Earlier quoted context omitted.
The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…
Both Fidelity and Schwab allow non-SMS 2FA. They both use Symantec VIP but it’s fairly easy (for developers at least) to export those tokens and import them into something like Authy, Google Authenticator etc. https://ketanvijayvargiya.com/257-symantec-vip-authy/
Hackers claim they breached T-Mobile more than 100 times in 2022
301–310 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#302You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#303Earlier quoted context omitted.
SMS as a second factor is almost a security downgrade. Phone companies are terrible, you shouldn't be trusting them with authentication. Plus it means you can't authenticate when your phone is out of coverage. Just a bad solution that shouldn't be used. TOTP is so easy to set up that it makes no sense to use SMS, and the even better hardware keys are only slightly less convenient.
SMS allows you to collect phone numbers which are quite good at identifying users for tracking and ad targeting though. And since most large tech companies are advertising companies (in whole or in part) it is no surprise they chose this as a second factor. Even if you try to avoid using SMS for 2FA they'll try to collect the number for account verification or recovery, with regular nags or lately go straight to exto…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#304Was thinking about moving a line to Google Fi for this reason. I know they just resell T-Mobile bandwidth, but would they provide better account level security? Is it common for Google Fi customers to get SIM swapped?
yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#305Earlier quoted context omitted.
SMS in unencrypted, and Google SE has been compromised for much if not all of 2022. From what I can tell the issue persists. I officially reported it in December, and again in January, and again in February. Pretty wild, TBH. Think about the number of services that have Google SE and Ads integration. Makes me nauseous. Did you happen to report to Apple and Google (for documentation)?
In what way is the google search engine compromised?
We need more robust security integration to catch things before they are pushed to results. I understand latency will increase, and some ads revenue will decrease. But like, isn't it also cool to have a customer base that is better protected against egregious attacks, attacks that could be prevented? IMO, yes. It's called "stewardship."
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#306Earlier quoted context omitted.
I've always figured I should have two numbers—one I let people know, and one for 2fa. But that's ~$20/mo and a moderate annoyance, so for now mostly just fingers crossed that eventually everywhere that matters will allow me to switch fully to authentication apps and hardware keys.
if you have an apple watch, depending on your plan, it may have a different phone number wonder if that works...
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#307Earlier quoted context omitted.
https://www.bleepingcomputer.com/news/security/google-fi-dat... This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."
> These attacks are conducted using social engineering, where the threat actor impersonates the customer and requests that the number be ported to a new device for some reason. To convince the mobile carrier that they are the customer, they provide personal information exposed to phishing attacks and data breaches. > As the Google Fi data breach includes phone numbers, which can easily be linked to a customer's name,…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#308This is why I buy service from Mint mobile using a fake name, a burner email address, and a prepaid debit card purchased at Walmart. Go to town with that info, hackers!
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#309This follows on the unpopular news story that T-Mobile will be requiring you to give them your debit card or bank account information to continue to qualify for their Autopay discount. https://www.cnet.com/tech/mobile/t-mobile-is-dropping-its-au...
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#310This was at least couple of decades ago but I remember how they would send your password to your phone over SMS.
https://plaintextoffenders.com/post/4567498592/t-mobilenet
And more recently in 2018:
https://plaintextoffenders.com/post/174100751368/meint-mobil...
A few more in the master list here:
https://github.com/plaintextoffenders/plaintextoffenders/blo...