Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

11–20 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#12
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.

did you try to port it without marking it as portable in Google Voice? I would be interested to see if that flag actually matters.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#13
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

I think it depends on the mobile provider and country.

Most of these attacks are social engineering.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#14

Earlier quoted context omitted.

I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.

did you try to port it without marking it as portable in Google Voice? I would be interested to see if that flag actually matters.

I tried to port out in early 2017 without unlocking the number at GV and the receiving provider said the sending provider had rejected the port request.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#15
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password.

The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done.

The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just happen to call “2FA.”

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#16

Earlier quoted context omitted.

Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.

There's many 2FA apps compatible with the TOTP and HOTP standards and they rarely, if ever require an update. Absolutely minimal 3rd party involvement, I'd say less than most web browsers these days as there really isn't a significant attack surface for the apps.

If you're truly paranoid, TOTP and HOTP are absurdly easy to implement if you've got an HMAC primitive:

https://en.wikipedia.org/wiki/HMAC-based_One-time_Password_a...

https://en.wikipedia.org/wiki/Time-based_One-time_Password_a...

https://github.com/google/google-authenticator/wiki/Key-Uri-...

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#17
post #15
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

If you register your phone nr your password basically get useless as someone can remotely (from another country even) steal your phone number and then reset your password.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#18
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.

Many of these services, I believe google is one, still require mobile phone as a fallback option.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#19
post #11
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

For paypal, texting is even the only 2FA option for non-US citizens. Baffling.

You can use a symantec hardware token.

Paypal’s ceo is head of symantec’s board. Paypal must use symantec software wherever it is available, and their mfa is no exception.

This is still baffling as you say though, because symantecs mfa system does allow for other mechanisms.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#20
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

Google has a new account setting called Advanced Protection. All it accepts is two hardware U2F keys (primary and backup) and your password. It supposedly makes your Google account pretty hardened. The only issue is that you can only use Chrome with U2F keys right now because Firefox U2F isn't fully baked yet.

I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as much 3rd party stuff, but I only keep my Google account (right now) for my old email address that's already forwarded to my new email address, Google Music, and Google Pay, so that doesn't affect me much. If you use a lot of 3rd party apps or get your mail via IMAP and the like, it's going to be more difficult.

A weird thing is that Google doesn't seem to allow for U2F key use without Advanced Protection turned on, which is puzzling to me.

Post reply on HN