Live data from Hacker News

Nine Charged in Alleged SIM Swapping Ring

krebsonsecurity.com

21–30 of 41 posts

Re: Nine Charged in Alleged SIM Swapping Ring

#21
post #18

Several sites that I use, even some that support TOTP, still require a phone number. I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft (assuming you protect your GV account of course) and relatively safe to use. https://support.google.com/voice/answer/1065667#xferout

SMS as a second factor is not and is unlikely to be secure for a second factor anytime in the near future given the design of SS7 and the glacial pace that the global telecom industry moves at for upgrading core infrastructure. The lock prevents port-out attacks, but is still not sufficient for considering SMS as okay to use for a second factor. Use TOTP instead.

Re: Nine Charged in Alleged SIM Swapping Ring

#22
post #18

Several sites that I use, even some that support TOTP, still require a phone number. I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft (assuming you protect your GV account of course) and relatively safe to use. https://support.google.com/voice/answer/1065667#xferout

SMS as a second factor is not and is unlikely to be secure for a second factor anytime in the near future given the design of SS7 and the glacial pace that the global telecom industry moves at for upgrading core infrastructure. The lock prevents port-out attacks, but is still not sufficient for considering SMS as okay to use for a second factor. Use TOTP instead.

I use something more secure than SMS as my sole second factor where I can. Unfortunately some sites still require a phone number. I’ve edited my comment to be clear about that.

So if you have to use a phone number, is GV the least bad option?

Re: Nine Charged in Alleged SIM Swapping Ring

#23
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

They don't have to be totally unique and secure for most users. It's an imperfect solution to a difficult problem - throttling user account creation.

Using phone numbers for throttling user account creation has no security problem. Using phone numbers for 2FA has no security problem compared to password 1FA. The security problem comes when companies use phone numbers for 1FA (during account recovery).

Re: Nine Charged in Alleged SIM Swapping Ring

#24
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

This is why I hate Apple’s new policy of requiring 2FA with a mobile number for new accounts. Luckily I created my account before it was official policy, but I’m afraid their going to force it on me someday. And if you turn on 2FA, you only have 2 weeks to turn it off.

It's fine to require 2fa as long as using an app instead of SMS is allowed.

SMS only 2fa should really be discouraged

Re: Nine Charged in Alleged SIM Swapping Ring

#26
post #2

Mobile phone numbers aren't unique and secure identification of users, stop treating it as such.

They don't have to be totally unique and secure for most users. It's an imperfect solution to a difficult problem - throttling user account creation.

It's an imperfect solution to a difficult problem - throttling user account creation.

A very imperfect solution when it comes to FastMail.

In moving my accounts from Gmail to FastMail it wouldn't allow me to add more than x number of accounts verified with the same cellular number. Even though they were paid accounts. So some of my family remains on Gmail because I only have one phone number that receives SMS messages.

Re: Nine Charged in Alleged SIM Swapping Ring

#27
post #9
post #7

Earlier quoted context omitted.

What is, though?

A private key with an associated public key signed by one or more entitities that have verified the owner of the private key.

signed by one or more entitities

Sounds like another opportunities for the advertising companies like Google and Facebook to uniquely identify us.

Re: Nine Charged in Alleged SIM Swapping Ring

#28
It's interesting seeing all these novel ways of stealing cryptocurrency. So far we have seen Twitter scams where people impersonate high profile accounts in the hope people will think it's a real cryptocurrency giveaway and actually send funds to various wallets.

Then there is the cryptominer/cryptojacking technique where the unused CPU power of personal computers is used to mine various cryptocurrency (often stealthily run in the background and the user is unaware they are mining cryptocurrency).

Then there was that recent story of the so called 'cryptocurrency bandit' who scraped wallet addresses and then broke into the wallets which were encrypted with a weak password.

If anyone on here knows of other novel techniques (aside from what I mentioned and the SIM-swapping method); then I would love to hear the methods.

Re: Nine Charged in Alleged SIM Swapping Ring

#29

It's interesting seeing all these novel ways of stealing cryptocurrency. So far we have seen Twitter scams where people impersonate high profile accounts in the hope people will think it's a real cryptocurrency giveaway and actually send funds to various wallets. Then there is the cryptominer/cryptojacking technique where the unused CPU power of personal computers is used to mine various cryptocurrency (often stealth…

People have programs that scan github uploads for AWS, etc credentials accidentally uploaded by victim and spawn images that mind crypto for the attacker’s.

https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...

Re: Nine Charged in Alleged SIM Swapping Ring

#30

It's interesting seeing all these novel ways of stealing cryptocurrency. So far we have seen Twitter scams where people impersonate high profile accounts in the hope people will think it's a real cryptocurrency giveaway and actually send funds to various wallets. Then there is the cryptominer/cryptojacking technique where the unused CPU power of personal computers is used to mine various cryptocurrency (often stealth…

You forgot about cracking ipmi hashes, this has been an incredibly popular way to steal wallets off servers.
Post reply on HN