Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

221–230 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#221
post #208

Earlier quoted context omitted.

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…

> My 2FA for gmail is now my iphone and ipad sorry - how does that work? what's the platform / messaging service?

Authenticator app that generates one-time codes; no messaging (or even being online) required after the initial sync.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#222

Earlier quoted context omitted.

> Provide me one legal use case better suited to cryptocurrency than the US dollar. Sending money to people overseas without extortionate fees. Surprisingly not everyone overseas is linked with international terrorism as you imply.

Stellar and IBM's WorldWire are hoping to tackle the remittances issue! Check it out if you haven't.

Neither of those solutions need or benefit from BlockChain.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#223

Earlier quoted context omitted.

Yes, my google account was simjacked last year. I lost access to my email, photos, and ability to login via Google. They were after my Coinbase account (luckily the only account I used real 2FA on). They could have initiated bank transfers too but didn’t try. Customer support for personal gmail accounts is almost nonexistent. Fortunately I had a friend who worked at Google and had them put a word in on my reset reque…

Go through the password reset process with google and it's worse than most people think. The first thing it asks you is: > Enter the last password you remember using with this Google Account Which of course the attacker knows because they changed your password. If they don't know that you can click try again and go through the various two factor methods set up (hardware token, totp code, sms) and then the very last a…

>> Enter the last password you remember using with this Google Account

> Which of course the attacker knows because they changed your password.

The site asks for the last password you remember using, not the last password that was used (presumably by the attacker). I don't think this is as bad as you think; the attacker doesn't likely know the previous password, or else they would not have needed to hijack your phone number.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#224
post #207

Earlier quoted context omitted.

Most chip credit transactions in the US dont use a pin yet.

Correct, and they won't any time soon. This US is a Chip + Signature market, which still incorporates cryptographic elements on the card itself as the secret. In a Chip + PIN transaction, the second factor is your digital PIN, whereas in the Chip + Signature transaction the second factor is your signature. It's still 2fac, but more importantly, in neither case is the secret on the front of the card.

a signature doesnt stop the transaction from going through. if i dispute a transaction, I can go "thats not my signature."

do most people sign their name on those digital pads, or do they scribble random patterns?

a signature is not a pre-authentication factor, a PIN is.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#225

I wonder how nobody sees the elephant in the room. 2FA by SMS is terribly insecure. Numerous security researchers recommended never using it. Using phone numbers as primary authentication mechanism is insecure and never should be used. Phone numbers can be spoofed, SMS messages can be intercepted, SIM port attacks can and will happen. If your email or banking accounts depend on 2FA by SMS, especially when SMS can be…

I know SO many real banks which still use 2FA by SMS.

And it was a hell of a fight to even get _those_.

Alliant Credit Union, for example, only just rolled out SMS-based 2FA in the past ~year. No TOTP/U2F/FIDO* options at all (in fact, according to https://dongleauth.info/, exactly zero major banks/CUs in North America support anything better than SMS or TOTP).

When I can lock my GitHub account more securely than my _money_, it's a bit (read: lot) depressing.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#226

Earlier quoted context omitted.

Stellar and IBM's WorldWire are hoping to tackle the remittances issue! Check it out if you haven't.

Neither of those solutions need or benefit from BlockChain.

Your comment couldn't be more asinine.

Did you even bother to google search them? Here I'll help.

https://www.stellar.org/

https://www.ibm.com/blockchain/solutions/world-wire

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#227
post #167

Earlier quoted context omitted.

Personally I use Google Authenticator. The lack of a backup is a feature not a con IMO. Every account I have setup with TOTP I also make sure to print out the recovery codes and put them in a safe, and use them if my device is ever destroyed. When I switch phones (which for me happens maybe once every 2-3 years at most), I go through the shitty process of transferring the TOTP codes over to the new device, but it doe…

Google Authenticator does not help prevent against a compromised device (as all TOTP secrets and seeds are on device) and is truly a pain when working with multiple phones. Personally I use Yubico Authenticator as all the TOTPs live on my Yubikey. That, in combination with a password then clicking on a totp i want and tapping my yubikey provides me with only that code. When I first seed the yubikey with a new TOTP i…

Doesn't this mean your password manager is still single factor? Access that, access everything. That's the problem I was trying to avoid.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#228
post #87

Earlier quoted context omitted.

I really need to call out crypto shill when I see it. As it stands, bitcoin is utterly unusable for micropayments, the transaction fees are way too high for that. There has been attempts at creating micropayment services on top, these all have failed to gain traction. I still maintain as I did several times here in the past: bitcoin (and in general, crypto"currencies" because they are not currencies) are a scam, a ne…

Bitcoin isn't the only crypto. Dogecoin is great for microtransactions.

I pay all my dogs in Doge

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#229
post #66
post #5

This is frightening. If you're using texts for 2-factor auth you're at the mercy of your phone service provider's customer service. And they're trying to balance being helpful with security, which can be in opposition. Losing $100,000 with no hope of recovery is the kind of thing that could sink many people's finances. His summary of how to avoid having this happen to you: * Use a hardware wallet to secure your crypt…

There may not be a choice. Vanguard refused to log me in until I configured 2-factor SMS.

Vanguard also offers 2FA with voice-automated calls. I wonder, would getting a landline and using that with a Yubikey be any more secure?

https://investor.vanguard.com/security/security-keys

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#230
post #224

Earlier quoted context omitted.

Correct, and they won't any time soon. This US is a Chip + Signature market, which still incorporates cryptographic elements on the card itself as the secret. In a Chip + PIN transaction, the second factor is your digital PIN, whereas in the Chip + Signature transaction the second factor is your signature. It's still 2fac, but more importantly, in neither case is the secret on the front of the card.

a signature doesnt stop the transaction from going through. if i dispute a transaction, I can go "thats not my signature." do most people sign their name on those digital pads, or do they scribble random patterns? a signature is not a pre-authentication factor, a PIN is.

There are three security elements aspects to the EMV standard: card duplication (your card is the real deal), cardholder verification (you are the real deal), and lending (that you still have available credit).

Having a chip prevents (or at least is intended to prevent) card skimming. EMV payments cannot be re-played, cards cannot be duplicated and neither the card nor the reader can be tampered with. The magstripe of a chip card includes a flag indicating the card has a chip so even if you duplicated the stripe, it still wouldn't work. That is a material improvement over magstripe-only cards, and the private key is embedded within the silicon in a highly tamper-resistant way. This got the US the bulk of the 'win'.

With respect to cardholder verification, the Cardholder Verification Methods range, from least to most secure (from the perspective of a bank): None (i.e. have at it), Signature, PIN and CDCVM (ApplePay, etc). The CVM is negotiated between the card and the reader on insertion (EMV) or presentation (NFC/EMV). Each of these CVMs will impact to some extent things such as how likely a transaction is to be approved vs declined, how much you're charged in interchange to make up for it, and so on.

Yes, PINs are more secure in some ways because they provide a pre-payment second factor and in some ways yield a false sense of security. For instance, if someone sees you key in your PIN, you'll have a harder time claiming fraud, and in Europe it's on you to prove that. In the US, it's on the merchant. The trade-off here is again more time. Merchants are often willing to pay a slightly higher interchange rate to get people through the line faster, and signature is unequivocally faster than Online pin (requiring another network request to decrypt/verify) and still faster than Offline pin (which only works in Europe and is capped through floor limit).

Consider this from the perspective of all the layers of security even an EMV signature payment has. Tamper-proof physical card required that cannot be cloned, tamper-proof terminal, the card yields a signed payment request to your acquirer who can flag it as fraudulent, to the issuing bank who can flag it as fraudulent, and all the way back down to the card which can itself mark your transaction as fraudulent (it's called a reversal). Then you sign. And your photograph / video is likely recorded by the merchant at the point of sale, too. PIN or no-PIN, in a low fraud rate market, the win is small but the cost in added time can be really high.

If this mattered in the US and PIN were truly advantageous, restaurants could configure their terminals to request signatures or no verification while high-ticket size merchants could still capture PINs. They could still make this change at any time, really, all the tech out there more or less supports it. During the EMV transition all this was considered, and the decision was made it wasn't worth it.

tl;dr: Sometimes the 'less secure' method get you the bulk of the security win while yielding more profit for the merchant.

Source: I worked in payments for years including during the EMV switchover :) Hope that helps!

Post reply on HN