requires password and SMS to do anything. The problem is that nearly every single 2fa setup out there does something radically stupid such as use your 2fa method for password reset, or a combination of 2fa + email. This is horribly, horribly broken and worse than "no 2fa at all." All it takes is a SIM clone to steal your phone #, which you use to…
Could you elaborate on why Authy is not safe? In my setup, 1) after adding the devices I wanted to add, I've disabled multi-device (which keeps the existing devices, but prohibits adding new devices), 2) for new devices, it requires a backup password (once) to decrypt the credentials retrieved from the cloud, and 3) IIRC, it requires authorisation from one of the trusted devices to add a further device. All in all, i…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#297Can anyone recommend a US based bank (or a bank that accepts US customers) that 1) has either a 2FA token for phone e.g. with Google Authenticator, a hardware token, or some kind of other token based factor; and 2) has strong security when calling? I generally don't need a physical presence. My current two banks don't have direct 2FA enabled. As far as I remember, the questions available to one of my banks (credit un…
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#298Earlier quoted context omitted.
> Yeah, Identity theft is one of those crimes where the authorities don't really care. There is no such thing as "identity theft". You can't steal who someone is, that's bullshit. It's rather some party not making sure it's actually you they are talking to, and then claiming that you are responsible for it anyway because they fell for someone else's scam.
And piracy is an act of robbery on the high seas. When the name sticks, there's usually nothing we can do. Sad but true.
We should call it what it is: fraud. Whether that's bank fraud, computer fraud or wire fraud, banks should be responsible for compensating individuals for the losses incurred. One way to encourage this change is a change in the language we use surrounding these crimes.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#299This happened to me. 1. I believe it began with the hacker getting DOB/SSN. 2. Called wireless provider, and hacker forward all calls and texts to a burn phone. Eventually, the hacker ported my wireless phone to another provider/number (not sure which), and the phone registered to my provider did not work anymore. The landline phone was also forwarding calls to another number.* 3. Hacker gained access to email (as th…
> 1. I believe it began with the hacker getting DOB/SSN We [the US] dramatically over-rely on SSN. At least one upside to ubiquitous biometrics will be that we can start layering more authentication measures in an effective and consumer friendly way.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#300Earlier quoted context omitted.
Or use a Google Voice number to setup 2FA on the same account. That way you can only ever login if you have a device on your person already logged in. If somehow you're away from technology long enough that all your devices are locked, use a printed backup code to unlock one.
But, if you use Google Voice number on your other Gmail account, they say it's not recommended because you can get locked out of both. I think you can use Google Voice number on everything other than your main Gmail account. So, to be extra safe, after you've set up your 2FA for gmail, make sure to change your recovery phone # to something other than your main telco or google voice number.