My experience is that after you give your phone number to most companies it effectively becomes a single factor: it's trivial to get them to change passwords with that alone. AFAICT, the only protection is to not give them your phone number in the first place.
> "the only protection is to not give them your phone number in the first place." That has its own risks. If you don't provide it to google and your account gets hacked, it's extremely hard to get it back. (My wife lost her original gmail account that way about 2 years ago. And of course there was no way to get any live support to try & fix it) Basically if you don't provide your number, you're more open to the more…
> "It doesn't leave much to choose from."
With Google anyway you're down to 2FA using an authentication app (possibly U2F but I haven't checked on that recently) and backup codes which should also protect you from traditional hacking.
This is why I use Google Voice with 2 factor authentication for my SMS. Google has no customer service to socially engineer.
Voice is the best, even as it's the worst.
I'm scared though, Voice seems to be an after though for google. They've killed Hangouts, which is the only app that text works with (if you have another way tell me), not given it any update love in forever and have been ending projects more actively recently.
Passwords don't work these days for sophisticated attacks. Phishing is too easy. I repeat, they don't work. No 2FA means you'll experience many successful account takeover attacks on your customers. 2FA does not mean you won't, though. Coinbase had a great talk about account takeover attacks on the recent DefCon. They receive some of the most sophisticated attacks, sometimes when attackers already have control of eve…
It's not clear to me how 2FA would help against a phishing attack. Is there something I'm missing? My understanding is that 2FA helps protect against weak passwords and password leaks. That's it. If you give me your password via a phished site, then you'll also just as readily give me your 2FA code. Then I can log into your account and turn off 2FA, generate new login codes, or just keep the login session running ind…
Maybe if you set up a site that looks like a login form phishing for the PW then immediately forwarding it to the target site, then do the same for a 2FA token you have a point.
But in any other case where the victim isn't in the loop, that 2FA protects them (hopefully). If you haven't been to target.com in a week, you're not going to click the pop-up on your phone to log in out of the blue (hopefully).
Ideally your 2FA methods are not as simple as just sending a code and having the user parrot it back though. There might be some cryptography going on that would make it even harder for the attacker to interfere.
It likely would have made tracking the perpetrators easier if there was a paper trail in the markets.
There's enough volatility and turnonver in Twitter's stock that anyone who made a few single comma trades wouldn't ever be directly identified. Buy some options several days in advance, drop the tweet, then sell right when volume shoots through the roof.
There are automated systems employed by exchanges that analyze trades and are undeterred by volume. If someone burned this on a couple single comma trades, goodness.
It’s a good enough solution. Especially for those with disposable income, they’re not changing numbers often, if ever.
Good enough, as long as you don't get assigned a number that previously belonged to a porn-addicted weirdo, or criminal, or dead-beat who doesn't pay their bills, or any number of other not-nice things that can turn your life into a hot mess despite never doing those things yourself.
Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
There's an MVNO owned by the Canadian ISP tucows called Ting, I used them for my primary mobile service for some time (I would still but I wanted access to Verizon's 700 and 800 Mhz bands for better coverage at my residence so I switched). Anyhow last time I checked they've since added several awesome (and self configurable via their account dashboard) features like multi factor auth settings for # porting, comprehen…
> There's an MVNO owned by the Canadian ISP tucows called Ting, I used them for my primary mobile service for some time (I would still but I wanted access to Verizon's 700 and 800 Mhz bands for better coverage at my residence so I switched). Anyhow last time I checked they've since added several awesome (and self configurable via their account dashboard) features like multi factor auth settings for # porting, comprehensive forwading options, port locking, locking a line to a sim or device, among other security related overlays to their service some assible via REST API, IIRC. They offer live, immediatly accessable by phone call, north american based (US/Canada), friendly, usually native english spreaking knowledgable support agents and start their minimum service tier pricing at $6/line/month with the ability to toggle (block) voice, sms and data services for each line. For Wow, I use this company for my elderly father for a resounding monthly bill of ~$7/8 for years and had no idea they were also Tucows.
It's 1 FA authentication because all you need is the phone to access the account. The password is irrelevant since all you need is access to the reset code that is sent via SMS. However, since you don't really even need access to the phone and can easily social engineer access to messages sent to the phone, it's not really a full one factor.
Using your logic, doesn't the ability to social engineer access to a password make passwords less than 1 FA as well?
It's 1 FA authentication because all you need is the phone to access the account. The password is irrelevant since all you need is access to the reset code that is sent via SMS. However, since you don't really even need access to the phone and can easily social engineer access to messages sent to the phone, it's not really a full one factor.
Using your logic, doesn't the ability to social engineer access to a password make passwords less than 1 FA as well?
A password is a factor of authentication, so by definition is 1FA. Any service which allows access to the account through social engineering could be labeled as having less than 1FA.
If an attacker could access your account without knowing any of your secrets, then it's really 0FA.
Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
> Number porting should require an SMS to the existing SIM with the ability to respond NO to cancel the process and flag the request as fraud
This is an excellent idea. And I wish all the cell phone carriers would adopt this, if not already.
Twitter uses SMS as a single factor, because you can reset the password with only access to the text message. If Twitter was using SMS only as a 2nd factor, this attack would not have worked without also knowing Jack’s password or having access to his email. Twitter’s password reset function could require an SMS code and then send a password reset email to complete the process. Number porting should require an SMS to…
> Number porting should require an SMS to the existing SIM with the ability to respond NO to cancel the process and flag the request as fraud (e.g. whoever made the request on the carrier side should be flagged, to fish out compromised support reps). Better yet, a YES text should be required with a port
Or require YES text for immediate port. Then if you can't do that because you've lost your phone, then it should delay for 24 hours, then do the port.