Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

51–60 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#51
post #6

Earlier quoted context omitted.

For UK numbers I can also recommend these guys: https://www.aa.net.uk/telecoms.html Their technical support is actual tech support, with tech guys that won't take any bullshit, especially if you have 2FA (TOTP-based) on your account. The numbers are not recognised as VoIP and will work with every single service (I have yet to find one that will fail). I believe they are partnered with a local carrier that does some m…

Except their text messages only appear to be processed every half hour or so... which makes it useless for 2FA most of the time (the only reason I went with them).

Strange - I get their texts immediately.

Which numbers are you using? 07 ones or 020?

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#52
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

Google has a new account setting called Advanced Protection. All it accepts is two hardware U2F keys (primary and backup) and your password. It supposedly makes your Google account pretty hardened. The only issue is that you can only use Chrome with U2F keys right now because Firefox U2F isn't fully baked yet. I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as…

Weird, I have U2F keys in my non-Advanced Protection account.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#53
post #36

This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…

There definitely needs to be more stringent protocols in place for transferring numbers, but I have to disagree with the 72-hour delay idea - it may hamstring those who are porting numbers for legitimate reasons. For example, I lost my phone on a Thursday a couple months ago and desperately needed it for work the following week. Ordered a replacement phone as well as SIM with express shipping. Received both over the…

That's why I said it should be optional. A lot of people wouldn't want this. Some would. I definitely would.

For me the potential delay in the event of a lost/stolen/upgraded device is well worth it when the flip side is the potential nightmare resulting from the damage done if the person gets into an important account.

It seems to me like requiring some secondary form of authentication can always be bypassed at the discretion of the agent helping you because there will always be a possibility that the customer lost/can't remember the secondary key or ID.

Although, now that I think about it… UPS does something interesting to verify your account. They ask you to input a unique set of numbers that appear on your last invoice to link your account and verify your ID. Not foolproof by any means, but it's enforced for every authentication by design. Definitely more secure than the current PIN.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#54
post #42
post #15

Earlier quoted context omitted.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

Just today Google prevented me from logging in with the correct password and asked for a phone number as additional verification. Any phone number. The account has no associated number so it's not a verification at all!

That's not for your benefit, that's for them to verify you're a human / not a spammer / collect information (at least that seems like the most reasonable explanation to me).

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#55
post #24

Earlier quoted context omitted.

Paypal, an actual bank, still only allows SMS 2fa. It's stupid.

Wrong. TOTP is supported, although hidden.

https://www.paypal-community.com/t5/Tips-from-Moderators/Pay...

It uses Verisign's VIP app instead of Google Authenticator (or Authy or whatever).

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#56
post #45

Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything .

>can be done in 2 minutes

Citation needed. Extra credit for WikiHow step by step with badly drawn art.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#57
post #15

Earlier quoted context omitted.

2FA over SMS is fine. It’s not the most secure thing, but it’s an improvement over just having a password. The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done. The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just h…

The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"

It frustrates me how almost every company's "secure question" system is utterly retarded and recklessly dangerous.

1. They draw from fixed unimaginative pools of often-overlapping questions, so that a breach in one company compromises you on multiple others.

2. Unlike a password, the actual secret question is often plaintext

If I had to design a replacement... The user would always be allowed to define custom questions, all questions could be assigned multiple synonymous correct answers (e.g. "Dr. Smith", "Doctor Smith"), and they all go through a one-way hash with salt.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#58
post #45

Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything .

Trivial if you have access to an SS7 network that has a direct access or a roaming agreement with the network of the victim, and the proper tools to do that. But you will not manage to do it within 2 minutes if you have.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#59
post #27

This marketing entrepreneur talks down a ransom seeker with a heart warming story AND manages to record it? Sounds a little too good to be true

The accent of the "scammer" in the call is definitely not German.

Germany has a ton of immigrants, they don't all speak with German accents.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#60
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

You know pre-paid burner phones are a reasonable option to harden security at your own pace, right? No one is forcing you to use the same number for everything. And don't complain that it's just too expensive and unrealistic to maintain more than one phone number, because that is simply untrue. Yes, I am aware of NIST's guidelines, regarding SMS as a layer of multi-factor authentication [0]. Those guidelines are for…

Seems pretty wasteful solution if everyone maintains a secondary burner phone for login. But it works for the short term, and I would worry about fees, and inactivity cancelations.
Post reply on HN