Live data from Hacker News

Second factor SMS: Worse than its reputation

ccc.de

271–280 of 323 posts

Re: Second factor SMS: Worse than its reputation

#271
post #221

Earlier quoted context omitted.

That is a security win. On a rooted phone, you've made it possible for other apps to spy on and steal your banking information. Bank apps not running on phones where security has been compromised seems entirely reasonable.

> Bank apps not running on phones where security has been compromised seems entirely reasonable. I have root access on my laptop and I log in to my bank's website just fine. Making apps not run on rooted phones is just perpetuating the cycle of forcing users to comply with the restrictions placed upon them by Apple and Google. Root access != less secure. It means control over the device you paid for and own.

...and you're probably less safe as a result. In the 90s and early 2000s, running as root (admin) was the Windows default for home computers, and that's why we had such a malware and spyware problem then. It wasn't until UAC limited user and app permissions on purpose and Windows Defender became standard that it began to get better.

Root access for you means you have control, sure. But it often does mean you're less safe too, depending on your OS's security model and what other apps can run as you. That's why limited sudo and other "root ish, but only in small doses" models were made. And that's assuming you know what you're doing.

For Jane Grandma, root of any sort means power she'll never need and a footgun to lose her life savings with. It's a good thing mobile phones protect ordinary users from themselves. Most people don't need root access any more than they need the ability to reprogram the ECU on their car.

Besides, on a rooted phone, I thought there were already ways to fool an app into thinking it's not rooted...? Or did they change that?

Re: Second factor SMS: Worse than its reputation

#273

Earlier quoted context omitted.

There is zero reason for ad companies or ad networks to be covered by any safe harbor provisions of the law. They should have 100% criminal liability for every mal-advertisement they send to a user.

Ads are a paid transaction and Ad Companies absolutely need to be held liable for the money that they take because of who they take it from voluntarily . Google should be ashamed at all the money they are making from scammers and criminals and other evils. They should have a terrible score at every agency remotely like the Better Business Bureau. They should be tarred and feathered in public opinion. The brand name s…

> Google should be ashamed

"Do no evil. Instead enable others to do evil profitably and take a cut off the top."

Re: Second factor SMS: Worse than its reputation

#274
post #132

Earlier quoted context omitted.

Only by those who never worked on these kind of services. Running something like a webmail service is being flypaper for dickheads. As soon as you gain any sort of popularity you will have some very hard and sharp lessons about the lengths spammers will go through to make abuse your service. First rule of designing anything: "if some cunt can make a buck by completely fucking over your system then that cunt will comp…

You don't even have to be running a webmail service, the instant you use any service to send an email with even one user-controlled field (even something as innocuous as their name) you already have a problem.

Yeah, I meant "webmail" in the broadest possible sense. And it's even broader than that: anything that allows making anything public really: from forum comments to Instagram to WordPress sites to Wikipedia.

Remember that for about ten years there was a person who consistently and frequently inserting images of ceiling fans in random articles.

Re: Second factor SMS: Worse than its reputation

#275

Earlier quoted context omitted.

Why isn't there any market fulfillment for "safe, non-intrusive ads", on the part of a vendor? Is it because it's not possible, or not worth the overhead either because of cost or no effect on consumer behavior/blocking? This seems like it ought to be low-hanging fruit. I would have less aversion to clicking on ads if I did not default to it being a security risk.

Google’s search ads have become explicitly more intrusive and less distinguishable from the real content over time, deliberately and knowingly. It’s funny, that while many parts of Google are making improvements to the web security ecosystem, they are completely ready to throw it out of the window when it comes to making them more money.

You mean you can’t see the “promoted content” label that is 1 px high?

Re: Second factor SMS: Worse than its reputation

#276
post #65
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

> an attacker who paid for Google Ads for a search term like "BANKNAME login" I tried out buy Google ads once out of curiosity cause they gave me a free credit. It was crazy how many ridiculous stipulations and guidelines I had to work around before they'd accept my ad. How are they that strict for me, but seemingly they'll sell to a phishing page that's impersonating a bank and targeting it to people searching for t…

Don’t they usually put in “legitimate” ads and info then swap out the content afterwards with the spamscam?

Re: Second factor SMS: Worse than its reputation

#277
post #66
post #43

Earlier quoted context omitted.

Another lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank

This might not be sufficient anymore. Many online payments are rendered either on the shop's pages or on a third party payment provider, including 3DSecure implementations. These don't redirect to any sensible bank URLs. Both of my banks use a payment flow which uses a hardware authenticator. But only one bank seems secure: it prompts for an amount and a reference and generates an OTP based on that. This is distinct…

I have a couple of bills to pay to the city and the 3rd party pay processor (they switched a couple years back) they got looks like the page was made by a moderately talented 5th grade web developer. I actually called them to verify I had the exact URL correctly and also told them the page looked like it was made by complete amateurs and was kind of scary it was so poorly done.

Re: Second factor SMS: Worse than its reputation

#278

Earlier quoted context omitted.

Or skip the website and use their native app.

then you can't block anything

Why do you need to block stuff on your bank? I do all my banking through their app tbh. If I had to block stuff from the bank then I’d switch banks.

Re: Second factor SMS: Worse than its reputation

#279
post #42

A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the add…

This is a great example of why a search engine shouldn’t overtly let people pay them to alter rankings lol.

And why ads should be to the side at the very least and not mixed with search results

Re: Second factor SMS: Worse than its reputation

#280
post #65

Earlier quoted context omitted.

> an attacker who paid for Google Ads for a search term like "BANKNAME login" I tried out buy Google ads once out of curiosity cause they gave me a free credit. It was crazy how many ridiculous stipulations and guidelines I had to work around before they'd accept my ad. How are they that strict for me, but seemingly they'll sell to a phishing page that's impersonating a bank and targeting it to people searching for t…

Don’t they usually put in “legitimate” ads and info then swap out the content afterwards with the spamscam?

I have an ads account; I don't see them checking I haven't done a switcheroo on the landing page contents. I think I could easily put a JS redirect on the landing page, if nothing else worked.

They are reasonably strict about the keywords though -- I often go into a "verifying" stage when setting up the ads.

Post reply on HN