I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…
This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…
The Most Expensive Lesson of My Life: Details of SIM Port Hack
111–120 of 251 posts
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#112In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…
An attacker can call support, give them plausibly correct information gleaned from public sources, and nicely claim to have forgotten the answers to your recovery questions ("Oh, it might have been a jumble of letters and numbers... silly me..."). There are enough incorrectly trained support people who will let this through to make the tactic effective on average.
Your point is obviously correct, but everything is so hopelessly broken that it almost doesn't matter in practice.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#113Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#114https://www.silvermillerlaw.com/current-investigations/crypt... comes up on a search and says they'll do contingency in cases like this. Got nothing to lose.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#115I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…
> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…
This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out.
Note that all telcos will prevent the number being ported out if you owe them any money on the account.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#116I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…
This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#117Earlier quoted context omitted.
There may not be a choice. Vanguard refused to log me in until I configured 2-factor SMS.
I would consider that an alarming sign that I need to change investment companies asap (probably after loudly complaining and trying to change it, since Vanguard is somewhat unique).
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#118Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#119Earlier quoted context omitted.
> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…
Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead. This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out. Note that all telcos will prevent the number being ported out if you owe them any money on the account.
Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack
#120Earlier quoted context omitted.
because they can (usually) revert it. Because reversibility is a good thing.
Fraudulent transactions made with a regular bank account are pretty irreversible too. There's a whole extra layer of infrastructure on top of the 'core' banking services that allows them (banks) to 'reverse' a fraudulent transaction. But I'd be very very surprised if fraudulent charges are 'reversible' in any other way than the bank reimbursing the account holder. In other words, crypto-currency exchanges could do th…