[0]: https://en.wikipedia.org/wiki/Alice_and_Bob#Cast_of_characte...
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
311–320 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#312Earlier quoted context omitted.
Interesting. When two crimes both take similar effort to commit, and similar effort to investigate, I'm not sure if the higher dollar amount should be defacto prioritized. I am going away from SMS based 2FA where I can. For services where it is used, anyone have opinions on using 2FA via a SMS to VOIP number with a provider who has better account security/authentication tools than most telcos (e.g. google, etc)?
"I'm not sure if the higher dollar amount should be defacto prioritized." Why not? Higher net worth equates to higher taxes paid - the 250k victim has been paying the investigators a more substantial sum, and should receive a more substantial response from them. "Size matters" sums it up to me.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#313Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#314Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#315Earlier quoted context omitted.
Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.
adb backup com.google.android.apps.authenticator2 all the codes are stored in the sqlite3 database which you can open with standard command line tools. there are also more user friendly backup apps such as helium, but adb works quite nicely.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#316Earlier quoted context omitted.
Could you elaborate on why Authy is not safe? In my setup, 1) after adding the devices I wanted to add, I've disabled multi-device (which keeps the existing devices, but prohibits adding new devices), 2) for new devices, it requires a backup password (once) to decrypt the credentials retrieved from the cloud, and 3) IIRC, it requires authorisation from one of the trusted devices to add a further device. All in all, i…
How well do you trust the customer service rep at Authy against social engineering? Especially when someone has control over your email, phone, and potentially many other accounts already.
1) I trust them ever so slightly more than your average off-shored telco rep.
2) AFAIK, they do not hold the credentials in unencrypted form, they're only decrypted on the device with the backup password.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#317Earlier quoted context omitted.
> 1. I believe it began with the hacker getting DOB/SSN We [the US] dramatically over-rely on SSN. At least one upside to ubiquitous biometrics will be that we can start layering more authentication measures in an effective and consumer friendly way.
Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. These things are not secret, and having me say mine does not prove that you're talking to me.
I honestly don't see how you didn't just restate what I said with different language, while simultaneously saying you disagree with me.
Either way, I agree, and don't really think this is worth a cyber-argument so not sure if I should even be responding. Oh well.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#318Earlier quoted context omitted.
The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…
Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.
I had somebody buying products on Amazon using my company's IBAN numbers. Amazon were super frustrating to deal with. They kept asking for my amazon account details and I kept explaining that the company doesn't have an amazon account. They didn't know how to proceed ! But in the end they did reverse the charge.
My girlfriend had somebody buying groceries using her numbers. They just write numbers in and signed the sheet of paper at the store. The store refused to take responsibility for doing this without ID-ing the person. The police were more understanding.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#319Earlier quoted context omitted.
I don't doubt that. In my experience sometimes a phone number is required and sometimes not. When it prompted for a phone I didn't find a way to work around that.
I find that when I create a dummy account from a clean browser (no cookies) with a VPN, a phone number is required. I wouldn't be surprised if they do some internal risk/dodginess assessment based on several factors.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#320So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…
The problem with this otherwise good idea is that google will not allow you to keep this account as an island.
Eventually you will get the "we've noticed something suspicious about your account" dialog which requires entering some other, unrelated phone number. You're locked out until you do so.
The suspicious behavior is, of course, signing up without a live phone number.
Ironically, they will accept any number you input with no verification that it is related to the account in any way. They just want to see a live, carrier number input.
(This has been my experience from within the US)