Live data from Hacker News

I know someone whose 2-factor phone authentication was hacked...

williamedwardscoder.tumblr.com

31–40 of 75 posts

Re: I know someone whose 2-factor phone authentication was hacked...

#31
post #12

If RSA 2-factor tokens can be hacked (or "stolen" I guess, but the effect is the same), there's not much hope for the rest of us. Still a whole lot better than not doing 2 factor.

The attack was on a phone call message for 2-factor authentication "Your one time password is XXXXXX. Please use this to login now" not an RSA token.

Re: I know someone whose 2-factor phone authentication was hacked...

#32
post #14

Earlier quoted context omitted.

(TL;DR at bottom) I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account. So, it seems to me that it's worse than having no second factor at all. After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact informati…

2FA using phone calls/SMS is basically lameness (similar to KBA; it protects against huge numbers of users with bad passwords being a vulnerability to the bank, and is a cheap compliance step, but provides no additional security to a targeted victim). Overarching all of this, there's a great opportunity to fix things in the desktop -> mobile transition; desktop OS security is IMO a lost cause, but mobile started from…

Apple cares too much about user experience than to foist this type of inanity on users.

Re: I know someone whose 2-factor phone authentication was hacked...

#33
post #3

I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...

Is it possible that the app runs in sandbox? Or is that already the case?

> Is it possible that the app runs in sandbox? Or is that already the case?

Why does that matter?

Re: I know someone whose 2-factor phone authentication was hacked...

#34
post #32
post #14

Earlier quoted context omitted.

2FA using phone calls/SMS is basically lameness (similar to KBA; it protects against huge numbers of users with bad passwords being a vulnerability to the bank, and is a cheap compliance step, but provides no additional security to a targeted victim). Overarching all of this, there's a great opportunity to fix things in the desktop -> mobile transition; desktop OS security is IMO a lost cause, but mobile started from…

Apple cares too much about user experience than to foist this type of inanity on users.

Single-Signon is basically universally regarded as the ideal user experience.

Enter your passcode (or otherwise ID yourself to the device), and then everything "just works", with no need to remember or type passwords to every single site. Apple's already perfectly content to consider iPads and iPhones single-user devices, and with OS X, you can have multiple user logins with fast user switching.

Re: I know someone whose 2-factor phone authentication was hacked...

#35
post #18

Wish he had stated which UK bank since most of the ones I am aware of use 2-factor authentication using a card reader device. They even seem to use an identical card reader!

I looked into this a while ago and I believe that Lloyds TSB must be the bank as it uses telephone authentication as follows: http://www.lloydstsb.com/security/security_improvements_we_h... "When you set up a new payment, we’ll give you a call to ensure that the instruction is coming from you. Step-by-step payment security: All you need is a telephone near you. You’ll be able to choose which number we call you on, pr…

It sounds like LloydsTSB to me too, not only is the process for sending money as above, but you don't need your card to login (there is a User ID number, a password and a "memorable phrase" which you have to give three digits of).

While it's convenient as you don't have to remember the card reader when you want to login, it does worry me that it is less secure and vulnerable to keyloggers.

Edit: Halifax is also the same, but then it is owned by Lloyds and has recently transitioned its backend to the same platform as Lloyds uses.

Re: I know someone whose 2-factor phone authentication was hacked...

#36

Earlier quoted context omitted.

(TL;DR at bottom) I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account. So, it seems to me that it's worse than having no second factor at all. After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact informati…

> I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. (Disclaimer: I work for a telephone and software-based 2factor provider) If your telephone-based 2 factor authentication is being thwarted by voice mail hacking, the problem lies in the implementation of the phone call itself, not necessarily the method. Unfortunately, certain solutions a…

none of this applies to the user. There's nothing they can do about the process except not use it - my examples were specifically Google's solution.

Several companies were in the news after they got burned with it.

Re: I know someone whose 2-factor phone authentication was hacked...

#37

I'm a pretty big fan of the rolling token 2-factor authentication model, with the app on your phone presenting you the rolling token. The Blizzard login app is the biggest single example that comes to mind. SMS really isn't secure, I think something like this could be a good next step to phase in.

How would this help preventing the situation described in the article?

Re: I know someone whose 2-factor phone authentication was hacked...

#38
post #26
post #3

I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...

You can still press "don't have your phone?" and send a code through SMS, unless there's a way to disable that.

Wait what? What good would receiving an SMS be if you don't have your phone?

Re: I know someone whose 2-factor phone authentication was hacked...

#39

I'm a pretty big fan of the rolling token 2-factor authentication model, with the app on your phone presenting you the rolling token. The Blizzard login app is the biggest single example that comes to mind. SMS really isn't secure, I think something like this could be a good next step to phase in.

How would this help preventing the situation described in the article?

it does not rely on the phone companies, rather an app from blizzard

Re: I know someone whose 2-factor phone authentication was hacked...

#40
post #26

Earlier quoted context omitted.

You can still press "don't have your phone?" and send a code through SMS, unless there's a way to disable that.

Wait what? What good would receiving an SMS be if you don't have your phone?

It goes to a backup number you add that is the phone number of a friend or other phone number you specify.

Don't do what I did and stupidly use your google voice number. facepalm

Post reply on HN