A hacker got all my texts for $16
141–150 of 296 posts
Re: A hacker got all my texts for $16
#142Earlier quoted context omitted.
I just transferred my phone number to google voice when I moved out of the country. When I moved it back I simply transfer it back to my carrier
There seem to be horror stories on reddit about Google Voice numbers being terminated for people out of the country too long. Is there a stable inexpensive phone number service for folks that are outside the US a lot?
Re: A hacker got all my texts for $16
#143Earlier quoted context omitted.
Not being able to access your account for 3 days when you need to recover your password is not going to be a viable business decision for most services. I think you are SEVERELY underestimating how often the average user needs to recover their password.
My partner resets her Google password every time she logs in. It's just part of the normal flow for her. She probably does it with everything, but I'm not listed as a recovery on the other things. Something better would be great. She's probably an extreme example, but I think we techy people tend to have a warped view of how comfortable "normal people" are with effective password management.
https://support.google.com/accounts/answer/6361026
I.e. use smartphone prompts as the first factor (without causing password resets), while the password is just a backup when the phone is not available.
Re: A hacker got all my texts for $16
#144Earlier quoted context omitted.
Someone is going to have to take one for the team and SIM swap a senator if we ever want that requirement in the states.
Followed by a six month government contractor bidding process, two years of development hell, and a half-based solution that either doesn't work or requires fifty extra convoluted steps.
Re: A hacker got all my texts for $16
#145Earlier quoted context omitted.
Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…
One Time Passcode seeds are a globally available ID system. and I really don't call them second factor, that conflates the whole issue of where they are stored, how they are synced and used. people should be able to recover access to their one time passcode seed and there is little excuse for this.
While if I lose my SIM card, I'll walk to one of my operator's shops (there's probably one within 1km), show them my ID, and they'll replace the SIM. It's the only digital identifier that I could bootstrap from if I lost access to everything in one go.
Re: A hacker got all my texts for $16
#146Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .
Agreed. Users have it in their power not to use services that require a phone number for SMS verifcation.
Re: A hacker got all my texts for $16
#147Earlier quoted context omitted.
> due to peculiarities of the NANP phone number scheme I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions. This report lists a long chain of buck-passing companies that have exploited an obvious…
Pretty sure a hacker would be perpetrating an actual, punishable-by-trial crime in forging those legal documents. That's generally the first regulation that the US imposes. A disinclination to regulate anything is a good idea in a society that generally punishes bad behavior after the behavior has been perpetrated. I would have doubts for instance about government regulating the process for sending and receiving SMS…
Re: A hacker got all my texts for $16
#148Re: A hacker got all my texts for $16
#149Earlier quoted context omitted.
"sms based one time passcodes" needs to die and the companies that know better should be fined and sanctioned, particular the ones that are demanding SMS based OTP so they can also add your phone number to their social graph
Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…
No. Send me an email, let me upload my ID, anything but SMS. SMS is completely insecure. Not only can it be passively sniffed along the way, not only can malicious actors intercept it without access, not only can pretty much any employee at my telco access it, not only can pretty much any employee at my telco get tricked into intercepting it, but by default (and therefore for the vast majority of users), it'll show up while the phone is locked!
Re: A hacker got all my texts for $16
#150Earlier quoted context omitted.
I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).
> due to peculiarities of the NANP phone number scheme I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions. This report lists a long chain of buck-passing companies that have exploited an obvious…
The regulation seeks to promote competition and consumer choice. An onerous verification process would undermine that goal. Security is not a consideration.
This is sort of the point with regulation. The regulator makes the rules it thinks are best according to the considerations it thinks are important at the time. If someone later shows up with different considerations, they can go to hell.