Live data from Hacker News

How SMS fraud works and how to guard against it

apuchitnis.substack.com

61–70 of 107 posts

Re: How SMS fraud works and how to guard against it

#61
post #58
post #49

Earlier quoted context omitted.

Google Authenticator does not back up TOTP state to Google. In fact, AFAIK, the app does not talk to the internet, at all, much less does it associated with a Google account. You can transfer your Google Authenticator state to another phone. This is accomplished through scanning QR codes -- no data is transferred over a network. This is a relatively new feature; for many years, Google Authenticator refused to provide…

> It's designed this way Its a bad design then :) . I dropped gauthenticator years ago because of the ridiculously user unfriendly inability to transfer/backup auth codes. What a braindead UX assumption. If you pursue security purity too far, people just wont use it.

You can transfer the state between phones now, they relented on that (a good thing, IMO).

Again, if you want auto backup to the cloud then you might as well just not use 2FA and rely on your password manager alone.

Personally I use hard keys wherever possible. Much better UX (and security) than any authenticator app. Just have to buy and register a few of them so you have backups if one breaks.

Re: How SMS fraud works and how to guard against it

#62

This makes the assumption that Twitter blocked it due to SMS fraud. While that's a plausible theory an equally plausible theory is that they were worried about account hijacking and security (and allowed twitter blue subscribers to continue to use it on a you can pay me to be stupid context) which seems equally plausible. I take issue with a lot of the assumptions in the article but this is funny: > Identify and bloc…

The numbers are most of the time not premium in the 1-900 sense of the word. They can just appear to be regular mobile or landline numbers in another country and would not be picked up by that library, at least not reliably. There are databases that track some of these numbers but they are usually sold to telcos and are pretty expensive. The only solution is rate limits per number, per IP, and set a max price per SMS of $0.05-$0.10 or so (make your Papua New Guinea users use an Authenticator app instead).

Re: How SMS fraud works and how to guard against it

#63
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

See what happens to your authenticator app after a factory reset. It is extremely risky to use them for 2FA. SMS always works.

If this is work related authentication and they expect you to use your personal property to run an app, then you're just playing a role as a puppet in their useless security theater. If your employer was serious about security then you'd be issued a dedicated device for auth.

Re: How SMS fraud works and how to guard against it

#64
post #5

If you haven't done this, set the MaxPrice field when sending SMS with an API provider such as Twilio. The message will fail to send if the cost of the sms exceeds the price you set. https://support.twilio.com/hc/en-us/articles/360014170533-Us...

You can also use geo-permissions to block delivery to certain countries: https://console.twilio.com/us1/develop/sms/settings/geo-perm...

Re: How SMS fraud works and how to guard against it

#65
Another technology to read up on is Silent Network Auth: https://www.twilio.com/blog/silent-network-authentication-sn...

If you operate a mobile app, this allows you to force a data packet over the device’s SIM that the carrier can validate. Platforms like Twilio/Boku have worked with the carriers to provide an API for this.

SMS is completely removed from the process and SMS pumping becomes a non issue.

Another option that could be mentioned in the article is using WhatsApp for OTP delivery. It’s the de facto messaging app in many countries with scketchy carriers, precisely because people don’t enjoy paying 5 cents per SMS.

Re: How SMS fraud works and how to guard against it

#66
post #62

This makes the assumption that Twitter blocked it due to SMS fraud. While that's a plausible theory an equally plausible theory is that they were worried about account hijacking and security (and allowed twitter blue subscribers to continue to use it on a you can pay me to be stupid context) which seems equally plausible. I take issue with a lot of the assumptions in the article but this is funny: > Identify and bloc…

The numbers are most of the time not premium in the 1-900 sense of the word. They can just appear to be regular mobile or landline numbers in another country and would not be picked up by that library, at least not reliably. There are databases that track some of these numbers but they are usually sold to telcos and are pretty expensive. The only solution is rate limits per number, per IP, and set a max price per SMS…

IMO WhatsApp is also a great option for 2FA in many countries. OTP is one of the approved outbound templates that WA will let you deliver without an inbound message.

Re: How SMS fraud works and how to guard against it

#67
post #52

Earlier quoted context omitted.

How is this fraud? If you require me to use SMS (deprecated), you are doing me a disservice and you should pay for the consequences. Use e-mail. It's free, works across countries, across SIM cards, allows for alphanumeric IDs, and is decentralized and not controlled by telcos.

Some folks build (or use) telecommunication systems that work for (cell) phones. Believe it or not but for receiving a notification via text message you nobody needs to install any apps or even require a smartphone and/or internet access :)

It's still mostly used for malicious tracking. In many countries you have to use your identity to get a phone number, and SMS verification exploits this to track users.

Re: How SMS fraud works and how to guard against it

#68
post #22
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…

Is email worse? Email for the most part does not require you to enter into an agreement with a predatory or monopolistic phone company, and there are services to generate single use emails that you can segregate between services.

Re: How SMS fraud works and how to guard against it

#69
post #52
post #5

If you haven't done this, set the MaxPrice field when sending SMS with an API provider such as Twilio. The message will fail to send if the cost of the sms exceeds the price you set. https://support.twilio.com/hc/en-us/articles/360014170533-Us...

How is this fraud? If you require me to use SMS (deprecated), you are doing me a disservice and you should pay for the consequences. Use e-mail. It's free, works across countries, across SIM cards, allows for alphanumeric IDs, and is decentralized and not controlled by telcos.

> Use e-mail. It's free

And the email that my service sends you so that you can complete registration will land straight in spam where you won’t find it.

I’ll stick to SMS for activating accounts.

Re: How SMS fraud works and how to guard against it

#70
post #12

I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?

authenticator apps come with privacy concerns. Right now, Microsoft has no means to collect my location data, they don't have any access to my phone, including my phone's camera. The moment I install Microsoft authenticator that situation changes. No thanks.

SMS has even more privacy concerns. To be able to receive SMS, the network must know your location. You are also forced to use proprietary firmware for most radio components. SMS is also subject to attacks against the telecom, such as by tricking their staff into producing a new sim card with your number.
Post reply on HN