Live data from Hacker News

Even with 2FA, Google accounts can be hacked with just a phone number

ello.co

21–30 of 128 posts

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#21
This is why I always recommend against using SMS-based 2-factor. Without even doing any serious research, it seemed pretty obvious to me from day one that at the very least someone like NSA/FBI could forge your number somehow with or without the carrier's help, but there's also the potential for other attackers to do it, too.

Call forwarding didn't even cross my mind, but it just goes to show how ridiculously broken SMS-based two-factor authentication really is then, and even worse than I thought.

Ideally what I'd want is an NFC ring or a smart band/watch that can use FIDO's U2F or a similar protocol that works through NFC, to do 2-step verification for me.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#23
post #11

Earlier quoted context omitted.

They enabled call forwarding and got Google to call with a password reset code.

Its not clear how they got his phone number though.

Phone book? Leaked address book? Leaked account database? Assume your phone number is public knowledge.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#25

This just happened to me. The same timeframe, the same vector of attack, but a different target. They wanted my Twitter handle. Fortunately it was an old handle that Twitter had locked down and was not transferable. The hacker succeeded in making me lose my handle for a few days, but some friends came to my aid and I was able to get resolution through Twitter support. My telecom company was helpful at first, but then…

I would advise to have them write on the account that in no circumstance are they to authorize you without the passcode.

This is the weakest part of the chain. We all forget our passwords.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#26
post #16

Disable SMS for 2-step and SMS for password resets and use a 2-step mobile app. https://support.google.com/accounts/answer/1066447

After enabling 2FA, disabling SMS for 2-step and SMS for password resets, and ensuring that you don't have any phone number set as a way to get into you account, what is your plan for continuing to use your account if your phone is stolen?

Also other trusted devices can bypass 2factor.

Less secure, of course, but my desktop and laptop bypass two factor.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#27
This is precisely why I thought Digits was such a terrible idea (check my comment history, it's there.) SMS is so incredibly insecure that anyone relying on it should not consider themselves security savvy. SMS TFA is lipstick on a pig. Cellphones are so cheap these days, they should all come with a TFA app pre-installed. I'm also not too keen on websites making it so easy to change your username. The story of @N on Twitter comes to mind. Is anyone working on Digits without the SMS part?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#28
post #2

Well I heard from a friend of mine that in Argentina the cellphone provider can access to your info. The case was this one. He was cheating her girlfriend, a friend of her accessed to my friend's text messages log, saw the evidence, and told to the gf about it. Apparently, but I never confirmed this, the friend (the one who read the messages) worked in the cellphone provider of my friend. Since then I know I can't tr…

Of course your cell phone provider can access your call logs. Probably even fairly low-level workers can get full access under certain conditions. And of course some workers will abuse that access for personal reasons. What did you expect? That workers at a phone company wouldn't be able to access your account info? Ideally, it would be compartmentalized, but...

I would expect auditing if not compartmentalization, and big legal risks from unauthorized access that mean a majority chance of getting fired.

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#29
post #2

Well I heard from a friend of mine that in Argentina the cellphone provider can access to your info. The case was this one. He was cheating her girlfriend, a friend of her accessed to my friend's text messages log, saw the evidence, and told to the gf about it. Apparently, but I never confirmed this, the friend (the one who read the messages) worked in the cellphone provider of my friend. Since then I know I can't tr…

Of course your cell phone provider can access your call logs. Probably even fairly low-level workers can get full access under certain conditions. And of course some workers will abuse that access for personal reasons. What did you expect? That workers at a phone company wouldn't be able to access your account info? Ideally, it would be compartmentalized, but...

That's a problem "low-level workers can get full access". I expect that someone with a higher rank than a low level.

That kind of people could work as little as several month (or even just weeks), make a huge damage and then what. No control?

Re: Even with 2FA, Google accounts can be hacked with just a phone number

#30
Incredible the lack of barriers in place for adding a forwarding number to a cellphone account. Maybe the attackers got the last 4 of his CC from a hacked set? Or maybe the same for his social. And from there they were able to authenticate with the telco rep
Post reply on HN