Live data from Hacker News

I know someone whose 2-factor phone authentication was hacked...

williamedwardscoder.tumblr.com

1–10 of 75 posts

Re: I know someone whose 2-factor phone authentication was hacked...

#2
Two factor authentication is still, in my opinion, the strongest way to go. This case is really the phone company's fault, maybe they'll learn from this and start teaching the customer support reps what the difference is between a correct password and an incorrect password.

Re: I know someone whose 2-factor phone authentication was hacked...

#3
I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number.

iOS: http://itunes.apple.com/us/app/google-authenticator/id388497...

Android: https://play.google.com/store/apps/details?id=com.google.and...

Re: I know someone whose 2-factor phone authentication was hacked...

#4

Two factor authentication is still, in my opinion, the strongest way to go. This case is really the phone company's fault, maybe they'll learn from this and start teaching the customer support reps what the difference is between a correct password and an incorrect password.

Luckily for Gmail, its virtually impossible to call anyone at Google. Maybe all the talk of "Gmail's lack of support" is actually a security feature :)

Re: I know someone whose 2-factor phone authentication was hacked...

#5
Something like the Google Authenticator App instead of an SMS would remove the phone company from the equation, also my bank gives me an actual device on which I have to punch my code in to log into my bank account. These remove allot of the social engineering options that thieves have.

Re: I know someone whose 2-factor phone authentication was hacked...

#6
post #3

I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...

Does the app notify you when authentication is attempted? The reason I still use SMS is that I will instantly get notified if someone has my password and attempts to access my account.

Re: I know someone whose 2-factor phone authentication was hacked...

#7
post #6
post #3

I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...

Does the app notify you when authentication is attempted? The reason I still use SMS is that I will instantly get notified if someone has my password and attempts to access my account.

I was worried about someone getting into my account so I made this: http://blog.jgc.org/2011/06/my-email-canary.html

Re: I know someone whose 2-factor phone authentication was hacked...

#8
post #6
post #3

I use the Google Authenticator app, which makes the token only available to that specific device, rather than through SMS. This gets around the problem of cloning a phone number. iOS: http://itunes.apple.com/us/app/google-authenticator/id388497... Android: https://play.google.com/store/apps/details?id=com.google.and...

Does the app notify you when authentication is attempted? The reason I still use SMS is that I will instantly get notified if someone has my password and attempts to access my account.

You cant log in without the App from an untrusted computer, the app is not connected to the internet, there are no notifications.

Re: I know someone whose 2-factor phone authentication was hacked...

#9

Two factor authentication is still, in my opinion, the strongest way to go. This case is really the phone company's fault, maybe they'll learn from this and start teaching the customer support reps what the difference is between a correct password and an incorrect password.

(TL;DR at bottom)

I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account.

So, it seems to me that it's worse than having no second factor at all.

After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact information or second factor linked to the Google account? Hear me out.

Most people who are 'targets' (consider a millionaire VC who gets his contact details out a lot) are already far more compromised if their computer (personal laptop) has a keylogger or remote screen software (backdoors) by someone who knows who this person is, targetted the laptop they do all their work and most of their shopping on, and has gotten in. usually this hasn't happened. if this HASN'T happened, typing the password on that laptop via https is secure and doesn't allow anyone to get in. So, we have a stepwise function:

  ^
  |                                  
  |                                  
  |                                  you've been targeted and rooted: they can keylog
  |                                  and do A N Y T H I N G in your name from machine
 R|                                ------------------------------------------------->
 i|                               |
 s|                               |
 k|                               |
  |                               |
 o|                               |
 f|                               |
  |                               | 
 p|                               |
 a|                               |
 i|                               |
 n|                               |
  |                               |
  //                              //
  |                               |
  |                               |
  |                               |
  | (few people know it's your    |
  | laptop, none has rooted it)   |
  -================================------------------------------------------------->
                       Level you are breached
so either someone is in looking over your shoulder (which a lot of people would like to be doing when you're a target)... and can remote control/ do stuff in your name (perhaps when you're not using the computer), keylog and basically do anything you can do or have been doing....

or nobody is in yet. (Except as general malware that doesn't know who you are, nobody is remote controlling/keylogging you and checking those files.)

This is MOST of the cases - how do you even know which of millions of computers out there that are 'mostly secure' except against a targeted attack with a lot of known information about the laptop target, is the one that belongs to this millionaire VC? They'd have to look through millions of computers to find him or her...

I'm not talking about a botnet you're part of that has millions of users. I'm talking about someone targeting you.

So, it's basically vulnerability exposure is a STEP function, with a function that goes from "no remote keylogging; even though I'm important no one knows my computer's mac address or what software it's running" at x = 0 to whatever, with a corresponding horizontal y value of "low level of exposure", to, at the next step, "a keylogger is installed on my computer" having a HUGE jump in exposure rating to "totally fucked since now they have my every credit card, can see my every email, etc etc etc. They can just watch over my network and whenever I make a purchase, also make themselves a purchase."

Since Google services can be accessed via https, between those two steps, aren't you "safe as long as no one is getting into your computer since they don't even know this computer belongs to a strong target?"

But with the second factor, you're adding a step there between that stepwise leap:

-> Someone's figured out my phone number; now if they can hack my voice mail they can get Google to send a reset code to it, get the reset code, and take over my account.

The point is: WITHOUT breaching the original second step (i.e. even finding out what physical mac address or, at a given time, IP address, belongs to 'you', or what hardware and software you're even running.)

Your email address and phone number you use, meanwhile is in some sense 'totally public' as that is where you're MEANT to be reached. Both of those things are things that you give out willy-nilly, unlike any information about which computer in America is yours.

So it seems to me that not introducing an insecurity step between step 0 and step 1 would be a good solution: use a secure password, don't write it down anywhere, and use it from computers which aren't especially linked to you or particularly 'tainted'.

why make yourself a target with hackable 2-factor authentication?

TL;DR: your phone number is supposed to be public, your email is supposed to be public, the phone company is not a security token. Don't use the second Google factor.

Post reply on HN