Live data from Hacker News

Nine Charged in Alleged SIM Swapping Ring

krebsonsecurity.com

31–40 of 41 posts

Re: Nine Charged in Alleged SIM Swapping Ring

#31
post #18

Several sites that I use, even some that support TOTP, still require a phone number. I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft (assuming you protect your GV account of course) and relatively safe to use. https://support.google.com/voice/answer/1065667#xferout

> I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft...

I see this sentiment posted here a lot and I'm here to say that it is sadly not a good hope. When you do a number port, the automated/efficient/normal path is that your new provider (the "gaining" provider) submits a request to the number portability authority requesting that your number be moved to its routing away from your old provider (the "losing" provider). The authority passes along the information that the gaining provider submitted and gives it to the losing provider. The losing provider is then responsible for returning an automated "yes," "no," or "wait." If "wait," the losing provider is supposed to reply again within 1 to 7 days indicating actual yes or no; if no reply, then the port will complete with no further action. If yes, then the port will complete. If no, then the port is rejected.

Now, here's the major hole: It is entirely possible to do what's called a "force port," wherein the gaining provider attests to the number portability authority that the gaining provider Really For Sure Totally Does have authorization from you (the subscriber) to take routing for the requested number. This is only supposed to be used in the case of a recalcitrant losing provider or where the losing provider has no automated system and the subscriber wants/needs the number moved Very Fast Now. But, realistically, this very much can be abused and, if an attacker is motivated, will be abused.

There's nothing Google (or, more accurately, its underlying carrier, Bandwidth.com in most cases) can do to stop a force port. All the "unlock" feature on Google Voice does is cause an automated port request to be approved if the other subscriber information matches. If an unlock is not done, then Google Voice will simply return "nope" on all port requests. But a force port can still go around that and, disturbingly, the losing carrier may not even know that a force port was done until days later when it notices that the LRN (local routing number) database no longer points the lost number at its service.

So, SMS is still a terrible idea for verification even on Google Voice numbers.

Re: Nine Charged in Alleged SIM Swapping Ring

#32
post #9

Earlier quoted context omitted.

A private key with an associated public key signed by one or more entitities that have verified the owner of the private key.

signed by one or more entitities Sounds like another opportunities for the advertising companies like Google and Facebook to uniquely identify us.

There are blind signature schemes.

Re: Nine Charged in Alleged SIM Swapping Ring

#33
How do you trick employees at mobile phone stores into seizing control of a phone number? You give him a fake ID, he checks the ID card's serial number, citizenship number, name, surname, date of birth in the mobile operator's application (which checks it from the governmental API service) or himself from the e-government web site. In this way he understands wheter the ID is real or not and wheter it was stolen or not. If it is real it hands you a new SIM in few minutes. (now it is even harder with ID cards with chips).

If you want to change the owner of the number the employee scans both of your documents and sends it to a governmental bureau and if they approve then the number is transported to the new person. Which it takes at least few days (I think it is intentionally slow).

This one will not save your Google account but it will save your bank account. If you change your SIM card you cannot login to your bank account. You need to recreate a password by calling the bank and answering tons of questions and revalidating your phone number. You might wonder how does a bank knows that a SIM card has been changed. I wonder it too. But the mobile operator probably informs all banks via a API. U have faced this personally 2 or 3 times and my friends have faced it too. So, it is real. (not related but there is also mobile digital signature thing that you can login to bank account, mobile phone operator's web site or your e-government account)

This is how it works in Turkey. I know United Statians don't like 1984 style states but I wanted to share.

Re: Nine Charged in Alleged SIM Swapping Ring

#34
post #14
post #4

Earlier quoted context omitted.

Or, phrased another way: we are NOT in possession of a phone number any more than we are in possession of an IP address. Both are transiently assigned to us to the computer with a cellular modem in our pockets

Not really. For all intents and purposes you do "own" the number. You can take it to any carrier you want (local number portability), and carriers can't expropriate it. Try doing that with a /32 you got from your ISP, even a static one.

The point is you own it in one sense, but the phone company can reassign to someone else (even if temporary, it's still gone). It's not locked to a physical device at your house that no one else can change, it's not like a diamond ring on your finger.

Re: Nine Charged in Alleged SIM Swapping Ring

#35
post #22

Earlier quoted context omitted.

SMS as a second factor is not and is unlikely to be secure for a second factor anytime in the near future given the design of SS7 and the glacial pace that the global telecom industry moves at for upgrading core infrastructure. The lock prevents port-out attacks, but is still not sufficient for considering SMS as okay to use for a second factor. Use TOTP instead.

I use something more secure than SMS as my sole second factor where I can. Unfortunately some sites still require a phone number. I’ve edited my comment to be clear about that. So if you have to use a phone number, is GV the least bad option?

I think it's better than the phone company, but as discussed, someone could force steal your number. Secondly, if someone hacks your gmail, they can access google voice themselves but just logging in as you.

My freaking gmail is my main barrier against the world. I sure as heck use a yubi key (I have multiple) plus password. If my gmail is hacked, I'd be in trouble like a lot of tech people. I think that's the ultimate - break into gmail and you'd have endless things to steal.

Re: Nine Charged in Alleged SIM Swapping Ring

#37

It's interesting seeing all these novel ways of stealing cryptocurrency. So far we have seen Twitter scams where people impersonate high profile accounts in the hope people will think it's a real cryptocurrency giveaway and actually send funds to various wallets. Then there is the cryptominer/cryptojacking technique where the unused CPU power of personal computers is used to mine various cryptocurrency (often stealth…

People have programs that scan github uploads for AWS, etc credentials accidentally uploaded by victim and spawn images that mind crypto for the attacker’s. https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...

Wow. I’m always amazed at the lengths people will go to to abuse anything and everything.

Re: Nine Charged in Alleged SIM Swapping Ring

#38

It's interesting seeing all these novel ways of stealing cryptocurrency. So far we have seen Twitter scams where people impersonate high profile accounts in the hope people will think it's a real cryptocurrency giveaway and actually send funds to various wallets. Then there is the cryptominer/cryptojacking technique where the unused CPU power of personal computers is used to mine various cryptocurrency (often stealth…

Any attack vector that would otherwise be foiled by a bank is a vulnerability in the case of Bitcoin. It has no consumer protections, like chargebacks or other fraud protections (lost or stolen "cards" or PIN-codes/passwords). There is no automatic or manual review of large transactions built into Bitcoin, which large bank transactions undergo to prevent theft.

Bitcoin has exactly one security measure: that it's mathematically very unlikely that someone will guess or generate the same private key as you (IF you don't use one of the many faulty ways of generating your own key, which are widespread online). From there, the sky is the limit.

You can hack someone's computer or server using whatever vulnerability you wish and steal their private key. You can physically gain access to a computer or simply use violence to demand someone's keys. You can offer a product or service, receive payment, and then simply never deliver the product or a refund. Or someone can seem to pay, you give them a product in return, but the transactions are later unconfirmed after they're long gone.

Some of these things are possible with regular banking, but in nearly all cases funds can be recovered or reimbursed to the account holder.

Bitcoin was not made with these protections in mind whatsoever. And the high-level platforms, even after more than half a decade, have failed to secure themselves or their customers consistently. They are often hacked and resort to going into hiding or creating complex ICOs, IEOs, "haircuts" or other trickery to cover up losses.

Re: Nine Charged in Alleged SIM Swapping Ring

#39
post #18

Several sites that I use, even some that support TOTP, still require a phone number. I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft (assuming you protect your GV account of course) and relatively safe to use. https://support.google.com/voice/answer/1065667#xferout

> I hope that since you have to “unlock” your Google Voice number before it can be ported, it’s immune to theft... I see this sentiment posted here a lot and I'm here to say that it is sadly not a good hope. When you do a number port, the automated/efficient/normal path is that your new provider (the "gaining" provider) submits a request to the number portability authority requesting that your number be moved to its…

Is getting a landline, and using a bank which offers 2FA via automated voice calls secure enough?

Re: Nine Charged in Alleged SIM Swapping Ring

#40
post #17
post #9

Earlier quoted context omitted.

A private key with an associated public key signed by one or more entitities that have verified the owner of the private key.

And how many people have those? With appropriate knowledge of how to generate, store, sign, backup, and secure the keys? On the front page of HN at the moment we have "we lost millions of dollars of Oracle DB due to key management issues". Key management is hard . Every few months a crypto exchange discovers this by either leaking or entirely losing their keys. It's basically just people with Estonian e-identity card…

> With appropriate knowledge of how to generate, store, sign, backup, and secure the keys?

I believe this could be solved by improving the interface used to accomplish these tasks (rather than using openssl req directly). Web browsers ask to save passwords and other sensitive information. There's no reason why they cannot relatively securely store a private key and the associated certificates.

> Key management is hard

That is true, but requiring key/certificate based auth in addition to the username and password for authentication means that attacks would have to be distributed amongst the users of a given website and the website itself rather than just attacking the website or some 3rd party used for 2FA (email or cell phone).

And breaches where backend databases are compromised and user credentials are retrieved also happen. But due to people re-using credentials on multiple services, they also get compromised on unrelated services. Using a private key and a certificate per service, it would be much harder to do something like that.

Post reply on HN