Live data from Hacker News

A hacker got all my texts for $16

vice.com

91–100 of 296 posts

Re: A hacker got all my texts for $16

#91
post #66

In Australia it's mandated you're sent a message before rerouting or migrating to another provider. Surprised this isn't enforced in the other countries, it costs next to nothing to implement and is just an additional step in the account migration process. I'd love to see companies allow for opt in additional security measures, like banks or telco's calling me - having a verbal password to confirm things, that level…

I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).

> due to peculiarities of the NANP phone number scheme

I suspect more like due to peculiarities of the United States of America. Such as a disinclination to regulate anything, trusting that somehow this time the most profitable course for corporations will also work out OK for its citizens even if it didn't on previous occasions.

This report lists a long chain of buck-passing companies that have exploited an obvious defect and then escaped any responsibility for the consequences. Notice how the only work they made the hacker do was legal paperwork to cover their backsides, no actual technical countermeasures. Because nobody at these companies cared if it was used this way, they only wanted to make sure if they got sued they would be able to blame somebody else and get away with it.

Re: A hacker got all my texts for $16

#92
post #66

Earlier quoted context omitted.

I think this particular issue is specific to North America, due to peculiarities of the NANP phone number scheme (inter-provider texts are routed quite differently from voice calls, if I understand it correctly). In other countries, the two channels are more closely coupled (but SIM swap and/or number porting attacks are still possible, depending on the provider‘s security protocols).

SIM swaps are relatively easy in Australia, requiring only some fairly simple social engineering of staff in a phone store. Number porting is trickier, requires a name and account number (or DOB in the case of a prepaid account) of the victim and they receive an SMS informing them their number was ported in advance.

I couldn't even get my own number ported in Australia (to a new provider on a new SIM). The old provider said the authentication failed. I gave up pretty quickly and just went with a new number.

Re: A hacker got all my texts for $16

#93

Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…

But what is an appropriate level of liability here? Phone companies never signed up to be the guardians of our digital lives, and the tech industry at large has just built a castle on shakey foundations.

And there are obvious trade-offs here, if we make number portability harder, it means you're somewhat hostage to your phone provider.

Re: A hacker got all my texts for $16

#94
post #8

Earlier quoted context omitted.

Nonsense. SMS is a great recovery factor, both for people who forget their password, and for those who lose access to their other second factors. (E.g. email address or a smartphone app). The thing that makes SMS uniquely good at this is that there is infrastructure around for people to replace their lost SIM cards, and that SMS available globally (vs regional identity systems like the bank ids in Nordic countries).…

Not being able to access your account for 3 days when you need to recover your password is not going to be a viable business decision for most services. I think you are SEVERELY underestimating how often the average user needs to recover their password.

My partner resets her Google password every time she logs in. It's just part of the normal flow for her. She probably does it with everything, but I'm not listed as a recovery on the other things.

Something better would be great. She's probably an extreme example, but I think we techy people tend to have a warped view of how comfortable "normal people" are with effective password management.

Re: A hacker got all my texts for $16

#95

My strategy is to have a second phone that has Authenticator and is also the phone for any SMS based 2FA. The phone is locked in a file cabinet when not in use and never leaves my desk. An extra phone only costs me $10/month. Well worth the peace of mind.

You have to pay a monthly fee to own a phone?

Re: A hacker got all my texts for $16

#96
> While adding a number, Sakari provides the Letter of Authorization for the user to sign. Sakari's LOA says that the user should not conduct any unlawful, harassing, or inappropriate behaviour with the text messaging service and phone number. But as Lucky225 showed, a user can just sign up with someone else's number and receive their text messages instead.

Um, what?!

Re: A hacker got all my texts for $16

#97

Lots of comments here along the lines of "SMS 2FA is bad", but hell, if the phone companies had an appropriate level of liability here (which should be a shit ton), this should be impossible. And it's not just about 2FA, most of humanity expects that if someone else texts them, those texts will go to their phone and only their phone unless they've given explicit verifiable consent. I mean, in this case all the hacker…

When they invented text messaging, heck even the phone system itself, did they provide anything that said there was an expectation of privacy? Not sure which is why I'm asking.

Is the initial set of expectations the immutable legal standard?

Re: A hacker got all my texts for $16

#98
post #49

So, when my nontechnical friends ask me what they should be using for 2FA, I'm kind of at a loss what to tell them. It's either a false sense of security (e.g., SMS), or too complicated for them (Yubikey). There's got to be a better system.

Authenticator Apps?

TOTP is only better than SMS against SIM swapping, a rare threat. They are identical against phishing, an enormously more common problem. For a typical user the delta in security when transitioning from SMS to TOTP is minimal.

Re: A hacker got all my texts for $16

#99
post #65
post #7

Earlier quoted context omitted.

It's neither convenient nor stable for anyone moving between countries either. When given the choice between a service that uses my phone number as my permanent user identifier and one that uses my email, I'll always go for the latter. Unfortunately, big parts of the industry seem to be headed the other direction.

I just transferred my phone number to google voice when I moved out of the country. When I moved it back I simply transfer it back to my carrier

There seem to be horror stories on reddit about Google Voice numbers being terminated for people out of the country too long.

Is there a stable inexpensive phone number service for folks that are outside the US a lot?

Re: A hacker got all my texts for $16

#100

How do you protect against this type of attack?

I believe the practical solution for many people is to switch the 2FA to an authenticator on-your-phone code generator, which someone cannot hack easily. Most important account / banks / etc services now offer this option. The only thing is, though, make sure to keep backups of the codes you use to initialize the authenticator app, because for some services there is no recovery if you lose your phone or don't have ba…

> which someone cannot hack easily

Everybody gets phished. Much easier than sim swaps.

Post reply on HN