Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

111–120 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#111

I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…

I've ported out my google voice numbers several times.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#112

In all seriousness folks, as someone who long ago worked for a big wireless carrier, do not use SMS-based two-factor auth for anything. Number porting is a huge and easily performed attack vector, it requires very, very little information, a lot of which can be gathered from publicly available resources... or pretty easily obtained via social engineering. To make matters worse, the information doesn't even need to be…

Many services will happily send an SMS account recovery/reset link regardless of how vehemently we refuse to use SMS-based two-factor auth.

An attacker can call support, give them plausibly correct information gleaned from public sources, and nicely claim to have forgotten the answers to your recovery questions ("Oh, it might have been a jumble of letters and numbers... silly me..."). There are enough incorrectly trained support people who will let this through to make the tactic effective on average.

Your point is obviously correct, but everything is so hopelessly broken that it almost doesn't matter in practice.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#113
Seems like 2FA in this case is significantly weaker than 1FA if you have a long password. I suppose it depends on if it is easier to answer the security questions or to convince a customer support rep, but my security questions are pretty obscure and I have a security question salt that I always append to the answer.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#114
Everybody involved in something like this should be suing the phone company that gave away their phone number in violation of policy.

https://www.silvermillerlaw.com/current-investigations/crypt... comes up on a search and says they'll do contingency in cases like this. Got nothing to lose.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#115
post #96

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…

Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead.

This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out.

Note that all telcos will prevent the number being ported out if you owe them any money on the account.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#116

I was attacked in the same manner this weekend. I'll dump what I know below in the hopes it helps someone. I lost money when MTGox went under and made some online posts (on reddit, I think) several years ago. Maybe this is what caused me to be targeted? This weekend a malicious actor posing as the account holder on my account was able to get my number transferred to his phone. At&t fraud says this happened at a store…

This is the reason I have disabled SMS as a recovery option in my gmail/google account. My 2FA for gmail is now my iphone and ipad. THey have to know my password and get one of my devices to hack my account. I also use protonmail and for SMS based 2FA, I plan to use a google voice number from a totally different google account w/c forwards the text to my protonmail account. Google voice numbers cannot be ported out.…

Porting out GVoice numbers is harder, but it can absolutely be done, I've moved a purely Google Voice number to T-Mobile before.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#117
post #66

Earlier quoted context omitted.

There may not be a choice. Vanguard refused to log me in until I configured 2-factor SMS.

I would consider that an alarming sign that I need to change investment companies asap (probably after loudly complaining and trying to change it, since Vanguard is somewhat unique).

Fidelity also only uses SMS-based 2FA :-/

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#119
post #96

Earlier quoted context omitted.

> I'll put your request in now but it will wait for 5 business days before it happens This to me seems to be a complete misunderstanding of the telcos business and motivations. They sell mobile telephony - voice, sms, and data - and their _prime objective_ is to make it as easy as possible for their customer to spend as much money doing that as possible. Making you wait five days to get reconnected to "your number" w…

Yes, Paypal is bad, they took away their support for the Symantec 2FA codes and forced users in many countries to use SMS instead. This is pretty easy for the telco to prevent, though. Your existing telco should simply phone you and ask if you wish to leave them before letting the number get ported out. Note that all telcos will prevent the number being ported out if you owe them any money on the account.

[deleted]

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#120
post #59

Earlier quoted context omitted.

because they can (usually) revert it. Because reversibility is a good thing.

Fraudulent transactions made with a regular bank account are pretty irreversible too. There's a whole extra layer of infrastructure on top of the 'core' banking services that allows them (banks) to 'reverse' a fraudulent transaction. But I'd be very very surprised if fraudulent charges are 'reversible' in any other way than the bank reimbursing the account holder. In other words, crypto-currency exchanges could do th…

They are generally reversible until they cross borders, then it gets way more complicated. Most of these scammers are outside the US, they immediately make an international wire transfer of the money, then split it apart to a bunch of separate accounts, in order to make reverting impossible
Post reply on HN