Live data from Hacker News

A hacker got all my texts for $16

vice.com

81–90 of 296 posts

Re: A hacker got all my texts for $16

#81

Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .

Agreed. Users have it in their power not to use services that require a phone number for SMS verifcation.

The local government here has a covid tracking system that uses SMS verification and many stores won't let you in without using it.

Re: A hacker got all my texts for $16

#82

Earlier quoted context omitted.

Not being able to access your account for 3 days when you need to recover your password is not going to be a viable business decision for most services. I think you are SEVERELY underestimating how often the average user needs to recover their password.

tell me. On some little-used accounts of mine i need a new password for every login. Then there's one particular account which never lets me login. I have to make a new password every time...

I had one like this. I’d type the new password, confirm it, get “success!” And then type the exact same thing to log in and it would fail.

Turned out that the text box for entering the new password allowed a different number of characters than the one for logging in.

Re: A hacker got all my texts for $16

#83
post #66

Earlier quoted context omitted.

I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).

SIM swaps are relatively easy in Australia, requiring only some fairly simple social engineering of staff in a phone store. Number porting is trickier, requires a name and account number (or DOB in the case of a prepaid account) of the victim and they receive an SMS informing them their number was ported in advance.

Yeah getting thee account ID can be a pain, I've learned that the number in the UI and bill is not the identifier they want. Security by poor implementation.

Re: A hacker got all my texts for $16

#84

Earlier quoted context omitted.

Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. Feels like the industry needs to push for a dedicated, universal, probably physical, tool for 2FA.

> Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. This is not the case in my experience. Many apps that once used Authenticator-based TOTP now use app-based push alerts (Steam Authenticator, Blizzard Authenticator, Google->GMail App, etc.), but I haven't noticed a trend toward actual SMS. Are there major orgs that switched to…

The shit part is I now need 50 apps on my phone to use stuff. I don't want the steam app, I have no use for it. But features of my steam account are now limited because I don't use the app.

Re: A hacker got all my texts for $16

#85

Earlier quoted context omitted.

When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.

If I understand correctly, the initial telephone systems were run by manual operators at a physical switchboard, who could listen in to anything that was said on any line. Many people also had party lines, where someone (in another house or apartment) could pick up their phone and listen to your conversations. So, no, not much of an expectation of privacy - at least, there shouldn't have been.

If there was no expectation of privacy, the police would not need a warrant to tap a line.

Re: A hacker got all my texts for $16

#87
post #49

So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.

Authenticator Apps?

The annoying part is most of them are very hard to move over to a new phone or backup

Re: A hacker got all my texts for $16

#88

Earlier quoted context omitted.

When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.

When cell phones first became big, probably 10-15 years ago at least, there was a website for my area I lived in at the time (southern Illinois) that would list texts and people could vote on the funniest ones. There were some really private messages that would hit the top (obviously phone numbers weren’t displayed.) So it used to be people had the assumption that texts were public, because for some carriers they bas…

This is hilarious.

Do you happen to have any links regarding this? Would love to read more.

Re: A hacker got all my texts for $16

#89
post #82

Earlier quoted context omitted.

tell me. On some little-used accounts of mine i need a new password for every login. Then there's one particular account which never lets me login. I have to make a new password every time...

I had one like this. I’d type the new password, confirm it, get “success!” And then type the exact same thing to log in and it would fail. Turned out that the text box for entering the new password allowed a different number of characters than the one for logging in.

wha? Who does that? I don't think that's my problem, though i go crazy every time my password isn't recognized, i go through the process and this message comes up "you must use a different password". And i can't even just go back to the login menu. It's too late! And i paid money for this account.
Post reply on HN