Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

31–40 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#31
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

I ported my Google Voice number to T-mobile about 6 years ago, replacing my main number

Great decision as I got to reset my social graph - no services would try to auto-connect me with everyone from high school and college that had data dumped their contacts

10/10

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#32
post #9

One does not even need to bribe or defraud telecom employees, the biggest gaping hole is the fact that roaming requests are insecure, and SMSes are plaintexted. On "certain Russian forums" the talk is that was the way how British MPs were deprived of their email mailboxes in 2016. Somebody dug up their IMSIs from leaks and public dbs, and sent roaming requests through Megafon - Russia's biggest telco

> One does not even need to bribe or defraud telecom employees

wow, no proof of stake required, rating 1/5

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#33

This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…

The lack of security of cell phone providers is absolutely infuriating considering the sheer number of people who are paid $20/h that have ability to see and manipulate records at the likes of AT&T, Sprint, TMO and VZ not to mention those who work for resellers like BestBuy that are authorized to make activation and porting related changes.

It reminds me of MJR confidently stating that the maximum cost of gaining access to any secure network is min:

1) A yearly salary of the lowest paid employee who has access (i.e. someone's secretary)

2) A price of a Desert Eagle

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#35
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

I ported my Google Voice number to T-mobile about 6 years ago, replacing my main number Great decision as I got to reset my social graph - no services would try to auto-connect me with everyone from high school and college that had data dumped their contacts 10/10

Is it worth it though? Now you can't fully rely on your phone number for 2FA, T-mobile is one of the providers notoriously known for transferring numbers without asking too many information.

My daily number, not connected to any 2FA (for which I use Google Voice) is a T-mobile, and a couple years ago I bought a nano sim to replace a larger sim, and the call center operator transferred the number without me having to answer almost anything overly personal, I think they just asked for a PIN which I'd obviously forgotten and with some mild additional information it was reset right there. It was truly shocking, the old sim just got disconnected from the network instantly.

For 2FA via text, Google Voice is IMHO the only choice, by far.

And for social graph implications, on your google account you can choose to not be discoverable to other people via your phone number, and that includes the Google Voice number since it's explicitly listed there (of course I assume it doesn't work the other way around, which seems to be the thing you are bothered by, I'm usually worried about being discovered by others than being shown a list of people I might know).

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#36

This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…

There definitely needs to be more stringent protocols in place for transferring numbers, but I have to disagree with the 72-hour delay idea - it may hamstring those who are porting numbers for legitimate reasons.

For example, I lost my phone on a Thursday a couple months ago and desperately needed it for work the following week. Ordered a replacement phone as well as SIM with express shipping. Received both over the weekend, called the provider to port from the lost SIM to the new one, and was able to work on Monday.

Having an unavoidable X-hour long delay before the port went through would've been awful. I'm sure there's another way to accomplish the same goal - perhaps requiring more info than just account number / PIN / password, implementing physical ID verification, etc.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#37

Earlier quoted context omitted.

Bank of America does not or is not able to send 2FA SMS to Google Voice numbers.

That's not true, I have both my Bank Of America and Merrill Edge accounts protected with 2FA using my Google Voice number, and it's been working fine for at least a couple years (when I switched to that method), I use both of them weekly receiving their authentication text via GV and never had a problem.

Interesting, I tried years ago and it didn't work, maybe it has changed. Good thing is BoA also emails 2FA codes, so don't need SMS anyway.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#39
post #15
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#40
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

You know pre-paid burner phones are a reasonable option to harden security at your own pace, right?

No one is forcing you to use the same number for everything. And don't complain that it's just too expensive and unrealistic to maintain more than one phone number, because that is simply untrue.

Yes, I am aware of NIST's guidelines, regarding SMS as a layer of multi-factor authentication [0]. Those guidelines are for large organizations that dictate user behavior in a top-down hierarchy. Individual security profiles are much more flexible, and don't require the same degree of adherence to recommended practices.

[0] https://pages.nist.gov/800-63-3/sp800-63b.html

Post reply on HN