The amazing thing is with Wells Fargo that if you have a RSA SecurID 2FA FOB for access to your bank accounts, and you have a phone number configured for the account, you can use EITHER the 2FA RSA one-time pin, OR SMS verification to log into your bank account web page. I mean this is a bank, are these guys for real?
Yes, although there is actually a lower transaction limit on sessions initiated with SMS 2FA vs SecurID.
Man sues AT&T over 'SIM Swap' hack allegedly involving employees
41–50 of 129 posts
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#42Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#43Earlier quoted context omitted.
Yes, although there is actually a lower transaction limit on sessions initiated with SMS 2FA vs SecurID.
Which almost furthers the point that this is bad, isn’t this an acknowledgement by them that SMS 2FA is less secure? If it’s less secure and you have SecurID, why can’t I disable SMS?
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#44Earlier quoted context omitted.
Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.
It's rather sad that Canadian banks still view SMS as the best way forward. They'll text you, they'll email you, they'll validate over the phone... all of which are really this same problem. I'm waiting for the days our banks will accept multiple 2FA solutions.
https://www.cbc.ca/news/business/banks-deny-compensation-onl...
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#45Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#46He's got good evidence. The SIM-swappers have actually been convicted. ATT says it's "an industry" problem, but it's 100% their problem. They are doing nothing to stop employees from robbing their customers. Of course the victim could probably have protected his "life savings" better, but that's not the point.
Ideally it wouldn't be possible for a single employee to do this.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#47I wish him the best of luck but considering AT&T was a party in the big Supreme Court decision setting the precedent, I predict this falls down the dark hole of mandatory, binding arbitration about twelve minutes after the first hearing on a motion to dismiss and compel arbitration. We’ve collectively given up our rights to sue in many instances (including when signing up for HN-backed services run by people who shou…
So it gets moved to arbitration. If anything, it will move quicker and cost him less than a court case would.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#48He's got good evidence. The SIM-swappers have actually been convicted. ATT says it's "an industry" problem, but it's 100% their problem. They are doing nothing to stop employees from robbing their customers. Of course the victim could probably have protected his "life savings" better, but that's not the point.
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#49This is exactly the kind of thing that needs to start happening to actually motivate the companies to stop allowing this BS. Good luck! Also, don't have your life savings in crypto, but if you must, then please for the love of everything holy don't put it someplace where a SIM swap attack is enough to get it out. Irreversible transactions are kind of the whole point of it, so you need to be much more careful with cry…
Indeed, listen to NIST: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance.
Edit: https://twitter.com/skunkworker/status/1131297869703438337
@ChaseSupport Hey Chase, when will offline TOTP be added for a more secure login?
Thank you for reaching out! What we have is the multi-factor authentication on all online accounts. You can visit https://tinyurl.com/y7r2fztd for more info on how we protect and secure your information. ^AA
Re: Man sues AT&T over 'SIM Swap' hack allegedly involving employees
#50Currently working on finishing moving passwords from a Google account to my password manager and resetting them all, as well as replacing anything that uses an SMS 2FA with a time based authenticator or other alternative where possible. Planning on getting a FIDO key to use where I can. Also setting up a Voice number on an account that's used for nothing else besides 2FA in the instances where there is no better form of authentication.