Live data from Hacker News

Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

codewriteplay.com

111–120 of 388 posts

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#111

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

This is very common scam. AFAIK it’s a way to create a new Google Voice account (linked to your phone number) with the goal of using that account for other scams so that they can’t be tracked.

I fell for it, but since I already had a Google Voice account linked to that phone number, it didn’t work for the scammer. But he didn’t realize what it didn’t work.

I quickly realized that something wasn’t right (and Googled the mechanics of the scam) and then was able to waste his time for another 30min.

The reason I fell for it was because they use a text message from Google in some African language, so I didn’t immediately realize what was going on. Still dumb to not pay more attention…

But it taught me to not list my phone number in the open on Craigslist.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#112

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

How would someone use that code to hack into my GV account? Wouldn't they also need to know my password or have access to my e-mail account to login or to reset your password?

They don’t.

They want to link a new GV account to a real phone number that is not theirs, so that they can use the GV number for other scams.

It only works when your phone number doesn’t already have a GV linked to it.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#113

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

oh dang...good to know

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#114
post #84
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Nice. I do something similar but forward it to Slack. I also have it auto-answer 2FA calls and automatically hit the # key. Yeah, call it not real 2FA, but it's really companies that choose to not use U2F are at fault.

"I also have it auto-answer 2FA calls and automatically hit the # key."

One year at defcon - maybe 20 years ago - the speaker told an anecdote about a user who had set up a webcam and put their RSA token under it.

And we all laughed ... "haha what a dummy ... I can't believe users are so stupid" ...

But secretly I thought it was genius.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#115
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Do you pay for a separate phone line for the mule?

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#116

I had someone contact me on Facebook marketplace, we agreed upon a time/price and then they asked for my phone number (which I sadly gave them). Then they said "I'm going to text you a code, so I can verify you are legit". The text I got was from Google Voice's 2FA.....

How would someone use that code to hack into my GV account? Wouldn't they also need to know my password or have access to my e-mail account to login or to reset your password?

Because OP specifically mentioned Google Voice, my guess is that it was a phone number "ownership" code, rather than a 2FA code per se.

The attacker was probably trying to create a new Google Voice account forwarding to OP's phone number. They could then use the new GV account as its own "legitimate" phone number in order to engage in other scams.

(Alternatively, OP's password might have already been compromised, and this was the last stage of a targeted attack by someone trying to get into their account.)

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#117
post #115
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Do you pay for a separate phone line for the mule?

In many countries, a pre-paid phone costs almost nothing to keep active.

I keep a UK number for some 2FA systems, it costs about £0.10 per year. I just have to send an SMS every 6 months to keep the line active.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#118
What is the point of setting up a hardware or Google Authenticator-type 2FA solution when most companies will fallback to SMS? Is there a way to prevent the SMS fallback (last I checked it was 'No' for most sites except maybe Google if I remember, and then you still had to go in and manually delete it)?

Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like most 2FA is just opening up a much easier attack vector (social engineering a phone number port) vs guessing a long, random, unique password. A password manager with browser plugin (or iCloud Keychain) mostly solves the phishing issue if you stop a second to think on the rare occasions when you need to manually copy/paste because of a weird subdomain or partner domain.

I've been 'about to' set up 2FA for over a decade now, but it always seems like a bad idea.

Edit: Also, who's to say customer service agents won't/don't fallback to sending an SMS reset code even if the account supposedly requires a dongle or app for 2FA.

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#119
post #115
post #66

In other news, I built and deployed a "2FA Mule" last weekend. It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1]. It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work. The "2F…

Do you pay for a separate phone line for the mule?

[deleted]

Re: Facebook hacker beat my 2FA, bricked my Oculus, and hit the company credit card

#120
post #22

Here's my guess at what happened: How was the account hijacked? Via cookie theft. The author installed malware, maybe some dodgy windows binaries or malicious browser extensions. No amount or type of 2FA on sign-in will protect you against the session cookie being stolen. (Now, additional 2FA on sensitive actions might). Why was the account was banned with such finality, with no chance of appeal? Probably for somethi…

>cookie theft

I think that's quite likely. I have a (somewhat throwaway) FB account, not much of a profile and mainly used for a local cause. Co-admining a page I'd clicked on a clickbaity headline posted to the page and several days later my account was disabled.

The account recovery process was completely broken/circular but somehow the account revived itself after a week.

The fact that my 'friend suggestions' were untainted by a friends list seemed to confirm the hack as all my suggestions were from people in an entirely new continent.

Nd ads/CC attached to the account.

Post reply on HN