Where and how do these people get access to the PSTN?
So, essentially, to get in you just need to find the weakest telco connected to the main SS7 network and own them, and use their infra as a staging point.
21–30 of 225 posts
Where and how do these people get access to the PSTN?
So, essentially, to get in you just need to find the weakest telco connected to the main SS7 network and own them, and use their infra as a staging point.
Banks here in the UK use your chip & pin based card as a second factor (or rather, as the two factors - the chip you have, the pin you know) - they give you a little card reader that can use the card and pin to provide a 2FA token for logging in or sign requests to send money. It's a much better system. Of course, some banks don't use it to it's full potential - many use it only for signing money transfers, but it's…
Sure and much more inconvenient one, because you have to carry this device with you everywhere. Even much better system would be a living being at each ATM machine checking your credentials.
When I asked (via Twitter) if my credit union would provide a secure 2FA option, they told me: > We're always on the lookout of how we can keep our members' accounts secure. Right now, the Mobile Texts are FFIEC compliant.
Namecheap only supports SMS 2FA. The have been suggesting they will support Authenticator for years now https://blog.namecheap.com/two-factor-authentication/ Pretty unacceptable considering how important domain control is.
I personally had my domains on hold frozen without traffic being routed to my servers when my ex-gf chat with them gave my username (no password) and claimed it is her account because obviously she knew my full name and address where I live. While they didn't give her access to my account they sure froze my domain for about 5 days until everything got solved.
Not long after I moved to NameSilo.
[1] https://www.amazon.de/ReinerSCT-Tanjack-chipTAN-SmartTAN-Tan...
The Sueddeutsche article claims that German customers were affected too. Most German banks I know of support TAN-generators[1] which are completely unhackable by any known methods. Insert your card, scan the barcode on your screen, confirm the target IBAN and amount, and you get a unique TAN that is calculated from your transaction parameters. [1] https://www.amazon.de/ReinerSCT-Tanjack-chipTAN-SmartTAN-Tan...
Isn't this the old "SMS is not 2FA, stop calling it that" argument?
Yep. Everyone has been saying SMS is not a secure channel for forever now, and this is only one of many possible attacks that can be used to trivially bypass SMS based auth. It's sad but true that in general banks have some of the weakest security on the internet, most online games do a better job protecting user accounts from unauthorized access.
It's different here in Norway; the banks require two factor authentication to log in as well as signing transactions.
I don't claim it's perfect but at least no one can log in unless they control both factors.