Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

131–140 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#133
post #26

Earlier quoted context omitted.

It doesn't stop incompetent dataroom operators either from forcing their users to give them their phone numbers for 2fa purposes. And there is absolute gold in those datarooms if you know where to look. Recent offender: "iDeals proposes to protect your account with 2 factor authentication. It means that each time when you will be accessing the project/ changing your password/ accessing the protected versions of docum…

There’s a far worse example: PayPal only supports SMS based 2FA, or, if you dig through their old website with archive.org, you can find a way to use one of their proprietary 2FA devices. Support for TOTP? HOTP? Nope.

> PayPal only supports SMS based 2FA

You can still use Symantec’s VIP (Validation & ID Protection) authenticator app instead of SMS. I just set it up a few moments ago following these instructions:

https://www.eff.org/deeplinks/2016/12/how-enable-two-factor-...

then deactivated the former SMS-based Security Key.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#136
It's insane how much easier it is to transfer a phone number than a domain name.

I also find it odd Facebook, and other sites will let you signup solely with a phone number. There's prepaid cell phone providers that recycle phone numbers, etc. Just seems so stupid to rely on a phone number for authentication alone, but two factor I'm okay with since you still need to know the password. Twitter has a developer product where you can be texted a code to login using only a phone number, which to me just seems wrong to do.

It'd be nice if trying to port a number, change important info, etc if they had to actually call you or text you first to confirm. But one of the problems is people will lose their phones, and need a new sim or phone... That I think I'd have a requirement to actually visit the store - but that doesn't work to well with prepaid phone providers without physical stores selling via other stores like Walmart, Target, etc. Maybe in that case without nearby stores, partner with your retailers to verify ID or fax a ID in.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#137

NIST has already been discouraging the use of SMS for 2fa[0], but that apparently won't stop the subset of incompetent IPSec consultants who still recomment SMS based 2fa. [0] www.slate.com/blogs/future_tense/2016/07/26/nist_proposes_moving_away_from_sms_based_two_factor_authentication.html

Is 2fa with SMS safer or less safe than no 2fa at all?

It's certainly safer than only using a password if you use the same password on lots of sites, since the odds of any password database being hacked are higher than the odds of your phone being targeted.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#138
post #91
post #87

So 2FA reset via SMS is bad, which I agree but what are the alternatives to prevent a meltdown when your 2FA device dies? I have had two phones die on me that was my 2FA device, plus OS upgrades, so I have gone through resetting 10-20 2FA accounts a few times. Though with upgrades usually I foresaw that and downgraded my 2FA before hand. All I wish for was that resetting 2FA would be a very very slow step by step pro…

I use 2FA code generator in cloud-synced 1Password. That endures all software upgrades, unlike Google Authenticator or Authy.

If all this information is in 1Password then I guess you are back down to one factor - your 1Password master password. Which may be ok with you. Just pointing it out.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#139

What settings exactly do I have to change to get GMail to never unlock my account by SMS alone? I have enabled proper 2FA on my Google account with U2F, but I haven't disabled everything else yet because I only have one token, and I still need something like TOTP for stuff that uses Google accounts, but doesn't support U2F. As a closely related remark, I wish U2F would just get popular enough, it's pretty convenient,…

Go to "account recovery" option and remove the phone number listed there.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#140
post #104

Last year when I upgraded my phone I was amused — but mostly horrified — by how easily one could get a SIM card for my own phone number with less than a modicum of information on me. As I required to upgrade my Micro SIM to a Nano SIM, I went to one of my provider's shops and asked for a Nano SIM for phone number X. I was then asked to verbally confirm my name and address — and that's it. No ID card confirmation, no…

Last week I walked into a T-Mobile store and asked for a new SIM card to replace one I lost. I gave them the phone number and apparently an invalid pin (the sales rep verified that I gave him the wrong PIN). I asked if I should do something else to verify it was my account and nothing. They didn't ask for name, ID, or anything else, and they didn't charge me for the SIM card. I went home and popped it in and my account had clearly been transferred -- I didn't have to do any other activation steps or anything.

Great customer service experience, but horrible security.

Post reply on HN