Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.
Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.
Err. That's pretty much every implementation of 2FA around the world.
Why isn't this more well known ?
Guess what the send you when you forget your 2FA or password? Yep, an SMS. So out the door goes the whole point of 2FA. Your three factors (account name / email address + password + Google Authenticator) have now been reduced to one factor: your email address.
I can rent a mobile tower in Malaysia or some other asian country, advertise your phonenumber as roaming there for about €10/h and start intercepting all your shit. Or just get your telco's inept service dept to forward your number somewhere else.
Lessons here:
1. Even the giants get it wrong. 2. There is no security anywhere in the tech world. Literally everything is broken. Your electronic car locks / starter system, your phone, your internet, everything is horribly horribly horribly broken beyond any imagining, even for hyper-tech savvy people. 3. Remove your phonenumber as a backup device from your google account and never use it as a backup device every again.
Edit: Oh, you said that.
Since the problem is that hijacking numbers is easy, shouldn't that apply to “anyone who relies on telephone numbers”, not just “anyone who relies on SMS”?
SMS isn't the only telephobe-number-based second-factor.
When it came out. If you wanted to "borrow" someone's phone number. All you had to do was clone the MAC address of the VoIP (EMTA) port
If someone called the number. Both you and the victims phones would ring
Things got a bit different with MDN and MIN were different to ESN pair. Calls still came but you couldn't auth or call out for data services.
It's all a bit old now, but look up QPST, QXDM for the past decade and 20 years ago look up Oki900.
Unfortunately I don't really remember the details, since I worked on the core data network at the time.