Live data from Hacker News

Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

nytimes.com

1–10 of 28 posts

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#4
Perhaps using a non-published extra phone number registered to someone else (perhaps your child) can provide protection? It's security through obscurity but with the phone number being the crucial piece of information, keeping it secret will go a long way.

Of course the real fix would be to have better trained people working at the call centers.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#5
I submitted this apparently just after: https://news.ycombinator.com/item?id=15070199

I got hacked a week ago in this exact fashion (I haven't tried to keep it a secret that I was involved in Bitcoin earlyish-on). I don't think they were able to get anything (largely because I am mostly out of the crypto space) but please remove cellphone 2FA from all your online dealings and add something like Google Authenticator instead (don't forget to print out, or at least encrypt a PDF of, the backup codes!)

My mistake was LEAVING cellphone 2FA in there on my main Google account even after I had activated Google Authenticator.

That was a mistake, because you can actually remove cellphone 2FA after adding GA 2FA. Which you should do!

My 2nd mistake was using a dumb PIN on my cellphone account.

The cellphone companies could prevent this attack entirely by requiring in-person (with ID) transfers of cellphone numbers to new hardware, at the store. Given the infrequency that I would have to do that, the extra inconvenience is acceptable.

After getting hacked and trying to move most of my online affairs to another account still under my control, I noticed that Facebook has a "name 5 trusted friends" feature which helps you regain access to an account after it's compromised, which might be useful to others... only issue being that once my private messaging and files are discovered (google drive :( ), the damage is already done.

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#7
post #5

I submitted this apparently just after: https://news.ycombinator.com/item?id=15070199 I got hacked a week ago in this exact fashion (I haven't tried to keep it a secret that I was involved in Bitcoin earlyish-on). I don't think they were able to get anything (largely because I am mostly out of the crypto space) but please remove cellphone 2FA from all your online dealings and add something like Google Authenticator i…

Those "two-factor" authentication often turn out to be one factor in reality - for some time, knowing your phone was the only thing needed on Gmail to initiate password recovery with banal questions. This is how an attempted hack of British MPs was done (a Russian cellphone operator rerouted their phones using a roaming request, while KGB guys were trying to pound password recovery on MPs' private mailboxes)

The same password recovery vulnurability was present on Facebook for some time as well

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#8
post #5

I submitted this apparently just after: https://news.ycombinator.com/item?id=15070199 I got hacked a week ago in this exact fashion (I haven't tried to keep it a secret that I was involved in Bitcoin earlyish-on). I don't think they were able to get anything (largely because I am mostly out of the crypto space) but please remove cellphone 2FA from all your online dealings and add something like Google Authenticator i…

Is having Project Fi (Google as the carrier) safer?

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#9
This was raised by Kraken back in November 2016. Shortly afterwards I removed mobile phone as 2FA from all my accounts.

The simple fact is that I don't own my mobile number; the mobile operator does. As such I should not use it as 2fa.

https://blog.kraken.com/post/219/security-advisory-mobile-ph...

Re: Identity Thieves Hijack Cellphone Accounts to Go After Virtual Currency

#10
In Turkey, when you move your phone number, 2FA automatically gets locked (you can't receive the code till you reactivate) for banks, requiring calling customer service or visiting a branch to reactivate.

It would be nice to have a similar system for all kind of 2FA solutions involving cell phones.

Post reply on HN