Live data from Hacker News

Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

forbes.com

311–320 of 382 posts

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#311
Seems pretty silly putting any form of security apparatus into a technology which could possibly have been engineered from the ground up to be SIGINT-enabled. It's as if GSM was deliberately designed by the intelligence community to be available for eavesdropping. They build the protocol with just enough good security that Johhny can't intercept his wife's calls to check for cheating, but with enough bad security that intelligence services (and sophisticated criminals) can play Mallory[0]

[0]: https://en.wikipedia.org/wiki/Alice_and_Bob#Cast_of_characte...

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#312

Earlier quoted context omitted.

Interesting. When two crimes both take similar effort to commit, and similar effort to investigate, I'm not sure if the higher dollar amount should be defacto prioritized. I am going away from SMS based 2FA where I can. For services where it is used, anyone have opinions on using 2FA via a SMS to VOIP number with a provider who has better account security/authentication tools than most telcos (e.g. google, etc)?

"I'm not sure if the higher dollar amount should be defacto prioritized." Why not? Higher net worth equates to higher taxes paid - the 250k victim has been paying the investigators a more substantial sum, and should receive a more substantial response from them. "Size matters" sums it up to me.

That's not how modern Western societies work. Plutocracy has been tried, and found to be devastating for society, human dignity, and the human condition in general, not to talk about the rampant corruption it invites.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#315

Earlier quoted context omitted.

Not to mention you lose your Authenticator if you upgrade/lose/break your phone, but U2F keys are (practically) forever.

adb backup com.google.android.apps.authenticator2 all the codes are stored in the sqlite3 database which you can open with standard command line tools. there are also more user friendly backup apps such as helium, but adb works quite nicely.

Last I checked, adb backup doesn't backup the secrets. Has that changed?

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#316
post #296
post #272

Earlier quoted context omitted.

Could you elaborate on why Authy is not safe? In my setup, 1) after adding the devices I wanted to add, I've disabled multi-device (which keeps the existing devices, but prohibits adding new devices), 2) for new devices, it requires a backup password (once) to decrypt the credentials retrieved from the cloud, and 3) IIRC, it requires authorisation from one of the trusted devices to add a further device. All in all, i…

How well do you trust the customer service rep at Authy against social engineering? Especially when someone has control over your email, phone, and potentially many other accounts already.

Good question!

1) I trust them ever so slightly more than your average off-shored telco rep.

2) AFAIK, they do not hold the credentials in unencrypted form, they're only decrypted on the device with the backup password.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#317

Earlier quoted context omitted.

> 1. I believe it began with the hacker getting DOB/SSN We [the US] dramatically over-rely on SSN. At least one upside to ubiquitous biometrics will be that we can start layering more authentication measures in an effective and consumer friendly way.

Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem. These things are not secret, and having me say mine does not prove that you're talking to me.

> Relying on it is not the problem. Treating it (or "date of birth" or "mother's maiden name") as a secret for use in authentication is a big problem.

I honestly don't see how you didn't just restate what I said with different language, while simultaneously saying you disagree with me.

Either way, I agree, and don't really think this is worth a cyber-argument so not sure if I should even be responding. Oh well.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#318
post #172

Earlier quoted context omitted.

The ACH model is fundamentally insecure: anyone who knows your account number can pull money from it, and the protocol makes no allowance for the bank to check with you first. I don't think choice of bank matters very much. You can manage your risk somewhat by: 1) Using credit and not debit cards for day to day spending. 2) Maintaining your long term wealth in separate accounts at separate institutions and not linkin…

Why they keep that system? In most of Europe you got "normal" banking system where you can give everyone your account number and worse thing they can do is to put some money there. In US it seems #freemarket is putting externalities (security) on the customer.

überweisung isn't really that secure.

I had somebody buying products on Amazon using my company's IBAN numbers. Amazon were super frustrating to deal with. They kept asking for my amazon account details and I kept explaining that the company doesn't have an amazon account. They didn't know how to proceed ! But in the end they did reverse the charge.

My girlfriend had somebody buying groceries using her numbers. They just write numbers in and signed the sheet of paper at the store. The store refused to take responsibility for doing this without ID-ing the person. The police were more understanding.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#319
post #270

Earlier quoted context omitted.

I don't doubt that. In my experience sometimes a phone number is required and sometimes not. When it prompted for a phone I didn't find a way to work around that.

I find that when I create a dummy account from a clean browser (no cookies) with a VPN, a phone number is required. I wouldn't be surprised if they do some internal risk/dodginess assessment based on several factors.

Can you then remove it after the fact? I was able to remove the phone number from my account without it complaining.

Re: Hackers Are Hijacking Phone Numbers and Breaking into Email, Bank Accounts

#320

So, I've read the article a couple of times, It's pretty long. For those of you looking to get the most bang for your buck, I think the following advice is Golden: 1. Do NOT secure your sensitive accounts (facebook, primary email, bank accounts, twitter, etc) with your telco phone #. Telco Phone number is NOT secure! "Create a brand new Gmail email account. Do not connect it to any of your existing email accounts. (W…

"Once you’ve created the new island-unto-itself email address, create a new Google Voice number." Use this Google Voice # to secure your primary accounts, and don't have your telco # listed in any of those accounts."

The problem with this otherwise good idea is that google will not allow you to keep this account as an island.

Eventually you will get the "we've noticed something suspicious about your account" dialog which requires entering some other, unrelated phone number. You're locked out until you do so.

The suspicious behavior is, of course, signing up without a live phone number.

Ironically, they will accept any number you input with no verification that it is related to the account in any way. They just want to see a live, carrier number input.

(This has been my experience from within the US)

Post reply on HN