Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

61–70 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#61
post #24

Earlier quoted context omitted.

Paypal, an actual bank, still only allows SMS 2fa. It's stupid.

Wrong. TOTP is supported, although hidden.

According to some threads I've read it doesn't work in all circumstances.

Personally I wouldn't risk it since it could mean risking getting locked out of your account.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#62
post #7

Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.

Google has a new account setting called Advanced Protection. All it accepts is two hardware U2F keys (primary and backup) and your password. It supposedly makes your Google account pretty hardened. The only issue is that you can only use Chrome with U2F keys right now because Firefox U2F isn't fully baked yet. I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as…

For what it's worth, I use a U2F key regularly with Firefox. Just enable the security.webauth.u2f flag under about:config. I realize that's not a good solution for everyone, but if you're just looking to do it for yourself it works.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#63

This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…

I talked to my cell phone provider and asked them if there was anything they could do to prevent transfering of my number.

They said the best they could do was to add a note to my file to check id in store before transferring.

This is better than nothing, but relies on the CS representative actually seeing the note on my file. Even then, there might be ways around it.

And more importantly, it does noting to stop someone asking another provider to port my number to them. Apparently Inter-provider ports are all automated and there is nothing anyone could do to stop it.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#64
post #45

Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything .

Trivial if you have access to an SS7 network that has a direct access or a roaming agreement with the network of the victim, and the proper tools to do that. But you will not manage to do it within 2 minutes if you have.

You are thinking about it from the wrong angle. Even less than 2 minutes.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#65
post #23
post #17

Earlier quoted context omitted.

If you register your phone nr your password basically get useless as someone can remotely (from another country even) steal your phone number and then reset your password.

That would be one factor, no?

I mean if SMS is not just used as second factor, but also used for password reset/override, it basically become a one factor. So yes.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#66

Earlier quoted context omitted.

I ported my Google Voice number to T-mobile about 6 years ago, replacing my main number Great decision as I got to reset my social graph - no services would try to auto-connect me with everyone from high school and college that had data dumped their contacts 10/10

Is it worth it though? Now you can't fully rely on your phone number for 2FA, T-mobile is one of the providers notoriously known for transferring numbers without asking too many information. My daily number, not connected to any 2FA (for which I use Google Voice) is a T-mobile, and a couple years ago I bought a nano sim to replace a larger sim, and the call center operator transferred the number without me having to…

totally worth it, that number can be used to create a new google voice number.

Offering SMS based one time codes - with no OTP protocol alternative - should be considered negligence of the legally sanctionable kind.

and finally who cares about your social graph on Google? Thats not the issue at alllll

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#67
post #24
post #18

Earlier quoted context omitted.

Many of these services, I believe google is one, still require mobile phone as a fallback option.

Paypal, an actual bank, still only allows SMS 2fa. It's stupid.

And even this option is not available in all countries. I've almost stopped using Paypal completely because of this.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#68
post #41

Earlier quoted context omitted.

The "best" part is password recovery — where SMS is typically the "second factor" to a completely insecure "secure question"

You have no obligation to answer the secure questions truthfully, or not to write a long random string of text... Starting with "Do not accept the answer if I can't spell this exactly" in case a human gets involved...

Of course you'll be SOL if you legitimately lose your password and the answers to those questions.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#69
post #18

Earlier quoted context omitted.

Many of these services, I believe google is one, still require mobile phone as a fallback option.

Google requires at least 2 ways of 2fa protection. You can enable a third one and disable the phone completely.

Requiring the phone number is mostly an anti-bot/spammer measure. Once they've seen your phone number you don't need to let them use it anymore.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#70
post #45

Taking over the SMS functionality of any phone number in the US is trivial and can be done in 2 minutes. The phone will continue to operate as normal and the victim will likely take a while to notice anything is wrong. Never ever use SMS to secure anything .

Trivial if you have access to an SS7 network that has a direct access or a roaming agreement with the network of the victim, and the proper tools to do that. But you will not manage to do it within 2 minutes if you have.

I was thinking of someone just walking into their local cellphone store and sweet talking the person behind the counter to transfer their number off of their old "broken" phone.
Post reply on HN