Live data from Hacker News

A hacker got all my texts for $16

vice.com

141–150 of 296 posts

Re: A hacker got all my texts for $16

#141
Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

Re: A hacker got all my texts for $16

#142
post #99
post #65

Earlier quoted context omitted.

I just transferred my phone number to google voice when I moved out of the country. When I moved it back I simply transfer it back to my carrier

There seem to be horror stories on reddit about Google Voice numbers being terminated for people out of the country too long. Is there a stable inexpensive phone number service for folks that are outside the US a lot?

I used the Republic Wireless wifi only service for $5/month. Still more expensive than it _needs_ to be, but well worth it.

Re: A hacker got all my texts for $16

#143

Earlier quoted context omitted.

Not being able to access your account for 3 days when you need to recover your password is not going to be a viable business decision for most services. I think you are SEVERELY underestimating how often the average user needs to recover their password.

My partner resets her Google password every time she logs in. It's just part of the normal flow for her. She probably does it with everything, but I'm not listed as a recovery on the other things. Something better would be great. She's probably an extreme example, but I think we techy people tend to have a warped view of how comfortable "normal people" are with effective password management.

Google has the following. Would you consider it to be "something better"?

https://support.google.com/accounts/answer/6361026

I.e. use smartphone prompts as the first factor (without causing password resets), while the password is just a backup when the phone is not available.

Re: A hacker got all my texts for $16

#144
post #127

Earlier quoted context omitted.

Someone is going to have to take one for the team and SIM swap a senator if we ever want that requirement in the states.

Followed by a six month government contractor bidding process, two years of development hell, and a half-based solution that either doesn't work or requires fifty extra convoluted steps.

Nah, it's cheaper and easier for them to mandate that the companies take care of it.

Re: A hacker got all my texts for $16

#145
post #8

Earlier quoted context omitted.

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

One Time Passcode seeds are a globally available ID system. and I really don't call them second factor, that conflates the whole issue of where they are stored, how they are synced and used. people should be able to recover access to their one time passcode seed and there is little excuse for this.

TOTP is globally available, but does not have an established way of recovering your key if it's lost. ("Little excuse" or not, people will not back up the key or print backup codes.)

While if I lose my SIM card, I'll walk to one of my operator's shops (there's probably one within 1km), show them my ID, and they'll replace the SIM. It's the only digital identifier that I could bootstrap from if I lost access to everything in one go.

Re: A hacker got all my texts for $16

#146

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

Agreed. Users have it in their power not to use services that require a phone number for SMS verifcation.

More and more services are supporting - or worse, requiring - SMS-based or phone-based 2FA. Moreover, people frequently do not "have it in their power" not to use a particular service. For example, I decided to log in to Fidelity the other day, since I still have a 401(k) with them from an old employer who did matching. They require call or SMS 2FA. And you could draw even stronger requirements to various government services in various countries.

Re: A hacker got all my texts for $16

#147

Earlier quoted context omitted.

> due to peculiarities of the NANP phone number scheme I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions. This report lists a long chain of buck-passing companies that have exploited an obvious…

Pretty sure a hacker would be perpetrating an actual, punishable-by-trial crime in forging those legal documents. That's generally the first regulation that the US imposes. A disinclination to regulate anything is a good idea in a society that generally punishes bad behavior after the behavior has been perpetrated. I would have doubts for instance about government regulating the process for sending and receiving SMS…

That doesn't work well when the criminals are working from a sunny foreign beach resort.

Re: A hacker got all my texts for $16

#148
Based on the high level description given in the article it seems to be related to enum lookup or net number. It's basically a kind of DnS lookup for phone numbers used for sms routing. Also this is used for routing sms that are belonging to a user to an application (in case you want to reroute your sms to an application). The company will change the enum code for the number to a.code that belong to the company and reroute the messages to its services. So the hack is not really a hack in a sense that it work as intendant, the safety net is missing though. The company operating the enum is supposed to check the legitimacy of the change.

Re: A hacker got all my texts for $16

#149
post #8

Earlier quoted context omitted.

"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

> SMS is a great recovery factor

No. Send me an email, let me upload my ID, anything but SMS. SMS is completely insecure. Not only can it be passively sniffed along the way, not only can malicious actors intercept it without access, not only can pretty much any employee at my telco access it, not only can pretty much any employee at my telco get tricked into intercepting it, but by default (and therefore for the vast majority of users), it'll show up while the phone is locked!

Re: A hacker got all my texts for $16

#150
post #66

Earlier quoted context omitted.

I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).

> due to peculiarities of the NANP phone number scheme I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions. This report lists a long chain of buck-passing companies that have exploited an obvious…

Number portability is regulated: https://www.fcc.gov/general/wireless-local-number-portabilit....

The regulation seeks to promote competition and consumer choice. An onerous verification process would undermine that goal. Security is not a consideration.

This is sort of the point with regulation. The regulator makes the rules it thinks are best according to the considerations it thinks are important at the time. If someone later shows up with different considerations, they can go to hell.

Post reply on HN