Live data from Hacker News

A hacker got all my texts for $16

vice.com

291–296 of 296 posts

Re: A hacker got all my texts for $16

#291

Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)

That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.

there can at least be a notification and a delay, so I have 12-48 hours to respond if I get an emergency alert that my service is about to be deactivated

Re: A hacker got all my texts for $16

#292

Earlier quoted context omitted.

Until they're targeted. You can fool carrier customer service with no training.

Yes, that is indeed what I said. edit: everyone has a threat matrix they have to deal with.

NOBODY is targeted to be robbed until they are — what?

Re: A hacker got all my texts for $16

#293
post #45

Earlier quoted context omitted.

My reading of this article suggests that the PIN requirement for number porting is bypassed in this forwarding scenario, since this method is claimed to be distinct from simjacking. That is, the number hasn't been ported by the FCC's guidelines, although I didn't glean exactly how that's happening by these retail providers.

SMS routing and number porting are different things, as the voice and SMS operate independently. I headed Engineering for a company that allowed you to SMS enable your landline or toll-free number, and our automated flow for non-toll-free landlines required receiving a code via telephone call (to avoid the situation of compromised SMS routing). We didn't support numbers that were not in those two buckets, i.e. mobile…

Thanks. So, as with simjacking, a bad actor, e.g. an employee at a company with poor internal controls, can sell (or inadvertently give) access to anyone's 2FA codes.

Re: A hacker got all my texts for $16

#294

Earlier quoted context omitted.

I tried to get T-Mobile to stop giving my location to anyone that hits their APIs with a 'Yes I have permission' flag set. There's no opt-out for it, and no enforcement of the permission requirement. Their support had me snail mail a letter to some PO box. I never got a response. And now they're going to start outright selling their customer activity after forcibly un-opt-outing* everyone who opted out in their priva…

Wow. How long does your number go unavailable if you port out? I may.

When I ported over to Project For a few years ago, it took about 30 minutes. I think there's a "pre-transfer" step that gets everything ready to cutover before you confirm.

Re: A hacker got all my texts for $16

#295

Earlier quoted context omitted.

I'm under the assumption that wiretapping to create evidence is illegal, but wiretapping to get a warrant probably happens all the time. (AKA Judge and Police officer listen to illegally captured audio - Judge approves official warrant to make future recordings legal)

Wiretapping by a private person should not happen.

"should not" and "does not" are not equal statements.

Re: A hacker got all my texts for $16

#296

Isn't this easy solvable with additional SMS token approval as mentioned in article? > "orsman added that, effective immediately, Sakari has added a security feature where a number will receive an automated call that requires the user to send a security code back to the company, to confirm they do have consent to transfer that number. As part of another test, Lucky225 did try to reroute texts for the same number with…

Sakari just was dumb, and deserves the bad press. I've built similar products and we launched with the "phone call to verify" feature to specifically prevent this type of abuse.

I agree
Post reply on HN