Live data from Hacker News

A hacker got all my texts for $16

vice.com

121–130 of 296 posts

Re: A hacker got all my texts for $16

#121

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

> It's a convenient and stable identifier

It is not stable in the least for millions of Americans, especially those who live in poverty (I'm not sure about the rest of the world). Phones are lost or stolen, phone numbers changed because of being harassed by debt collectors, ex-partners, current partners, etc. And if it isn't stable, it isn't convenient.

Re: A hacker got all my texts for $16

#122
post #82

Earlier quoted context omitted.

I had one like this. I’d type the new password, confirm it, get “success!” And then type the exact same thing to log in and it would fail. Turned out that the text box for entering the new password allowed a different number of characters than the one for logging in.

wha? Who does that? I don't think that's my problem, though i go crazy every time my password isn't recognized, i go through the process and this message comes up "you must use a different password". And i can't even just go back to the login menu. It's too late! And i paid money for this account.

I know a popular bank integral to the functioning and liquidity of an entire state whose "eBanking" features are like this, in 2021.

Re: A hacker got all my texts for $16

#123
post #8

Earlier quoted context omitted.

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

Google is also a culprit in this same way. Activate normal 2fa, but when you click forgot password, conveniently it says Should we send a code to your phone?

Google does not offer me this option, I just checked.

If I claim to have forgotten my password, the first idea it has is that I should prove I still have my Security Key

Then it suggests it could send codes to my GMail (which might actually be useful if I have another device signed into that) or to another email address it knows about (it deliberately redacts part of each address in case I am not me)

Then it resorts to suggesting I try passwords I remember using on this account. I don't know what happens if I give it a password I haven't used for a few years, 'pass' means I keep a complete git history of Google passwords but I am reluctant to mess with this

Then it says too bad, it cannot authenticate me.

Re: A hacker got all my texts for $16

#125

Earlier quoted context omitted.

Agreed. Users have it in their power not to use services that require a phone number for SMS verifcation.

The local government here has a covid tracking system that uses SMS verification and many stores won't let you in without using it.

I hear you, this comes up more and more often. I remember reading that Singapore had something like this (for contact tracing, I think), but they'd give you a dedicated device if you didn't have a phone. Ugh.

I like telling companies who want my number: No, my phone is for people I know to call me, not corporations. Other times I tell them that I don't have a phone and ask them if they are refusing me service. Not saying I have a perfect record, sometimes it is convenient to have the mechanic call when the car is done, etc. But the more I see companies who don't need a dossier on me asking for my personal info the harder I want to push back. I seek out and appreciate organizations that don't do this. I joke that I might end up living in a commune one day!

I can see this becoming a bigger problem. I've been following the idea of covid-vaccination-tracking applications, and don't have a good feeling about any of that. I'm expecting that the vaccination campaign will work well enough for that idea to be a moot point, but also expecting that companies and governments will want to do the extra tracking anyways, because their incentives are not aligned with the general population for stuff like this.

Re: A hacker got all my texts for $16

#126
post #116

Earlier quoted context omitted.

SIM swaps are relatively easy in Australia, requiring only some fairly simple social engineering of staff in a phone store. Number porting is trickier, requires a name and account number (or DOB in the case of a prepaid account) of the victim and they receive an SMS informing them their number was ported in advance.

I thought they require ID for buying SIMs in Australia, surely they also require ID for switching your number to a new SIM?

That requirement is there for new or ported-in services.

But when you Sim swap, it's tied to the same account. So if you can convince the minimum wage hourly wage contract employee at a franchisee that you're the account holder, no worries.

Worse, most of those stores are using generic accounts and/or passwords.

Telstra years ago had a policy along the lines that store accounts could be not tied to a specific employee, so long as the store manager/team leader rotated the passwords and kept records. in reality it's something stupidly guessable that rotates only when required and all the staff know them.

Optus effectively has the same thing - I had an issue getting a SIM established and sat with an employee for about an hour as they re-rolled the account about 10 times. By the end I knew the passwords for all the accounts in the store, plus other identifiers and numbers.

Re: A hacker got all my texts for $16

#127

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

Someone is going to have to take one for the team and SIM swap a senator if we ever want that requirement in the states.

Followed by a six month government contractor bidding process, two years of development hell, and a half-based solution that either doesn't work or requires fifty extra convoluted steps.

Re: A hacker got all my texts for $16

#128
post #59

Earlier quoted context omitted.

I believe the practical solution for many people is to switch the 2FA to an authenticator on-your-phone code generator, which someone cannot hack easily. Most important account / banks / etc services now offer this option. The only thing is, though, make sure to keep backups of the codes you use to initialize the authenticator app, because for some services there is no recovery if you lose your phone or don't have ba…

Hi, which bank(s) offer this? > switch the 2FA to an authenticator on-your-phone code generator, which someone cannot hack easily. I remember looking a few months ago and they only offered SMS 2FA. Thanks

Sorry, I should've been more specific/accurate. I meant brokerages, like Fidelity, Etrade, Schwab -- where you're likely to have more funds/$ than a regular consumer bank. They do offer it. Even Amazon offers it.

And you are right, I have not seen any of the banks I use convert to authenticator (BofA, Chase, etc).

I can only guess that they think it's too difficult for the average consumer to understand or implement. But the fact that they don't even offer as an option is unfortunate.

edit: actually I correct myself, seems like BofA may actually offer something like this: https://play.google.com/store/apps/details?id=com.bankofamer...

However, I can't tell/test because I don't use Android

Re: A hacker got all my texts for $16

#129

Earlier quoted context omitted.

When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.

Wiretapping (without a warrant) is stupidly illegal.

Saying something is illegal and expecting everyone to follow the law is just pinky-swearing.

Re: A hacker got all my texts for $16

#130
post #76

Earlier quoted context omitted.

Agreed. Users have it in their power not to use services that require a phone number for SMS verifcation.

But we often don't. I just got my covid shot and with it a request to sign up for vsafe, which needs a phone number. (Which means i can't sign up since I have anti spam protection on and so their texts don't get through )

Tell them you have no phone. It seems to disarm people. You're not telling that you refuse their request, and getting into a power struggle. Then ask them if that means you can't get a vaccination or whatever. This has worked every time so far for me.

It doesn't get easier. It probably would if more of us did it, though.

Post reply on HN