Getting Hacked, Lessons Learned
avc.com
avc.com
Verizon accounts are by default secured only by the last 4 SSN numbers of the account holder, with an optional 5 alphanumeric password. AT&T was worse as there was no default verification required, it was only presented as a recommended validation to me. I could type in any AT&T phone number and click the "Skip Verification" button. Many employees get in the habit of doing this by default to save time and that makes the problem worse, as they ignore the large "VERIFY CUSTOMER" text.
Don't remember the password? No problem, It was not uncommon for me to make a quick call to my account manager for whatever carrier and simply ask them for the last 4 digital of the social or the password. Im not sure if they just trusted me, or if this was normal practice. But I could get into anybodys account, for the 3 major carriers, with little to no verification.
Thats not even mentioning being able to search through BestBuys entire customer database.
Porting of numbers if an obvious vector for this kind of attack, but its also worth noting that swapping the ICCID on the line (the SIM card number) is a much more effecient solution, as it doesn't require the attacker to setup new cell phone service anywhere. Carriers are starting to catch on to this though as more of these attacks happen to high profile users.
[0] https://www.theregister.co.uk/2017/05/03/hackers_fire_up_ss7...
I needed an untraceable email to send from for reasons I won't go into but couldn't create one.
If you're poor but need a webmail account you need a phone. You can't even put in a fake number since you need to reply to the approval link setup email. Gmail, Outlook, Yahoo, everyone one I tried all require a phone.
I was going to use that as a plus, as I have now had to switch phones twice, and re-setting up my GA 2FA sites on the new phone was a major PITA - I thought Authy would make that easier, but now I guess that feature could be an attack vector too?
https://support.twilio.com/hc/en-us/articles/223182508-Authy...
This should be the default really.
I thought the main difference was that the 2FA service details were saved in the cloud so you could sync up to multiple mobile devices using the Authy app?
I'd recommend disabling multi-device support which is enabled by default or adding a backup/restore prassphrase to make it more difficult to add new devices without also cracking the prassphrase.
More:
https://en.wikipedia.org/wiki/Signalling_System_No._7
http://thehackernews.com/2017/05/ss7-vulnerability-bank-hack...
https://blog.lastpass.com/2017/05/announcing-cloud-backup-fo...
I would still say it's not recommend to backup those keys in the cloud, and I hope LastPass at least has the common sense not to keep those keys on the same server as the LastPass passwords. However, a middle ground may be backing up the keys before you change/reset your phone, and then disabling the feature (I'm not sure if they actually wipe or reset those keys every time you disable the backup feature, though, but I hope they do that).
Authy can be used just as a SMS-based 2fa, and this is as insecure as Google SMS. Note that this is still more secure than you (or me) implementing you own code via sms, because they do intelligence on the phone numbers, especially on critical operations like changing phone/merging accounts.
Then there's Authy app with the TOTP code, similar to Google Authenticator. From a security perspective it is true that having Authy on multiple devices slightly decreases your security, as an attacker could steal any device and bypass your 2fa.
I'm not convinced when people say that they can turn off Authy with just a phone verification (i.e. stealing the phone number), vs you can't on Google Authenticator. The fact that you have Google Authenticator, maybe even as a default, doesn't mean you don't have SMS too as an option, so the same attack can happen on Google.
Also, note that for many critical operations, in Authy and Google, you receive a notification. In particular, if you have many devices connected, you'll receive multiple notifications with an higher probability of catching the issue on time.
It would be nice to see explicit examples of the attacks mentioned. If you have someone's password and phone number [], you have a lot, and you can probably fool Google, Facebook, or any big as you can fool Authy.
let's also remember that 2fa is the 2nd factor. Your first factor, the password, should be strong as well.
Facebook calls these "code generator applications" and maybe that term will catch on.
Even if you forget about sms, sms is still available to get a code and bypass 2fa.
Authy itself, if you have the app, never sends you sms but push notification.
I'm not sure duo is relevant in this discussion, no consumer app that i know/i'm aware of uses duo.
Used that way --- the default way --- you can't bypass it with SMS.
Responses were like GA is better because there's no SMS. This is true if you look at GA vs Authy mobile apps.
This is false, if you look at the consumer services where you enabled 2fa (Google, Facebook, Twitter, Instagram, Coinbase, Twitch...). They all require SMS to setup 2fa, and let you use SMS to bypass GA.
You can not bypass GA with an SMS (the TOTP), you can bypass the service 2fa, because for availability reasons they must provide you more than a single 2fa method.
https://www.authy.com/phones/change/
It says they may perform "additional security checks" in the help but what are they? The wooliness of this makes me very nervous. (I don't use Authy fwiw)
Account recovery and 2 factor auth is always that week link. If you don't want to get hacked in this unsophisticated way just because someone is targeting you - then just remember your password the old fashioned way and close all the other doors. even postit notes are more secure because they are not remotely exploitable.
So if one can obtain the phone number (which can often be found publicly) and though social engineering have the carrier route the number to a new device, just from the phone alone one can break into gmail and thus also coinbase.
it is not 2FA ..more like 0 factor authentication because all you need is a phone number and the ability to impersonate the account holder
That is really bad
The social engineering only gives you access to receive SMS. It does not give access to a complete backup or gmail's password.
How do I do this for my cell provider (T-Mobile USA)?
Jokes on them, my number is ported to google voice, and they don't have customer service...
>Free VZQ Msg: You're on the phone with Verizon and just authenticated with an alternative method. Not you? Please call us at 800-922-0204 immediately.
And one of CB's followup recommendations is:
>Make urgent text alerts actionable through SMS. If I received the original alert and was able to text a reply stopping it, or even delaying it, this entire hack would have stopped in its tracks. Instead I was told to ‘immediately’ call a number for Verizon that no one was there to answer.
It seems inevitable that the Verizon SMS alert as a bonafide safety check would embolden social engineers to use that very same method to trick people into calling their own 800-555-2222. Then, a fake Verizon customer service agent "phishes" for even more sensitive identification data by asking official-sounding questions in the guise of "verifying the account".
The tone of that Verizon SMS is panic-inducing and it's very easy for people to not realize they need to verify that the 800-922-0204 is actually a legitimate Verizon phone#. Even if non-techies take the extra step of googling "800-922-0204", they may get conflicting information and get confused on whether it's safe to call back: e.g. http://stopthecap.com/2015/10/05/got-a-call-from-1-800-922-0...
EDIT ADD: I think it's very challenging to come up with a generalized decision tree for non-techies (e.g. your 75-year old grandmother) to follow such that they know they are "really really REALLY talking to Verizon".
If the techie-grandson thinks they can simply the decision matrix by instructing his grandmother to simply get a hold of him when she receives such an alert, then in the 15 minutes plus it takes the grandson to research the legitimacy of the SMS, the grandmother's life savings in the bank account is drained. In that scenario, the alert was legitimate. The extra delay introduced by the grandson made the situation worse.
In substituting in-person transactions that require biometric verification (e.g. thumbprint at the bank counter) with non-physical "information verifying other information over information channels to unlock access", it creates new vectors of social engineering attacks. It's a very hard safety problem to solve for the mass population.
[1] https://cdn-images-1.medium.com/max/800/1*TJo_9dnPNqJC0eecYp...
As long as that's secure, I think that's the solution to knowing who you are talking to.
Bitcoin has some interesting properties, but holding bitcoins directly is definitely not right for anyone who can't be trusted to keep their critical credentials secure no matter what.
I don’t think so. I had this kind of incident and nobody from bank noticed it (60 euro paid over night 3:35 AM from central europe to fake company somwhere in tax paradise, summer 2014). If i asked why and how it was possible, they replied with formal letter how much sorry they are. Nothing more.
I was in touch with ViSA guys and they confirmed payment as fraud and returned my money back to me.
Around 10 years ago i was in national bank. We had small project for entrance gateway automation. Control unit was strange DIY solution.
Banks aren’t so secure as we think. At least in my country.
I worked for big oil company and even their infrastructure and solutions are far from ideal. So i don’t have false expectations about security.
>"Call your cell phone provider and put a “do not port under any circumstances” hold on your phone number.
Is "porting" the same as call forwarding (which I assume would also forward SMS) ? Or is porting a means to upgrading to a new phone or changing carriers while keeping your phone number ? The latter isn't something I want to disable.
Mobile phone carriers are permitting phone numbers to be ported to a new phone held by a thief with nothing more than a billing address. The idea behind adding that "don't port under any circumstance" message is to force an in-store visit with some type of legal identification before a phone number is ported to a new device.
If you don't use SMS to secure your bank account, then maybe this advice is overkill. But if you are using a service that holds a large part of your assets and can only 2FA with SMS, then you really ought to make taking over your mobile phone number as hard as possible.
I asked someone with no prior Bitcoin experience to test a checkout process with Bitpay[1], and the 3rd[2] time they had to pull out their phone they were really frustrated at all the steps. Plus, doing that many on-chain transactions is going to add a 30% overhead to a common purchase.
Am I wrong to advise users interested in single <$100 transactions to skip all the apps and use their exchange's wallet? I hear a lot of people recommending that everyone operate their own wallet. But since this page is in Bitpay's checkout funnel the wallet must be very important.
[1] The "How do I pay this?" on a Bitpay invoice links to this: https://bitpay.com/pay-with-bitcoin
[2] Once to install the wallet app; once for Coinbase to set up 2FA; once to set up 2FA for the wallet app
2. 2fa makes people think they're safe, when they're often not. (ss7 is weak thus sms, etc)
3. There's not really a "secure" email account. The admin can read your mail. There's not really a "secure" phone number. The admin can use your number.
4. This seems ok, if your phone isn't pwned.
5. If you don't hold the keys, you don't own the coins. DO YOUR OWN COLD STORAGE.
TOTP and U2F ("Authenticator" and Yubikeys) have a great track record.
Just keep your mouth shut where you store your values and you're most likely less a target these days.
Also, avoid 2FA based on SMS like hell. This method has been broken multiple times in Germany where SS7 (the GSM signaling system) was involved.
When signing in from an unknown location, the app pops up and says "are you trying to sign in?" Just click yes.
[0] https://krebsonsecurity.com/2016/01/guy-who-tried-to-frame-m...
How do I do this for AT&T?
Even if you don't use SMS as a second factor, unless you regularly switch carriers, there's no downside to doing this.
HOTP and TOTP are IETF standards and any compatible app should work. Android Token works great and is 67kb in size.
Last time i tried to use Google authenticator it phoned home supposedly connecting my mobile IP address to my DSL IP adress thus making me less secure
Perhaps there should be a service able to reboot your computer remotely and scan any hardware device, bios configuration, iptables, init programs and much more, applying machine learning or other tools to detect hidden agents waiting to attack.
Fred Wilson's post discussed how he was hacked, how he knew he was hacked, and what actions should be taken to avoid being hacked.
FWIW, not a downvoter.
+ How easy is it to see all the processes running on your machine?
+ Is it easy for you to limit the permissions of your browser?
+ Is it easy to monitor weird network activity?
+ Do you have some idea about the security standards of the software you use? This does not say that it needs to be open source, there might be other ways.
+ Do you have the right setup to receive security updates.
+ Do you restrict yourself to non-mainstream software to reduce the chance to be a target?
+ Do you consider read-only media at the time you do your banking?
There is a lot you can do without opening up your computer to a remote scan.