Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

381–388 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#381
post #216

Earlier quoted context omitted.

How would you prevent a Cambridge analytica style data "breach"?

You make explicit that all data that people enter, they enter for purposes of sharing. At the same time, you ban creating profiles with data that has not been explicitly shared. IMO: - Make a telefone-book style listing, or searching for "all metalheads OK - Tracking users on your site -> OK - Tracking users on third party sites, and then aggregating this data, so you can see "people who searched for baby carrages" o…

"You make explicit that all data that people enter, they enter for purposes of sharing."

I think the data captured by CA was also entered for the purposes of sharing, (often) limited to friends and friends of friends. I think the crux of this all is that as a society we haven't really established how those rights are transferred. If I share my email address with a friend, can they share it with their contact management app? I'm not sure how you create a consistent policy in a federated model.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#382

This is what I'm worried about, to be honest. Not necessarily getting hacked but just getting flagged, banned and burned with no recourse. This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues. These tech companies should offer actual support the moment you spend money with th…

>This is why I commented on an article here some weeks ago that if they ever offered any paid user experience they'd be in trouble because they'd actually have to help their users with their issues. Facebook has offered a paid user experience to Oculus users for several years now, and so far no one has forced them to actually help users with these issues. Not the market, not regulators, and certainly not users. They…

https://www.techradar.com/news/people-are-buying-the-oculus-...

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#383
post #162
post #115

Earlier quoted context omitted.

Do you pay for a separate phone line for the mule?

Yes. I have a dedicated account with a verizon MVNO and this account has no other SIMs or accounts associated with it. However, depending on how I choose to use it I can point 2FA for numerous different services to this one SIM. I just don't want to point multiple accounts at the same service to this SIM since that's a clear, common identifier and correlates those two accounts better than probably anything else could…

- If you use different services with the same SIM, using a phone number to identify you across platforms is my primary concern.

- Yet, confirmer SIMs can't really be throwaways. I'm 'stuck' with a prepaid the same way people are stuck in to gmail — they have 400 accounts with the e-mail address.

I've had it before, where I got locked out of accounts, with no way to delete the account, or even do a data takeout. The only way forward has been the same SIM.

The only way forwards would be to 'start a SIM farm': buy those SIM slot AliExpress boards, and sell(/use) a forwarder service.

(here is business plan, on how risky, and expensive to the customer it'd be)

The 'challange' is keeping track of multiple people, to avoid same-site conflicts. Users would hopefully be encouraged to tell where they are using the phone, as to not get an used one themselves.

For Estonia, the minimum of keeping alive a prepaid is topping up 3€ every 6 months, per SIM (whereas new is 1€).

Of course, IoT numbers are available, but they aren't likely a valid option, as they definitely aren't meant for burners, and even a single misuse/complaint would likely shut everything down. More on this later.

Assuming there would be (monthly) paying customers, prepaids could do. It'd be a bit pricey, I'd start at ~10€/mo/user, assuming small users (few sites) would use the same sites, and larger ones needing many, many numbers. Billing per new site isn't likely very cheap either.

That aside, hardware is the most concerning, AliExpress pricing is 12-22€/slot depending on how bulk you go. Hundreds or even few thousands of euros in upfront needed. (Side note, on a >100 users scale, old phones etc aren't feasible; otherwise go with android dual SIMmers (using feature phone nokias for the price of nothing and stuff would be cool, but custom fw, and soldering each one isn't worth the time), and WiFi (on the scale WiFi stops working, you'll have bigger problems to deal with, and it'd be extra hardware cost as ell) (Side note 2: 'sim banks' exist, what allow to connect many SIMs to one modem, it'd bring the hardware cost to ~2€/sim, unsure if they can be online at once (though 'click here and wait 5-10s before clicking send SMS' could work for the user); even if they can be online, you still run in to the interference and 'why is there 1000 phones in this house' problem)

I'd say after a few hundred, it probably makes sense to start building them yourself.

For a good user experience, you have to keep them always online as well. Building a SIM-switcher would be likely as expensive, as well. The real concern is interference and infrastructure — having hundreds or thousands of devices in the same spot will not work well in physics, nor the service provider coming knocking.

Now, even small scale, it'd make sense to be your own service provider. This way you could get SIMs, and can connect directly to the network. You could emulate devices a this point, not needing any SIM cards either.

Problem is, all of your network activity is for SMS confirmations. That is going to get many strange looks.

The bonus of being in a small country is, that the other way, you can be friends with the person, who happens to be a head or person actually doing things, at a telecommunications provider.

Though, on a large enough scale, you're going to have actual overhead to their network. That's when you'll need to start paying for the service. Pricing for businesses isn't cheap.

**

Well, that was a wall of text. Insanities.

So — assuming you aren't a large-enough service provider already, normal long-term vEriFiCatIoN is deadly, assuming you need captchas on many accounts.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#384
post #258

Earlier quoted context omitted.

Just think of it as like paying to see a movie. I bought a $10 app once, used it for what it was for, and now several phones later, I don't know or care what's happened to it. I got my value out of it and don't need to hoard every possession I "buy". Remember people who used to have a huge collection of video tapes or CDs? They hardly used them for anything except decoration of their living room. Hoarding old crap th…

You know, many people find collecting things to be a pleasant and relaxing hobby. Perhaps, for some people, having a large collection of tapes or CDs, displaying the collection is part of the point. People gather enjoyment from different types of things. Not everyone aspires towards minimalism.

Then buy something that you can keep instead of a revocable license to use something on someone else's computer.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#385
post #381

Earlier quoted context omitted.

You make explicit that all data that people enter, they enter for purposes of sharing. At the same time, you ban creating profiles with data that has not been explicitly shared. IMO: - Make a telefone-book style listing, or searching for "all metalheads OK - Tracking users on your site -> OK - Tracking users on third party sites, and then aggregating this data, so you can see "people who searched for baby carrages" o…

"You make explicit that all data that people enter, they enter for purposes of sharing." I think the data captured by CA was also entered for the purposes of sharing, (often) limited to friends and friends of friends. I think the crux of this all is that as a society we haven't really established how those rights are transferred. If I share my email address with a friend, can they share it with their contact manageme…

The German Facebook clone back in the day was called StudiVZ which means "Student's directory". This was before social media and was more of a social network. Everything you put in there you do because you want it to be public, like your number in a telefone directory. It was almost a pure platform for self-presentation, like MySpace or LinkedIn.

I'm well aware of "more is different" aka the dialectic transform of quantity in quality. Lots of data that in individually innocent can be problematic if somebody amasses it. But especially for this reason I think it is not good to have these kind of semi-public spaces where the data is public and the only protection is it is cumbersome to collect. Public data should be clearly public, and private data should be clearly private, and the UX should be really clear so people know what is happening.

(By the way, I'm not even sure CA was a "scandal" or that it was bad for FB. I think the only effect was that FB used it to justify locking down their API more.)

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#386

Earlier quoted context omitted.

How is it possible that some kind of imaginative script can be enough to get SMS sim swapped? Why aren't the operators requiring a strong identification via a passport or something like that? Maybe I'm really dumb but that just boggles my mind, whether or not there exist other types of alternatives to 2FA.

They could require this. Most of the big operators have physical stores where they could do an ID check. There should be an advanced protection mode where SIM swaps and other sensitive operations require physical authentication.

Yes this, please!

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#387
post #115

Earlier quoted context omitted.

Do you pay for a separate phone line for the mule?

In many countries, a pre-paid phone costs almost nothing to keep active. I keep a UK number for some 2FA systems, it costs about £0.10 per year. I just have to send an SMS every 6 months to keep the line active.

It's very easy to forget to send the sms, which will then make you loose your number. The carrier will take the number back and assign it to another person.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#388
post #387

Earlier quoted context omitted.

In many countries, a pre-paid phone costs almost nothing to keep active. I keep a UK number for some 2FA systems, it costs about £0.10 per year. I just have to send an SMS every 6 months to keep the line active.

It's very easy to forget to send the sms, which will then make you loose your number. The carrier will take the number back and assign it to another person.

This must be automated.
Post reply on HN