Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

131–140 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#131
post #2

> I want to start by pointing out I use two-factor authentication just about everywhere and Facebook is not an exception. I wish he'd mention what kind of 2FA. The reason you _really_ should use U2F/WebAuthn is because it does origin binding which, unlike entering a TOTP, a code from your hardware token/authenticator app on your phone/SMS/etc is not phishable, i.e. you can't enter it by accident on accounts.google.co…

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

>Beating 2FA is almost always SMS hijacking

How exactly does this get executed? I'm pretty technical, but I cant fathom exactly how this occurs;

You hijack a cell tower, then have some system to listen to un-encrypted SMS traffic??

Plz ELI5

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#132

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

> Beating 2FA is almost always SMS hijacking That's most definitely not true, as someone who works in this space. Plain old phishing is much more common, where the hacker tricks a user into entering their code into a malicious website. To echo OP, this is why it's important to support non-phishable types of 2FA.

I wondered about this in regards to Crypto and NFT's in the digital wallet space. It seems like Metamask with a ledger wallet is stadard, but I have a theory that if you're not sophisticated and you get into Crypto/NFT's, it may be safer to just use Coinbase Wallet, as it is less popular target than matamask and you're able to leverage Coinbase's ongoing security updates. and if you're not sophisticated, you're just as likely to lose your stuff via user error with a hard wallet set up.

Just don't click on giveaways and never enter your secret code

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#133

Earlier quoted context omitted.

> PCs/ laptops/ etc. can use little USB hardware devices, from outfits like Yubico This is actually built into most computers now -- Windows Hello, and Apple has something similar. Websites can check the attestation response to specifically block those, however. (Seems like Github allows it, and I've written code that allows it.) > I think some iPhones do facial recognition instead? Yup, they use whatever you use to…

Can you hold your NFC Yubikey to the back of an iPhone? I thought Apple didn’t do NFC, appart from ApplePay?

Your recollection was correct but is now a few years out of date. As is typical Apple they intro'd it (in 2017 IIRC) as a 1st party dogfood item, started read only. Then in 2019 with iOS 13 allowing far more power including full range of two way authentication capability. Yubico blogged about it [0] after the announcement, and Apple's HIG on use of NFC [1] is also available. Also, Safari itself needed to have support added, but that too is now available.

So old workarounds like using the lightning port are no longer necessary, though AFAIK are still supported. It's nice to have it there as well since to really be most effective every platform a user has needs to support hardware 2FA. If something still needs SMS or OTP or whatever that becomes the weakest link.

----

0: https://www.yubico.com/blog/yubico-ios-authentication-expand...

1: https://developer.apple.com/design/human-interface-guideline...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#134
post #82

Earlier quoted context omitted.

> it is generated on a separate device which does not communicate with your browser, and does not know the target domain. No, not always and many password manager solutions do integrate with your browser and know the domain for the password.

Then that's not TOTP https://datatracker.ietf.org/doc/html/rfc6238 but something different. Do you know how it is called and which products support it? I'd love to read up about it!

Yes, it is TOTP:

https://github.com/tadfisher/pass-otp

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#135
I really think for the Oculus side of this, they should be on the hook for refunding a significant portion of the cost of the user's Oculus library when they ban the account.

This would put the cost of a ban to Facebook for real users in the order of hundreds of dollars which is more than enough to have a support person do a realistic evaluation of the situation. It also reflects the non-recoverable portion of the cost to most users - you can sell the headset, but you can't transfer the value of the library to anybody. That is a straight up and very significant financial loss.

While other aspects of the ban policy are obviously still very problematic, the fact that an arbitrary ban that is caused by actions outside the user's control can result in hundreds of dollars of losses sits at a whole different level and should be legally problematic for Facebook.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#136
post #112

Earlier quoted context omitted.

How would someone use that code to hack into my GV account? Wouldn't they also need to know my password or have access to my e-mail account to login or to reset your password?

They don’t. They want to link a new GV account to a real phone number that is not theirs, so that they can use the GV number for other scams. It only works when your phone number doesn’t already have a GV linked to it.

Wouldn't the victim have to send the code back to the scammer for it all to work?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#137
post #42

Earlier quoted context omitted.

“If you lose your key and are still signed in on one of your devices, visit account.google.com to add or replace a key. Otherwise, submit a request to recover your account. Google may take a few days to verify that it’s you and restore your access.” I trust that it would be (potentially much) harder than normal, but it still seems to be possible.

I was under the impression you were screwed in that case, thanks for pointing out that I was wrong. It's lot less secure than I thought.

IIRC, Google will stop the "several day process" if you log in at any time.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#138
This is what I'm worried about, to be honest. Not necessarily getting hacked but just getting flagged, banned and burned with no recourse.

This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues.

These tech companies should offer actual support the moment you spend money with them with some actual recourse to solve problems, especially if it's caused by them. It's insane to me that they can just go and run away with your money or burn your account at a moment's notice, even when it's just some automated filter going crazy. At the bare minimum something like Amazon has should be the standard the moment you operate a paid digital software repository or sell a digital service or ads. Losing your investment should not happen to you unless you're a really blatant abuser and if you're the one getting abused your bank or credit card provider should never be your only line of defense.

I'm baffled that they have not been in any real conflict over this with any consumer protection agency for any of our governments.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#139

Earlier quoted context omitted.

Beating 2FA is almost always SMS hijacking, but sometimes it's social engineering where the attacker has figured out just the right script to tell support ("oh, I dropped my phone and it won't turn on...") to get it disabled. edit: correction, beating 2FA without phishing -- like in the post where he lost his account while asleep.

> Beating 2FA is almost always SMS hijacking How exactly does this get executed? I'm pretty technical, but I cant fathom exactly how this occurs; You hijack a cell tower, then have some system to listen to un-encrypted SMS traffic?? Plz ELI5

It's zero cost and zero effort to port someone's number out, or get a new SIM card issued for the existing account.

I've worked with a bunch of streamers and YouTubers, and the threat model is such that people have shown up with professionally made printed fake IDs to attempt hijacking in an actual retail carrier store.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#140
post #111

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

This is very common scam. AFAIK it’s a way to create a new Google Voice account (linked to your phone number) with the goal of using that account for other scams so that they can’t be tracked. I fell for it, but since I already had a Google Voice account linked to that phone number, it didn’t work for the scammer. But he didn’t realize what it didn’t work. I quickly realized that something wasn’t right (and Googled t…

That foreign language thing is genius. I've never heard of that before.
Post reply on HN