Can We Stop Pretending SMS Is Secure Now?
krebsonsecurity.com
krebsonsecurity.com
Twitter for example let's you sign up without a number but it then suddenly detects "suspicious activity" and demands your number. Many other sites enforce it or heavily nag you in the name of security.
I’ve been trying to get Google to stop giving out my birthday for years when I had to enter it for wallet or something. I get birthdays on my calendar from people I emailed once and never knew, or wanted to know their birthday.
Similarly, my contacts have gotten peoples phone numbers changed based on changes made in various subsystems that overwrote the number that I manually entered.
With online ancestry sites (birth place, mother's maiden name, first name of paternal grandfather), Facebook and Classmates.com (high school mascot, pet's name) and so on it feels like anything "real" could be compromised. Or give somebody enough ammunition to pretend to be me.
I use fake answers but it means carefully logging the answers so I don't forget them.
1. https://unix.stackexchange.com/questions/26205/why-does-unix...
Funny how my best friend from high school is named yiKooPh2 (not a real value of course).
Similar dick-ish behaviour on Steam. I didn't have a 'profile to comment' on the comment section of a game (Saboteur 2 - Avenging Angel)(I cannot remember the room that gives you the 'god mode')
I went on to create a 'profile to comment'. When I proceeded to write the actual comment I was informed that 'I am not allowed to comment on this game' (I had already logged in with my Steam account. Those *** just wanted the extra info only to tell me what they knew (that I would not be allowed to comment anyway). I deleted said 'profile to comment' but now those *** will keep that info forever.
This is not related to SMS (I thought we established that even with someone with $50k -or less- to burn can read the SMS messages of their neighbours)(https://www.intercept.ws/catalog/interceptors/)
Spam is mostly prevalent because it's cheap and easy to throw millions of requests at the wall and see what sticks. If it did cost really any money at all it wouldn't be remotely worth it.
To require the attacker to know your phone number and do costly and/or time consuming things to get access to it means moving from "script kiddie re-using username+password from leaked user databases" to "targeted attacks".
Sure, it's not Safe(tm), but it's a big step up from just username+password.
That leaves us with physical keys, which the average consumer probably doesn't want to carry around all the time (easy enough to keep on keychain, but most people don't carry keys around their own home).
Disclaimer: I’m very far from a cybersecurity expert.
1. Consumers are terrible at security. Asking them to subscribe to a password management/MFA tool is likely to fail. If this were baked into iOS/Android, this would be better.
2. Many banks don't support this MFA scheme. A quick poke around 2fa.directory shows a massive number that don't support MFA at all, and another huge bunch that do SMS/email but not software/hardware. This puts consumers in the position of juggling multiple MFA schemes to access various sites.
I don't disagree with you in principle. But until there's a more standard approach to MFA, people will continue to use SMS because it's easy and broadly available as an MFA scheme.
Most places that offer 2FA auth apps also offer backup codes, which can be stored in any password manager, or offline in a little black book.
No, since you can back up the seed in a secure location.
username+password+sms = username+sms (no password)
But I agree, and would take it a step further:
username+password+sms = username+sms || username+password
And in the worst scenarios:
username+password+sms = sms || username+password
And the same goes for email instead of SMS as well, in most scenarios.
Adding SMS seems to add new points of attack that either hurt the user or just delays the hurting.
I feel like much of what's wrong with SMS 2FA comes down to a misguided idea of "everyone has exactly one phone number", which is simply not true for a lot of people.
As someone else pointed out: that's not true if the SMS authentication can be used to recover the password. But let's for the sake of discussion rule those cases out.
Then yes, SMS verification does perhaps add a tiny bit of "security" to the process for the reason you describe. But that tiny bit of security has to be weighed against the enormous extra burden placed on the users performing the (far more plentiful) legitimate logins. Than burden may well be worth it if a lot of extra security is gained. I think it's definitely not for the "security" provided by SMS.
These accounts are only worth anything as long as they’re cheaper and easier to use than stolen credit cards.
No, it is unfortunately actually much worse.
If the account only has name+password and you use a properly good password, nobody will ever guess it (within the lifetime of the universe and all that).
But if the account also has a phone number and the attacker can trigger an SMS challenge to reset the password, now your wonderfully complex password is meaningless. The attackers just intercepts the SMS and done, they own the account.
It is equivalent to the problem of allowing "security questions" with trivially discoverable answers. A site may enforce 20+ character passwords (great!) but then forces user to enter the name of their best friend in high school (trivially findable in e.g. facebook for most people) and lets any attacker bypass the password with just the so-called security questions, rendering the strong password meaningless.
Also, did you know (tm) that other 2FA mechanisms such as OATH or Fido/fido2 don’t involve stuff arriving anywhere, other than the actual 2fa code? You generate it locally and then type it when promoted by the remote application.
If you need 2FA, you have a computer with a suitable internet connection. If you can’t use non-SMS 2FA it’s likely you also actually have no use for it.
I rather have a unique password then rely on SMS anything especially if that account allows you to reset your password by SMS.
sms is also on the same security level with email, fax or a signed letter but way more convenient
No, it's really not. Email can be cryptographically signed, SMS can not.
And some 2FA are actually less demanding wrt. information delivery then SMS.
Also often less accessible, in the circumstances where those SMS challenges show up most often (traveling, for instance).
Can anyone please confirm that in a country that does not allow porting numbers without a code being sent to said number, and does not allow interceptions of the type described in the article, that using SMS for MFA is, in fact, secure?
Nope.
Nobody's going to be able to give you this reassurance, or least they shouldn't, because it isn't true.
It may not even be better than nothing. For example you get email that says your bank has detected large withdrawals from your account and to fill out a web form if you want them to block these withdrawals. The site linked from the email looks reassuringly authentic, and you get a SMS as you expected during the login process. Genuine right? Nope, you've just been phished and you've helped your attackers by giving your real SMS code to their phishing site.
Maybe if there hadn't been the seemingly genuine SMS message you'd have slowed down and realised that the bank's name isn't spelled "Furst Springfield Bonk" or that it wasn't previously hosted on a $1 per month bulk hosting site under a directory named "/wordpress/cgi-bin/cgi-bin/cgi-bin". Maybe not. Either way the SMS didn't help you.
Also, in most countries with any sort of number portability a minimum wage employee at a phone store is authorised to override this (after all they just checked your photo ID right? Or at least they clicked a box labelled "Check photo ID") and issue sims with your number activated to... well, they're authorised to give them to you, but they can give them to the hot guy who paid for shots for them and all their friends last night. It's only a part-time job, worst case if the boss finds out they get fired. So don't tell the boss.
There are plenty of problems. You should not be relying on SMS for multi-factor authentication in 2021. If you still are, make your way calmly towards the exits, find a solution that actually works.
They could also ask you to enter the code from your hardware token, and accept whatever code you type. Phishing is a different story, not really related to SMS.
> Also, in most countries with any sort of number portability a minimum wage employee at a phone store is authorised to override this
I don't know about other countries, but here in Israel when you port to a different network a code gets sent to the number you're porting, which you need to provide to the new network.
Where there might be an issue is if you claim to have lost your SIM card. This happened to my wife recently - they did give her a new one in the store, but I instantly got an email telling me about it, so it's not so easy to do that undetected.
To the extent there's a "code from my hardware token" it's some blob of data processed by the web browser and there's no way for a normal user to get it let alone enter it into a phishing site for whatever good that would do.
If you're going to bother overhauling your authentication strategy you need to actually counter real threats like phishing. WebAuthn does that. Deploy WebAuthn.
You never own your phone number, yet services enforce it as single point of failure into your security concept.
There really is nothing sane about this at all.
This particular issue might be US-specific, but the fundamental security problems of SMS are not US-exclusive
Further, You can detect SS7 attacks. Major Banks already has measures in place...
Any network in existence that has roaming enabled is vulnerable to fake roaming requests, and they cannot be "firewalled."
Seeing you implying that CDMA is somehow more resistant than GSM means you know very little how cell networks work. The telephony layer for both is SS7.
The Telecoms do prevent it with Firewalls.
As for CDMA, Please see,
https://www.wyden.senate.gov/imo/media/doc/Verizon%20SS7%20L...
I so far never heard of anything like this.
Banks can see. There are lot of APIs on the web that provides this capability.
One example,
How many operators in the world sell them this access?
Please try attacking this Firewall.
CDMA carriers don't use SS7 for SMS unless you're on Roaming.
That's too much of a simplification. At an absolute level, true.
But security is relative and needs to be measured with the threat models you care about.
Intercepting an email from your bank (let's say) to your email server (whoever provides it) is in practice exceedingly difficult, requires the attacker is in control of a transit point between them.
Intercepting SMS, as described in the article, is trivial and can be done by just about anyone who cares to go for it.
Letterheads for identity assurance were very much part of the security theatre of their day.
In the case of domain transfers it might have really not been about security at all. Given the other dark patterns associated with that business I'd not be surprised if the requirement existed purely as a soft lock-in measure, to create friction to make transferring out more of a hassle.
The actual source is a Vice article, the author of which contracted a hacker to actually run an op on them as part of the investigation. However, submitting that directly would have simply attracted a bunch of really great political commentary instead of a discussion on SMS.
Involving SMS in the authentication process raises the bar significantly for script kiddie attacks using password databases. It also forces a larger and more detailed forensic trail for any attack.
If the FCC would require mobile providers to add crypto features to SMS that prevent spoofing, would it not be possible to do so?
You can potentially BGP hijack a domain (via DNS) and e-mail (via SMTP) as a private individual so easily. Image a nation-state. These protocols only have bandaids like DNSSEC and RPKI stopping you from doing it, which both have painfully small adoption and don't realistically stop a determined attacker.
This could happen at anytime by an individual with the motivation, and it only needs to be successful for a few minutes to gain access to a huge amount of private data.
This has to be a huge national security risk, right? Why do we not take it seriously?
No you can't.
Well various attacks exist against ip routing, dns, email forging etc,in practice they are really hard to pull off as an individual who isn't in a privileged network position (with possible exception of email forging. That one is a bit easier depending on stuff)
> You can potentially BGP hijack a domain (via DNS)
I think you might be confusing stuff here. Unless you bgp hijack the nameserver, but if you have that ability, why not go after the site directly?
Using this, you can advertise any IP prefix you want. Since a lot of providers advertise /23+ as well, if you hijack the /24, you will always be the BGP best path and will be able to accomplish a full internet-wide hijack.
Of course, the task requires a few weeks of planning and execution, but that doesn't stop it from being possible.
If you are a nation-state, you already have all of the above, and nobody to hold you accountable for using it.
Few weeks? With most providers you can get this done within 24h from the initial email to sales@
I’ve never had to deal with colo or think about hardware to have my IPs announce.
Shorter ASPath, planning which Tier 1/2 is the best to hijack from, and lack of LOA requirement or RPKI.
If an attacker wants to do this - they don't want to "just" cause damage. This is a limited opportunity. They want to do it right, and that takes planning.
I do agree that your idea is possible, but I don't think it captures the full severity of the issue.
Yes you can
> they are really hard to pull off as an individual who isn't in a privileged network position
“privileged network position”, as in someone with a couple of thousand dollars to spend.
The lion share of mailers don't check even them.
domains and BGP don't really interact, can you explain what you mean?
At this point you can give any answers you like for such queries.
If the domain has DNSSEC, you either have to choose answers you've seen that may be misleading (e.g. old but still not expired answers) or some resolvers might notice your answers are bogus.
Many domains today don't have DNSSEC, so, you could give any answer and it will be indistinguishable from an answer by the legitimate authoritative DNS servers. Nobody would know any different.
Now that you can cause traffic to go wherever you want, you can easily satisfy most of the Ten Blessed Methods and get yourself certificates in the Web PKI ("SSL Certificates") or whatever else you needed to achieve.
In the distant future sometimes it may be possible that a recursive is able to assure itself that the answer is genuine via DPRIVE [DNS over HTTPS, or TLS, or QUIC or whatever else is invented] instead but in practice most of the routes by which we could get genuine answers ultimately rely on DNSSEC (DPRIVE is still doing something useful for you - privacy benefits, particularly oblivious transfer could mean you get trustworthy answers with a promise that your honest broker doesn't know what you asked, and the authoritative servers know what was asked but not who asked it)
What do you suppose you can do to give that effect?
In the US SMS case LOAs work because it's in the interests of the people who can make it happen to make it happen. The LOA is just to cover their backsides, "Why did you redirect this Michigan man's SMS messages and thereby enable his life savings to be stolen?" "Oh we had this Letter of Authorization, so we honestly believed it's what he wanted". They don't believe that, but their lawyers are confident that it's enough excuse that, at least until after somebody powerful is inconvenienced, it will hold up.
But nobody benefits from helping you give effect to your (convincing but bogus) LOA for my email. My ISP doesn't want anything to do with this work, if you're lucky they'll tell you that it's none of their business - more likely it just goes in the round file and you never hear back from them.
There is no central clearing house for email that you can give a few bucks to for my emails so long as you have an LOA to keep them on the right side of the law. Instead for email everybody involved is getting paid by me, not by you, so they've got no reason to help you at all.
To any ISP as I ask them to announce your MX IP addresses.
> There is no central clearing house for email that you can give a few bucks to for my emails so long as you have an LOA to keep them on the right side of the law.
There is, it’s called BGP.
Sure, TOPT would be far better, but reading this article I'm more concerned with how easy it is to get access to someone's SMS/VoiceMail than anything else.
i guess the pandemic has left us with little choice but meeting in person is still the only way to have a private conversation and i guess this won't change in the near future given the state of society.
Upstream agreements already block Mobile carriers.
Further, SMS from Short Codes are blocked by default. You can only receive SMS from long-numbers. Eg Wicker ..
I'm confused, didn't the article say "A few minutes after they entered my T-Mobile number into Sakari, Lucky225 started receiving text messages that were meant for me"? T-Mobile is a normal cellular carrier here isn't it? What part of it required a VOIP line?
P.S. You can edit your old comments instead of leaving 4 different ones in the same thread.
EDIT: Looking at this 5-day-old user's history, I think it's safe to say we shouldn't take the comments at face value:
https://news.ycombinator.com/item?id=26455000
I'm hoping he lied and T-Mobile SMS can't just be redirected.
Update: So his allegation is there is no reporter supposedly and it's a paid article.
I want to know who is right wealthyyy or Lucky225
Well what. It's obvious who you are. You are Lucky...
Account age is biased way to trust an individual. I could have bought an old HN account from someone but I didn't.
I have known about this attack since 2012, but I did not publicly talk about how insecure SMS is for promoting an anti-fraud product.
Note, this is just the tip of the iceberg. There are other attack vectors that only I know!
I don't care whether you believe me or not. This is a fake news at it's best.
Regarding my comments,
[1] That lady is self marketing guru. It's confirmed everywhere even Reddit.
[2] Modern C++ is simpler than TypeScript, Go, Rust. Modern C++ become more like Python.
https://preshing.com/20141202/cpp-has-become-more-pythonic/
https://web.archive.org/web/20131015192353/http://cpp-next.c...
[3] The comment about Christ is a Joke. Can't I make Jokes on HN?
I've built a very similar product to ZipWhip. These restrictions are likely enforced by ZipWhip, there is nothing structural at the NetNumber or other level that technically prevents you from taking over SMS message routing or receiving messages from short codes on mobile numbers. Submit the SPID change to NetNumber and you're off and running!
The secujrity
It is worth noting that the mobile carriers will periodically "reset" these changes to fix the routing (T-Mobile is one of the more aggressive ones here) and that continued violations by MVNOs like Sakari would eventually result in a loss of access for them.
In Sakari's case, they were doing no due diligence or much to prevent the fraud. My own company's workflow for landlines placed a telephone call to the customer's number to give them a code to use in the registration process (remember, the attack noted in the article doesn't port the number, it just reroutes SMS). For toll-free numbers, we required legal documentation to prove that you owned the number. We also didn't allow any mobile numbers to be registered at any time.
The ability to hijack text messages through an online service was also shown in an article Krebs' source mentioned [2].
Perhaps you're right that upstream agreements with mobile carriers should already be blocked, but in practice it's been proven not to be.
There was a change to NetNumber's systems on 11 March to combat this, but there's no guarantee that their competitors don't have similar flaws or that the measures taken were good enough to stop the attack in practice.
Even still, if the problem might be fixed in the entire US, that doesn't mean anything for the rest of the world.
[1]: https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
[2]: https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
NetNumber has no competitors. It's a routing database.
The Vice article is a paid piece. This attack doesn't work with any of US Mobile carriers.
A lot of people confirmed this as FUD.