Too many services use phone numbers as the keys to the kingdom. It's a convenient and stable identifier, but holy shit it's not designed for security at all .
Agreed. Users have it in their power not to use services that require a phone number for SMS verifcation.
A hacker got all my texts for $16
81–90 of 296 posts
Re: A hacker got all my texts for $16
#82Earlier quoted context omitted.
Not being able to access your account for 3 days when you need to recover your password is not going to be a viable business decision for most services. I think you are SEVERELY underestimating how often the average user needs to recover their password.
tell me. On some little-used accounts of mine i need a new password for every login. Then there's one particular account which never lets me login. I have to make a new password every time...
Turned out that the text box for entering the new password allowed a different number of characters than the one for logging in.
Re: A hacker got all my texts for $16
#83Earlier quoted context omitted.
I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).
SIM swaps are relatively easy in Australia, requiring only some fairly simple social engineering of staff in a phone store. Number porting is trickier, requires a name and account number (or DOB in the case of a prepaid account) of the victim and they receive an SMS informing them their number was ported in advance.
Re: A hacker got all my texts for $16
#84Earlier quoted context omitted.
Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. Feels like the industry needs to push for a dedicated, universal, probably physical, tool for 2FA.
> Does anyone know why services like Google Authenticator were ditched industry wide in favor of SMS codes? It has never made any sense to me. This is not the case in my experience. Many apps that once used Authenticator-based TOTP now use app-based push alerts (Steam Authenticator, Blizzard Authenticator, Google->GMail App, etc.), but I haven't noticed a trend toward actual SMS. Are there major orgs that switched to…
Re: A hacker got all my texts for $16
#85Earlier quoted context omitted.
When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.
If I understand correctly, the initial telephone systems were run by manual operators at a physical switchboard, who could listen in to anything that was said on any line. Many people also had party lines, where someone (in another house or apartment) could pick up their phone and listen to your conversations. So, no, not much of an expectation of privacy - at least, there shouldn't have been.
Re: A hacker got all my texts for $16
#86Re: A hacker got all my texts for $16
#87So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.
Authenticator Apps?
Re: A hacker got all my texts for $16
#88Earlier quoted context omitted.
When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.
When cell phones first became big, probably 10-15 years ago at least, there was a website for my area I lived in at the time (southern Illinois) that would list texts and people could vote on the funniest ones. There were some really private messages that would hit the top (obviously phone numbers weren’t displayed.) So it used to be people had the assumption that texts were public, because for some carriers they bas…
Do you happen to have any links regarding this? Would love to read more.
Re: A hacker got all my texts for $16
#89Earlier quoted context omitted.
tell me. On some little-used accounts of mine i need a new password for every login. Then there's one particular account which never lets me login. I have to make a new password every time...
I had one like this. I’d type the new password, confirm it, get “success!” And then type the exact same thing to log in and it would fail. Turned out that the text box for entering the new password allowed a different number of characters than the one for logging in.