Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

321–330 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#321

Earlier quoted context omitted.

Some domain registrars are so completely incompetent (ie Dotster), I'm disappointed they're still in business. Literally clueless "customer support" staff that either don't auth (experienced that personally), or refuse to follow the written rules to everyone's detriment. Recent example: https://issues.apache.org/jira/browse/INFRA-13657 Note - Don't use Dotster (specifically) for your domains. If you're using them now…

At least you have a legal path: https://www.google.com/amp/s/www.forbes.com/sites/theyec/201... Not exactly an easy thing to do with a phone number.

[deleted]

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#322

Earlier quoted context omitted.

> 1. I believe it began with the hacker getting DOB/SSN We [the US] dramatically over-rely on SSN. At least one upside to ubiquitous biometrics will be that we can start layering more authentication measures in an effective and consumer friendly way.

Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. These things are not secret, and having me say mine does not prove that you're talking to me.

In my (shared) office, everyone knew each other's last 4 SSN digits, because whenever on the phone to some random customer service rep, we had to give them to "authenticate".

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#323

Earlier quoted context omitted.

adb backup com.google.android.apps.authenticator2 all the codes are stored in the sqlite3 database which you can open with standard command line tools. there are also more user friendly backup apps such as helium, but adb works quite nicely.

Last I checked, adb backup doesn't backup the secrets. Has that changed?

I don't know but I've been using this technique for a year or two now with great success. The Google authenticator just stores its secrets in the salute db every app gets.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#324
post #65

A few months ago I took 3 of my 4 kids to a birthday party at a minigolf course. I played some holes with my youngest I had taken with me, and then left the two older ones at the birthday party with the understanding that their mother would pick them up (as we had discussed earlier) After leaving the party with my youngest, I went to the grocery store, and then on home. When I got home my wife was gone, which I expec…

Without meaning to pick on T-Mobile, the stories I'm hearing here, including yours, lead me to believe that T-Mobile is liable for damages. As in, they didn't take reasonable precautions to safeguard your account, and you suffered financial damages as a result.

I am generally of the philosophy that you should trust no one to do the right thing, but these cases seem to be overlooking the obvious that the phone companies are fucking up on security.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#325
post #26

Earlier quoted context omitted.

There’s a far worse example: PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices. Support for TOTP? HOTP? Nope.

Those proprietary 2FA devices are just TOTP with a weird provisioning system. You can use a tool such as https://github.com/dlenski/python-vipaccess to use google authenticator/freeotp etc. to access paypal. That said... I believe you still need a mobile number enrolled to enable a token.

Thanks! I didn't realize that was possible either. I just switched my paypal account to use google authenticator instead of sms, which besides being more secure, is much more convenient since I don't get cell reception in most of my apartment and have to put my phone near a window to get the sms.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#326

Earlier quoted context omitted.

"I'm not sure if the higher dollar amount should be defacto prioritized." Why not? Higher net worth equates to higher taxes paid - the 250k victim has been paying the investigators a more substantial sum, and should receive a more substantial response from them. "Size matters" sums it up to me.

That's not how modern Western societies work. Plutocracy has been tried, and found to be devastating for society, human dignity, and the human condition in general, not to talk about the rampant corruption it invites.

> "That's not how modern Western societies work."

Are you sure? Maybe you believe they shouldn't work that way, but do you believe they truly are blind to the net worth of the offended party?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#327
For 2FA I like how Microsoft does it. You have an app on your phone. When they need to authorize you, they push to the all and it automatically pops up with approve and decline buttons. You verify the code is the same on the phone and screen and hit approve. It's an easier workflow than having to open Google authenticator, find the code, and enter it.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#328
post #172

Earlier quoted context omitted.

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

it seems #freemarket is putting externalities (security) on the customer. More like corporatist government regulations are putting the burden on the customer.

My CEO went to a local large bank and demanded as a condition of his business with them that they have an out-of-band communication (a phone call or SMS or whatever) with him before any outbound wire transaction can be attempted. They rejected his condition because they interpreted it as both (1) added liability due to all of the customers that could potentially claim they should have been similarly protected and (2) too much effort/cost/resources/whatever.

I don't deny that there are _corporatist government regulations_ (which largely prevent the best qualified engineers/entrepreneurs from wanting to tackle the consumer fintech problems), but banks are dragging their feet and the #freemarket hasn't developed a viable alternative yet.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#329
post #65

A few months ago I took 3 of my 4 kids to a birthday party at a minigolf course. I played some holes with my youngest I had taken with me, and then left the two older ones at the birthday party with the understanding that their mother would pick them up (as we had discussed earlier) After leaving the party with my youngest, I went to the grocery store, and then on home. When I got home my wife was gone, which I expec…

Without meaning to pick on T-Mobile, the stories I'm hearing here, including yours, lead me to believe that T-Mobile is liable for damages. As in, they didn't take reasonable precautions to safeguard your account, and you suffered financial damages as a result. I am generally of the philosophy that you should trust no one to do the right thing, but these cases seem to be overlooking the obvious that the phone compani…

Large companies like cell providers have concentrated benefits and their customers have diffuse costs. They force a large contract on you (because they have an oligopoly and you have only ~4 or fewer realistic choices) and that contract almost always contains a "no class action" and a "forced arbitration" clause. While those clauses exist, we are at the mercy of cell providers. Potentially very large customers (large companies and governments) might be able to demand changes in the contract, but it's unlikely to automatically filter down to the individual consumer.

I'm starting to worry about similar weak process security on the part of the IRS and Social Security. You can theoretically opt out of using a cell phone, but it's far harder to opt out of government programs that are forced on you with the threat of state force.

Post reply on HN