Live data from Hacker News

A hacker got all my texts for $16

vice.com

41–50 of 296 posts

Re: A hacker got all my texts for $16

#41

How do you protect against this type of attack?

I believe the practical solution for many people is to switch the 2FA to an authenticator on-your-phone code generator, which someone cannot hack easily.

Most important account / banks / etc services now offer this option.

The only thing is, though, make sure to keep backups of the codes you use to initialize the authenticator app, because for some services there is no recovery if you lose your phone or don't have backups.

Re: A hacker got all my texts for $16

#42
Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible.

And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent.

I mean, in this case all the hacker did was fill out a form and say pretty please. I hope phone companies that allow this get sued.

Re: A hacker got all my texts for $16

#43

SMS-2F needs to die. It has absolutely no benefit other than perhaps as protection against credential stuffing.

I like not being locked out of my applications when my phone goes for an unexpected swim and I have to replace it. The numerous emails I get when I log in from a new device serve me pretty well, all things considered

Secure phones are sub-$200.

If you have multiple accounts, services, etc, then backing up your 2FA codes, or registering two devices/phones at the same time should be on your radar.

Re: A hacker got all my texts for $16

#44
post #7

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

It's neither convenient nor stable for anyone moving between countries either. When given the choice between a service that uses my phone number as my permanent user identifier and one that uses my email, I'll always go for the latter. Unfortunately, big parts of the industry seem to be headed the other direction.

International relocation is a very good point!

Something I hadnt considered. Thanks!

Re: A hacker got all my texts for $16

#45

It’s worth pointing out that often LOA forms ask for a PIN, usually the same PIN as would be required to check voicemail. A better telecom company might make the PIN something harder to remember but enforcing such things would also make it harder to switch carriers, particularly if it replaced today’s standard forms of ID checks. It’s better to assume that until phone numbers can be locked and unlocked the way domain…

My reading of this article suggests that the PIN requirement for number porting is bypassed in this forwarding scenario, since this method is claimed to be distinct from simjacking. That is, the number hasn't been ported by the FCC's guidelines, although I didn't glean exactly how that's happening by these retail providers.

Re: A hacker got all my texts for $16

#46
In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process.

I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level of security seems to only be available to VIPs.

Re: A hacker got all my texts for $16

#48

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

The whole 2 factor thing really falls down if sms is a part and you aren’t getting the messages. I had a miserable time trying to get into Backblaze recently, with even the ability it offered to switch sms providers failing. The list of valid keys they give you on setup bailed me out eventually, but it took me a while to remember them.

> remember them

Uh. You're supposed to memorise them? I printed them out and stuck them in a safe place.

Re: A hacker got all my texts for $16

#49

So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.

Authenticator Apps?

Re: A hacker got all my texts for $16

#50

Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…

When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy?

Not sure which is why I'm asking.

Post reply on HN