Live data from Hacker News

A hacker got all my texts for $16

vice.com

171–180 of 296 posts

Re: A hacker got all my texts for $16

#171

Earlier quoted context omitted.

Oh no, if I cycle enough through Other Ways or I don't have my phone (while having my phone number connected with Google Account), it offers me to confirm my phone number with showing number as *** & last 4 digits. When I confirm the phone number, it sends a 6 digit SMS code prefixed with G-, like G-123456 The input box on page has already a read only G- text, & then a box for 6 digit code. After I confirm code from…

Interesting. I can't get it to give me any options like that personally. (Maybe because I have a security key active?)

Oh yeah, I also agree n believe that's the reason. Although having a key active does not mean the super secure government level threat protection, if one activates that threat from state protection, many of the account recovery options become unavailable.

I assume the number of account recovery options diminish with increasing levels of protection.

Re: A hacker got all my texts for $16

#172

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

Same in India too. And the reply SMS contains a code that needs to be given to the destination provider, for the MNP process to proceed.

Re: A hacker got all my texts for $16

#173

Earlier quoted context omitted.

They have it, it’s called FIDO2, and it even works with existing devices such as Touch ID or Windows Hello in common browsers such as Chrome. Even Google doesn’t promote Google Authenticator now, but they keep it around for legacy reasons because it still works, until you lose your phone. That’s where FIDO2 shines: just authenticate more than one device, including purchased hardware tokens if you want something cheap…

can FIDO2 be implemented for day-to-day use right now, such as email access? sms 2FA and authenticator are built-in to most applications, so it makes it easy to use. and how do you do estate planning? I'd like to give my family access to all of my private keys for everything when I pass.

It’s built in to Safari, Chrome, Edge and other browsers, apps can easily integrate with system libraries for Windows Hello or Touch ID as they would anyway.

As for estate planning, set up a spare key that you can keep at a relative’s place, or add others’ accounts to your “Family” in Google/Microsoft/Apple/etc. Either they have their own keys and the company is aware of the handover or they have a copy of yours — such as you logging in on their device or keeping a FIDO2 key at their house and they can pretend to be you. A service like 1Password Family could also be of use here.

Re: A hacker got all my texts for $16

#174

Earlier quoted context omitted.

Wiretapping (without a warrant) is stupidly illegal.

Saying something is illegal and expecting everyone to follow the law is just pinky-swearing.

Yeah! Why have laws anyways? Every law will be broken sooner or later and it’s not like we have institutions tasked with enforcing laws. /s

Re: A hacker got all my texts for $16

#175

Earlier quoted context omitted.

They have it, it’s called FIDO2, and it even works with existing devices such as Touch ID or Windows Hello in common browsers such as Chrome. Even Google doesn’t promote Google Authenticator now, but they keep it around for legacy reasons because it still works, until you lose your phone. That’s where FIDO2 shines: just authenticate more than one device, including purchased hardware tokens if you want something cheap…

> , until you lose your phone. Just like any other password or data, 2fa strings also need to be backed up, like in a password database (separate from the usual one).

True, but last I checked, Google Authenticator and other similar apps (except maybe Authy or password managers) would refuse to upload or backup keys to iCloud Backups for odd reasons. Presumably they wanted the same sort of identity properties that something like Touch ID has, and thus would be solved by having more than one ID.

Unfortunately most people have only one phone, so that didn’t work until options came along where you could add more than one token/device instead as backup.

Re: A hacker got all my texts for $16

#176
post #113

Earlier quoted context omitted.

I realise TFA is about the US, but it’s worth noting that in most of the world, SMS is pretty much just used for receiving messages from your bank and other automated stuff these days.

Sure, and instead, people use apps like Signal or WhatsApp, which are tied to phone numbers, on which the attacker can now register to your phone number thanks to his receiving your SMS...

Absolutely. Was just responding to SMS being a direct part of people's "social existence", which it really isn't in most of the world.

As you say, though, it's one step away from things that are in fact directly used for communication.

Re: A hacker got all my texts for $16

#177

Earlier quoted context omitted.

> , until you lose your phone. Just like any other password or data, 2fa strings also need to be backed up, like in a password database (separate from the usual one).

True, but last I checked, Google Authenticator and other similar apps (except maybe Authy or password managers) would refuse to upload or backup keys to iCloud Backups for odd reasons. Presumably they wanted the same sort of identity properties that something like Touch ID has, and thus would be solved by having more than one ID. Unfortunately most people have only one phone, so that didn’t work until options came al…

Oh no, the string and/or QR code should be backed up when one is setting up the 2FA.

If you have that seed phrase, & any device with correct time can calculate the TOTP code, even a simple local javascript app.

Obviously that phrase leaked would mean hacker can also generate codes. So that's why those phrases should be kept extra safe, away from normal passwords.

Re: A hacker got all my texts for $16

#178

Earlier quoted context omitted.

True, but last I checked, Google Authenticator and other similar apps (except maybe Authy or password managers) would refuse to upload or backup keys to iCloud Backups for odd reasons. Presumably they wanted the same sort of identity properties that something like Touch ID has, and thus would be solved by having more than one ID. Unfortunately most people have only one phone, so that didn’t work until options came al…

Oh no, the string and/or QR code should be backed up when one is setting up the 2FA. If you have that seed phrase, & any device with correct time can calculate the TOTP code, even a simple local javascript app. Obviously that phrase leaked would mean hacker can also generate codes. So that's why those phrases should be kept extra safe, away from normal passwords.

HN died on me before I was able to add the link of little utility I cooked to readd those totp seed phrases: https://spa.bydav.in/otp.html

Re: A hacker got all my texts for $16

#179

Earlier quoted context omitted.

This doesn't sound like something your average user is going to be doing in most cases - keeping a backup, secondary phone. We've already successfully gotten people to start using some level of 2FA in the form of SMS-based identity validation along with their password. That's a pretty impressive step forward, and sufficient for most non-specifically targeted users' usage.

Until they're targeted. You can fool carrier customer service with no training.

Yes, that is indeed what I said.

edit: everyone has a threat matrix they have to deal with.

Re: A hacker got all my texts for $16

#180

Can they do this with a Google Voice phone number? I always hate hearing how I’m basically surviving hacks because of obscurity.

Yes. There's nothing special about a mobile phone number when it comes to SMS delivery. The underlying infrastructure company given in the article, Bandwidth, provides phone number provisioning and bulk service for Google's Voice product. On-net (one number hosted by Bandwidth to another number hosted by Bandwidth) might be slightly more of a hurdle to intercept or redirect but off-net is fairly trivial. Heck, even w…

"Yes. There's nothing special about a mobile phone number when it comes to SMS delivery."

This is false.

"Mobile" numbers - numbers that are classified as belonging to an actual mobile carrier - are indeed different than non-mobile numbers.

For instance, you cannot send SMS from a short-code to a non-mobile number. Which means, your twilio number (which is not a mobile number) cannot receive 2FA (or any other SMS) from the 5-digit "short code" numbers that gmail (and most banks, etc.) use for new account verification, etc.

Non mobile numbers are, in many ways, second class citizens in the mobile-operator ecosystem.

Post reply on HN