Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

41–50 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#41
post #15

Earlier quoted context omitted.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"

You have no obligation to answer the secure questions truthfully, or not to write a long random string of text... Starting with "Do not accept the answer if I can't spell this exactly" in case a human gets involved...

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#42
post #15
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

Just today Google prevented me from logging in with the correct password and asked for a phone number as additional verification. Any phone number.

The account has no associated number so it's not a verification at all!

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#43
post #6
post #2

I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?

For UK numbers I can also recommend these guys: https://www.aa.net.uk/telecoms.html Their technical support is actual tech support, with tech guys that won't take any bullshit, especially if you have 2FA (TOTP-based) on your account. The numbers are not recognised as VoIP and will work with every single service (I have yet to find one that will fail). I believe they are partnered with a local carrier that does some m…

Except their text messages only appear to be processed every half hour or so... which makes it useless for 2FA most of the time (the only reason I went with them).

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#44

This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…

T-Mobile has put in place some protections to prevent unauthorized transfers of your account to new SIM cards, I just had to deal with them last night - actually. Swapping SIM cards for a line must either be done in-store where your photo ID can be verified, or over the phone but only after confirmation of a OTP sent to account managers via SMS.

I know T-Mobile actually had some issues with this in the past, so even though I miss the convenience of going to t-mobile.com/sim to swap a card out I feel it's a much better solution security-wise.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#45
Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#46
post #36

This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…

There definitely needs to be more stringent protocols in place for transferring numbers, but I have to disagree with the 72-hour delay idea - it may hamstring those who are porting numbers for legitimate reasons. For example, I lost my phone on a Thursday a couple months ago and desperately needed it for work the following week. Ordered a replacement phone as well as SIM with express shipping. Received both over the…

> Having an unavoidable X-hour long delay before the port went through would've been awful

What if that "unavoidable X-hour long delay" prevented your 2-FA codes from being compromised during a targeted attack?

To be fair, very few people are individually targeted in these types of attacks (statistically).

It would be great to have a 72-hour delay on transfer if it were on an opt-in basis.

(Side note: has anyone tried to disable web access to text messages on a Verizon line?)

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#47
post #5

Earlier quoted context omitted.

I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.

And since there is no google customer service, nobody can social engineer it out of you!

Google Voice is on track to be a core service in Gsuite, which has pretty impressive phone support in my experience.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#48
post #38

2FA security aside, it really is remarkable how Jared was able to talk the hacker down. We seem to really undervalue those sorts of social skills. Jared's one conversation could have saved hundreds of thousands of dollars (for himself and others).

When a social engineer I meets a social engineer II the better social engineer gets the upper hand. In this case it was not the hacker.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#49
The "OG account" stuff is fascinating. ( see e.g. https://waypoint.vice.com/en_us/article/43ebpd/the-long-weir... for screenshots of forum or https://medium.com/@N/how-i-lost-my-50-000-twitter-username-... ).

Also fascinating is that the only functional support channel is "write a blog post and hope a lot of people upvote it on a news aggregator".

Two really interesting trends there.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#50
post #18

Earlier quoted context omitted.

Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.

Many of these services, I believe google is one, still require mobile phone as a fallback option.

Google requires at least 2 ways of 2fa protection. You can enable a third one and disable the phone completely.
Post reply on HN