Live data from Hacker News

Listen to a SIM-Jacking, Account-Stealing Ransom

motherboard.vice.com

91–95 of 95 posts

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#91

Earlier quoted context omitted.

Wrong. TOTP is supported, although hidden.

https://www.paypal-community.com/t5/Tips-from-Moderators/Pay... It uses Verisign's VIP app instead of Google Authenticator (or Authy or whatever).

You can use any TOTP app.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#92
post #61

Earlier quoted context omitted.

Wrong. TOTP is supported, although hidden.

According to some threads I've read it doesn't work in all circumstances. Personally I wouldn't risk it since it could mean risking getting locked out of your account.

I've been using it for a few years now and I haven't encountered a place where I couldn't use it. It might force you to enter the TOTP code at the end of your password though, but it works.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#93
post #87

Earlier quoted context omitted.

Could you please elaborate about google thing you mentioned? I am interested in making my ATT sim morr secure..

It replaces the SMS 2FA with a Google prompt app on the phone for Gmail verification. So it doesn't make the SIM more secure but the SIM get hacked it doesn't allow the attacker to gain access to Gmail.

Also if your public SMS reset number is in google voice, a hacker can't port it off of Google easily because you need to log into your google account to port it, which requires 2fa. They have to figure out your real number, but you never give that out to anyone or you just use google hangouts SMS instead of forwarding text messages to your insecure phone.

Re: Listen to a SIM-Jacking, Account-Stealing Ransom

#94
post #11

Earlier quoted context omitted.

For paypal, texting is even the only 2FA option for non-US citizens. Baffling.

You can use a symantec hardware token. Paypal’s ceo is head of symantec’s board. Paypal must use symantec software wherever it is available, and their mfa is no exception. This is still baffling as you say though, because symantecs mfa system does allow for other mechanisms.

I can't. It only seems to be available for US citizens.
Post reply on HN