Live data from Hacker News

A hacker got all my texts for $16

vice.com

111–120 of 296 posts

Re: A hacker got all my texts for $16

#111
post #49

Earlier quoted context omitted.

Authenticator Apps?

The annoying part is most of them are very hard to move over to a new phone or backup

Do any of them work on desktops? I keep around a spare iPad to run my authentication apps, but I'd rather have it installed on my computer instead.

Re: A hacker got all my texts for $16

#113
post #18

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

This is about complete takeover of SMS for a phone number. The threat model is beyond 2FA, imagine being able to impersonate anyone over text. Social engineering gone to the next level. This isn't about just taking over accounts, it is about taking over a huge chunk of someone's social existence.

I realise TFA is about the US, but it’s worth noting that in most of the world, SMS is pretty much just used for receiving messages from your bank and other automated stuff these days.

Re: A hacker got all my texts for $16

#114

Earlier quoted context omitted.

> Imagine if they demanded your SSN to sign up? A phone number is no different or less sensitive a unique identifier, perhaps even moreso these days. The goal is for the service to have a unique identifier, and phone numbers happen to be a really good one to prevent spam also since it outsources verification of human entity to the phone companies.

You’re not wrong. The problem is the lack of an authoritative identity provider in the US.

No, that's not the problem, the problem is that many many organizations demand an authoritative identity when no such thing is necessary or advisable.

https://sneak.berlin/20200118/you-dont-need-to-see-my-id/

The US has plenty of centralized identity systems, including the Real ID one, a backdoor federal ID system that is required to board all commercial flights in that country.

Re: A hacker got all my texts for $16

#115
post #114

Earlier quoted context omitted.

You’re not wrong. The problem is the lack of an authoritative identity provider in the US.

No, that's not the problem, the problem is that many many organizations demand an authoritative identity when no such thing is necessary or advisable. https://sneak.berlin/20200118/you-dont-need-to-see-my-id/ The US has plenty of centralized identity systems, including the Real ID one, a backdoor federal ID system that is required to board all commercial flights in that country.

[deleted]

Re: A hacker got all my texts for $16

#116
post #66

Earlier quoted context omitted.

I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).

SIM swaps are relatively easy in Australia, requiring only some fairly simple social engineering of staff in a phone store. Number porting is trickier, requires a name and account number (or DOB in the case of a prepaid account) of the victim and they receive an SMS informing them their number was ported in advance.

I thought they require ID for buying SIMs in Australia, surely they also require ID for switching your number to a new SIM?

Re: A hacker got all my texts for $16

#117

Earlier quoted context omitted.

The annoying part is most of them are very hard to move over to a new phone or backup

Do any of them work on desktops? I keep around a spare iPad to run my authentication apps, but I'd rather have it installed on my computer instead.

Authy does but has some issues showing same site names as on PC so not perfect

Re: A hacker got all my texts for $16

#119
post #99
post #65

Earlier quoted context omitted.

I just transferred my phone number to google voice when I moved out of the country. When I moved it back I simply transfer it back to my carrier

There seem to be horror stories on reddit about Google Voice numbers being terminated for people out of the country too long. Is there a stable inexpensive phone number service for folks that are outside the US a lot?

I've been looking into Google Voice alternatives, and https://voip.ms/ looks good.

Re: A hacker got all my texts for $16

#120
post #93

Earlier quoted context omitted.

But what is an appropriate level of liability here? Phone companies never signed up to be the guardians of our digital lives, and the tech industry at large has just built a castle on shakey foundations. And there are obvious trade-offs here, if we make number portability harder, it means you're somewhat hostage to your phone provider.

Phone companies are guardians of our our accounts with them. The absolutely bear responsibility if poor security or loopholes allow someone to gain any sort of access to our accounts. Security and convenience are often a trade off. Clearly service providers are not properly judging where that balance should be.

Sure, to a point. But the right costs and trade-offs aren't the same if you're protecting your spotify account vs millions of dollars in cash.
Post reply on HN