Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

21–30 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#21
post #15
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

> ...it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just happen to call “2FA.”

...or when they want it to be able to call or text you with other BS entirely. I hesitate to give my cell number to any company. I have a separate number (formerly a landline, now strictly a voicemail box) that I use specifically for companies.

I gave my cell number to a new dentist recently, thinking "medical office, probably important they be able to reach me." That turned out to be a mistake. They subscribed me to an automated appointment confirmation service, and they also send me a text (from a different number than the confirmation service) after I finish a visit to solicit reviews. This is exactly why I hate giving it out.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#22
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

Bank of America does not or is not able to send 2FA SMS to Google Voice numbers.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#23
post #17
post #15

Earlier quoted context omitted.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

If you register your phone nr your password basically get useless as someone can remotely (from another country even) steal your phone number and then reset your password.

That would be one factor, no?

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#24
post #18

Earlier quoted context omitted.

Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.

Many of these services, I believe google is one, still require mobile phone as a fallback option.

Paypal, an actual bank, still only allows SMS 2fa. It's stupid.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#25
This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, but just knowing my number was on that list worried me. I called AT&T and asked them to put a note in my account that said not to allow my phone number to be transferred to another SIM. They said they did it, but again I don't know how effective that is.

I understand why they make it possible to move a number to a new SIM, but I really wish you had an option to force a notification and delay the transfer for a number off days. Even a three day delay would be enough. You'd put in the request and they'd send a notification via SMS/call and email, and then the transfer wouldn't happen for 72 hours.

I would gladly deal with the potential inconvenience of not having access to my phone for a few days if it meant that it would make it harder to transfer my number to a different SIM. I don't think this should be mandatory, but I'd like the option.

It's just WAY too easy to call a cell provider and have them transfer your number to a new SIM and all the security measures that they use are easily defeated. Once you have someone's social security number you can spend 99¢ on a public records dump and get enough information to convince just about any customer service person to do whatever you want.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#26
post #9

One does not even need to bribe or defraud telecom employees, the biggest gaping hole is the fact that roaming requests are insecure, and SMSes are plaintexted. On "certain Russian forums" the talk is that was the way how British MPs were deprived of their email mailboxes in 2016. Somebody dug up their IMSIs from leaks and public dbs, and sent roaming requests through Megafon - Russia's biggest telco

I doubt that was necessary. Many of the telcos use atrocious pin security for voicemails- and they fail to prevent spoofed calls to their voicemail servers. Makes for a bad combination.

SS7 hacking to achieve that end would be a higher barrier to entry and more likely to get caught.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#28
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

Bank of America does not or is not able to send 2FA SMS to Google Voice numbers.

That's not true, I have both my Bank Of America and Merrill Edge accounts protected with 2FA using my Google Voice number, and it's been working fine for at least a couple years (when I switched to that method), I use both of them weekly receiving their authentication text via GV and never had a problem.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#29
post #24
post #18

Earlier quoted context omitted.

Many of these services, I believe google is one, still require mobile phone as a fallback option.

Paypal, an actual bank, still only allows SMS 2fa. It's stupid.

Wrong. TOTP is supported, although hidden.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#30
post #11

Earlier quoted context omitted.

For paypal, texting is even the only 2FA option for non-US citizens. Baffling.

You can use a symantec hardware token. Paypal’s ceo is head of symantec’s board. Paypal must use symantec software wherever it is available, and their mfa is no exception. This is still baffling as you say though, because symantecs mfa system does allow for other mechanisms.

Paypal's Symantec HW token can be replaced with a TOTP app.
Post reply on HN