Live data from Hacker News

“Mobile emulator farms” used to steal millions from US and EU banks

arstechnica.com

21–26 of 26 posts

Re: “Mobile emulator farms” used to steal millions from US and EU banks

#21
Either only few phones had SMS as MFA or SMS swapping wasn't used at all. The later is more logic:

- You have to have a physical/esim card which costs money to buy and is perfectly Geo-trackable.

- You can only SIM-swap by duping any given cellular operator in personal interaction with their Support. Article says US & Europe - different countries, different mobile operators. Each such call is recorded, costs air time money, again Geo locates the caller.

What is more probable - yet another stupid malware was installed on phones, which can easily read Device ID/SMS received. In such case, great that Trusteer busted this operation (I guess, no mentioning of LE involved), but nothing news-worthy in technological sense. So, it is still better to have SMS as MFA versus no MFA at all, and of course it is time to switch to Authenticaiton Apps for MFA/Hardware keys.

Re: “Mobile emulator farms” used to steal millions from US and EU banks

#22

Either only few phones had SMS as MFA or SMS swapping wasn't used at all. The later is more logic: - You have to have a physical/esim card which costs money to buy and is perfectly Geo-trackable. - You can only SIM-swap by duping any given cellular operator in personal interaction with their Support. Article says US & Europe - different countries, different mobile operators. Each such call is recorded, costs air time…

> Each such call is recorded, costs air time money, again Geo locates the caller.

Air time is practically free and untraceable. How do you think the ‘I’m Bob with Microsoft’ scam works?

Re: “Mobile emulator farms” used to steal millions from US and EU banks

#23
post #3

Earlier quoted context omitted.

Issue their own hardware tokens to customers? A FIDO NFC key can be pretty cheap, though I guess the really low-end phones might not have NFC.

SMS is mostly popular today because it’s user friendly. I can’t imagine that most users would like carrying around separate hardware tokens. I would imagine there’s some point at which there’s an equilibrium between fraud costs and customer acquisition/retention costs.

Mine lives on my keyring and is smaller than my house key or bike key, and I'd argue holding it against the back of my phone is actually more user friendly than typing in a number from a text message.

Re: “Mobile emulator farms” used to steal millions from US and EU banks

#24
post #5
post #4

In the US at least, the bank is responsible for losses right? At what point do they begin to secure all this? I have a number of accounts and not one is true 2FA: only one is SMS, the rest are user/password only.

> At what point do they begin to secure all this? When the cost of fraud handling exceeds that of redoing their security, I guess. It'd have to be a 10x or more factor though, because companies seem to be quite accepting of existing / recurring costs. That said, my banks have had 2FA for a long time. The one started off 20 years ago with a device where you'd punch in the numbers on screen, it would give you some numb…

I would add that simply answering a ping on the account's SMS is emphatically NOT by itself 2FA.

Re: “Mobile emulator farms” used to steal millions from US and EU banks

#25
post #23

Earlier quoted context omitted.

SMS is mostly popular today because it’s user friendly. I can’t imagine that most users would like carrying around separate hardware tokens. I would imagine there’s some point at which there’s an equilibrium between fraud costs and customer acquisition/retention costs.

Mine lives on my keyring and is smaller than my house key or bike key, and I'd argue holding it against the back of my phone is actually more user friendly than typing in a number from a text message.

It's convenient if you have one. If you had one for each financial institution you deal with, it might be a different story.

Re: “Mobile emulator farms” used to steal millions from US and EU banks

#26
post #23

Earlier quoted context omitted.

Mine lives on my keyring and is smaller than my house key or bike key, and I'd argue holding it against the back of my phone is actually more user friendly than typing in a number from a text message.

It's convenient if you have one. If you had one for each financial institution you deal with, it might be a different story.

It's a smaller inconvenience than one more key on my keyring, so a handful of them wouldn't be a big problem.
Post reply on HN