Live data from Hacker News

Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

ptsecurity.com

1–10 of 56 posts

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#3

Arg. I wish this article were more substantive, since it's an important topic. But there are no details.

After tons of reports of Coinbase accounts being broken into they looked into it, replicated it and then reported it.

SMS isn't a secure nor authenticated transport and never has been. Avoid anything that uses SMS as a transport for secrets or phone numbers as auth.

It's not just SS7 vulns but also number portability.

afaik Coinbase is still using SMS as an optional second factor, while iCloud still only allows SMS.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#4
post #3

Arg. I wish this article were more substantive, since it's an important topic. But there are no details.

After tons of reports of Coinbase accounts being broken into they looked into it, replicated it and then reported it. SMS isn't a secure nor authenticated transport and never has been. Avoid anything that uses SMS as a transport for secrets or phone numbers as auth. It's not just SS7 vulns but also number portability. afaik Coinbase is still using SMS as an optional second factor, while iCloud still only allows SMS.

> while iCloud still only allows SMS

? I’ve had 2FA turned on for my iCloud account for a while, any time I’ve needed to authorize a device I’ve had to approve it on my iMac or iOS device, it doesn’t use SMS.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#5
post #4
post #3

Earlier quoted context omitted.

After tons of reports of Coinbase accounts being broken into they looked into it, replicated it and then reported it. SMS isn't a secure nor authenticated transport and never has been. Avoid anything that uses SMS as a transport for secrets or phone numbers as auth. It's not just SS7 vulns but also number portability. afaik Coinbase is still using SMS as an optional second factor, while iCloud still only allows SMS.

> while iCloud still only allows SMS ? I’ve had 2FA turned on for my iCloud account for a while, any time I’ve needed to authorize a device I’ve had to approve it on my iMac or iOS device, it doesn’t use SMS.

you can approve login requests using notifications but you need at least one backup trusted phone number on your account

see step 2: https://support.apple.com/en-au/HT204915

"trusted phone number" is an oxymoron

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#6

Arg. I wish this article were more substantive, since it's an important topic. But there are no details.

This piece is half an advert but it’s the best article I’ve found that plainly describes the issue:

https://www.telecomdefense.com/ss7-vulnerabilities/

TL;DR; The system that allows our phone networks to work together was designed decades ago with minimal security.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#7
Slightly less exciting TLDR: as many of you already know, SMS isn't a good second factor for auth. That includes entrusting your Bitcoin wallet's private keys to a company using SMS for 2FA. Let's mention "cryptocurrency" as well to show up in more news alerts.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#9
I was targeted this evening by a hacker who ported my phone number, and then got into FB + Yahoo (SMS reset).

The motive appears to be bitcoin, based on the people contacted via facebook.

Is it possible the initial PIN that was sent by Tmobile was intercepted via SS7? I am trying to find out if my phone (android) is compromised as well.

The accounts and phone number are back under my control but I want to find out the vector as soon as possible -I don't trust tmobile to honor requests not to allow porting.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#10
post #3

Arg. I wish this article were more substantive, since it's an important topic. But there are no details.

After tons of reports of Coinbase accounts being broken into they looked into it, replicated it and then reported it. SMS isn't a secure nor authenticated transport and never has been. Avoid anything that uses SMS as a transport for secrets or phone numbers as auth. It's not just SS7 vulns but also number portability. afaik Coinbase is still using SMS as an optional second factor, while iCloud still only allows SMS.

Maybe it's time for SSMS? The extra S being for secure, of course. Something encrypted and requiring authentication would be good - and maybe (tangentially related) not letting just anyone transfer your phone number to a new phone contract. That should require ID and some level of additional authentication.

It's like the whole thing is a house of cards. I'm half amazed that it works as well as it does and isn't exploited more often.

Post reply on HN