Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

141–150 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#141

Is Google's password reset system a massive security risk? I set up a couple of recovery phone numbers without thinking about it too much, but after reading this it seems like I'm just a little bit of social engineering away from having my Gmail account taken over, along with anyone else who set up a recovery number. If someone took over my SIM and reset my password overnight, they would have 8 hours to do whatever t…

Yes, my google account was simjacked last year. I lost access to my email, photos, and ability to login via Google. They were after my Coinbase account (luckily the only account I used real 2FA on). They could have initiated bank transfers too but didn’t try.

Customer support for personal gmail accounts is almost nonexistent. Fortunately I had a friend who worked at Google and had them put a word in on my reset request otherwise I would have been SOL.

Disable phone number resets and switch to Google Authenticator w/ backup codes ASAP.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#142

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

> Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked.

Funny because that's exactly what happens in France when you do so. I must have sounded a bit dumb when I asked when my number would be active when I changed from Tello to Verizon. I couldn't believe it was effective right away.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#143
Seems like a "better than nothing" mitigation for sites that insist on SMS 2FA is using a Google Voice number so the recovery # is 2FA protected.

Out of curiosity are there any decent free/cheap voip services that support 2FA aside from Google Voice? Using the same provider for email + recovery codes makes me a little nervous.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#144
post #124

It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…

>It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new

I remember first hearing about them in 2016:

https://www.ftc.gov/news-events/blogs/techftc/2016/06/your-m...

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#145

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

So what’s the alternative? Especially financial institutions insist on using SMS in addition to even hardware keys. It’s crazy.

Or allowing one to "confirm" their accoubt via SMS if they've lost the TOTP code generating device.

(Because no one would lie about that)

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#146

Is Google's password reset system a massive security risk? I set up a couple of recovery phone numbers without thinking about it too much, but after reading this it seems like I'm just a little bit of social engineering away from having my Gmail account taken over, along with anyone else who set up a recovery number. If someone took over my SIM and reset my password overnight, they would have 8 hours to do whatever t…

Yes, my google account was simjacked last year. I lost access to my email, photos, and ability to login via Google. They were after my Coinbase account (luckily the only account I used real 2FA on). They could have initiated bank transfers too but didn’t try. Customer support for personal gmail accounts is almost nonexistent. Fortunately I had a friend who worked at Google and had them put a word in on my reset reque…

Go through the password reset process with google and it's worse than most people think. The first thing it asks you is:

> Enter the last password you remember using with this Google Account

Which of course the attacker knows because they changed your password. If they don't know that you can click try again and go through the various two factor methods set up (hardware token, totp code, sms) and then the very last and also terrible option is putting in the date the account was created. If your account has been owned the attacker likely knows this too. Advanced account protection is pretty much the only option if you've had your account breached at any time.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#147

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

So what’s the alternative? Especially financial institutions insist on using SMS in addition to even hardware keys. It’s crazy.

Many carriers let you set an "account password" or "account pin" - changes can't be made to the account without it (even with personal info like SSN, bday, etc)

Financial institutions offer it to sometimes - my credit union requires the account password, or a visit to a branch to show ID - no amount of personal info will allow you access.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#148
post #107

Earlier quoted context omitted.

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…

I'm fairly certain that any phone number in the US has to be portable by law.

You can port out a voice number - it's $3 if it was originally a voice number:

https://support.google.com/voice/answer/1065667?hl=en

Weirdly, you can't port a Gsuite google voice # to a gmail account. (I looked into it when considering canceling my Gsuite account)

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#149
This inspired me to disable SMS verification on my Google account. Now, the attacker may be able to port my phone number, but without my logged in Android phone, or one of my printed pass codes, they would not be able to subvert my email address.

I was wondering how the attacker found out this guy's phone number, so I searched my own online. Disconcertingly, it was visible on truepeoplesearch.com. So I also submitted a record removal request there.

I mean, I think the best option is to not own any assets that can be fraudulently, irreversibly transferred away. That's what I do. But a little extra security won't hurt.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#150
post #124

It's an extremely odd decision by the author to publish this piece. Port attacks on cryptocurrency accounts is nothing new, and outside of publishing the number ($100k!) there is nothing special about this account of events vs the countless other near identical articles that have been published on Medium on the same old attack. The reason I say it's odd is that he's an engineering manager at BitGo, which is a leading…

BitGo also secured the wallets for Bitfinex leading to a hack in 2015, never fully explaining the circumstances. https://en.m.wikipedia.org/wiki/BitGo#Bitfinex_hack
Post reply on HN