Live data from Hacker News

Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

arstechnica.com

101–110 of 225 posts

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#101
post #62

Earlier quoted context omitted.

Google Authenticator provides a list of backup codes that you can print and put in your wallet, or store as a secure note (e.g. in 1Password): https://support.google.com/accounts/answer/1187538?hl=en

Google provides backup codes, not Google Authenticator. Each service you add to your Authenticator keychain will have its own backup codes, if any.

Yes, thanks for the clarification.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#102
post #44

Earlier quoted context omitted.

If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.

But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…

Take government issued ID into the bank. They can reset everything for you.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#103
post #14

When I asked (via Twitter) if my credit union would provide a secure 2FA option, they told me: > We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.

I wonder if there would be some way to have FFIEC revoke their acceptance of SMS as 2FA?

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#106
post #42
post #36

Earlier quoted context omitted.

You dont even need to buy a $18 hardware token. You can use a software TOTP token (ie. google authenticator)

So long as you never switch or factory reset phones, because Google Authenticator, by design, never reveals the private keys. (I've locked myself out of accounts because I broke my phone and had to get a new one.) Also, do you really trust your Android phone with your TOTP private key? How do you know there isn't malware running on it as root?

There are alternative TOTP apps that offer backup options.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#107
post #97
post #90

Earlier quoted context omitted.

Note that one time codes do not protect against phishing the same way U2F does (U2F is always bound to secure origin).

U2F is great but everything is better than SMS.

Except SMS is better than nothing, right? Yes it's flawed. But it's a harder attack than simple password auth. An attacker has to to target an individual and know their phone number, and be able to spoof their phone.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#108
In August, Lieu called on the FCC to fix the SS7 flaws that make such attacks possible. It could take years to fully secure the system given the size of the global network and the number of telecoms that use it.

One of the newly discovered great sins of the early 21st century, is to disseminate insecure code. Before the public became widely aware of chemical pollution, I'm sure many polluters thought themselves innocent and environmentalists as pernicious busybodies.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#109
post #97

Earlier quoted context omitted.

U2F is great but everything is better than SMS.

Except SMS is better than nothing, right? Yes it's flawed. But it's a harder attack than simple password auth. An attacker has to to target an individual and know their phone number, and be able to spoof their phone.

It depends. SMS is better than nothing as a second factor, but SMS has a weird way of worming its way into single-factor status. I think people should avoid SMS 2FA, and should be skeptical of the security of companies that offer only SMS and neither of TOTP or U2F.

Re: Thieves drain 2FA-protected bank accounts by abusing SS7 routing protocol

#110
post #44

Earlier quoted context omitted.

If you have a phone you can run a 2FA app though like Google Authenticator. Much more secure.

But what happens when thieves steal my phone? How do I authenticate then? Most places use SMS as a backup, which gets us back to the original problem. People with popular YouTube accounts have to deal with this all the time and the advice right now seems to be to buy a burner phone on a false name[1] and never share the phone number with anyone, which is just crazy. [1] Fraudsters are able to convince phone employees…

write down the secret from when you set up 2FA and store wherever you keep your valuables. Get a new phone and re-use the same secret.
Post reply on HN