Live data from Hacker News

Freedom Mobile's 4 digit password limit

null.pink

11–20 of 27 posts

Re: Freedom Mobile's 4 digit password limit

#11

Earlier quoted context omitted.

It's a five-digit pin you can guess at infinitely.

How? The login screen only allows 4 digit pins, and if you get it right then you have to confirm with 2FA.

Getting the correct phone number and pin combo is step one. That's the four digit pin.

Step two is as many tries at the 2FA as you would like. The format is 0#####. It will take some time for sure, but you get to control the phone number as your prize

Alternatively, the 4-digit pin is the security for their support line. You can obtain that without guessing the 2FA. Social engineering takes care of the rest.

Re: Freedom Mobile's 4 digit password limit

#12

Earlier quoted context omitted.

How? The login screen only allows 4 digit pins, and if you get it right then you have to confirm with 2FA.

Getting the correct phone number and pin combo is step one. That's the four digit pin. Step two is as many tries at the 2FA as you would like. The format is 0#####. It will take some time for sure, but you get to control the phone number as your prize Alternatively, the 4-digit pin is the security for their support line. You can obtain that without guessing the 2FA. Social engineering takes care of the rest.

Mobile account authorization is critical for national security because of the rampant requirement to use cellphones as 2FA / password reset for everything else, including GC Key itself. The government needs to step in. The question is what particular person in the government has the power and motivation to do so. Have you tried the CCTS? CSE? They might have some power, but the upcoming potential Cyber Security C-26 act should spell it out for them.

It should be doable to find some big fish to take this on, especially since everyone is vulnerable to SIM swaps assuming every other Canadian phone company has such lax security.

Re: Freedom Mobile's 4 digit password limit

#13

It's clear the only way to achieve progress in the world today is 'Name & Shame'. Hell, I've got better security for my email then I can get from Canadian Banks! I'm not surprised that Freedom Mobile is so lax. I've been a customer since they were originally called "Wind" (at the time it was the only company that my N900 would work with). The only thing that they had going for them over the competition was good price…

> Hell, I've got better security for my email then I can get from Canadian Banks At this point why not switch to a US one? > I hate all Canadian telecommunications companies. Seems every thread about telecom ends up with a rant about Canadian providers. Why is the country so backward? They had Nortel and Blackberry not long ago.

> At this point why not switch to a US one?

As a Canadian I offer two things:

1) it is a pain for people to call you and have to pay long distance every time they call. Yes, long distance to the US is still a major thing in Canada.

2) I recently moved but kept my old phone number / area code. The number of times I call people and they don’t answer but then call me back right away and say “oh I saw an Ontario number and thought it was spam” is probably 4 out of 5 calls I make. People aren’t as accepting of non-local area codes as in the US. Probably because of the ridiculous number of scam calls we get.

Edit: > Seems every thread about telecom ends up with a rant about Canadian providers. Why is the country so backward? They had Nortel and Blackberry not long ago.

Because Canadian providers are in bed with the competition bureau and other regulators that essentially allow them to twist the rules to ensure the current oligopoly is permanent and allows them to charge the highest mobile rates in the world, by far. Canadian consumers by and large hate the situation but politicians don’t listen and it isn’t a big enough issue for a complacent populace to vote on.

Re: Freedom Mobile's 4 digit password limit

#14

Earlier quoted context omitted.

Getting the correct phone number and pin combo is step one. That's the four digit pin. Step two is as many tries at the 2FA as you would like. The format is 0#####. It will take some time for sure, but you get to control the phone number as your prize Alternatively, the 4-digit pin is the security for their support line. You can obtain that without guessing the 2FA. Social engineering takes care of the rest.

Mobile account authorization is critical for national security because of the rampant requirement to use cellphones as 2FA / password reset for everything else, including GC Key itself. The government needs to step in. The question is what particular person in the government has the power and motivation to do so. Have you tried the CCTS? CSE? They might have some power, but the upcoming potential Cyber Security C-26…

I worked with the Office of the Privacy Commissioner of Canada(OPC) on this a few years ago. I don't have credentials and that's enough for them not to take it seriously.

I'm the only reason the 2FA is there. That change was the only change they would commit to. A few days ago is the first time since that I've logged into my account.

I'm planning to contact the Competition Bureau tomorrow with the information. They are currently looking at Freedom's viability under a significantly less powerful company than Shaw Communications Inc.

Re: Freedom Mobile's 4 digit password limit

#15

Earlier quoted context omitted.

Mobile account authorization is critical for national security because of the rampant requirement to use cellphones as 2FA / password reset for everything else, including GC Key itself. The government needs to step in. The question is what particular person in the government has the power and motivation to do so. Have you tried the CCTS? CSE? They might have some power, but the upcoming potential Cyber Security C-26…

I worked with the Office of the Privacy Commissioner of Canada(OPC) on this a few years ago. I don't have credentials and that's enough for them not to take it seriously. I'm the only reason the 2FA is there. That change was the only change they would commit to. A few days ago is the first time since that I've logged into my account. I'm planning to contact the Competition Bureau tomorrow with the information. They a…

I dunno, but it doesn't really seem like Privacy or Competition is the right angle for this, they're luxuries after all, and it's not really relevant for those political maneuverings. Security is more important. The right actors could hack the entire financial system and more with these kinds of vulnerabilities, with targeted sim swaps. Take for example, the currently unfolding Twitter hack that puts 400m Twitter users' phone numbers up for grabs - including every big fish there is.

Call yourself an anonymous Russian hacker and that might get their attention.

Re: Freedom Mobile's 4 digit password limit

#16
Weak security sucks. However, this has been known about for years. People at Freedom Mobile know about it, customers know about it, the parent company knows about it. It's just that nobody has prioritized fixing it. Having seen the insides of several Canadian telco's security branches, it's a mixed bag. Some are better than others, but in general smaller, non-RoBelUs (Rogers, Bell, Telus) carriers tend to have atrocious (or non-existant) security. And even among the big-3, there are marked differences in their security maturity levels.

Re: Freedom Mobile's 4 digit password limit

#17

Earlier quoted context omitted.

How? The login screen only allows 4 digit pins, and if you get it right then you have to confirm with 2FA.

Getting the correct phone number and pin combo is step one. That's the four digit pin. Step two is as many tries at the 2FA as you would like. The format is 0#####. It will take some time for sure, but you get to control the phone number as your prize Alternatively, the 4-digit pin is the security for their support line. You can obtain that without guessing the 2FA. Social engineering takes care of the rest.

From the article it was not clear that the 2FA was the 5 digit pin.

10 guess every 10 minutes with an expectation that after 5000 guesses you'll have a correct guess is 3.4 days (500*10 minutes).

Re: Freedom Mobile's 4 digit password limit

#18

Earlier quoted context omitted.

Getting the correct phone number and pin combo is step one. That's the four digit pin. Step two is as many tries at the 2FA as you would like. The format is 0#####. It will take some time for sure, but you get to control the phone number as your prize Alternatively, the 4-digit pin is the security for their support line. You can obtain that without guessing the 2FA. Social engineering takes care of the rest.

From the article it was not clear that the 2FA was the 5 digit pin. 10 guess every 10 minutes with an expectation that after 5000 guesses you'll have a correct guess is 3.4 days (500*10 minutes).

There's no timing limits but your own, the only limit I could note is 10 per code. You have to guess a lot, but you don't get stopped. There's also nothing you can do as a target, even if you know you're a target. Support cannot disable your account.

Re: Freedom Mobile's 4 digit password limit

#19

Weak security sucks. However, this has been known about for years. People at Freedom Mobile know about it, customers know about it, the parent company knows about it. It's just that nobody has prioritized fixing it. Having seen the insides of several Canadian telco's security branches, it's a mixed bag. Some are better than others, but in general smaller, non-RoBelUs (Rogers, Bell, Telus) carriers tend to have atroci…

[deleted]

Re: Freedom Mobile's 4 digit password limit

#20

Earlier quoted context omitted.

I worked with the Office of the Privacy Commissioner of Canada(OPC) on this a few years ago. I don't have credentials and that's enough for them not to take it seriously. I'm the only reason the 2FA is there. That change was the only change they would commit to. A few days ago is the first time since that I've logged into my account. I'm planning to contact the Competition Bureau tomorrow with the information. They a…

I dunno, but it doesn't really seem like Privacy or Competition is the right angle for this, they're luxuries after all, and it's not really relevant for those political maneuverings. Security is more important. The right actors could hack the entire financial system and more with these kinds of vulnerabilities, with targeted sim swaps. Take for example, the currently unfolding Twitter hack that puts 400m Twitter use…

I will reach out to CSE and CCTS when they open as well.
Post reply on HN