Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

331–340 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#331
post #327

For 2FA I like how Microsoft does it. You have an app on your phone. When they need to authorize you, they push to the all and it automatically pops up with approve and decline buttons. You verify the code is the same on the phone and screen and hit approve. It's an easier workflow than having to open Google authenticator, find the code, and enter it.

Google is starting to do this as well. You get a push notification instead of entering the code.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#332
post #261

Earlier quoted context omitted.

Yes, ID check is easily circumvented. People are the weakest link. The store reps are not government officials or police officers, nor do they scan ids. They may be convinced not to check your if, accept an id that isn't your drivers license, or anything else. The point is that by using an SMS as 2fa, is placing much of your security in underpaid cell phone store workers.

"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.

Sure, but the excuse is then, "I had everything stolen! My phone, my wallet, etc. I just need to get my phone back so I can pay my rent and get an Uber to the DMV to get my new license." Then if the clerk says, "Sorry can't help you until you have an ID," you freak out and start yelling and the manager comes over and says, "I'm so sorry sir, let's get this worked out," and does whatever you ask him to.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#333
post #237
post #198

Earlier quoted context omitted.

Jeremy Clarkson made a similar argument and even published his bank details. Then this happened: http://news.bbc.co.uk/1/hi/7174760.stm

For SEPA (Single European Payment Area) direct debits, you have 8 weeks to get a full and immediate refund. I'd assume that holds for the UK as well. Many companies (and individuals) in Europe publish their account numbers on their letter head and website, it really isn't a big deal. Anything else seems security by obscurity.

For SEPA-DD, 8 weeks is for no questions asked refund; in general for non-authorised payments you have 13 months to request a refund, but if it's 8+ weeks they can verify the lack of direct debit mandate before hand - but it seems to be the policy of most banks that they'll refund anyway immediately and let the merchant handle the problems.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#334

Earlier quoted context omitted.

it seems #freemarket is putting externalities (security) on the customer. More like corporatist government regulations are putting the burden on the customer.

My CEO went to a local large bank and demanded as a condition of his business with them that they have an out-of-band communication (a phone call or SMS or whatever) with him before any outbound wire transaction can be attempted. They rejected his condition because they interpreted it as both (1) added liability due to all of the customers that could potentially claim they should have been similarly protected and (2)…

The business model of all fintech is to ensure straight-through processing for as close to 100% of transactions as possible; if you have slightly more manual processing than competitors, then you can't be competitive price-wise.

A requirement "out-of-band communication [..] before any outbound wire transaction can be attempted" easily turns the processing cost (not price) from $0.02 to $20+ per transaction, a thousandfold increase, and that's assuming that this'd be offered as standard product and not a special case for a single customer.

If it's not made as a standard product, then it's really painful - it would mean that either the whole staff&systems would have to be trained for that customers needs (not likely unless you're bringing 10+% of the whole bank's revenue) or the customer wouldn't be able to use any standard banking channels ever, not the normal branches, not the normal online services, not the normal call centres, only directly through your private bankers.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#335

Earlier quoted context omitted.

Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. These things are not secret, and having me say mine does not prove that you're talking to me.

> Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. I honestly don't see how you didn't just restate what I said with different language, while simultaneously saying you disagree with me. Either way, I agree, and don't really think this is worth a cyber-argument so not sure if I should even be responding. Oh well.

It would be just fine to rely on SSN as an identifier, even to a much larger scale as USA does now, if only it would be clearly assumed that this number isn't secret.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#336
post #291
post #261

Earlier quoted context omitted.

"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.

Having access to potentially thousands of dollars from cleaning up victim's accounts is an incentive to go and obtain a fake ID. Do the store clerks scan and verify that the ID is genuine somehow (check against a database, look at the photo) or do they just look at it in passing and give it back.

From an EU perspective, obtaining a fake ID isn't that likely - counterfeiting anything certainly is possible, but it's hard and expensive (harder than counterfeiting money), risky (being caught with a fake means jail time, it's a more severe crime than theft and there's no "take-backsies" if they don't like the ID) so fraud with fake IDs is extremely rare.

It may happen with certain large scale scams involving organized crime, but not for small amounts; it simply doesn't show up in practice. What does happen is use of real IDs that are stolen (or bought from homeless people), but most places that have some risks have access to registries where they can verify if the ID has been reported as stolen.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#337
post #261

Earlier quoted context omitted.

"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.

Sure, but the excuse is then, "I had everything stolen! My phone, my wallet, etc. I just need to get my phone back so I can pay my rent and get an Uber to the DMV to get my new license." Then if the clerk says, "Sorry can't help you until you have an ID," you freak out and start yelling and the manager comes over and says, "I'm so sorry sir, let's get this worked out," and does whatever you ask him to.

Not happening in EU - since in such a case the company not verifying the ID tend to get liability for losses, all companies have policies where such managers are prohibited to do so; they would be risking their own money (and job) for giving you stuff without proper authorisation.

I mean, as soon word would get out that some company allows that, they'd be exploited for free stuff in large amounts; all of the obvious loopholes have been tried and plugged in the last couple decades. USA has the problems only because they treat it as "stolen identity" instead of "someone defrauded a company with fake ID", and don't have proper universal IDs and try to make do with a mishmash of driver licences, names, addresses, SSNs, etc.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#338
post #141
post #123

Earlier quoted context omitted.

Yea, my wife uses a physical token generator now, and I use the app which is bound to my phone. Someone would have to physically have my phone (and unlock it) in order to access my bank now.

Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.

In such cases the bank would offer to send new tokens by physical mail to the registered address or receive them in a branch with proper ID.

I recall a case where an important customer was stuck abroad with everything stolen; they were sent replacement tokens and cards to be received at the embassy, which could properly ID them.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#339

Earlier quoted context omitted.

Last I checked, adb backup doesn't backup the secrets. Has that changed?

I don't know but I've been using this technique for a year or two now with great success. The Google authenticator just stores its secrets in the salute db every app gets.

Autocorrect kicked in there... sqlite* (it is absurdly difficult to put an asterisk at the end of a message on HN. it seems to require a trailing whitespace[1] for it to show up, however the input is trimmed, so...)

[1] https://news.ycombinator.com/formatdoc

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#340
post #141

Earlier quoted context omitted.

Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.

In such cases the bank would offer to send new tokens by physical mail to the registered address or receive them in a branch with proper ID. I recall a case where an important customer was stuck abroad with everything stolen; they were sent replacement tokens and cards to be received at the embassy, which could properly ID them.

Why can a bank have such a robust procedure for replacing tokens, and be trusted to follow it, but not have a similarly robust procedure for handling password resets?
Post reply on HN