This is something that really worries me. I use token based 2FA when I can but the reality is that I have like 50 accounts with 2FA and I forget which ones have SMS as a backup. I'm sure there's an account in there somewhere that's at risk. I have AT&T and use the extra security PIN code, but I know it's not 100% guaranteed. The other day I got a robocall asking for my PIN and last for of my social. I didn't do it, b…
I talked to my cell phone provider and asked them if there was anything they could do to prevent transfering of my number. They said the best they could do was to add a note to my file to check id in store before transferring . This is better than nothing, but relies on the CS representative actually seeing the note on my file. Even then, there might be ways around it. And more importantly, it does noting to stop som…
Listen to a SIM-Jacking, Account-Stealing Ransom
71–80 of 95 posts
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#72Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
The PSTN and phone system telecom industry in general is not hardened. The more you see the underpinnings of it, as I have, the more it looks like a bunch of 30-year-old bullshit held together with the technological equivalent of duct tape and twine.
SS7 needs to be burnt to the ground, the ashes stomped around on a bit, and shoveled into a dustbin.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#73Earlier quoted context omitted.
Google has a new account setting called Advanced Protection. All it accepts is two hardware U2F keys (primary and backup) and your password. It supposedly makes your Google account pretty hardened. The only issue is that you can only use Chrome with U2F keys right now because Firefox U2F isn't fully baked yet. I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as…
Weird, I have U2F keys in my non-Advanced Protection account.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#74Earlier quoted context omitted.
Google has a new account setting called Advanced Protection. All it accepts is two hardware U2F keys (primary and backup) and your password. It supposedly makes your Google account pretty hardened. The only issue is that you can only use Chrome with U2F keys right now because Firefox U2F isn't fully baked yet. I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as…
For what it's worth, I use a U2F key regularly with Firefox. Just enable the security.webauth.u2f flag under about:config. I realize that's not a good solution for everyone, but if you're just looking to do it for yourself it works.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#75Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#76Dear everyone at Apple, Facebook, Google, etc. Please stop and remove the ability to use texting as 2FA. The mobile telecom industry is not hardened.
> The mobile telecom industry is not hardened. The PSTN and phone system telecom industry in general is not hardened. The more you see the underpinnings of it, as I have, the more it looks like a bunch of 30-year-old bullshit held together with the technological equivalent of duct tape and twine. SS7 needs to be burnt to the ground, the ashes stomped around on a bit, and shoveled into a dustbin.
This happens to every system eventually if it lives long enough.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#77The "OG account" stuff is fascinating. ( see e.g. https://waypoint.vice.com/en_us/article/43ebpd/the-long-weir... for screenshots of forum or https://medium.com/@N/how-i-lost-my-50-000-twitter-username-... ). Also fascinating is that the only functional support channel is "write a blog post and hope a lot of people upvote it on a news aggregator". Two really interesting trends there.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#78Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#79Earlier quoted context omitted.
You have no obligation to answer the secure questions truthfully, or not to write a long random string of text... Starting with "Do not accept the answer if I can't spell this exactly" in case a human gets involved...
Of course you'll be SOL if you legitimately lose your password and the answers to those questions.
Re: Listen to a SIM-Jacking, Account-Stealing Ransom
#80Earlier quoted context omitted.
> The mobile telecom industry is not hardened. The PSTN and phone system telecom industry in general is not hardened. The more you see the underpinnings of it, as I have, the more it looks like a bunch of 30-year-old bullshit held together with the technological equivalent of duct tape and twine. SS7 needs to be burnt to the ground, the ashes stomped around on a bit, and shoveled into a dustbin.
> The more you see the underpinnings of it, as I have, the more it looks like a bunch of 30-year-old bullshit held together with the technological equivalent of duct tape and twine. This happens to every system eventually if it lives long enough.
a) only a certain elite group of people or companies will be able to use it (in this case, PSTN operators)
b) total trust between all parties using it, so there's no need for provably-hardened cryptography.
both of which are now laughable in a modern network security threat environment.
In this case SS7 was just never designed with the concept that malicious third parties might get access to it, or that it would not be operated by RBOCs (regional bell operating companies), or the international equivalent thereof (national run telcos such as British Telecom, Telecom Italia, etc).