Live data from Hacker News

How SMS fraud works and how to guard against it

apuchitnis.substack.com

51–60 of 107 posts

Re: How SMS fraud works and how to guard against it

#51
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

authenticator apps come with privacy concerns. Right now, Microsoft has no means to collect my location data, they don't have any access to my phone, including my phone's camera. The moment I install Microsoft authenticator that situation changes. No thanks.

Most sites that support authenticator apps support the TOTP standard that allows you to use any authenticator app. You don't have to install the app specific to the site, you can find a privacy-respecting one.

Re: How SMS fraud works and how to guard against it

#52
post #5

If you haven't done this, set the MaxPrice field when sending SMS with an API provider such as Twilio. The message will fail to send if the cost of the sms exceeds the price you set. https://support.twilio.com/hc/en-us/articles/360014170533-Us...

How is this fraud?

If you require me to use SMS (deprecated), you are doing me a disservice and you should pay for the consequences.

Use e-mail. It's free, works across countries, across SIM cards, allows for alphanumeric IDs, and is decentralized and not controlled by telcos.

Re: How SMS fraud works and how to guard against it

#53
post #51

Earlier quoted context omitted.

authenticator apps come with privacy concerns. Right now, Microsoft has no means to collect my location data, they don't have any access to my phone, including my phone's camera. The moment I install Microsoft authenticator that situation changes. No thanks.

Most sites that support authenticator apps support the TOTP standard that allows you to use any authenticator app. You don't have to install the app specific to the site, you can find a privacy-respecting one.

If I can find a privacy respecting one that's a good thing! I worked a job that tried to force us to use Microsoft authenticator but we pushed back after looking at the privacy policy and so instead we ended up with perfectly nice key fobs. It's hard to beat that for privacy.

Re: How SMS fraud works and how to guard against it

#54
post #22

Earlier quoted context omitted.

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

I finally got my 75-year-old mother to add 2FA/SMS to her online banking account. She calls me (from her landline ) every time she tries to login. I have to walk her through the process. We usually have to request a new auth code be sent at least twice. It generally takes 10 or 15 minutes, although, admittedly, half the time is her complaining. So, yeah, there's no way I could get her to use an Authenticator app. (Al…

Have you considered that your mother just uses this as an excuse to talk to you on a regular basis?

Re: How SMS fraud works and how to guard against it

#55
post #18

The article is describing one type of SMS Fraud, but I think Twitter got attacked using SMS Traffic Pumping Fraud. Twilio has the explanation https://support.twilio.com/hc/en-us/articles/8360406023067-S...

Ah yep - the one I describe is the same as the one Twilio discuss.

Re: How SMS fraud works and how to guard against it

#56
post #22
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

> it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA

As a data point, USAA (which is not the biggest bank, of course, but it is not tiny either) has supported TOTP for years. There are probably others, but at least some banks support relatively modern security.

Re: How SMS fraud works and how to guard against it

#57
post #54

Earlier quoted context omitted.

I finally got my 75-year-old mother to add 2FA/SMS to her online banking account. She calls me (from her landline ) every time she tries to login. I have to walk her through the process. We usually have to request a new auth code be sent at least twice. It generally takes 10 or 15 minutes, although, admittedly, half the time is her complaining. So, yeah, there's no way I could get her to use an Authenticator app. (Al…

Have you considered that your mother just uses this as an excuse to talk to you on a regular basis?

Absolutely. And it reminds me of a conversation I had with my grandmother's doctor a few years before she passed:

- How's grandma doing? Is she gonna be okay?

- Well, let me ask you, does she complain much?

- All the time!

- Then grandma's doing fine. It's when she stops complaining - then, it's time to be concerned.

Re: How SMS fraud works and how to guard against it

#58
post #49
post #38

Earlier quoted context omitted.

Wouldn't most people just use Google Authenticator and have it automagically back up to google's nigh unlimited storage space? Obviously not something anyone who respects their privacy would subject themselves to, but it seems to me like the easy path leads to these things being backed up. Obviously if google has your 2FA keys and you were using 2FA keys to log into your google account then you would need to recover…

Google Authenticator does not back up TOTP state to Google. In fact, AFAIK, the app does not talk to the internet, at all, much less does it associated with a Google account. You can transfer your Google Authenticator state to another phone. This is accomplished through scanning QR codes -- no data is transferred over a network. This is a relatively new feature; for many years, Google Authenticator refused to provide…

> It's designed this way Its a bad design then :) . I dropped gauthenticator years ago because of the ridiculously user unfriendly inability to transfer/backup auth codes. What a braindead UX assumption. If you pursue security purity too far, people just wont use it.

Re: How SMS fraud works and how to guard against it

#59
post #52
post #5

If you haven't done this, set the MaxPrice field when sending SMS with an API provider such as Twilio. The message will fail to send if the cost of the sms exceeds the price you set. https://support.twilio.com/hc/en-us/articles/360014170533-Us...

How is this fraud? If you require me to use SMS (deprecated), you are doing me a disservice and you should pay for the consequences. Use e-mail. It's free, works across countries, across SIM cards, allows for alphanumeric IDs, and is decentralized and not controlled by telcos.

Some folks build (or use) telecommunication systems that work for (cell) phones. Believe it or not but for receiving a notification via text message you nobody needs to install any apps or even require a smartphone and/or internet access :)

Re: How SMS fraud works and how to guard against it

#60
post #39

I feel like the easiest workaround is to a) not use an email with your name in it for any important login b) don't use those emails for more than one service c) use a separate SIM and device for 2FA (mint mobile etc) / banking apps that aren't up to speed with non SMS 2fa. It pains me to say this since Bank of America sucks, but their system now supports adding a Yubikey for login, nearly as good as Schwab before the…

> separate SIM and device for 2FA

Are you really suggesting having 5 different devices with separate SIM cards to receive 2FA messages? What exactly is the point here, just having different numbers? In that case some kind of text message forwarding service that gives you multiple virtual numbers would (still not free but much more reasonable than dealing with multiple devices)

Post reply on HN