Live data from Hacker News

A hacker got all my texts for $16

vice.com

251–260 of 296 posts

Re: A hacker got all my texts for $16

#251

Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.

SMS auth is great until your users move, get a new number and are locked out forever.

Pick you poison. Or even better, implement both and let your users pick.

Re: A hacker got all my texts for $16

#252

Earlier quoted context omitted.

Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. Feels like the industry needs to push for a dedicated, universal, probably physical, tool for 2FA.

They have it, it’s called FIDO2, and it even works with existing devices such as Touch ID or Windows Hello in common browsers such as Chrome. Even Google doesn’t promote Google Authenticator now, but they keep it around for legacy reasons because it still works, until you lose your phone. That’s where FIDO2 shines: just authenticate more than one device, including purchased hardware tokens if you want something cheap…

My biggest issue with FIDO is that it is tied to a hardware device. So if I ever lose it it is a huge pain. So you need at least 2 (so only one can be your laptop with fingerprint or face recognition) and if you even get another one you need to remember every single service that you used 2fa for and enroll it in each of them.

Re: A hacker got all my texts for $16

#253
post #119
post #99

Earlier quoted context omitted.

There seem to be horror stories on reddit about Google Voice numbers being terminated for people out of the country too long. Is there a stable inexpensive phone number service for folks that are outside the US a lot?

I've been looking into Google Voice alternatives, and https://voip.ms/ looks good.

I've been using voip.ms and it is fairly good. I wish the SMS support was a bit better but it does reliable deliver messages to email or SIP. (Large messages are not re-joined though and sending is based off of a code in the subject instead of an email address per-number which could be easily be added to an address book)

Re: A hacker got all my texts for $16

#254

Earlier quoted context omitted.

I tried to get T-Mobile to stop giving my location to anyone that hits their APIs with a 'Yes I have permission' flag set. There's no opt-out for it, and no enforcement of the permission requirement. Their support had me snail mail a letter to some PO box. I never got a response. And now they're going to start outright selling their customer activity after forcibly un-opt-outing* everyone who opted out in their priva…

I haven't heard anything about a t-mobile api leaking that data and my searches doetsn't return anything of value, can you provide more details?

It's not just T-Mobile, it was most US carriers.

Some examples:

- Vice paid a bounty hunter $300 to track a phone number [1]

- Police have paid these services to avoid warrant requirements, and corrections facilities use aggregator services to track numbers that inmates have calls with [2][3]

Apparently carriers claim to have stopped after getting fined $200m last year [4].

It was typically done through aggregators. EG, services that have similar access to multiple carriers and in turn expose a single endpoint to their own customers.

The aggregators pass on responsibility for obtaining consent to their end customers. Again, with no enforcement or ability for a target to opt out.

The only protection is an authentication requirement. But that just confirms you have a valid credential. Which you get either as an aggregator (to tmobile/other carrier directly), or as the client to an aggregator (to the aggregator's API to query multiple carriers).

Though even that authentication requirement has failed in the past, like when LocationSmart had a public demo page exploited. Inspection of the requests the page sent made it trivial to replay them with any phone number, skipping any consent checking. They just had to add "privacyConsent":"True" to the payload [5].

But yeah, it sounds like that is less of a worry now.

Instead, T-mobile is selling the location data, and basically anything whatever usage data they collect from your phone with their root-privileged app to advertising networks. They say it's a

Although their privacy page has this statement [6]:

> We do not use or share Customer Proprietary Network Information (“CPNI”) or precise location data for advertising unless you give us your express permission.

The 'express permission' here is deceptive. Users default to permit this, so it's hardly 'express'.

Further, they recently mass reset user preferences to clear the opt-out setting for users who previously opted out. Without consent.

So basically everyone is 'consenting' unless they very recently opted-out. Though I have little faith they won't change this from underneath their users again in the future. No doubt in the fine print of one of those 'annual privacy notices' or some such.

Still, if the wording and definition of 'express consent' is questionable above, they word it more explicitly in the more detailed privacy policy [7]:

> We and others may also use information about your usage, device, location, and demographics to serve you personalized ads, measure performance of those ads, and conduct analytics and reporting.

Their privacy page is deceptive about how anonymized their collection is [6]:

> When we share this information with third parties, it is not tied to your name or information that directly identifies you. Instead, we tie it to your mobile advertising identifier or another unique identifier.

Tying it to a mobile advertising id, or any kind of unique identifier, is not de-identification. It is trivial to tie this to an email or a larger profile generated by an advertising network and combine with, say, your desktop web browser. Or any account you login with that is associated to your email..

It's despicable. But sorry, I'll stop ranting now.

[1] https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-hunte...

[2] https://www.nytimes.com/2018/05/10/technology/cellphone-trac...

[3] https://www.zdnet.com/article/us-cell-carriers-selling-acces...

[4] https://www.nationalheraldindia.com/international/over-dolla...

[5] https://www.robertxiao.ca/hacking/locationsmart/

[6] https://www.t-mobile.com/privacy-center/our-practices/privac...

[7] https://www.t-mobile.com/privacy-center/education-and-resour...

Re: A hacker got all my texts for $16

#255
post #86

okay so how did he manage to pull this off and is this still possible? how would you protect yourself against this attack (i dont understand how it works)

The details are in the article, but essentially the attacker used a 3rd party bulk SMS service that allows it's users to use their own number and routes sms messages to said service provider. The attacker instead used the cell number of the author of the article, and supplied a fraudulent letter authorizing the re-routing of text messages through the bulk SMS service. The attacker works for a service, which purports…

and there are no checks and bounds on their side??? no regulations?

Re: A hacker got all my texts for $16

#256

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

> It's a convenient and stable identifier It is not stable in the least for millions of Americans, especially those who live in poverty (I'm not sure about the rest of the world). Phones are lost or stolen, phone numbers changed because of being harassed by debt collectors, ex-partners, current partners, etc. And if it isn't stable, it isn't convenient.

It is better in the US as generally all plays are country-wide but as a Canadian my number has changed many times.

- First number. - Moved to a different city for Uni. Switched number so that people didn't have to pay long-distance to call. - Moved back. - Move to Europe for a job. - Moved back.

I would never consider an identifier that is (loosely) tied to your location stable.

Re: A hacker got all my texts for $16

#257
post #76

Earlier quoted context omitted.

But we often don't. I just got my covid shot and with it a request to sign up for vsafe, which needs a phone number. (Which means i can't sign up since I have anti spam protection on and so their texts don't get through )

Tell them you have no phone. It seems to disarm people. You're not telling that you refuse their request, and getting into a power struggle. Then ask them if that means you can't get a vaccination or whatever. This has worked every time so far for me. It doesn't get easier. It probably would if more of us did it, though.

I got the vaccine not problem. With the vaccine came a sheet of paper requesting I sign up for vsafe which is a program unrelated to those giving the vaccine. It is probably useful to sign up, so I tried, but there wasn't an option of no phone, or at least not until it was too late.

Re: A hacker got all my texts for $16

#258

Earlier quoted context omitted.

Yeah! Why have laws anyways? Every law will be broken sooner or later and it’s not like we have institutions tasked with enforcing laws. /s

I'm under the assumption that wiretapping to create evidence is illegal, but wiretapping to get a warrant probably happens all the time. (AKA Judge and Police officer listen to illegally captured audio - Judge approves official warrant to make future recordings legal)

Wiretapping by a private person should not happen.

Re: A hacker got all my texts for $16

#259

Damn lies. Damn lies. The attack vector only works for VOIP or Toll Free Numbers. The upstream agreements already block Mobile numbers. This is paid marketing for his company.

Just adding that landline numbers, not just toll-free numbers, are probably vulnerable to this.

Re: A hacker got all my texts for $16

#260

Damn lies. Damn lies. The attack vector only works for VOIP or Toll Free Numbers. The upstream agreements already block Mobile numbers. This is paid marketing for his company.

Just adding that landline numbers, not just toll-free numbers, are probably vulnerable to this.

Yes, I forget to include it.
Post reply on HN