Live data from Hacker News

A hacker got all my texts for $16

vice.com

11–20 of 296 posts

Re: A hacker got all my texts for $16

#11

How do you protect against this type of attack?

Don't use Phone number based 2Factor or if you must use a number, keep it to an app (eg, Google Voice) and don't forward your Google Voice texts to your phone's number.

Basically, avoid using your carrier provided phone number for anything related to an account.

Re: A hacker got all my texts for $16

#12
post #8

Earlier quoted context omitted.

"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

I hate having to use a smartphone for auth in general. Especially when I have an app on my phone that expects me to be able to receive an SMS on the same phone. It’s like I need my phone to recover having lost my phone.

Re: A hacker got all my texts for $16

#13

SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.

Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me.

Feels like the industry needs to push for a dedicated, universal, probably physical, tool for 2FA.

Re: A hacker got all my texts for $16

#14
post #11

How do you protect against this type of attack?

Don't use Phone number based 2Factor or if you must use a number, keep it to an app (eg, Google Voice) and don't forward your Google Voice texts to your phone's number. Basically, avoid using your carrier provided phone number for anything related to an account.

Google Voice SMS might not be able to help since they are all in the same POTS ecosystem as well.

Re: A hacker got all my texts for $16

#15
post #11

How do you protect against this type of attack?

Don't use Phone number based 2Factor or if you must use a number, keep it to an app (eg, Google Voice) and don't forward your Google Voice texts to your phone's number. Basically, avoid using your carrier provided phone number for anything related to an account.

But Google Voice requires a Google account, and to create a Google account you need to provide a valid phone number. There are also a lot of service providers that don't allow you create an account without providing a valid phone number.

I wonder how high-profile politicians and celebrities deal with security issues like this? If this is really such an easy attack to pull off, what's stopping someone from shilling cryptocurrencies on celebrity social media accounts (again)?

Re: A hacker got all my texts for $16

#16
post #8

Earlier quoted context omitted.

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

I hate having to use a smartphone for auth in general. Especially when I have an app on my phone that expects me to be able to receive an SMS on the same phone. It’s like I need my phone to recover having lost my phone.

> I hate having to use a smartphone for auth in general.

Same, especially since I don't have a smartphone.

Often times I'll go a week without looking at my phone and by then it has lost its charge so if an app requires a OTP to do something I often need to wait a while before it's charged enough to receive a text.

I do have a Google Voice number but I've mistakenly used my real number for a few services that frequently require SMS confirmations.

Re: A hacker got all my texts for $16

#17
post #8

Earlier quoted context omitted.

"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

One Time Passcode seeds are a globally available ID system.

and I really don't call them second factor, that conflates the whole issue of where they are stored, how they are synced and used. people should be able to recover access to their one time passcode seed and there is little excuse for this.

Re: A hacker got all my texts for $16

#18

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

This is about complete takeover of SMS for a phone number.

The threat model is beyond 2FA, imagine being able to impersonate anyone over text.

Social engineering gone to the next level. This isn't about just taking over accounts, it is about taking over a huge chunk of someone's social existence.

Re: A hacker got all my texts for $16

#19

SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.

I like not being locked out of my applications when my phone goes for an unexpected swim and I have to replace it.

The numerous emails I get when I log in from a new device serve me pretty well, all things considered

Re: A hacker got all my texts for $16

#20
It’s worth pointing out that often LOA forms ask for a PIN, usually the same PIN as would be required to check voicemail. A better telecom company might make the PIN something harder to remember but enforcing such things would also make it harder to switch carriers, particularly if it replaced today’s standard forms of ID checks.

It’s better to assume that until phone numbers can be locked and unlocked the way domains can, with a random authorization code only accessible by real offline 2FA (though not all domain providers require it), and with the option of completely encrypted end-to-end texting (RCS?), well, then SMS won’t really be all that secure.

Post reply on HN