Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

1–10 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#3
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#4
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

I've ported one back out, you have to sign into your account and allow it.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#5
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.

And since there is no google customer service, nobody can social engineer it out of you!

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#6
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

For UK numbers I can also recommend these guys: https://www.aa.net.uk/telecoms.html

Their technical support is actual tech support, with tech guys that won't take any bullshit, especially if you have 2FA (TOTP-based) on your account.

The numbers are not recognised as VoIP and will work with every single service (I have yet to find one that will fail). I believe they are partnered with a local carrier that does some magic (call forwarding to some internal number?) so from the outside they look just like any other mobile number from that carrier.

(no affiliation besides being a satisfied customer for years)

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#8
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#9
One does not even need to bribe or defraud telecom employees, the biggest gaping hole is the fact that roaming requests are insecure, and SMSes are plaintexted.

On "certain Russian forums" the talk is that was the way how British MPs were deprived of their email mailboxes in 2016. Somebody dug up their IMSIs from leaks and public dbs, and sent roaming requests through Megafon - Russia's biggest telco

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#10
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.

There's many 2FA apps compatible with the TOTP and HOTP standards and they rarely, if ever require an update.

Absolutely minimal 3rd party involvement, I'd say less than most web browsers these days as there really isn't a significant attack surface for the apps.

Post reply on HN