Turn your Android phone into SMS API gateway
github.com
github.com
In Norway, there is a thing called "BankID on mobile", which is used for 2FA by government services, along with any companies requiring authentication with person's ID. Examples: banking, insurance, health and vehicle registration: you initiate a log in using either your personal ID or a combo of phone number+birthdate, and you receive this interactive, full-screen flash SMS asking you to ensure that a certain word combo matches, and to confirm the action with your PIN. To be clear, the interactive part does not come with some app, but it's a feature built into most smartphones.
This thing drives me nuts when traveling: it is slow when abroad and costs money. What's worse, is that it only works with a physical SIM, so I can't easily use a local SIM abroad. There is an alternative way of authenticating using a code-generating unit, but it is not perfect - you can only have one of them at a time, they're really fragile and non-waterproof.
What I'd like would be to leave my SIM at home, preferable inside of a hardware SIP gateway from Aliexpress, and proxy those prompts through a Telegram bot.
iOS visuals have changed since 2012, but the process is the same in 2021: 1. full-screen message 2. another full-screen message with a numpad and buttons.
I'm surprised that this feature is not massively used to scam people. Is it because sending service SMS is restricted to certain parties?
A flash SMS is kinda like a regular SMS (I remember receving them already on my Nokia 3310), and uses the same protocol. However, it will appear directly on the screen of the user and won't be saved in the received messages. You could also send one yourself, if you can send AT messages to your cell modem :)
Some more technical info: http://web.archive.org/web/20080327112445/http://www.dreamfa... http://web.archive.org/web/20080325030443/http://www.dreamfa...
This probably won't work with a normal GSM modem though, since the flash SMS is not supposed to be stored in GSM memory.
But it may work with the Auron SMS Agent for Android since that one uses the incoming SMS intend and forward to the PC based on that.
With the SMS Server you can configure automatic forwarding from SMS to E-mail (SMTP) to receive your 2FA code through e-mail.
You can download the free 30 day trial version of the SMS Server to try it out. So you can be sure that it works before making a decision.
(Download link: https://www.auronsoftware.com/download/)
Here’s a post from 2020 on the differences within Android to handle flash SMS: https://github.com/moezbhatti/qksms/issues/1536#issuecomment...
Here’s an app, pre-4.3, for sending Flash SMS: https://github.com/romankh/gat-app
There appear to be a couple online services that will let you send Flash SMS (Type 0) but Twilio is not one of them.
Edit: The terminology is confusing! I wrote “type 0” above when in fact it’s a “class 0” sms. Type 0 means a silent SMS, Class 0 means an SMS that’s display-only and not stored. See also https://www.contextis.com/en/blog/binary-sms-the-old-backdoo... for a brief overview, though I’m sure there are other, better sources.
BankID also needs to be tied to a specific SIM, so I suspect that they somehow store and validate SIM ID and IMEI on the other side.
Wallet apps sends outgoing SMS randomly to verify this. Suddenly my wallet apps stopped functioning as SMS couldn't be sent and I presumed I had messed up with telephony services with some security settings and was searching radio logs to find the culprit where I found that SMS validity was nil.
Searching further I found that our telecom oligopoly (soon to be duopoly) decided to remove outgoing SMS from low-tier plans. I don't do real-time communication, telephony services are only useful to me for receiving the 2FA OTP and so I had low tier plans. Goodbye wallet apps.
IIRC you can grab inbound Flash SMS from at least some devices using AT commands the same way you'd grab regular SMS. They won't show up in native messaging apps, however.
Some BankID providers lets you use a regular bespoke ios/android app as an online code generator. Then you only need regular internet access, for example over wifi.
Yes. As I have understood it, it’s a Java applet that runs on the SIM card itself.
And it probably being more than just flash sms is also evident from the fact that not all telcos are supported for use with BankID, even among Norwegian telcos.
You can test it here https://www.bankid.no/privat/los-mitt-bankid-problem/test-di... but it probably only accepts Norwegian numbers. Found via https://www.bankid.no/privat/bankid-pa-mobil/ which says that the link I said to test it at says that you can use that test to determine if your phone and subscription supports BankID.
It’s also worth noting that many telcos will charge you every time you use BankID. This annoyed me a lot so I switched to a different telco that’s cheaper and doesn’t charge for BankID.
It shouldn't cost you money abroad though, BankID Mobile is free on many networks but if you use a reseller like OneCall they are unable to differentiate SMS and BankID flash SMS so you will be charged for it.
You could use the BankID iOS app which does the authentication crypto in the iOS app instead of using the SIM app.
We really should ban SMS-based 2FA.
Keep one cheap phone mounted with a camera and robot arm poker, build the API on that, then get an additional SIM for your normal actually mobile use. Or eschew the camera by using LineageOS (which can ignore anti-screenshot measures) and screenshot over ADB.
If you're in the US, it costs only $20/mo for an basic level Google Fi SIM (T-mo + Sprint network) or $25/mo for a Visible SIM (Verizon network), and they will be seen as an actually mobile number by the network. I imagine there are similarly cheap deals in most other countries as well.
Didn't buy one of those phone numbers from an SMS API. Had good success with Tasker Android app.
https://play.google.com/store/apps/details?id=net.dinglisch....
(This was in 2012-13. Not sure if Tasker can do these things today what it could do in 2012, due to increased security limitations in Android)
Had a rule configured in Tasker to call a HTTP end point with the sender details. received timestamp and the text message content, whenever a message was received on the android phone.
Didn't have to write any code and could get it done in the Tasker app UI, as it had all the variables/tokens available and I just had to form the endpoint link to be pinged with those variables in the request.
A similar thing might be possible with Tasker or similar apps to do the other way round (ie, having the phone send an SMS via mobile network in response to a ping from another device on the wifi network)
Even though we could have used Twilio, we chose to do it this way because a lot of services filtered for VOIP numbers and refused to setup MFA on them. So we needed a real honest-to-god number which was extremely annoying.
Team member wrote up a short blog entry about it: https://obviate.io/2015/04/16/making-of-the-mfa-phone-becaus...
It's based on QKSMS: https://github.com/moezbhatti/qksms
QKSMS makes use of smsmms: https://github.com/klinker41/android-smsmms
I love GPL and FOSS :D
A programmable SMS gateway plus a cheap sms only sim card seems to be my best option. I was thinking about doing this with a usb 4g card, but this might be better.
Now I'd really love to see something like this that also supported programmable voice.
However, Google just killed my Google Fi account because I'm abroad to much. So now I need a new workaround.
If you're in the US a lot this could work for you.
Details !
Apparently, if I go back to the US and use it from there it will start working again.
Ironically, this happened weeks after I was using in the US for a month straight.
> The Services are offered only to residents of the United States. The Services must be primarily used in the United States (territories not included) and are not intended for extended international use. Further, the Services are designed for use predominantly within our network. If your usage outside our network is excessive, abnormally high, or cause us to incur too much cost, we may, at our option and sole discretion, suspend your Google Fi account, terminate your service, or limit your use of roaming.
Most likely they are sending SMS from a short-code - and a short-code cannot send SMS to a non mobile number.
Twilio numbers look and feel like "mobile" numbers (you can send SMS to/from them, for instance) but they are not.
So it's not so much a refusal on the part of your vendors (Apple, for instance) but something they simply cannot do.
Ironically, twilio themselves requires a 2FA process that cannot be satisfied with their own product.
Sure you can. We do it all the time at my job, for sending reminders of appointments and medication refill notices and such. We have test recipient numbers on all of the mobile networks and the big VoIP networks like Republic Wireless and Google Voice. I even have a test number from voip.ms on there.
The requirement is that the owning carrier of the number have a partnership with the short code provider platform. Twilio famously doesn't want to pay for that partnership. Bandwidth.com, that operates the bare metal of a lot of VoIP companies, does pay for it.
https://support.twilio.com/hc/en-us/articles/223181668-Can-T...
Many companies who do SMS for account verification check whether or not the number is hosted with a VoIP provider and purposefully do not send verification requests to those numbers. It's a fraud prevention tactic.
Try getting a Twilio number in another country where they can't tell. I won't say which one works for me publicly here in case there are employees of those companies lurking here.
This was a totally unexpected +1 when onboarding to matrix for personal use.
Most phones these days do have battery charging cut off, so they should be safe but still prefer to have one without battery for leaving it plugged in 24/7.
Gnokii was the tool... https://en.wikipedia.org/wiki/Gnokii
It was great for out-of-band network monitoring.
However, last I checked, those email-to-SMS gateways were shut down to prevent spam :(
Do you happen to remember the model of that Nokia? I had a guy in high school show this to me once, but nobody believed me when I told them! I knew I wasn't crazy haha
I used to use the radio to to pick up cordless phones (ie a normal phone with a base station, with the huge phones with big antennas), AM if I rememeber rightly, right towards one end of the dial
this kept me entertained for far too long for an 8-10 year old..
There's a list here.
Im guessing "unlimited" sms, is also similar to "unlimited internet", you start sending more than a 1000 sms messages a day you might get throttled?
This is usually (at least marketed as) a spam prevention system, so you don't blast people with a really cheap, disposable SIM card.
A "person" can't reasonably compose and send more than 3 or 4 messages per minute on average. Send "too many" as defined by the carrier and you will likely be cut off.
I received the bill at the end of the month stating the timestamp and recipient of every message. The PDF was regularly around 100 pages long.
Were I work, we've implemented a couple of nation-wide general population surveys regarding non-communicable diseases (working with those countries health authorities, of course). For the actual surveys, we get SMPP contracts with the local telcos because of this limit (and to get a vanity shortcode, reverse billing...).
We started thinking it would also be cheaper, too (due to the scale pricing) - but the human time required for working out contracts with developing-world telcos for a project involving state actors can easily counter that.
The throttling is something we need to take into account for the tiny-scale pre-tests we ran (while working out the contract) using an SMS Gateway App[0] we've built, similar to the one from this thread. The main difference is ours uses a queue-based protocol to exchange messages with a controlling server.
I was able to beat twilio for mass sms in pricing - but due to the carriers blocking a high percentage %10+ it isn't a good solution for 2fa etc. I have built apple labs too. Apple imessage used to allow quite a few messages before a block - but now they just block the entire device not the sim making it useless.
I had the devices just use a get request to check a queue in mysql.
my lab:
We've also built something similar but not quite the same for use with the Auron SMS Server: http://www.auronsoftware.com/products/auron-sms-agent-for-an...
In our case we chose to built a custom IMAP-like protocol for integrating with the Android app so 2 way communication would work without any extra steps.
But this project is definitely something that I'll look into supporting as well. The point of our software is to make integration as easy as possible by supporting as many protocols and devices as possible.
The cost of cloud providers in this space is neglible, but I'd still like to think about this as an exercise.
Not exactly a security issue per se but ordinary SIM cards/phone numbers are intended for personal use and are limited in how many messages you can send per minute/hour/day.
When your messages are blocked, your 2FA obviously fails.
If you're going to do this, you need to do it as part of a system where you use many providers and monitor success.
If the rate is high, it's almost certainly going to get blocked. But then, it may work better for some destinations than any commercial provider. Or it might continue to work when the commercial providers have outages, or the carriers do maintenance on their external connectors.
Some of the SMS aggregators use regular SIMs to send some messages, or contract with others to do so, it's generally called a grey route. Usually with more specialized equipment and more SIMs, but same basic idea.
I have 'sms' shortcuts defined as shell aliases and those aliases call 'curl' commands that hit twilios endpoint and fire off the SMS from my "mobile number" which is, of course, a twilio number.
So I can SMS people while flying on a plane or abroad without a proper SIM card ... or at my house where I have no mobile coverage.
"Personal" use implies limits of some sort imposed by the carrier --- often as they see fit. A person can't reasonably compose and send SMS at a rate of more than 3 or 4 per minute on average.
I have mobile network bills from when my sister was a teenager and people used SMS to text that show this is reasonable.
People at least used to use SMS as essentially a chat protocol, with each message often being only 1 or 2 words. 10+ messages pr minutes could easily be reached if you where having a conversation with someone.
The point is that the actual definition for "personal" use may vary by carrier but be aware there is one. If you are sending "too many" messages to "too many" different numbers, you are likely to be cut off.
Currently I am using gammu-smsd with a simple forwarding script (through Pushover) to deliver messages for my 2nd number.
For hardware I'm using older 3g/4g network USB stick plugged in my home server.
I developed an app to automate SMS text messages and getting Google’s approval to send SMS messages was more difficult than writing the actual app.
I have been looking for something like this, I built something similar but it used android debug bridge and a webserver on the laptop the device is tethered to. But I always wanted it as an android app.
Anyone know any similar projects?
At the time there were a lot of developing countries projects using SMS as their main interface (a lot of work with community health workers etc). Orgs like the UN would set up an SMS gateway by hooking a desktop with some hardware, and of course it would be very vulnerable to stuff like power outages, someone tripping over the wires etc and you had to get the technician to set it up again. With smartphones you had the all the required setup in one cheap, small and very durable package, no training required to operate.
Pushbullet also does something like this, and more!
[1] https://play.google.com/store/apps/details?id=com.llamalab.a...
[2] https://llamalab.com/automate/doc/block/sms_received.html