Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

81–90 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#81
post #36

So in this story Facebook was responsible for $50 of charges, a business disruption and a huge and ongoing hassle. And Facebook refuses so much as to pick up the phone to discuss it. In the old days the equivalent would have been one of those roach motel businesses rated 'F' on the Better Business Bureau, buckets arrayed on the floor to catch rain leaking through the roof. And yet in this day it's one of the most pro…

Companies like Facebook are as big as Nation States. Any positives that come out of this for the author are just a Facebook PR move. If they did care about users, their support system wouldn't be so anti-user.

It's trite at this point that someone will respond that the users aren't the customers, they're the product, but it's trite because it's often correct, and deserves to be said, so I guess I'll be the one to say it this time.

The sad thing is that this person actually is a customer because they bought a product and pay for things on it, but Facebook still doesn't realize that, or more likely these customers are such a small amount of their revenue they just don't care (and don't think it matters for growth of this area or don't care about that growth).

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#82
post #14

Earlier quoted context omitted.

How? TOTP does not embed the domain, as it is generated on a separate device which does not communicate with your browser, and does not know the target domain. TOTP is literally HMAC(shared-secret, time-interval) mapped to a short range (e.g. mod 10^6).

> it is generated on a separate device which does not communicate with your browser, and does not know the target domain. No, not always and many password manager solutions do integrate with your browser and know the domain for the password.

Then that's not TOTP https://datatracker.ietf.org/doc/html/rfc6238 but something different. Do you know how it is called and which products support it? I'd love to read up about it!

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#83
post #74
post #49

Earlier quoted context omitted.

If the session cookie was stolen, there's no new login to detect and send a security notification about.

Can't they detect that the session cookie is coming from a different IP than the one it was originally issued to?

[deleted]

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#84
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Nice. I do something similar but forward it to Slack.

I also have it auto-answer 2FA calls and automatically hit the # key.

Yeah, call it not real 2FA, but it's really companies that choose to not use U2F are at fault.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#85

Earlier quoted context omitted.

How does an sms hijacking attack typically work? I know sms isn't secure, but how does one go from having a password to bypassing the sms confirmation? Is it as easy as having the number and carrier?

It happened to me. Cellular carriers, in my case T-Mobile, didn't require any confirmation to port a number to a new phone/sim. Eventually some required the last 4 of your social security number to port a number, which we all know at this point are pretty much public anyway. T-Mobile now lets you set an arbitrary pin, which my parents promptly set to their DOB :facepalm: I haven't looked more into it, but as far as I…

You might want to edit out what your parents set their pin to! (You can email hn@ycombinator.com if you're past the edit window.)

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#86

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

Old school phishing is the most common MFA bypass. Here is a description how it works: https://github.com/wunderwuzzi23/KoiPhish Unless you use Yubikeys (webauthn) etc these phishing attacks just continue to work. I do consultancy in this space at times and about 95+% of folks who enter their password will also enter their MFA token.

Followed the link and the read me is bit spare on details. For the less technical this still would require the phishee to manually enter credentials which then can be relayed to the attacker. Correct? The article mentions this happened while the author was asleep — any thoughts on how that would work?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#87
post #2

> I want to start by pointing out I use two-factor authentication just about everywhere and Facebook is not an exception. I wish he'd mention what kind of 2FA. The reason you _really_ should use U2F/WebAuthn is because it does origin binding which, unlike entering a TOTP, a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable, i.e. you can't enter it by accident on accounts.google.co…

> I wish he'd mention what kind of 2FA...U2F/WebAuthn...origin binding...SMS

It shouldn't matter, because it's irrelevant to the point of the article, which is that Facebook (at least as reported) leaves a hacking victim with little or no recourse to get their account, and sometimes livelihood back.

An imperfect real-world analogy of your question is like asking about what precise brand of bear mace an assault victim was or was not carrying, and whether a better one would have helped. Perhaps it would have, but that's not the point. If having hardware tokens is so important, Facebook should be making them mandatory at its scale.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#88

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

How does an sms hijacking attack typically work? I know sms isn't secure, but how does one go from having a password to bypassing the sms confirmation? Is it as easy as having the number and carrier?

I accidentally ‘hijacked’ a number by typoing one number in my online request. I only found out after my wife pointed out my number was different after porting. It took a couple hours with the telco’s support agents, and practically no verification steps, to actually get my correct number back. Very sad state of affairs here.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#89

Earlier quoted context omitted.

>If you need to reset 2FA, go somewhere in person with a government-issued photo ID (which we already have procedures to replace) that all of the details of match. Very few people are going to want to pay for this labor if the perception of risk of using a free account is as low as it is now.

What about giving people a choice like this to pay for the labor? Either pay $1 per month for your account, and then this service is free for you whenever you need it, or have a free account, but then this service costs you $1000 if you ever need it.

That would be nice, but I imagine there's a perception problem with that.

Simply offering the option would bring the risk to the forefront of people's minds, and once you start exchanging money, lots of other thoughts and liabilities begin to enter.

If it is kept free, then the conversation ends there.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#90
post #84
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Nice. I do something similar but forward it to Slack. I also have it auto-answer 2FA calls and automatically hit the # key. Yeah, call it not real 2FA, but it's really companies that choose to not use U2F are at fault.

U2F is great, but these companies want to be able to provide 2FA for people who won’t/can’t have a dedicated hardware device for 2FA.
Post reply on HN