The Most Expensive Lesson of My Life: Details of SIM Port Hack
101–110 of 251 posts
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#102Earlier quoted context omitted.
>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…
What's a good secondary service to store the TOTP codes separate from passcodes? Authy, from what I understand, requires a phone number as backup, meaning it could be compromised by the same method Google authenticator can't be backedup, which is royally annoying when you change/lose devices Lastpass has some security issues, and one well known comment here has recommended no one use it. I heard someone say they use…
Means I don't have to worry about phone upgrades and such, and if the Yubikey were to stop working I still have it on my phone
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#103Earlier quoted context omitted.
> And while we are doing PSAs, I'd like to give one piece of seemingly conflicting advice: make sure you have backups of your multi-factor authentication systems. Yes! Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. The underlying keys can be manually shown and entered elsewhere if needed, and can be backed up with everything else that's valuable. > Print out 2-factor backu…
>Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. Personally I don't really like this feature and urge people to avoid it for "high security accounts". It's not a "second factor" if it's stored and input using the same device and authentication information as your "first factor" (your username and password). That's not to say it's useless, at the very least it's another laye…
I have this in case my yubikey ever dies and takes my totp codes with it.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#104In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#105In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…
I wish Google, Twitter et al would listen to this, but alas...
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#106For anything important I use air-gapped hardware tokens for 2FA. If a brokerage or bank doesn't support hardware token 2FA they don't get my business, full stop.
At the last startup I worked for, which was rather security sensitive, the leadership actually insisted on employees setting up gmail w/SMS 2FA on their smartphones. I kept using backup codes and never set it up.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#107I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…
This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#108Earlier quoted context omitted.
I wish Google, Twitter et al would listen to this, but alas...
Google offers 2FA using TOTP, and has for several years.
U2F is the current state of the art for 2FA. App/Device-based 2fa (krypton, Google App’s “approve on other device”, authy’s “approve on other device”, keybase, et c) are second.
TOTP is in a lot of ways more trouble than it is worth.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#109In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…
I wish Google, Twitter et al would listen to this, but alas...
You can set up Google Authenticator (or Authy) and a Yubikey as 2FA sources, then remove your phone number.
Much to my surprise, I was able to do this with PayPal where I set up two Symantec VIP Access IDs and was able to remove the phone number.
I wish I could do this with other accounts.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#110In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…