Live data from Hacker News

A hacker got all my texts for $16

vice.com

211–220 of 296 posts

Re: A hacker got all my texts for $16

#211
post #113

Earlier quoted context omitted.

I realise TFA is about the US, but it’s worth noting that in most of the world, SMS is pretty much just used for receiving messages from your bank and other automated stuff these days.

Sure, and instead, people use apps like Signal or WhatsApp, which are tied to phone numbers, on which the attacker can now register to your phone number thanks to his receiving your SMS...

If you tell Signal not to allow anybody else to re-register from your phone number without your PIN it will enforce this until at least seven days passes without you using Signal.

If you've uninstalled Signal or just never use your phone then yeah, after a week or so this proposed attack "works" and the safety numbers for any ongoing conversations with anybody reset (the attacker doesn't know the long term identity key for your phone so they'll get a new one, thus generating a different safety number), which will be notified to the other participants although since you presumably never use Signal there may not be any such conversations.

Re: A hacker got all my texts for $16

#212
post #93

Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…

But what is an appropriate level of liability here? Phone companies never signed up to be the guardians of our digital lives, and the tech industry at large has just built a castle on shakey foundations. And there are obvious trade-offs here, if we make number portability harder, it means you're somewhat hostage to your phone provider.

> Phone companies never signed up to be the guardians of our digital lives

The parent comment addressed this point. This is not just about 2FA. SMS users expect their communication are private, except (debatably) by the courts with a warrant.

Re: A hacker got all my texts for $16

#213

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

Back in the early days of mobile number portability the majority of telcos put in systems to make porting out harder, e.g. getting an unlock code. This gave them a chance to keep the customer when they called up.

Regulators (particularly in Europe) soon put a stop to that to promote competition. While this was good, the majority of regulators failed to put in a consumer protection mechanism to stop identity theft through account stealing.

The article describes a more insiduous attack, as the mobile account is still active (hiding the existence of the attack from the user), but the message destination has been rerouted, making all the linked accounts that use SMS as their 2FA also vulnerable.

Re: A hacker got all my texts for $16

#214
post #49

Earlier quoted context omitted.

Authenticator Apps?

The annoying part is most of them are very hard to move over to a new phone or backup

Google Authenticator now has an export and import feature where it bundles all your accounts into a QR code to scan on your new phone.

Might not be ideal for backup however

Re: A hacker got all my texts for $16

#215

Earlier quoted context omitted.

> due to peculiarities of the NANP phone number scheme I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions. This report lists a long chain of buck-passing companies that have exploited an obvious…

Pretty sure a hacker would be perpetrating an actual, punishable-by-trial crime in forging those legal documents. That's generally the first regulation that the US imposes. A disinclination to regulate anything is a good idea in a society that generally punishes bad behavior after the behavior has been perpetrated. I would have doubts for instance about government regulating the process for sending and receiving SMS…

A key part of regulation is placing the onus of solving problems on those best equipped to solve them.

You don’t need the government to mandate what the protocols should be, you just fine carriers for allowing this sort of bad outcome and let them sort things out.

Re: A hacker got all my texts for $16

#216
Isn't this easy solvable with additional SMS token approval as mentioned in article?

> "orsman added that, effective immediately, Sakari has added a security feature where a number will receive an automated call that requires the user to send a security code back to the company, to confirm they do have consent to transfer that number. As part of another test, Lucky225 did try to reroute texts for the same number with consent using a different service called *Beetexting*; the site already required a similar automated phone call to confirm the user's consent. This was in part "to avoid fraud," the automated verification call said when Motherboard received the call. Beetexting did not respond to a request for comment."

But it seems that the entire system is globally infested with security holes. Is this applicable worldwide or just limited to one country ?

Re: A hacker got all my texts for $16

#217
SMS is irredeemably broken, like all telco-designed garbage protocols. The only way you can incentivize companies to stop using it as security theater is to shift liability so any losses incurred by SMS jacking is automatically the liability of the company using SMS, just as nowadays any credit card fraud is borne by the company that is not using the EMV chip to secure a transaction.

Re: A hacker got all my texts for $16

#218

Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

A lot of times SMS 2FA significantly degrade security with services that allows you to "recover" access to your account via SMS.

Re: A hacker got all my texts for $16

#220
post #172

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

Same in India too. And the reply SMS contains a code that needs to be given to the destination provider, for the MNP process to proceed.

That is so sane, seriously sometimes it boggles the mind how banks to online stores will sms you to confirm ur identity yet sim swap is easy as it
Post reply on HN