Live data from Hacker News

A hacker got all my texts for $16

vice.com

131–140 of 296 posts

Re: A hacker got all my texts for $16

#131

Voip.ms, vonage/twilio, et al let you set up an SMS capable number really quickly and cheaply, available globally... And you'd be fully in control

No this doesn't work at all. As others have said, many companies will not let you set up an account or send SMS to numbers created this way.

Re: A hacker got all my texts for $16

#132

Can they do this with a Google Voice phone number? I always hate hearing how I’m basically surviving hacks because of obscurity.

It would be useful to understand the flow of an SMS from a source to a Google voice number. While you can't port a Google voice number, it seems like if you can intercept an SMS from a source before it gets to Google then this technique will work.

A useful strategy to help against this in any case is to use a different email address for every online service. Hackers generally can't initiate an account password reset if they don't know the account.

Also if you use a different phone number for account security than your public one then it's a lot harder for them to know what SMS to intercept. Security by obscurity sucks but in this world it may be your only practical choice.

Re: A hacker got all my texts for $16

#133
post #43

Earlier quoted context omitted.

Secure phones are sub-$200. If you have multiple accounts, services, etc, then backing up your 2FA codes, or registering two devices/phones at the same time should be on your radar.

This doesn't sound like something your average user is going to be doing in most cases - keeping a backup, secondary phone. We've already successfully gotten people to start using some level of 2FA in the form of SMS-based identity validation along with their password. That's a pretty impressive step forward, and sufficient for most non-specifically targeted users' usage.

Until they're targeted.

You can fool carrier customer service with no training.

Re: A hacker got all my texts for $16

#134

Can they do this with a Google Voice phone number? I always hate hearing how I’m basically surviving hacks because of obscurity.

Yes. There's nothing special about a mobile phone number when it comes to SMS delivery. The underlying infrastructure company given in the article, Bandwidth, provides phone number provisioning and bulk service for Google's Voice product. On-net (one number hosted by Bandwidth to another number hosted by Bandwidth) might be slightly more of a hurdle to intercept or redirect but off-net is fairly trivial.

Heck, even with "port lock" enabled on a Google Voice number, that is the barest of security against an attacker who has any kind of access better than "retail store employee." Working for a telco with access to our back-end port system, access several other people had, I could forcibly acquire a number by simply checking a box that said I had verified a written LOA even if the losing carrier responded with code 6P ("port-out protection enabled").

So, yes, you're likely sitting in a security-by-obscurity, or at least security-by-slightly-more-difficult-than-someone-else, situation.

Re: A hacker got all my texts for $16

#135
What I would find really interesting is if someone used this exploit to hack into the accounts of Sakari staff and sabotaged their service, deleting all their infrastructure from their cloud hosting provider etc. I'm sure Sakari would take this security hole more seriously if their own C-suite fell victim to it.

Re: A hacker got all my texts for $16

#136

Earlier quoted context omitted.

They have it, it’s called FIDO2, and it even works with existing devices such as Touch ID or Windows Hello in common browsers such as Chrome. Even Google doesn’t promote Google Authenticator now, but they keep it around for legacy reasons because it still works, until you lose your phone. That’s where FIDO2 shines: just authenticate more than one device, including purchased hardware tokens if you want something cheap…

can FIDO2 be implemented for day-to-day use right now, such as email access? sms 2FA and authenticator are built-in to most applications, so it makes it easy to use. and how do you do estate planning? I'd like to give my family access to all of my private keys for everything when I pass.

Yes, on shit tons of major services.

Register multiple/duplicate keys.

Re: A hacker got all my texts for $16

#137

So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.

Yubikey is complicated?

For many non-technical users, unfortunately, yes.

Re: A hacker got all my texts for $16

#138
post #132

Can they do this with a Google Voice phone number? I always hate hearing how I’m basically surviving hacks because of obscurity.

It would be useful to understand the flow of an SMS from a source to a Google voice number. While you can't port a Google voice number, it seems like if you can intercept an SMS from a source before it gets to Google then this technique will work. A useful strategy to help against this in any case is to use a different email address for every online service. Hackers generally can't initiate an account password reset…

> While you can't port a Google voice number

You absolutely can port a Google Voice number. End-user subscriber numbers must be portable per FCC rules. Google, operating services provided by Bandwidth.com (mentioned in the article), does enable port-protection by default but this is easy to bypass by an operator who, like in the article, checks the box that says something like "I have a valid written LOA, complete the port as an exception." This has legitimate uses (some losing providers are very ruthless about not following the rules and letting customers move numbers) but unscrupulous or lazy operators will check the box and move on.

Re: A hacker got all my texts for $16

#139
post #66

Earlier quoted context omitted.

I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).

> due to peculiarities of the NANP phone number scheme I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions. This report lists a long chain of buck-passing companies that have exploited an obvious…

Pretty sure a hacker would be perpetrating an actual, punishable-by-trial crime in forging those legal documents. That's generally the first regulation that the US imposes.

A disinclination to regulate anything is a good idea in a society that generally punishes bad behavior after the behavior has been perpetrated. I would have doubts for instance about government regulating the process for sending and receiving SMS - would you want every new software or protocol to have to go through some kind of bureaucratic review before it can be used?

Re: A hacker got all my texts for $16

#140
post #67

Earlier quoted context omitted.

I tried to set up a Twilio number specifically to handle these services that demand SMS for login. Weirdly it only works for a minority of services, I expect many use Twilio to send their auth texts and Twilio blocks sending these to their own numbers?

The reason most services require a phone number is so you can't just create a new account if you get banned and ideally your account is somewhat tied to a real person. They ban VOIP numbers because it would defeat the whole point.

What's preventing someone from getting mutiple regular phones and accounts for them then?
Post reply on HN