Live data from Hacker News

The Most Expensive Lesson of My Life: Details of SIM Port Hack

medium.com

51–60 of 251 posts

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#51

> Google Voice 2FA Unfortunately many places are actively refusing to work with Google Voice. I got a message from Bank of America saying specifically that they're removing Google Voice support: > You can't enroll in Zelle with a landline, Google Voice or VOIP (voice over internet protocol) phone number. (Section 3.C.3 Enrolling in the Service) This follows with some other unnamed (because I don't remember them) serv…

If you ported a previous phone number to google voice, how would they know?

I don't imagine they would know unless they check their service logs. I imagine that interconnectivity with (in my case: Bank of America) would cease. And I'm pretty cynical with tech so I suspect it would quietly cease.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#52
I'd like to point out that preventing things like this is literally this guy's day job. (Look him up)

And he didn't know about SIM attacks.

And he kept $100k of irreversibly transactible "money" on an exchange, despite their history of being hacked.

This is what happens when you get involved with organized crime (which I consider Bitcoin to be): you become a victim.

His lessons learned is of course not that reversible transactions is something good, not a "mistake" in the fiat banking system.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#53
post #15

Large tech companies like Google push 2-factor auth to "increase" security, but this article shows that 2-factor auth with SMS verification opens up a huge security hole since the attacker can access your email if they can get your provider to port your SIM over to their device. Am I missing something and if not how did companies like Google not foresee this huge security hole?

Google offers many different 2 factor methods including Google Prompt, TOTP, and security key - all of which are better choices than SMS. The author is right to say that SMS is not enough but he didn't go far enough: only use SMS-based 2FA if it's your only 2FA choice for your critical accounts, and consider alternative services if it's your only choice.

If you use one of those secure options, click the lost your device option, and then you can describe to everyone how secure the recovery process is.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#54
post #5

This is frightening. If you're using texts for 2-factor auth you're at the mercy of your phone service provider's customer service. And they're trying to balance being helpful with security, which can be in opposition. Losing $100,000 with no hope of recovery is the kind of thing that could sink many people's finances. His summary of how to avoid having this happen to you: * Use a hardware wallet to secure your crypt…

> * Use Google Voice for 2FA

I like this idea, insofar as the Voice number is not vulnerable to the SIM port attack.

But then I worry that it's yet-another-thing I'm to my Google account, which Google could always shut down at a moment's notice, with no explanation, and no recourse.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#55

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

> And while we are doing PSAs, I'd like to give one piece of seemingly conflicting advice: make sure you have backups of your multi-factor authentication systems.

Yes! Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. The underlying keys can be manually shown and entered elsewhere if needed, and can be backed up with everything else that's valuable.

> Print out 2-factor backup codes, put them somewhere safe, maybe split them in 2 and put half of the codes in one place, and half in another. Think through possible problems. It really sucks to have your house flood, then find out that your phone with the 2-factor app on it was destroyed, and your backup codes ruined as well...

Off site and offline backups are a good thing to have, especially with fire and water proof lockboxes. (think encrypted external drive lying around at work or at family/friend's house)

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#56
post #43

Earlier quoted context omitted.

Google offers many different 2 factor methods including Google Prompt, TOTP, and security key - all of which are better choices than SMS. The author is right to say that SMS is not enough but he didn't go far enough: only use SMS-based 2FA if it's your only 2FA choice for your critical accounts, and consider alternative services if it's your only choice.

The issue is that the forgot/lost device flow allows you to remove your more secure 2FA with only SMS verification.

You can turn off SMS/phone auth fallback, at least in gsuite.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#57
post #45
post #9

Earlier quoted context omitted.

This is not about porting the number to a different carrier or even a different owner though. It's more analogous to getting a replacement SIM card. The last time I had a phone stolen, I went to the carrier's store, they checked my ID, and gave me a replacement SIM. And the things is, if the customer service representative is empowered to do that, they could also be bribed by the attacker.

I checked, to get a replacement sim my carrier sends out inactive cards that needs to be activated through their web service using the printed number on the card. If you don't have an account you need to contact customer service, and to get through there they most likely authenticate you based on your SSN and an already active app on your phone (BankID) where you input your personal password. This has actually create…

See recent Tele2 attacks. This is a problem in Sweden too.

Maybe the Tele2 attacks made them finally sort things out.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#58

It's why most of 2FA implementations is BS. It's truly only whoever has access to your number or email can do whatever.

I wouldn't say it's BS. It's just not perfect.

The standard person today isn't capable of managing multiple secure tokens, and actually keeping them separate.

One smashed phone, and truly secure accounts would be lost forever, or require significant resources on the part of the provider to re-verify people's identities.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#59
post #12

Part of the problem here is the lack of fraud insurance from CoinBase/exchanges. If the attacker would have instead stolen from his bank (several US and Canadian banks I know happily allow logins with only a password or are only starting to introduce SMS-only 2fa), it is likely that the bank would have returned the money, whether they could revert the transaction or not, and then pursued the hackers themselves.

because they can (usually) revert it.

Because reversibility is a good thing.

Re: The Most Expensive Lesson of My Life: Details of SIM Port Hack

#60

I'd like to see more companies introduce "time locks" into various big aspects of accounts. Want to port a SIM? I'll put your request in now but it will wait for 5 business days before it happens, and at any point if you or someone claiming to be you calls up to stop it, we stop it, no questions asked. Want to change 2 factor information for an account? We can put in the request now and it won't take effect for a wee…

> And while we are doing PSAs, I'd like to give one piece of seemingly conflicting advice: make sure you have backups of your multi-factor authentication systems. Yes! Many password managers (at least KeePassXC/KeePass with plugin) can store and create TOTPs. The underlying keys can be manually shown and entered elsewhere if needed, and can be backed up with everything else that's valuable. > Print out 2-factor backu…

There are also tools to allow you to use those TOTPs without having a phone in general. You can always use those methods instead of using SMS or phones.
Post reply on HN