how is this even possible? must be usa?right? in finland non-standard numbers must start with different numbers so its easy to block them as invalid.
How SMS fraud works and how to guard against it
101–107 of 107 posts
Re: How SMS fraud works and how to guard against it
#102Another technology to read up on is Silent Network Auth: https://www.twilio.com/blog/silent-network-authentication-sn... If you operate a mobile app, this allows you to force a data packet over the device’s SIM that the carrier can validate. Platforms like Twilio/Boku have worked with the carriers to provide an API for this. SMS is completely removed from the process and SMS pumping becomes a non issue. Another optio…
I don't think that would go over very well in the less sketchy countries - I know many folks (myself included) who would be up in arms if a service requires WhatsApp just to send an OTP - in that (and any) case I'd prefer 2FA via authenticator apps
Re: How SMS fraud works and how to guard against it
#103Earlier quoted context omitted.
I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…
I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.
Which means that anyone else who can fake an ID is good to go with that verizon rep. Or the rep themselves.
I will always avoid connecting any account to SMS if at all possible, it's the worst of all options.
TOTP is the best, as it is an open standard and doesn't tie you to any device nor any vendor.
> I prefer SMS for 2FA because some authenticator apps get tied to a device.
No need! Just save the TOTP seed in a safe place such as a computer under your control (i.e. not a phone) or even a piece of paper in a safe.
Re: How SMS fraud works and how to guard against it
#104I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
People lose their phones and then your authenticator app doesn't work anymore, even if you restore from backup. And then the recovery mechanism is often a giant pain. Yes, that's pretty user unfriendly. It's a lot more common to lose your phone than lose your phone number.
Don't ever keep your TOTP seed solely on a phone. Yes, that is asking for trouble. But you can save it in a safe place and then you control it.
Re: How SMS fraud works and how to guard against it
#105I feel like the easiest workaround is to a) not use an email with your name in it for any important login b) don't use those emails for more than one service c) use a separate SIM and device for 2FA (mint mobile etc) / banking apps that aren't up to speed with non SMS 2fa. It pains me to say this since Bank of America sucks, but their system now supports adding a Yubikey for login, nearly as good as Schwab before the…
> separate SIM and device for 2FA Are you really suggesting having 5 different devices with separate SIM cards to receive 2FA messages? What exactly is the point here, just having different numbers? In that case some kind of text message forwarding service that gives you multiple virtual numbers would (still not free but much more reasonable than dealing with multiple devices)
Re: How SMS fraud works and how to guard against it
#106Earlier quoted context omitted.
I don't receive SMS, so I won't find that either. It's dated tech and I deprecated it 10 years ago. Also, we're SIM-swapping global nomads now, not some potatoes that sit on a couch in one country all year long. Phone numbers don't work anymore.
You may be in the minority here. As you are the only one inconvenienced, it also seems like a reasonable decision.
Re: How SMS fraud works and how to guard against it
#107Fraud requires that someone make a misrepresentation. Who makes a misrepresentation when SMS fraud is committed? What is the misrepresentation? Is there any chance that this isn’t actually fraud and that companies who send out tons of text messages to any number a person specifies are just paying for their extraordinarily poor design?
It's definitely fraud and it's definitely detectable when a 10000 block prefix of numbers sends 100x more SMS than every other prefix out of the blue. It's basically a referral marketing campaign where the fraudster does revenue share with local sketchy infrastructure providers.
Maybe this is taken care of in the user agreement or the terms of services? “User warrants that he is not trying to profit by use of the two factor auth system?” I’ve never read an agreement like this one.