In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…
Someone is going to have to take one for the team and SIM swap a senator if we ever want that requirement in the states.
A hacker got all my texts for $16
151–160 of 296 posts
Re: A hacker got all my texts for $16
#152Earlier quoted context omitted.
Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…
Google is also a culprit in this same way. Activate normal 2fa, but when you click forgot password, conveniently it says Should we send a code to your phone?
(Actually, it doesn't send a code to your phone. It either sends a prompt to your phone, OR you can open a buried menu in some app to GET a - essentially TOTP - code.)
Re: A hacker got all my texts for $16
#153Voip.ms, vonage/twilio, et al let you set up an SMS capable number really quickly and cheaply, available globally... And you'd be fully in control
No this doesn't work at all. As others have said, many companies will not let you set up an account or send SMS to numbers created this way.
Re: A hacker got all my texts for $16
#154Earlier quoted context omitted.
The local government here has a covid tracking system that uses SMS verification and many stores won't let you in without using it.
I hear you, this comes up more and more often. I remember reading that Singapore had something like this (for contact tracing, I think), but they'd give you a dedicated device if you didn't have a phone. Ugh. I like telling companies who want my number: No, my phone is for people I know to call me, not corporations. Other times I tell them that I don't have a phone and ask them if they are refusing me service. Not sa…
I also hate how its hard to explain to normal people. I don't have a problem with covid restrictions. I'm happy to wear a mask, social distance, etc. I just don't want to be sending the government with a horrible privacy/security history a log of everywhere I have been if I can avoid it. But you will be seen as some covid conspiracy theory nutcase if you object.
Its also awkward to keep telling stores I don't want to give them my address or phone number.
Re: A hacker got all my texts for $16
#155Earlier quoted context omitted.
Google is also a culprit in this same way. Activate normal 2fa, but when you click forgot password, conveniently it says Should we send a code to your phone?
Google does not offer me this option, I just checked. If I claim to have forgotten my password, the first idea it has is that I should prove I still have my Security Key Then it suggests it could send codes to my GMail (which might actually be useful if I have another device signed into that) or to another email address it knows about (it deliberately redacts part of each address in case I am not me) Then it resorts…
I can't say what it does currently but it used to say something along the lines of "you haven't used that password in a while. try something else."
Re: A hacker got all my texts for $16
#156SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.
Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. Feels like the industry needs to push for a dedicated, universal, probably physical, tool for 2FA.
Re: A hacker got all my texts for $16
#157Earlier quoted context omitted.
This is about complete takeover of SMS for a phone number. The threat model is beyond 2FA, imagine being able to impersonate anyone over text. Social engineering gone to the next level. This isn't about just taking over accounts, it is about taking over a huge chunk of someone's social existence.
I realise TFA is about the US, but it’s worth noting that in most of the world, SMS is pretty much just used for receiving messages from your bank and other automated stuff these days.
Re: A hacker got all my texts for $16
#158Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .
> It's a convenient and stable identifier It is not stable in the least for millions of Americans, especially those who live in poverty (I'm not sure about the rest of the world). Phones are lost or stolen, phone numbers changed because of being harassed by debt collectors, ex-partners, current partners, etc. And if it isn't stable, it isn't convenient.
Re: A hacker got all my texts for $16
#159Earlier quoted context omitted.
Someone is going to have to take one for the team and SIM swap a senator if we ever want that requirement in the states.
Followed by a six month government contractor bidding process, two years of development hell, and a half-based solution that either doesn't work or requires fifty extra convoluted steps.
Re: A hacker got all my texts for $16
#160Earlier quoted context omitted.
Google does not offer me this option, I just checked. If I claim to have forgotten my password, the first idea it has is that I should prove I still have my Security Key Then it suggests it could send codes to my GMail (which might actually be useful if I have another device signed into that) or to another email address it knows about (it deliberately redacts part of each address in case I am not me) Then it resorts…
> Then it resorts to suggesting I try passwords I remember using on this account. I don't know what happens if I give it a password I haven't used for a few years I can't say what it does currently but it used to say something along the lines of "you haven't used that password in a while. try something else."