Live data from Hacker News

A hacker got all my texts for $16

vice.com

281–290 of 296 posts

Re: A hacker got all my texts for $16

#281

SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.

I like not being locked out of my applications when my phone goes for an unexpected swim and I have to replace it. The numerous emails I get when I log in from a new device serve me pretty well, all things considered

This has happened multiple times to me. It's also an issue when working in a building with poor reception, or travelling abroad.

Re: A hacker got all my texts for $16

#282

Earlier quoted context omitted.

They have it, it’s called FIDO2, and it even works with existing devices such as Touch ID or Windows Hello in common browsers such as Chrome. Even Google doesn’t promote Google Authenticator now, but they keep it around for legacy reasons because it still works, until you lose your phone. That’s where FIDO2 shines: just authenticate more than one device, including purchased hardware tokens if you want something cheap…

My biggest issue with FIDO is that it is tied to a hardware device. So if I ever lose it it is a huge pain. So you need at least 2 (so only one can be your laptop with fingerprint or face recognition) and if you even get another one you need to remember every single service that you used 2fa for and enroll it in each of them.

> if you even get another one you need to remember every single service that you used 2fa for and enroll it in each of them

This is perhaps why FIDO2 works best when combined with single-sign-on systems, such as those promoted by large email providers, etc. Fewer accounts to have to manage 2FA devices for, and a greater chance that you've already signed in and authenticated your devices with all of them.

Personally, though, I use a password manager, and have some (but not all) sites tagged as 2FA in the password manager. So if and when it's time to add another key, I can just go down the list. Not as convenient as SSO-based 2FA, but sometimes you really don't want to sign in with Facebook, say. :)

Re: A hacker got all my texts for $16

#283

It’s insane that providers can do this. I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA. That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc. Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s t…

Further reading suggests this isn’t just voip numbers! How worrying!

Re: A hacker got all my texts for $16

#284

Earlier quoted context omitted.

I tried to get T-Mobile to stop giving my location to anyone that hits their APIs with a 'Yes I have permission' flag set. There's no opt-out for it, and no enforcement of the permission requirement. Their support had me snail mail a letter to some PO box. I never got a response. And now they're going to start outright selling their customer activity after forcibly un-opt-outing* everyone who opted out in their priva…

Capitalism doesn't ensure good things for people, just maximized profit for the best marketers. You want good things? The government has to require it. Otherwise it'll only happen if it's under the umbrella of maximized profit.

Meh.. every time an article comes out someone says this. Definately more complex than that. Look at Amazon as a counter example.. the reason they dominate is the combination of better product and maximizing efficiencies of scale. Additionally.. they rolled "profit" into growth, netting consumers on a whole better selection and service.

It is almost always better for the government to create "incentives" than to create "requirements" anyway. Instead of "requiring" a text before transfer. It would be better to hold both companies that facilitate a transfer without the customers autorization to large liabilities. This allows them to create a mechanism to prevent this that is probably better.

Re: A hacker got all my texts for $16

#285

Damn lies. Damn lies. The attack vector only works for VOIP or Toll Free Numbers. The upstream agreements already block Mobile numbers. This is paid marketing for his company.

Not sure why this isn't higher up. This is crucial information showing this is FUD. There are still grave vulnerabilities in mobile provider SMS (2FA or otherwise) due to how easy it is for a dedicated attacker to SIM swap, but this particular claim is completely misleading.

> Not sure why this isn't higher up. This is crucial information showing this is FUD.

It's already too high up given it's a blatantly baseless accusation. I'm confused why you think it's more credible than the article when it provides zero evidence.

Re: A hacker got all my texts for $16

#286

Earlier quoted context omitted.

Not sure why this isn't higher up. This is crucial information showing this is FUD. There are still grave vulnerabilities in mobile provider SMS (2FA or otherwise) due to how easy it is for a dedicated attacker to SIM swap, but this particular claim is completely misleading.

> Not sure why this isn't higher up. This is crucial information showing this is FUD. It's already too high up given it's a blatantly baseless accusation. I'm confused why you think it's more credible than the article when it provides zero evidence.

Both articles provides zero evidence other than concept of attack in general and all of them just claiming that mobile numbers can be hacked.

Re: A hacker got all my texts for $16

#287
That’s crazy that there is no verification system in place allowing the user to approve the forwarding.

Years ago I asked my carrier to not port or forward without me being physically present at a store. Maybe I should test them out to see if that’s still the case.

Regardless, I don’t use SMS MFA for anything important and even when I do, I have a 32 character password to go along with it.

Re: A hacker got all my texts for $16

#288

Earlier quoted context omitted.

Not sure why this isn't higher up. This is crucial information showing this is FUD. There are still grave vulnerabilities in mobile provider SMS (2FA or otherwise) due to how easy it is for a dedicated attacker to SIM swap, but this particular claim is completely misleading.

> Not sure why this isn't higher up. This is crucial information showing this is FUD. It's already too high up given it's a blatantly baseless accusation. I'm confused why you think it's more credible than the article when it provides zero evidence.

True. Evidence one way or the other is needed.

Re: A hacker got all my texts for $16

#289

Earlier quoted context omitted.

> Reminder: SMS 2FA adds only a negligible amount of security I would disagree. Obviously, there are better approaches, but consider basic password auth on desktop, that is easily exploitable en masse by botnets. if you add 2FA via SMS, you would need to exploit both devices (or attack SS7, transfer number or some other trick) and match infos from these devices. Can be done in targetted attack, but harder in en masse…

Congratulations, you've spotted the negligible amount, which I explicitly said was negligible, as opposed to zero. Just because something has some benefit does not mean that benefit is greater than the costs.

Wow, is there any reason to be so snarky and dismissive here?

Re: A hacker got all my texts for $16

#290
post #209

Earlier quoted context omitted.

I've never encountered this. All of my 20-something 2fa tokens I could recover with processes ranging from making videocalls to identify myself to getting a 24 hour slot in which all but the 2fa reset was locked.

I’d be curious to know which services are confirmed to have solid 2FA reset practices (i.e., you can do it if you lose your keys; no one else can do it). These would probably be smaller businesses that earn their revenue directly from paying customers (and would lose if you give up and cancel your card/block their transactions)—I can’t imagine this ever working for ad-driven whales like Google or Facebook, or large c…

> I can’t imagine this ever working for ad-driven whales like Google

Google was one of those that offers account recovery[1], but has it fully automated. I did not need it, because Google urged strongly to create backup tokens. I had those in my encrypted backup.

Focusing too much on what can go wrong is unproductive. I could also steal your iPhone, or force you to reveal a 2fa token using the Rubber Tube Decryption method.

There is no such thing as 100% security. And certainly not if it needs to be balanced against some real-world-ease such as "recovering after you dropped your iPhone in the toilet".

The 24hour recovery slot was at my cloud VPS service from which I got a bazillion warning mails. "your 2fa will be disabled in 48 hours, did you not initialize this, click here to ...".

The least secure was at my bookkeeper's online portal, where I could call them over the phone, offer some simple verification and have 2fa disabled. That does not remove my trust in them, because 1) it is an account that needs less security than e.g. my AWS account, and 2) they do know me personally and I them. It actually makes me trust them more because I know they are there for me when I need them.

-- [1] https://accounts.google.com/signin/v2/recoveryidentifier?flo...

Post reply on HN