Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

341–350 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#341
post #340

Earlier quoted context omitted.

In such cases the bank would offer to send new tokens by physical mail to the registered address or receive them in a branch with proper ID. I recall a case where an important customer was stuck abroad with everything stolen; they were sent replacement tokens and cards to be received at the embassy, which could properly ID them.

Why can a bank have such a robust procedure for replacing tokens, and be trusted to follow it, but not have a similarly robust procedure for handling password resets?

They definitely can, but some of them don't, especially in USA for various reasons.

I mean, any bank with proper procedures doesn't really have the concept of "online password" that's sufficient to do anything and makes 2FA mandatory; I believe in EU now it would be forbidden for a bank to have simply a username-password authentication.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#342

Earlier quoted context omitted.

That's not how modern Western societies work. Plutocracy has been tried, and found to be devastating for society, human dignity, and the human condition in general, not to talk about the rampant corruption it invites.

> "That's not how modern Western societies work." Are you sure? Maybe you believe they shouldn't work that way, but do you believe they truly are blind to the net worth of the offended party?

No, they are not. But ideally the advantage the 'richer' party has in influencing the effort of the investigators/judiciary to put forth more effort on their behalf is not written policy, it is corruption/cronyism. Should we create policy that prioritizes investigating an auto theft of a $100,000 automobile with more resources and severity that the theft of a $20,000 one, simply because the value is larger, or weight the effort based on the tax contribution of the victim? I would say absolutely not.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#343
post #320

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

"Once you’ve created the new island-unto-itself email address, create a new Google Voice number." Use this Google Voice # to secure your primary accounts, and don't have your telco # listed in any of those accounts." The problem with this otherwise good idea is that google will not allow you to keep this account as an island. Eventually you will get the "we've noticed something suspicious about your account" dialog w…

What an interesting way of increasing phone number data conversion rates.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#344
post #320

Earlier quoted context omitted.

"Once you’ve created the new island-unto-itself email address, create a new Google Voice number." Use this Google Voice # to secure your primary accounts, and don't have your telco # listed in any of those accounts." The problem with this otherwise good idea is that google will not allow you to keep this account as an island. Eventually you will get the "we've noticed something suspicious about your account" dialog w…

What an interesting way of increasing phone number data conversion rates.

Twitter does that too. At some point I created another account without specifying a phone number, posted a tweet from there and​ next thing you know they are flagging it for suspicious activity and asking for my phone number to unlock the account.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#345
post #265

Can anyone recommend a US based bank (or a bank that accepts US customers) that 1) has either a 2FA token for phone e.g. with Google Authenticator, a hardware token, or some kind of other token based factor; and 2) has strong security when calling? I generally don't need a physical presence. My current two banks don't have direct 2FA enabled. As far as I remember, the questions available to one of my banks (credit un…

They don't advertise this, but schwab offers 2fa with either a hardware token that they will ship you OR a 2FA token on your phone using https://m.vip.symantec.com/ . You have to call them up, but their customer service is pretty good.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#346

Earlier quoted context omitted.

> "That's not how modern Western societies work." Are you sure? Maybe you believe they shouldn't work that way, but do you believe they truly are blind to the net worth of the offended party?

No, they are not. But ideally the advantage the 'richer' party has in influencing the effort of the investigators/judiciary to put forth more effort on their behalf is not written policy, it is corruption/cronyism. Should we create policy that prioritizes investigating an auto theft of a $100,000 automobile with more resources and severity that the theft of a $20,000 one, simply because the value is larger, or weight…

I guess the theft of a more expensive car should be investigated with higher priority because selling it gives criminals more money to work with and leads to more severe crime. A group that can steal and sell a Lamborghini likely runs a much larger and more organized operation than a group which steals and sells old cheap cars.

This is all guessing though, I'd love to see more data on it.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#347
post #193
post #189

Earlier quoted context omitted.

Maybe we should increase the number of agents investigating this stuff, then? Fraud affects many more people than terrorism, but nobody gives the "there's just not enough agents" excuse for that. Also, only investigating fraud when there's lots of money involved means we're only helping rich people, who need the least help. Losing less money doesn't mean less impact on someone's life if that's all they have.

Because people are more terrified about a random bomb hitting a random place once in a while more than their accounts getting hacked and then finding themselves in a big trouble?

It takes a lot of work by the military-media-industrial complex to keep people that terrified about such a stupid ginned-up threat.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#348
post #172

Earlier quoted context omitted.

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

I never experienced this directly, but when Chip'n'Pin first came out, wasn't it the case that some European banks held customers responsible when it got hacked? The theory was apparently that it was "impossible" to hack Chip'n'Pin so something must have been the customer's fault...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#349

Not answering security questions truthfully is tricky. Yes, it's a problem that security questions turn hacking into a simple public records search. BUT most terms of service have a line like 'you warrant that you've been entirely truthful with us' or something. If you give the wrong security question to your bank, they potentially have grounds to freeze your money or screw you later. Why isn't the answer 'consumers…

I always fill in security questions with ascii85- or base64-encoded data from /dev/random , as much as the field allows. Then I throw the random string away.

This will bite me when I lose a password, and also when the web site uses security questions for anything else than password recovery. The latter almost bit me once on Adobe's forum website, when right after creating an account I wanted to change my initial password to something more secure. Luckily, I hadn't closed the window with the data yet, so I could still recover, and saved the random strings in the notes field of my password manager.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#350

Earlier quoted context omitted.

Yeah, Identity theft is one of those crimes where the authorities don't really care. It can be quite lucrative for the folks carrying it out since there are no consequences. The police are so overwhelmed and typically it is out of jurisdiction so their options are 0 to none to prosecute. The only way to guard against it is to keep your foot print small and give as little info as required.

> Yeah, Identity theft is one of those crimes where the authorities don't really care. There is no such thing as "identity theft". You can't steal who someone is, that's bullshit. It's rather some party not making sure it's actually you they are talking to, and then claiming that you are responsible for it anyway because they fell for someone else's scam.

Unfortunately, it doesn't work that way. The Uniform Commercial Code (in the US) has provisions about what constitutes accepting an instrument of payment taken in good faith, and that indemnifies a business. Maybe those laws should not exist and insurance should be the mechanism to cover loss stemming from fraud, but it doesn't work that way.
Post reply on HN