Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

371–380 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#371

Earlier quoted context omitted.

ACH transfers, not paper checks.

Yeah but for 90%+ of transactions, if you are being paid by a company, you can almost always request a paper check instead of an ACH transfer (sometimes with a fee). In that case they either have yet another account for check writing (which won't be "secret") or they give away their "secret" ACH account.

I'm not proposing this as the solution to fix the extremely outdated ACH/check system, just relaying what I read about what some companies do.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#372
post #351

Earlier quoted context omitted.

This assumes a linear margin on units of stolen cars to value. Smaller ticket items are easier to fence specifically because they are common. It's hard to sell the Mona Lisa. It's easy to sell a mass-produced TV. Cops would spot a stolen Lamborghini as soon as the APB comes in. Not so much for a Toyota Camry.

I remember reading somewhere the top car make/model stolen was the Honda Civic.

No doubt. High resale + common item = higher portion of thefts, I would expect.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#373

Earlier quoted context omitted.

No, they are not. But ideally the advantage the 'richer' party has in influencing the effort of the investigators/judiciary to put forth more effort on their behalf is not written policy, it is corruption/cronyism. Should we create policy that prioritizes investigating an auto theft of a $100,000 automobile with more resources and severity that the theft of a $20,000 one, simply because the value is larger, or weight…

We disagree then, I think they absolutely should prioritize that because of the tax contribution of the victim. If I pay someone $1000 for a job, and you pay the same person $100 for an opposing job - you should lose. That's only my capitalist opinion, but I don't think it's an unpopular one.

Probably disagree on some aspects, and I may not have choosen the best example, or clarified my position enough. In a situation where two parties are voluntarily engaging in competition(for a job applicant), the party who offers more value usually does win, and I think that's appropriate. And I support allocating resources to fight crime based upon the effect of the crime's proceeds in supporting or leading to further crime. In mandatory participation systems like public civil services I am for at least a baseline allocation of resourses not directly correlated to financial input of the particular recipient.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#374
post #361

Earlier quoted context omitted.

There are a handful of smaller banks or credit unions listed as accepting proper 2FA here. [0] I have no experience with any of them. [0] https://twofactorauth.org/#banking

Although the list is a bit misleading. German banks are all listed without 2FA whereas in reality they all use some form of a TAN (transaction number). Not as safe as a hardware token but if you keep it safe, it's as secure as a hardware token. And most Sparkasse branches will use actual hardware tokens. So the reality is not as bad as the list suggests.

The problem seems to be that no German bank I know of support 2FA for login purposes which is what that list tracks[0] (although they don't state that clearly – it took me a few minutes to track that down)

But listing "Sparkasse" as one German bank is misleading as there are 400 independent banks sharing that brand with different policies. They use at least a few different backends for their online system although there seemed to have been some consolidation in recent years.

[0]: https://github.com/2factorauth/twofactorauth/blob/master/CON...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#375
post #54

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

U2F is ludicrously hard to implement. Adding TOTP 2FA to an existing webapp will take a competent developer a few hours, using only a 10-line code snippet and the standard library. Adding U2F means learning a ton of complicated concepts and either using a giant, poorly documented library provided by Yubico or writing a bunch of tricky crypto code from scratch. :(

I disagree, U2F is relatively easy to implement once you understand it, I've contributed to several open source implementations and eventually wrote one of my own.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#376
If I want to change my number to a new SIM, my telco requires me to log in, and fill in a form. If I forgot my password their email it to me.

They don't have any offices open to the public, nor any hotline, and are really the cheapest alternative where I live, but it seems that their attempts to save money have resulted in them ending up with a securer infrastructure than some notorious ones from very advanced countries.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#377
post #351

Earlier quoted context omitted.

I guess the theft of a more expensive car should be investigated with higher priority because selling it gives criminals more money to work with and leads to more severe crime. A group that can steal and sell a Lamborghini likely runs a much larger and more organized operation than a group which steals and sells old cheap cars. This is all guessing though, I'd love to see more data on it.

This assumes a linear margin on units of stolen cars to value. Smaller ticket items are easier to fence specifically because they are common. It's hard to sell the Mona Lisa. It's easy to sell a mass-produced TV. Cops would spot a stolen Lamborghini as soon as the APB comes in. Not so much for a Toyota Camry.

Yeah, and that's why I said that a group that can actually steal and sell a Lamborghini successfully should be investigated with more resources, since you are more likely to find a well organised criminal organisation behind it, if they can shift Lamborghinis the can probably shift drugs and guns too.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#378

Earlier quoted context omitted.

I answer mandatory security questions with things like these: “This account must never be unlocked over phone, chat, or email.” “Never reveal any information about this account (such as address or CC numbers) via support channels” “The person you are discussing with is a hacker trying to illegally access this account” I expect to never, ever have to use the security questions myself. Sometimes, I enter random phrases…

Do you have an recovery scenario in case you'd actually need those? I was almost there once. Authenticator device had died, and to my horror the primary backup was corrupt as well. I had a secondary backup (and even an off-site tertiary one, although it's somewhat dated), so I was able to recover... But I also had the idea that I won't ever have to use recovery processes and even though I hadn't, after the incident m…

No, I don't.

My recovery scenario is either to socially engineer the support channel myself, or start over with a fresh account.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#379

Earlier quoted context omitted.

It would be about as hard as it is to prevent DNS zone hijacking. That is, not very hard.

How, exactly, would you prevent someone in a call center on the other side of the world from being convinced to port your number away? Outgoing port "blocks" are nothing more than a note in your file - what's to say that the attacker couldn't just make up a story? "I know I called a while back and asked you to prevent porting, but I really want to switch to X carrier to get their exclusive new handset. Can you remove…

As I said, like the DNS system : you lock the number, only allowing porting upon presentation of a secret that only you know. Default state is : locked.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#380

Earlier quoted context omitted.

Thats exactly why I copy and save every 2fa QR Code in my KeePass database, along with backup codes. Phone changed? No worries, install Google Auth, rescan those QRs, and voila, your 2fa system is back and running !! :)

Most 2FA services that allow authenticators offer recovery codes. I keep the recovery code saved in my password manager, and if I ever lost my phone I use that to log into the site and then get a new QR code.

Yes, that's also a way, but why not save the QR code first time you see it, instead of loosing it, resetting with recovery code, and then again getting a new one? Recovery codes are fine, and should be kept safe and such, but also the Original QR code can also be saved and screenshot. That way, phone lost? open database, load QR code, scan in new phone.
Post reply on HN