In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…
Nice one. My neighbour chaired the Australian inter-carrier roundtable implementing mobile phone number portability. I will send him a note! Other cool hacks of his: automatic video advertising scheduling system once saved Channel 9(?) from airing a gas oven ad during a Holocaust documentary. Scored a bonus for that one.
A hacker got all my texts for $16
221–230 of 296 posts
Re: A hacker got all my texts for $16
#222Earlier quoted context omitted.
That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.
Printed/saved backup codes are still an option. Can also attach multiple 2FA tokens to one account. That's what Google and many others provide. Their customers seem satisfied.
Luckily I was still signed in on a computer
Re: A hacker got all my texts for $16
#223It’s insane that providers can do this. I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc. Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s t…
Re: A hacker got all my texts for $16
#224Re: A hacker got all my texts for $16
#225How do you protect against this type of attack?
Don't use a phone. Lucky's company has this product that can monitor for the attack, but it won't prevent it: https://okeymonitor.com/
Re: A hacker got all my texts for $16
#226Earlier quoted context omitted.
That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.
Printed/saved backup codes are still an option. Can also attach multiple 2FA tokens to one account. That's what Google and many others provide. Their customers seem satisfied.
Vast majority of users don't bother with such complexities.
SMS is the easiest minimum entry barrier to 2FA. It is better than having just passwords.
Re: A hacker got all my texts for $16
#227Re: A hacker got all my texts for $16
#228Earlier quoted context omitted.
Oh no, if I cycle enough through Other Ways or I don't have my phone (while having my phone number connected with Google Account), it offers me to confirm my phone number with showing number as *** & last 4 digits. When I confirm the phone number, it sends a 6 digit SMS code prefixed with G-, like G-123456 The input box on page has already a read only G- text, & then a box for 6 digit code. After I confirm code from…
Interesting. I can't get it to give me any options like that personally. (Maybe because I have a security key active?)
Re: A hacker got all my texts for $16
#229It’s insane that providers can do this. I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc. Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s t…
Is there any chance my cellphone number is a VOIP-routable nubmer? Is there a way I can check to find out?
Im not sure what banks use, but I have had UK VOIP numbers flagged before when trying to register them for 2FA, so theres likely API providers for other countries.
Re: A hacker got all my texts for $16
#230In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…
There's no opt-out for it, and no enforcement of the permission requirement. Their support had me snail mail a letter to some PO box. I never got a response.
And now they're going to start outright selling their customer activity after forcibly un-opt-outing* everyone who opted out in their privacy settings previously..
*un-opt-outing -- ??? I don't know what to call this. It's not 'opting-in' since nobody has a choice.. 'resetting user selection without notification or consent' seems too mild and wordy.