Reminder: SMS 2FA adds only a negligible amount of security, if your company does 2FA via SMS you're doing nothing more than lulling your users into a false sense of security. Don't do it. Support proper 2FA. (And while you're at it, allow your users to decide how much they care about their account. Don't make the decision for them.)
That’s great until your users lose/break their phone and have no backups for their 2FA codes. “Sorry you’re locked out forever, good luck lol” Is not a response you can give to them.
A hacker got all my texts for $16
291–296 of 296 posts
Re: A hacker got all my texts for $16
#292Re: A hacker got all my texts for $16
#293Earlier quoted context omitted.
My reading of this article suggests that the PIN requirement for number porting is bypassed in this forwarding scenario, since this method is claimed to be distinct from simjacking. That is, the number hasn't been ported by the FCC's guidelines, although I didn't glean exactly how that's happening by these retail providers.
SMS routing and number porting are different things, as the voice and SMS operate independently. I headed Engineering for a company that allowed you to SMS enable your landline or toll-free number, and our automated flow for non-toll-free landlines required receiving a code via telephone call (to avoid the situation of compromised SMS routing). We didn't support numbers that were not in those two buckets, i.e. mobile…
Re: A hacker got all my texts for $16
#294Earlier quoted context omitted.
I tried to get T-Mobile to stop giving my location to anyone that hits their APIs with a 'Yes I have permission' flag set. There's no opt-out for it, and no enforcement of the permission requirement. Their support had me snail mail a letter to some PO box. I never got a response. And now they're going to start outright selling their customer activity after forcibly un-opt-outing* everyone who opted out in their priva…
Wow. How long does your number go unavailable if you port out? I may.
Re: A hacker got all my texts for $16
#295Earlier quoted context omitted.
I'm under the assumption that wiretapping to create evidence is illegal, but wiretapping to get a warrant probably happens all the time. (AKA Judge and Police officer listen to illegally captured audio - Judge approves official warrant to make future recordings legal)
Wiretapping by a private person should not happen.
Re: A hacker got all my texts for $16
#296Isn't this easy solvable with additional SMS token approval as mentioned in article? > "orsman added that, effective immediately, Sakari has added a security feature where a number will receive an automated call that requires the user to send a security code back to the company, to confirm they do have consent to transfer that number. As part of another test, Lucky225 did try to reroute texts for the same number with…
Sakari just was dumb, and deserves the bad press. I've built similar products and we launched with the "phone call to verify" feature to specifically prevent this type of abuse.