PayPal and Venmo are still letting SIM swappers hijack accounts
vice.com
vice.com
https://debtfreegeek.org/2017/09/22/become-usaa-member-even-...
https://www.usaa.com/inet/wc/investments-update?akredirect=t...
* I just tried to login with the first 8 characters of my password and it was not successful. * Also this password is autogenerated and contains plenty of special characters. * Their 2FA system no longer depends on the concatenation of password + token.
Also this reminds me of another HN discussion[1], which basically boiled down to the question of "Do you really think the only thing the bank does to log people on is to check the username and password?" I certainly hope not.
Put a few hundred thousand in the bank and you'll get all that stuff for free!
They use normal TOTP for 2FA so it'll work with whatever authentication software you use.
However they follow the modern tech trend of not having live tech support; you have to email them for support. But I've heard response times have gotten better recently.
I moved most of my money into RH for the interest, but still maintain Chase checking and credit card accounts. For sonething as important as banking, there's no substitute to having tons of physical locations with humans. For example I recently went to the bank to deposit tax refunds, which were not 'normal' checks. I don't think you can even deposit normal checks into RH. And I trust Chase's fraud protection systems more than RH.
Fidelity has a brokerage account, free checks, free ATM withdrawals via debit card, maybe also your 401k, free money wires, automatic investment etc.
The only thing they don't have are branches where you can deposit cash, but that's really never necessary - in an extreme case you can open another bank account, deposit cash, transfer to fidelity and immediately close it.
I'm not sure why anyone uses a bank other than Fidelity.
Looking at that link, pretty much none of the major US banks (Bank of America, US Bank, Wells Fargo, PNC, Chase, etc.) seem to support software 2FA token solutions (e.g., Google Authenticator, Authy, etc.). Not gonna lie, this is abysmal.
For credit cards with awful security, they don't care because the money they get from making it easy to sign up and use their services is far, far greater than the costs of dealing with fraud.
How accurate is this hypothesis of mine? It really can't be an education thing because I'm sure these companies have great engineers working there, both at the lower ranks and (at least sometimes) in upper management.
I'm so glad I'm out of the family tech support "business"; if only firing real customers were so easy...
Alternatively, use a physical token as the 2nd factor, then no recovery number is required.
T-Mobile sells me out once a year - I don't even give them my real name, they must get it from my credit card or something. This year I used a fake name "authorized user" card, still waiting to see if that keeps my latest number out of the databases or not, around nine months to go.
My T-Mobile number was simjacked last year, though afterwards once I reclaimed my number they let me set up a "secret word" that the person calling in has to give them and I haven't had any problems since.
It's disgusting to think about the record sharing, and I doubt it even protects against SIM swapping (or does it?).
We need to enforce tech companies to have proper customer support. We need to make a regulation that enables users to appeal or sue tech companies decision about their account. No more 'fix through hacker news submission or reply' please.
If they had zero other expenses and just ran the offices, they wouldn’t even be able to hire one worker for each store....
This kind of behavior is caused by rules that put the cost of fraud on the payment processor rather than the customer, even though the payment processor's primary tools to prevent it basically involve locking the customer's account based on vague suspicion and hearsay.
When someone has stolen your identity, there isn't really anything you can tell someone to prove you're you. Having your password or SSN or access to your email or the answers to your security questions tell them nothing. The perpetrator could have those things. Your account may have been created by the perpetrator to begin with and the person whose name is on it has never even used their service. How are they supposed to tell? Even if you're you, the perpetrator may still have access to whatever method was used to access your account to begin with and if they turned it back on there would be more fraud (which causes the payment processor to lose money instead of you). So your account is locked forever and you can pound sand.
The alternative to people getting locked out of their accounts is having accounts without reversible transactions. You don't want this for your brokerage account, but you do want it for the account you're using to buy things with petty cash. Because then the account never has more than $1000 in it to begin with, which limits your losses to that amount, but then the payment processor doesn't have any incentive to ban your account because the losses are yours. If you're careless and reuse passwords, you might lose the $1000, but you don't get banned forever from making financial transactions. Then you learn your lesson and do better next time.
That would also result in lower transaction fees, because most of the transaction fees go to paying the cost of fraud protection. And it would reintroduce the incentive to prevent fraud to the people best situated to do that (stop reusing passwords, people), so there would also be less fraud, which is better for everybody.
Granted it's obviously bullshit if they try to keep the money when your account had a positive balance.
The system they use actually works pretty well. They have a list of registered voters and when you vote they cross your name off the list. You have no way of knowing who has already voted, so if you give someone else's name you risk their name already being crossed off, and then you may be in for some questioning.
If you want to do something that would actually impact the election results (i.e. vote thousands of times and not just twice) then you would also have to come back in over and over using different names, which creates the obvious potential for the poll workers to recognize you. Avoiding that would require some kind of large conspiracy so that each person doesn't reappear enough times to be recognized or use the same names as one another, which then makes it much more likely that you're caught because one of your co-conspirators turns you in.
So the risk of getting caught is pretty high even without ID, especially if you're doing it with enough scale to really matter. Meanwhile the penalty is typically something like a year in prison per offense, which is a pretty high price to pay for one extra vote.
Some states do require identification, but it's up to each state decide what is required. See: https://en.wikipedia.org/wiki/Voter_ID_laws_in_the_United_St...
The first reason is that those IDs would then become massive theft targets. Because they're uniform, it provides economies of scale for criminals to figure out how to extract the private key from the ID, then pickpocket IDs and extract the private keys from them (or worse, figure out how to do it from across the room when it's in your pocket) and then we're back to square one.
Associating public keys with names, which is in general completely unnecessary (the key itself is the identity), also becomes a separate centralized single point of failure. Anyone who compromised that system could associate their own public keys with your name, and the more centralized the system is the more powerful the likely attacks against it would be because compromising it then has a higher payout.
A large centralized system like that is also inherently slow to change, which would result in a catastrophic failure if a vulnerability was ever discovered in the cryptosystem it uses or its implementation, because not only would every system relying on that system become simultaneously vulnerable, they would all have to be updated, which for a large bureaucratic system could take months or years. In the meantime you're forced to choose between continuing to operate the vulnerable system and being subject to an unlimited amount fraud, or shutting it down and having systems across the country offline for a lengthy period of time while everyone reimplements their interfaces with it.
A universal public key is also itself a huge privacy vulnerability. We already have this problem with social security numbers, which were never intended to be used outside of social security but have already entered use as a means to correlate surveillance data about a person. But social security numbers at least are considered sensitive data because they're used as shared secrets. A public key authenticates by use of the associated private key, so knowing the public key doesn't impair its security properties which would almost certainly lead to relaxed security requirements for their disclosure, and thereby further enable problematic public and private mass surveillance by using the public key as a universal database index.
The far better solution is to use public key cryptography, but have a separate keypair for each relationship. So you have a bank card and it has your private key associated with your bank account, which allows you to authenticate to your bank. Your employee ID allows you to authenticate to your employer. But then nobody can steal money from your bank account with your employee ID or break into your office with your bank card. And a general compromise of the security used by the DMV doesn't allow criminals to break into power plants and airports and banks and police stations, because they're not all using the same system. This vastly reduces the scope of compromise.
I never said the private key would be embedded inside the ID. In fact, I would think a paper copy at home would be most appropriate.
> Associating public keys with names
DMV, Passports, Banks, RealID already get our fingerprints. In fact, these could be SALT to the private key kept separate.
I hear your argument about centralization, but that genie is already out of the bottle. Making it better is a good idea, no? Also, if any vulnerability occurs, I can go back to DMV and register a new PP pair.
Still, I do like your idea of having PP pairs beyond just centralized entities.. start using them everywhere you have an account.
As soon as such a thing existed, people would want to start using it for everything, and nobody is going to want to do cryptography with pen and paper. It would end up in a card or device people would carry on their person so they could use it and then it would be a huge theft target.
> DMV, Passports, Banks, RealID already get our fingerprints.
It's the same problem, you'd have a central database mapping public keys to fingerprints and then it's a single point of failure/compromise. The attacker could get your fingerprints from the DMV, associate their public key with them and then start impersonating you using two factor authentication because they have your fingerprints and the corresponding private key to the public key the DMV has on record for you.
Let each entity maintain the mapping themselves. Your employer has a computer that says the ID badge with public key 1234 is yours. You don't need the DMV to do anything there, and then nobody can cross-correlate anything and if anybody breaks it they only compromise one system.
> I hear your argument about centralization, but that genie is already out of the bottle. Making it better is a good idea, no?
Getting rid of it is a better idea. Or start by making the centralized system worse and more restrictive so people use it for fewer things and replace existing uses with decentralized alternatives, and then get rid of it.
> Also, if any vulnerability occurs, I can go back to DMV and register a new PP pair.
They stole all your money, broke into your company and stole the trade secrets, filed separate fraudulent claims against your home, life, car and medical insurance policies, took out a second mortgage on your house, sold the title to your car and gained access to your computer where they found some information they're now using to blackmail you.
You can go to the DMV and change your public key, but that's closing the barn door after the horse has bolted. Better that only one of those things happen than all of them, no?
> The easiest way to make it impossible for SIM swappers to take over your accounts after they hijack your number is to unlink your phone number with those accounts, and use a VoIP number—such as Google Voice, Skype, or another—instead.
They don't mention that some carriers offer the ability to secure your account against unauthorized transfers, but it's opt-in. Here's how you can do it on Verizon:
Forcing spammers to have a non-voip number raises their costs, sometimes significantly, reducing their ROI and their interest in spamming our users.
We tried to make exceptions where we could, but it does suck for real people using voip numbers for whatever reasons.
As long as you aren't using SMS as your rate limiting step to aquire an account then then it doesn't matter if someone has 1 phone number or 1000 numbers. In the case that SMS verification is the rate limiting step, why not switch to an open captcha or similir system?
My point being that if he’s doing it right, he’s probably spending more time and money than it’s worth, and if he’s not, he’s banning legit users for the crime of not having a big-4 provider.
I have a smaller lesser known telephone operator friendly to a more advanced users, and my SIM-bound mobile phone number is rejected by big services like Google.
Not that I care anymore, I'll certainly not go to great lengths to use services which start their onboarding by blocking my number and forcing me to use big telco's services or some shady website.
It's possible that services more centered around VOIP vs an automation plateform might work. It's also possible that using a foreign VOIP number might work but that also might also cause issue if you try using it with a US bank.
And I'd rather not have some half baked solution using Google Voice.
If anyone knows how to get an shortcode enable number (not a short code number but rather a number that can recieve SMS from shortcodes) on Twilio or similar platform, it would be very easy to set up an SMS 2 EMAIL gateway. Perhaps if a number is ported to Twilio it will retain shortcode capabilities?
Besides finding a solution to the above problem, I suppose I could just get a GSM usb modem & SIM card for this purpose.
you can use jmp.chat, which is a SMS to XMPP service.
I switched to a dual-SIM phone.
Plus the more people that give out Google numbers, the harder it will be for banks to push back on this.
Presumably, the PIN is supposed to be verified by the tech support advisor which can get social-engineered or bribed.
Maybe the solution is to actually have real technical support that is tech-savvy and paid a good wage instead of the monkeys we currently have?
A CS agent can continue without a customer providing a PIN. It is the case for AT&T, T-Mobile and Sprint. I do not have a personal experience with Verizon but someone I know who works selling phones at a major retailer says that all PINs are just flags that pop up a message on screen.
At the native company stores for AT&T a customer must authorize everything with a PIN in addition to the ID.
Venmo, on the other hand, I will never use because of this "feature".
[0] https://old.reddit.com/r/verizon/comments/eve25m/comment/fkq...
The Match Group dating sites like Plenty of Fish and OkCupid recently made it a hard requirement to setup a 2FA phone number, even for existing accounts.
It's a super annoying trajectory, and I imagine potentially dangerous if one considers the dating sites and victims of abusive relationships attempting to get out. Making physical access to the phone all one needs to gain access to a dating profile is a clear regression from unsaved passwords.
Personally I find using phone numbers for this purpose as a cop-out, and like you said it's just a Twilio account away from being defeated. Like captchas it's only a matter of time before that is the baseline capability for bots and you're in no better place than before, except now your users have worsened security.
IMHO the true business incentive for requiring numbers is just getting identity-coupled phone numbers which add significant value to their collection of PII.
There are risks all around, but this article doesn't offer any good solution that customers are likely to adopt in meaningful numbers. Maybe PayPal and other companies should require people to use secure 2FA, but they'd lose too much business.
The "old ways" are usefully slow, have protections built around them for centuries of our culture, and I'd rather the annoying administrative headache and "slow" over the quick abuse of account recovery systems for theft and fraud.
Ultimately we need some mechanism for trusting and administering identity that is low friction and which can be used by 99.9% of users. The government offering a `login with apple id` like service would make sense. Then they could qualify various security chips, like the T2 or a YubiKey for use with the service. As an added benefit, we could stop using stupid things like SSNs, tax ids, and drivers license id numbers to prove identity.
Eventually we could do interesting things like abstracting mailing addresses. Instead of mailing a package to my street address, send it instead to "me", and then I can authorize USPS, UPS, FedEx, or whoever requests it to look up my real address when they are sorting and delivering mail. When I move, I just update the _one_ database with my new address and I am done.
There are some obvious concerns with the government acting as a clearing house for identity. Perhaps the better option would be for private companies to be able to implement some sort of standard API, and limit the government's involvement to auditing these services.
The next big hurdles are getting support from e.g. banks, getting keys into peoples' hands, and getting people familiar with them. Those efforts are underway in the corporate world and I am optimistic that they will cross-pollinate well into personal security. HN-ers are well positioned to help with all of these steps.
People already accept that they should lock their front doors and their cars with keys. Most people already lug a keychain around. I don't think it will be steady-state problematic to convince people to secure their bank accounts and email with keys. Example: my parents. I expected it to be difficult to convince them that they should use a U2F key to secure their gmail. It wasn't. Their response was more along the lines "of course we should use keys, why weren't we doing this before?" They don't know anything about crypto, but they get the metaphor, and since it gives them a clear path to action, they are willing to engage with it. The answer to why we weren't doing it before is that the previous implementations were a PITA in a way that U2F isn't (TOTP was slow and fiddly, ISO7816 required non-portable setup), but now that we have U2F, I think people will be more willing than many here expect.
If we can channel the fear of SIM swaps into U2F adoption, I think it actually stands a chance.
This method is highly effective at reducing fraud at the cost of penalizing a minority of legitimate users who actually do have to use Google voice / etc.
It should be noted though that factors like why is this number being looked up are considered too, ie: OTP is less risky than say account creation at a bank.
So my instinctual habit of adding and then deleting my credit card details whenever I need to do a Paypal payment was correct, after all...
and the study here: https://news.ycombinator.com/item?id=22016212
Instructions: https://twitter.com/ramsey/status/1235227940054585344
My wife got SIM jacked just a few weeks ago and we got extremely lucky that it didn't turn into a bigger problem. They did get a hold of her Venmo account, but fortunately it's not actually linked to our bank account (Venmo restricts the # of users that can link to a single bank account).
This only protects you from the old way where a scammer tries to convince well intentioned phone support or retail employees.
I'd love to be able to opt in to having to provide a photo id at a physical location in order to complete the SIM swap.
Or maybe the carrier can try to call or text the number for some sort of confirmation process. In our case, we never even got a warning that the swap was going to occur. We found out after my relative's email account was compromised.
This issue alone is enough to make me want to switch carriers, but AFAIK, all of them do not provide robust protection measures for this issue. I've considered Google Fi, but it might have poor coverage where some of my relatives are.
Google Fi provides sim swap attack protection. To bind a Google Fi # to a phone, you need to be able to log into your Google account on that phone (from the Fi app). There is no other way to bind a Fi number to a phone (customer service doesn't even have the power to do this).
This means that whatever 2FA you have setup on your Google account is the same protection you get against sim swap attacks.
To be fair, this has not happened to me yet (with gmail) or anyone I personally know, but it remains a concern for me due to the high impact such an event could have on my life.
Is there any bulletproof way that a non-US citizen could get their account reinstated or at least recover associated accounts?
Even for US citizen's, there isn't a full-proof way to deal with account recovery. I'd say your account getting locked for incorrect reasons is pretty rare.
I think one important thing to know is that account-suspension stories you read on the internet aren't always legitimate cases. While, yes, getting publicity about an account lock can get it a second look, bad actors know this as well. Those who have done "bad" things will use this same approach to try to get their accounts unlocked. Google won't publicly comment on any individual case, so you are getting a one-sided story about why an account was locked, so be skeptical when you are reading them.
I use a virtual number for all such services that demand an idiotic SMS verification code. I won't state which one I use here, but there are several services you can choose from that provide virtual numbers.
It's been such a relief to stay in SE asia for sometime where PayPal isn't associated with all kinds of online shopping. I can actually order online AND be given the choice to either pay online OR in person in cash.
PayPal and it's crappy culture needs to die.