In the opinion of HN is this the most secure way to do it while still allowing me to use services that force SMS based 2FA (almost everything) ?
Is there a better way?
161–170 of 342 posts
In the opinion of HN is this the most secure way to do it while still allowing me to use services that force SMS based 2FA (almost everything) ?
Is there a better way?
Earlier quoted context omitted.
I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…
That’s assuming you regulate a very specific thing versus the end goal. To me the appropriate regulation is to find a way to cause real harm to T-Mobile when they are breached. When repeated like this or if done through effectively negligence, then they shouldn’t be allowed to be in business anymore. We gotta stop the tiny fines.. jail, billions of dollars in fines, remove their business license… something large need…
Earlier quoted context omitted.
TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.
As sad as it is to write this, Apple corporate lines are Verizon - though they also have ATT available if you need it or have a preference. I only say this as I don’t know of any major corporation who picks TMO as their company lines. All this to say, I trust ATT and Verizon slightly more than T-Mobile
Earlier quoted context omitted.
> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…
On darknet diaries the stories told are a little more straightforward. They just walk in to the store, steal a tablet out of the manager's hands, run away with it, and make all the changes they can with the logged-in session until corporate locks out the device.
Earlier quoted context omitted.
No 2FA on your GMail? Any idea how G and A were compromised, password reuse?
Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.
Earlier quoted context omitted.
I think it has failed because the industry is moving way faster than most people can keep up. Even your average developer isn’t going to be aware of security changes in the industry to know what’s important or not. It’s going to be even less likely they someone not in engineering to remotely know what’s important or not. Security professionals know but do you seek out a cardiologist first before you ask your GP? Prob…
"People" don't need to keep up, the internal controls team needs to keep up, and it's possible to staff such a team with people who know how to mitigate phishing attacks when you are one of the largest corporate targets of phishing by volume on the earth.
If you’re trying to decide between electricians but you know nothing about electrical jobs, you’re going to be unable to make any meaningful decision. You’re just going to pick the one that sounds the best.
Heck, you could be using the same mediocre electrician for years and even recommend it to friends because you still have no clue about the workmanship.
The security situation with these companies shows no signs of improving. My hot take is to make many forms of hacking legal so long as the hacker reports their findings to the government. Let's have a free for all where every white hat and grey hat hacker gets to test the security of all companies, no permission from the companies required. Otherwise, it's only black hats that get to do the hacking, and they won't te…
Lack of knowledge of vulnerability is not the limiting factor in this case. All a "free for all" would do in this case is make more noise in which malicious actors can hide in the logs.
My conspiracy theory is that my idea will never be implemented because it would expose the "job creator" class to an objective measure of their competence, and they would not fare well. Headlines like "97% of US organizations are incapable of building secure systems" would not be fun.
Earlier quoted context omitted.
SMS 2FA is a security risk! I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.
How is SMS a security risk? As far as I know, SMS is closely tied to a person's identity, especially 'know your customer' regulations. I'm curious how it's a security risk; as far as I know they have to be unique, which is good
Earlier quoted context omitted.
Interesting... I had something similar happen to me, with minimal outward, acute damage (e.g., running up bills on random credit cards). It is reasonable to assume my entire identity is compromised. Sorry this happened. How do you know T-Mobile was the entry point, and not say, Google (e.g., Google Chrome, Google Ads)? What type of phone did you have (e.g., Android or iPhone)? What is your browser and Search Engine o…
I assumed it was T-Mobile after I wiped the phone and had the follow-up incident where a verification code via SMS was successfully verified. I used an iPhone, Safari mobile, Google search engine.
Did you happen to report to Apple and Google (for documentation)?