Earlier quoted context omitted.
2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…
The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"
Listen to a SIM-Jacking, Account-Stealing Ransom
41–50 of 95 posts
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#42Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…
The account has no associated number so it's not a verification at all!
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#43I remember reading somewhere that Google Voice numbers cannot be ported - and are useful in having them set as your 2FA for email accounts etc. Is that still correct?
For UK numbers I can also recommend these guys: https://www.aa.net.uk/telecoms.html Their technical support is actual tech support, with tech guys that won't take any bullshit, especially if you have 2FA (TOTP-based) on your account. The numbers are not recognised as VoIP and will work with every single service (I have yet to find one that will fail). I believe they are partnered with a local carrier that does some m…
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#44This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…
I know T-Mobile actually had some issues with this in the past, so even though I miss the convenience of going to t-mobile.com/sim to swap a card out I feel it's a much better solution security-wise.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#45Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#46This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…
There definitely needs to be more stringent protocols in place for transferring numbers, but I have to disagree with the 72-hour delay idea - it may hamstring those who are porting numbers for legitimate reasons. For example, I lost my phone on a Thursday a couple months ago and desperately needed it for work the following week. Ordered a replacement phone as well as SIM with express shipping. Received both over the…
What if that "unavoidable X-hour long delay" prevented your 2-FA codes from being compromised during a targeted attack?
To be fair, very few people are individually targeted in these types of attacks (statistically).
It would be great to have a 72-hour delay on transfer if it were on an opt-in basis.
(Side note: has anyone tried to disable web access to text messages on a Verizon line?)
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#47Earlier quoted context omitted.
I ported one out last year, I had to make it portable from inside my Google Voice account (a quite poorly documented pain, actually), but that's still a much higher bar than your average cell carrier.
And since there is no google customer service, nobody can social engineer it out of you!
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#482FA security aside, it really is remarkable how Jared was able to talk the hacker down. We seem to really undervalue those sorts of social skills. Jared's one conversation could have saved hundreds of thousands of dollars (for himself and others).
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#49Also fascinating is that the only functional support channel is "write a blog post and hope a lot of people upvote it on a news aggregator".
Two really interesting trends there.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#50Earlier quoted context omitted.
Or, allow it, and inform them there's a safer method called Google authenticator. Authenticators make your logins dependent upon 3rd party software, and is only as secure as how that single source of failure is.
Many of these services, I believe google is one, still require mobile phone as a fallback option.