Live data from Hacker News

A hacker got all my texts for $16

vice.com

201–210 of 296 posts

Re: A hacker got all my texts for $16

#201

So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.

What are the problem parts with yubikey? I've got a Fetian Epass and it feels like the most natural way of doing auth - here's a key, it goes on my keyring next to my locker key or my car key if I had one, I use it to log in like putting a key in a lock.

Re: A hacker got all my texts for $16

#202

Earlier quoted context omitted.

I completely agree. SMS 2FA is, at best, just adding a little hassle for the hacker. If it's not a targeted attack, there's a chance that the extra effort means they'll move on, but that won't stop any remotely determined hacker.

And isn't that true for most of the people? Still better than nothing right?

I'm not sure it's better, at least not in all cases. If you can reset your password or login without password using SMS, and you had a strong password, it could be worse.

Re: A hacker got all my texts for $16

#203
post #202

Earlier quoted context omitted.

And isn't that true for most of the people? Still better than nothing right?

I'm not sure it's better, at least not in all cases. If you can reset your password or login without password using SMS, and you had a strong password, it could be worse.

that would be a veryy incorrect implementation of 2FA. Wouldn't be surprised if some service works that way, but would def. be unfortunate

Re: A hacker got all my texts for $16

#204

Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

That’s great until your users lose/break their phone and have no backups for their 2FA codes.

“Sorry you’re locked out forever, good luck lol”

Is not a response you can give to them.

Re: A hacker got all my texts for $16

#206

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

Nice one. My neighbour chaired the Australian inter-carrier roundtable implementing mobile phone number portability. I will send him a note! Other cool hacks of his: automatic video advertising scheduling system once saved Channel 9(?) from airing a gas oven ad during a Holocaust documentary. Scored a bonus for that one.

Re: A hacker got all my texts for $16

#207

Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.

Printed/saved backup codes are still an option. Can also attach multiple 2FA tokens to one account. That's what Google and many others provide. Their customers seem satisfied.

Re: A hacker got all my texts for $16

#208

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

In Canada with tell you can put a “lock” on your account so there is additional steps like going into a store with is to remove it before you can port a number of sim swap (I think) Still don’t use my phone number on my google accounts thou

You can do the same in the US. However the bad guys just recruit low level retail employees to do the SIM swaps (which happens in Canada too).

Re: A hacker got all my texts for $16

#209

Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.

I've never encountered this. All of my 20-something 2fa tokens I could recover with processes ranging from making videocalls to identify myself to getting a 24 hour slot in which all but the 2fa reset was locked.

Re: A hacker got all my texts for $16

#210

Earlier quoted context omitted.

Someone is going to have to take one for the team and SIM swap a senator if we ever want that requirement in the states.

Except they'll just punish the "hacker", make a big fuss about it, then the Telco's will donate money to the senator till they drop it.

> will donate money

Sakari (and the likes) will complain that government regulation is keeping the food of the hard workers table, and the gov has no right to intervene to the free market!!

In parallel they will 'lobby' (or as we call it in Europe "bribe") the key politicians and ask to a) either change that Bill down to the point that it is rendered useless, or b) cancel it altogether, and stock market will go up!!

Post reply on HN