Live data from Hacker News

A hacker got all my texts for $16

vice.com

221–230 of 296 posts

Re: A hacker got all my texts for $16

#221

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

Nice one. My neighbour chaired the Australian inter-carrier roundtable implementing mobile phone number portability. I will send him a note! Other cool hacks of his: automatic video advertising scheduling system once saved Channel 9(?) from airing a gas oven ad during a Holocaust documentary. Scored a bonus for that one.

The ads are scheduled to be shown automatically? I thought advisers choose the show and pay for it

Re: A hacker got all my texts for $16

#222

Earlier quoted context omitted.

That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.

Printed/saved backup codes are still an option. Can also attach multiple 2FA tokens to one account. That's what Google and many others provide. Their customers seem satisfied.

I disabled some 2fa cause I once replaced my phone without following some script to copy across the 2fa app

Luckily I was still signed in on a computer

Re: A hacker got all my texts for $16

#223

It’s insane that providers can do this. I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc. Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s t…

Yes, this is only for VOIP. The author of article is dishonest. He mentioned that his TMobile phone number got hacked but I am willing to bet that this is a marketing .. .

Re: A hacker got all my texts for $16

#225

How do you protect against this type of attack?

Don't use a phone. Lucky's company has this product that can monitor for the attack, but it won't prevent it: https://okeymonitor.com/

Banks already has tools that detects SIM Swaps and SS7 attacks. It's just hard to make decisions. Banks care about false positives too.

Re: A hacker got all my texts for $16

#226

Earlier quoted context omitted.

That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.

Printed/saved backup codes are still an option. Can also attach multiple 2FA tokens to one account. That's what Google and many others provide. Their customers seem satisfied.

> Printed/saved backup codes are still an option

Vast majority of users don't bother with such complexities.

SMS is the easiest minimum entry barrier to 2FA. It is better than having just passwords.

Re: A hacker got all my texts for $16

#227
post #49

Earlier quoted context omitted.

Authenticator Apps?

The annoying part is most of them are very hard to move over to a new phone or backup

Then use other ones :)

I currently use Aegis and Bitwarden. AndOTP also allows you to export tokens.

Re: A hacker got all my texts for $16

#228

Earlier quoted context omitted.

Oh no, if I cycle enough through Other Ways or I don't have my phone (while having my phone number connected with Google Account), it offers me to confirm my phone number with showing number as *** & last 4 digits. When I confirm the phone number, it sends a 6 digit SMS code prefixed with G-, like G-123456 The input box on page has already a read only G- text, & then a box for 6 digit code. After I confirm code from…

Interesting. I can't get it to give me any options like that personally. (Maybe because I have a security key active?)

I have a security key active but it still offers to send me an SMS code for some reason (worryingly, to a phone number I no longer have... should probably get on to changing that)

Re: A hacker got all my texts for $16

#229

It’s insane that providers can do this. I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc. Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s t…

Is there any chance my cellphone number is a VOIP-routable nubmer? Is there a way I can check to find out?

Twilio has a (US-only) API for this: https://www.twilio.com/docs/lookup/tutorials/carrier-and-cal...

Im not sure what banks use, but I have had UK VOIP numbers flagged before when trying to register them for 2FA, so theres likely API providers for other countries.

Re: A hacker got all my texts for $16

#230

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

I tried to get T-Mobile to stop giving my location to anyone that hits their APIs with a 'Yes I have permission' flag set.

There's no opt-out for it, and no enforcement of the permission requirement. Their support had me snail mail a letter to some PO box. I never got a response.

And now they're going to start outright selling their customer activity after forcibly un-opt-outing* everyone who opted out in their privacy settings previously..

*un-opt-outing -- ??? I don't know what to call this. It's not 'opting-in' since nobody has a choice.. 'resetting user selection without notification or consent' seems too mild and wordy.

Post reply on HN