Upstream agreements already block Mobile carriers.
Further, SMS from Short Codes are blocked by default. You can only receive SMS from long-numbers. Eg Wicker ..
Upstream agreements already block Mobile carriers.
Further, SMS from Short Codes are blocked by default. You can only receive SMS from long-numbers. Eg Wicker ..
I'm confused, didn't the article say "A few minutes after they entered my T-Mobile number into Sakari, Lucky225 started receiving text messages that were meant for me"? T-Mobile is a normal cellular carrier here isn't it? What part of it required a VOIP line?
P.S. You can edit your old comments instead of leaving 4 different ones in the same thread.
EDIT: Looking at this 5-day-old user's history, I think it's safe to say we shouldn't take the comments at face value:
https://news.ycombinator.com/item?id=26455000
I'm hoping he lied and T-Mobile SMS can't just be redirected.
Update: So his allegation is there is no reporter supposedly and it's a paid article.
I want to know who is right wealthyyy or Lucky225
Well what. It's obvious who you are. You are Lucky...
Account age is biased way to trust an individual. I could have bought an old HN account from someone but I didn't.
I have known about this attack since 2012, but I did not publicly talk about how insecure SMS is for promoting an anti-fraud product.
Note, this is just the tip of the iceberg. There are other attack vectors that only I know!
I don't care whether you believe me or not. This is a fake news at it's best.
Regarding my comments,
[1] That lady is self marketing guru. It's confirmed everywhere even Reddit.
[2] Modern C++ is simpler than TypeScript, Go, Rust. Modern C++ become more like Python.
https://preshing.com/20141202/cpp-has-become-more-pythonic/
https://web.archive.org/web/20131015192353/http://cpp-next.c...
[3] The comment about Christ is a Joke. Can't I make Jokes on HN?
I've built a very similar product to ZipWhip. These restrictions are likely enforced by ZipWhip, there is nothing structural at the NetNumber or other level that technically prevents you from taking over SMS message routing or receiving messages from short codes on mobile numbers. Submit the SPID change to NetNumber and you're off and running!
The secujrity
It is worth noting that the mobile carriers will periodically "reset" these changes to fix the routing (T-Mobile is one of the more aggressive ones here) and that continued violations by MVNOs like Sakari would eventually result in a loss of access for them.
In Sakari's case, they were doing no due diligence or much to prevent the fraud. My own company's workflow for landlines placed a telephone call to the customer's number to give them a code to use in the registration process (remember, the attack noted in the article doesn't port the number, it just reroutes SMS). For toll-free numbers, we required legal documentation to prove that you owned the number. We also didn't allow any mobile numbers to be registered at any time.
The ability to hijack text messages through an online service was also shown in an article Krebs' source mentioned [2].
Perhaps you're right that upstream agreements with mobile carriers should already be blocked, but in practice it's been proven not to be.
There was a change to NetNumber's systems on 11 March to combat this, but there's no guarantee that their competitors don't have similar flaws or that the measures taken were good enough to stop the attack in practice.
Even still, if the problem might be fixed in the entire US, that doesn't mean anything for the rest of the world.
[1]: https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1...
[2]: https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
NetNumber has no competitors. It's a routing database.
The Vice article is a paid piece. This attack doesn't work with any of US Mobile carriers.
A lot of people confirmed this as FUD.