For 2FA I like how Microsoft does it. You have an app on your phone. When they need to authorize you, they push to the all and it automatically pops up with approve and decline buttons. You verify the code is the same on the phone and screen and hit approve. It's an easier workflow than having to open Google authenticator, find the code, and enter it.
Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
331–340 of 382 posts
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#332Earlier quoted context omitted.
Yes, ID check is easily circumvented. People are the weakest link. The store reps are not government officials or police officers, nor do they scan ids. They may be convinced not to check your if, accept an id that isn't your drivers license, or anything else. The point is that by using an SMS as 2fa, is placing much of your security in underpaid cell phone store workers.
"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#333Earlier quoted context omitted.
Jeremy Clarkson made a similar argument and even published his bank details. Then this happened: http://news.bbc.co.uk/1/hi/7174760.stm
For SEPA (Single European Payment Area) direct debits, you have 8 weeks to get a full and immediate refund. I'd assume that holds for the UK as well. Many companies (and individuals) in Europe publish their account numbers on their letter head and website, it really isn't a big deal. Anything else seems security by obscurity.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#334Earlier quoted context omitted.
it seems #freemarket is putting externalities (security) on the customer. More like corporatist government regulations are putting the burden on the customer.
My CEO went to a local large bank and demanded as a condition of his business with them that they have an out-of-band communication (a phone call or SMS or whatever) with him before any outbound wire transaction can be attempted. They rejected his condition because they interpreted it as both (1) added liability due to all of the customers that could potentially claim they should have been similarly protected and (2)…
A requirement "out-of-band communication [..] before any outbound wire transaction can be attempted" easily turns the processing cost (not price) from $0.02 to $20+ per transaction, a thousandfold increase, and that's assuming that this'd be offered as standard product and not a special case for a single customer.
If it's not made as a standard product, then it's really painful - it would mean that either the whole staff&systems would have to be trained for that customers needs (not likely unless you're bringing 10+% of the whole bank's revenue) or the customer wouldn't be able to use any standard banking channels ever, not the normal branches, not the normal online services, not the normal call centres, only directly through your private bankers.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#335Earlier quoted context omitted.
Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. These things are not secret, and having me say mine does not prove that you're talking to me.
> Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. I honestly don't see how you didn't just restate what I said with different language, while simultaneously saying you disagree with me. Either way, I agree, and don't really think this is worth a cyber-argument so not sure if I should even be responding. Oh well.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#336Earlier quoted context omitted.
"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.
Having access to potentially thousands of dollars from cleaning up victim's accounts is an incentive to go and obtain a fake ID. Do the store clerks scan and verify that the ID is genuine somehow (check against a database, look at the photo) or do they just look at it in passing and give it back.
It may happen with certain large scale scams involving organized crime, but not for small amounts; it simply doesn't show up in practice. What does happen is use of real IDs that are stolen (or bought from homeless people), but most places that have some risks have access to registries where they can verify if the ID has been reported as stolen.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#337Earlier quoted context omitted.
"The store reps are not government officials or police officers, nor do they scan ids." Neither they are here (in EU), but nobody is going to talk to you unless you provide an ID anyway. Asking for ID doesn't seem too hard, even for non-trained personnel. You don't have to be a detective to match name/code on ID with the name/code on account.
Sure, but the excuse is then, "I had everything stolen! My phone, my wallet, etc. I just need to get my phone back so I can pay my rent and get an Uber to the DMV to get my new license." Then if the clerk says, "Sorry can't help you until you have an ID," you freak out and start yelling and the manager comes over and says, "I'm so sorry sir, let's get this worked out," and does whatever you ask him to.
I mean, as soon word would get out that some company allows that, they'd be exploited for free stuff in large amounts; all of the obvious loopholes have been tried and plugged in the last couple decades. USA has the problems only because they treat it as "stolen identity" instead of "someone defrauded a company with fake ID", and don't have proper universal IDs and try to make do with a mishmash of driver licences, names, addresses, SSNs, etc.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#338Earlier quoted context omitted.
Yea, my wife uses a physical token generator now, and I use the app which is bound to my phone. Someone would have to physically have my phone (and unlock it) in order to access my bank now.
Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.
I recall a case where an important customer was stuck abroad with everything stolen; they were sent replacement tokens and cards to be received at the embassy, which could properly ID them.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#339Earlier quoted context omitted.
Last I checked, adb backup doesn't backup the secrets. Has that changed?
I don't know but I've been using this technique for a year or two now with great success. The Google authenticator just stores its secrets in the salute db every app gets.
Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts
#340Earlier quoted context omitted.
Are you sure your bank wouldn't allow someone to disable it over the phone like they allowed someone to change your password? People lose cell phones just as they forget passwords, so there is surely a way for customer support to deal with it.
In such cases the bank would offer to send new tokens by physical mail to the registered address or receive them in a branch with proper ID. I recall a case where an important customer was stuck abroad with everything stolen; they were sent replacement tokens and cards to be received at the embassy, which could properly ID them.