Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

301–310 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#301
post #104

Last year when I upgraded my phone I was amused — but mostly horrified — by how easily one could get a SIM card for my own phone number with less than a modicum of information on me. As I required to upgrade my Micro SIM to a Nano SIM, I went to one of my provider's shops and asked for a Nano SIM for phone number X. I was then asked to verbally confirm my name and address — and that's it. No ID card confirmation, no…

Exact same thing happened to me. Upgraded my phone, needed to switch over to nano sim, walked into T-Mobile and chatted up the sales clerk and then walked out with my new nano sim without showing ID. I was dumb founded that it was so easy.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#302
It seems a simple solution would be for the phone company to send a confirmation SMS or automated voice call to confirm number porting or any other major action. Is there a reason they don't do this? It seems like a good balance between convenience and security.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#303
Someone should write a comprehensive guide on how to protect your accounts while preventing yourself from being locked out of said accounts.

Seems like some combination of the following:

* using Google Voice for all account recovery situations that require a phone number

* Calling your cell phone provider to have a note that states do not allow for number porting

* Use hardware 2fa tokens. Have two setup, one as a backup in case you lose one.

* Keep a copy of your recovery codes somewhere accessible

* Probably have a safety deposit box with your backup 2fa token and recovery codes stored.

* Primary email provider should use a hardware token and not have sms recovery

* Use unique passwords everywhere and use a password manager

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#304

It seems a simple solution would be for the phone company to send a confirmation SMS or automated voice call to confirm number porting or any other major action. Is there a reason they don't do this? It seems like a good balance between convenience and security.

There was this recent case showing how not to do this feature. https://medium.com/@CodyBrown/how-to-lose-8k-worth-of-bitcoi...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#305

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

There are also measures that can be taken when using SMS based MFA, via services that check if the SMS is forwarded to a burner phone, or do a SIM check with the phone. In addition the SMS based MFA services should be leveraging fraud score and number deactivation checks for the target numbers to catch the most obvious fraud scenarios.

Not sure a lot of the companies providing these services actually do that though. And all-in-all, non-SMS based MFA is going to be better anyway.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#306

Someone should write a comprehensive guide on how to protect your accounts while preventing yourself from being locked out of said accounts. Seems like some combination of the following: * using Google Voice for all account recovery situations that require a phone number * Calling your cell phone provider to have a note that states do not allow for number porting * Use hardware 2fa tokens. Have two setup, one as a ba…

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#307
post #298

Earlier quoted context omitted.

And piracy is an act of robbery on the high seas. When the name sticks, there's usually nothing we can do. Sad but true.

The problem with the phrase "identity theft" is that it puts the onus of security onto the consumer to secure their personal details instead of onto the bank/telcos/etc to secure their systems. We should call it what it is: fraud. Whether that's bank fraud, computer fraud or wire fraud, banks should be responsible for compensating individuals for the losses incurred. One way to encourage this change is a change in th…

> The problem with the phrase "identity theft" is that it puts the onus of security onto the consumer to secure their personal details instead of onto the bank/telcos/etc to secure their systems.

And it's really even worse than that, as you are assigned blame for something that the party blaming you is itself forcing you to do. Like, they won't open an account for you unless you tell them your SSN, but then they blame you if you don't keep your SSN secret.

It's reasonable to some degree to expect that you keep your password secret. It's a different thing altogether to take information that is unavoidably known to lots of parties, or in many cases even outright essentially public info (like, stuff you can just buy as a database) as proof of identity, and then insist that you are legally responsible for a contract or whatever they made with someone who knew your DOB or something.

It's really not much different than just throwing darts at a phone book, and then pretending that the fact they hit your name proves that you now have a contract with them ... no, it doesn't, and it's your fucking problem if you think it does.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#308

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

so why do well-respected companies like Google and Stripe do it?

They also (most likely) include many other, even network packet level checks in addition to primary and secondary authentication. Its not as simple as it looks to the honest end user.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#309

Earlier quoted context omitted.

Or use a Google Voice number to setup 2FA on the same account. That way you can only ever login if you have a device on your person already logged in. If somehow you're away from technology long enough that all your devices are locked, use a printed backup code to unlock one.

But, if you use Google Voice number on your other Gmail account, they say it's not recommended because you can get locked out of both. I think you can use Google Voice number on everything other than your main Gmail account. So, to be extra safe, after you've set up your 2FA for gmail, make sure to change your recovery phone # to something other than your main telco or google voice number.

Same account. You can use the Google Voice number to 2FA its associated gmail account. A printed backup key will protect you from getting permanently locked out. But nobody will be able to login without physical access to your device or printed key.

This is how 2FA was meant to work. It should always require a physical device only you have access to. Otherwise it's just using 1FA two times.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#310
post #287

Earlier quoted context omitted.

Chase has 2FA with a token. See: https://www.jpmorgan.com/tss/General/Improved_Security_and_1...

Is that for Chase, or J.P. Morgan? My understanding is that Chase doesn't offer a 2FA besides SMS and when I go into my account settings I don't see anything that lets me enable 2FA.

Same.
Post reply on HN