Live data from Hacker News

Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

ptsecurity.com

51–56 of 56 posts

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#51
post #15

Sadly, as far as I know, Paypal only allows SMS. I believe business account, you cannot link your Paypal to Braintrees and thus you cannot use any 2-auth authenticator. If I am wrong, please correct me, but I see no other options on Paypal, which is ridiculous, considering Paypal is such an important service. SMS should not be used for any critical services, but in cases like Paypal there is no choice.

It is possible to enroll hardware tokens, but I believe SMS is a prerequisite. It's also allegedly possible to deactivate in a bunch of other ways, e.g. by adding a new credit card. https://github.com/dlenski/python-vipaccess

Paypal itself I do not believe supports hardware token. If that is possible, it should be a bug, because that's a non-public feature...

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#52
post #35

Earlier quoted context omitted.

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

I don’t mean to say it was OP’s fault but you shouldn’t really use your primary phone number for 2FA anyways. Using a burner dumb phone dedicated only for 2FA should be standard, right?

Does Tmobile offer 2FA that isn't SMS based?

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#53
post #35
post #9

I was targeted this evening by a hacker who ported my phone number, and then got into FB + Yahoo (SMS reset). The motive appears to be bitcoin, based on the people contacted via facebook. Is it possible the initial PIN that was sent by Tmobile was intercepted via SS7? I am trying to find out if my phone (android) is compromised as well. The accounts and phone number are back under my control but I want to find out th…

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

Unfortunately I don't guard my name + number like I do my passwords. Who knows how they found it, in a post equihax world I'm not sure anyone can consider this private.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#54
post #35

Earlier quoted context omitted.

What a frightening experience! I'm sorry this happened to you. Curious to understand how these attacker obtain your phone number in the first place? I mean it's not something you publish widely right?

I don’t mean to say it was OP’s fault but you shouldn’t really use your primary phone number for 2FA anyways. Using a burner dumb phone dedicated only for 2FA should be standard, right?

It turns out the hacker stole a dealer's ID which meant the OTP sent to my phone was never needed / used. The dealer id overrides the need for a password.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#55
post #37

This is why I use a hardware wallet https://trezor.io

I'll be a happy man when the code and specs for this little guy become public: https://firefly.city ("Airgap" ETH wallet for $5)

Oh shit, I swear I did not see that coming

https://www.reddit.com/r/ethereum/comments/71jc83/firefly_up...

New crowd-funding page!

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#56
post #45
post #7

Slightly less exciting TLDR: as many of you already know, SMS isn't a good second factor for auth. That includes entrusting your Bitcoin wallet's private keys to a company using SMS for 2FA. Let's mention "cryptocurrency" as well to show up in more news alerts.

Paypal is offender number one. I don't understand why they can't use google authenticator. Is it some kind of pride thing, like paypal and Amazon?

Basically its a hangover from the PayPal football days (A PayPal branded Verisign 2fa token hardware device) they used to sell.. No idea why they don't transition over to Google Auth Style TOTP Algo.

But They still haven't ported all their systems to 2FA yet. Some pages require you to enter your password and append your 2fa token to the end of it (Mainly when logging in on mobile) and I know of a couple of stores that due to their PayPal integration I can not get to the final "Pay Now" page on paypal even though I successfully log into PayPal. But when you would normally get to that final page to press "Pay" the page just times out. I have to disable 2fa and do it again.

You can use "Symantec VIP" (it was renamed after Verisign was brought out). Though they don't make the sign up very easy. You have to go to the 2 factor page ("Security key") under security, press "Get security key", when prompted to enter your phone number press "cancel" then press "Activate your PayPal or VIP (VeriSign Identity Protection) token" and then enroll up as normal.

Its not Google Auth and it kinda feels like I can now gaining a collection of 2FA apps (iirc Namecheap's non sms 2fa is powered by Authy but you can not use Authy) so I do which they would all adopt a standard.

Post reply on HN