SMS phishing is way too easy
bejarano.io
bejarano.io
The article's attack is relatively benign - the user simply goes to a website. Sure they may end up putting info in that website, but probably not. Plus existing systems for malicious website filtering can kick in to prevent this.
The more concerning attack is the social engineering one where a third party says something like "let me 'verify' your identity, I'll send you a number tell me what it is" then triggers an identity verification request on the domain (this can be done either manually or part of a sign up flow for some honeypot service). Now the target needs only relay 6 digits to someone they already "trust" and are in a conversation with, versus in the article's example they needed to put their full account info into an unknown website.
There are institutions out there that are training your users to ignore your security advice.
They phish users with horribly made emails with no formatting, then they send the same sort of emails for legitimate things. They give security advice and then break their own security advice.
Unless you’re a government (or contractor) your threat model isn’t some side channel timing attack on your CPU, its users complacent with security created by you. Legitimate emails should look legitimate the first time, security advice applies always and everywhere. It’s not that hard.
Narrator: No, it was not Fidelity, but a scammer who needed the code to drain the customer's Fidelity account.
It’s a horrible system. They’re shouting themselves in the foot on security.
In my experience, it was also a bank that used this practiced.
Thank goodness it’s not a big deal to gain access to someone’s bank account. /s
FTFY.
HN discussion (8 days ago): https://news.ycombinator.com/item?id=31862994
I think a lot of people on this thread are forgetting just how easy it is to spoof SMS.
- SMS has a field called sender ID, which is set by the sender, requires no identity verification, and can be any arbitrary short string.
- This allows anyone to send messages to any number, identifying themselves as whoever they want to impersonate.
- And since there’s no sender phone number in the message, your phone can’t tell real and fake messages apart.
- And so it groups them into the same conversationEven my former bank did this. Companies can include the warning all they want, but they’re already teaching consumers to ignore it and break the rules.
There’s a standard format for doing that: https://github.com/wicg/sms-one-time-codes
https://developers.google.com/business-communications/verifi...
Btw, in some sense this is exactly the same stuff you'd have to do to make committing to a single-bit work. Or encrypting a short message, in a way that's not easy to crack.
In the app/website: "You will receive an SMS with two 6-digit numbers, one to certify that we sent it to you and another to type bellow. Our chosen number is 887-987, type the another one"
In the SMS: "Two-way verification. Check if it's us with number 887-987 and confirm with number 543-621"
1234-_______, and email/sms will have two numbers 1234-554566.
Don't think they explained the reason for the first part in the message though. Just highlighted it in a different color.
[1] https://philipnyecom.files.wordpress.com/2017/02/otp.jpg
But it will still protect against the fake messages like the ones being discussed here, and if someone has a duplicate SIM you are buggered in a number of other ways too.
Though this method, and several others that are effectively the same, only offers any protection if the user has the ware-with-all to bother verifying the other number. Unfortunately that means that in many cases it won't help at all because many would not be aware of the other number and expect to find it when the fake messages come in - unless the user knows to expect and require it the fact a fake message doesn't have it makes no difference.
The word you're looking for is "wherewithal", I believe.
It sounds like we want identity verification, which while solved for computers, is much harder for humans.
I like it, at least, for now. It's better than the current situation.
Potentially disabling URLs from alphanumeric senders is a good idea, but it’s also very easy to get virtual numbers for sending SMS spam.
I think a good balance would be making URLs not clickable for any number that is not in your contacts which also makes it difficult to copy and paste for an average user.
The onus is then on providers to make sure anyone they may send links to saves the number as a contact and that they always use the same number, and have that number on their website.
So when you register for delivery notifications a message goes out saying you should save the contact number. If all Fedex notifications come from the same number the user only needs to do this once.
I guess this is one reason Apple has verified iMessages when you talk to them. The background is a different color, I think, to signify their verified status.
Honestly, SMS today just exists as a legacy, because of status quo. Just like 'normal' phone calls.
Of course, both are still quite important in the real world.
> If you send a message from iMessage to someone with Android it goes via SMS.
Interesting. I think there are some Android messaging apps that also fall back to SMS, but it's not a behaviour I would find particularly useful.
I don't use WhatsApp, so with people who do not have Telegram I use SMS. The more annoying and conotated with spam SMS is, the more pushy people become with insisting on WhatsApp. Luckily I'm often in a position to absolutely resist, but I can see how others, such as job hunters or Tinder hookups, would be pressured into installing the spyware.
This is not being done by Facebook/WhatsApp themselves, but keeping SMS annoying is certainly in Facebook's interest.
They haven't gotten to blocking messages that don't register but have raised the fees and fines for folks who don't register and they're able to track down.
It’s profitable on multiple levels to allow this, so corporations ensure the political class doesn’t enact legislation for consumers.
The main use case for this is redirection, when I get a call from A to my office O, it will also call my mobile phone M, but it is my PBX at O that start the call, so normally I would have O as caller on my phone, but I want A, so my PBX must be able to set the caller ID to A. I cannot use redirection at the carrier level, because a number might redirect to multiple mobile phone at the same time or recording the call or any feature that are provided by a PBX.
I guess this is a very common use case and it make it trivial to spoof caller ID.
There is an easy fix to this and I believe Twilio does this ...
You allow senders to announce CID for any number they have validated with your service (in this case, Twilio) ... so you prove to Twilio that you control that number and they they let you set that number as CID.
Seems like a very simple and elegant solution ... and allows for the use-cases that you are alluding to.
Now the states get the choice to regulate women's bodies
Ugh
But yea, trigger laws enacted have now regulated women's bodies in something like 15-20 States or something? It's disgusting
They haven't managed to hijack an actual sender though, and their domain names still look slightly shady because they're things like citi01.
They AT&T one is html wrapped so I can't even click the link without seeing what it is (and don't want to because maybe there is some exploit that launches an app that does something? Am I too paranoid?)
It's basically the same setup I use with emails.
Not entirely sure if it's safer that way. But so far I get SMS spam only on the "burner" number.
What you actually want is a "2F Mule":
Since moving a mobile number to twilio and setting up forward scripts, I can get SMS, including short code sms, but the 2FA sms do not get delivered.
Twilio support said it is blocked from the sender side due to the provider being Voip. As hard as it is to believe, I think they're telling the truth.
Anyone in Australia who wants to do this without carrying 2 phones can check out my product BenkoPhone
Even thought I never saw that happen nothing is stopping them from just giving my number some else.
It's so stupid to depend on something like this
Time taken: 20s
Annoyance saved: very
Doesn't make any sense. Companies can stop sending, but that doesn't prevent scammers from sending it. If anything, Apple or Google can run an in-device ML model to understand if a link is scammy/phishy vs genuine. They do it all the time on your browser.
It makes a lot of sense. Just like "we will never ask for this code over the phone", it becomes a rule "we will never send a URL in an SMS", and people learn not to click any of them.
Similarly, when I get a call I now ask them how I can call back. I don't think this is outlandish if companies are consistent with this.
It's a fucking game, protecting against gold farmers. How about protecting my non-virtual gold?
Banks have to price in the risk that, if something does go wrong, they could have regulators on their back. And uh, have poor incentive structure wrt being perfectly allowed to do everything by the book and slipping responsibility if the book is just wrong.
I don't know why (maybe criminals are more likely to go for your WoW account assuming the legal consequences are less) but I would advise all companies to examine how Blizzard, Valve, and others handle account security.
What I ask is for iOS and Android to have the "this message was not verified" warning, as shown in the last screenshot, whenever the sender ID is displayed without any form of verification (such as, the aforementioned country-specific sender ID registries).
If browsers show "not secure" unless verified by SSL, apps should show "not verified" unless verified _somehow_.
The "how" may or may not be possible at this moment, but in any case, warn by default.
Is that naive?
there's really no good reason for the automatic contactification of email addresses. if I want someone's emails to be marked as being from John Smith, I will do that myself. if amazon or x known company is sending me an email, I do not care, identify the sender as the email address it was sent from.
Ideally I'd carry round a phone-sized PC running Linux with mobile capabilities, but as it is I settle for my laptop and a brick phone. I appreciate that android would be better - and is in fact a computer running linux the size of a phone, but it's not really the same.
Whenever I get phishing SMS they always come from a random 10-digit phone number so it's pretty clear they're scams. Reputable companies send these types of messages with short-codes, which are a 5 or 6-digit numbers that is very expensive and require thorough vetting by the carriers.
Don't get me wrong, carriers have been making strides to lower the amount of spam that's sent through the air (A2P requirements, toll-free number verification requirements, etc), but a determined scammer can still exploit SMS/MMS pretty easily.
Most people will trust a toll-free number just as much as a shortcode, and since tons of legitimate companies use toll-free numbers for messaging it just blurs the line of what a "reputable" number looks like.
Even SendGrid, which is owned by Twilio, uses toll-free numbers for their 2FA messages instead of shortcodes.
As far as I could tell (although I retired in 2019, so might be out of date), you can't use one short code through multiple aggregators, so if you want the benefits of multiple routes, you've got to have multiple shortcodes or live with sending from regular phone numbers.
Sadly, Novant Health (a hospital system) uses a regular 10-digit number for their patient portal 2FA. When I was in college, accessing sensitive info like your SSN and W2s in Banner also had 2FA via a 10-digit number. (This was an entirely separate system from the login 2FA provider, Duo, which uses shortcodes in addition to U2F tokens and their app.)
https://support.sms.to/support/solutions/articles/4300056265...
Probably no nation has protection from spoofed numeric sender ids, but based on the sms phishing attempts I get, that's not a big deal. Apparently people will tap on links from their bank from any number anyway.
Not to mention how widespread the coverage is. There are many places around the world where you have cell connectivity but no Internet.
In short, you can't get rid of it short of throwing away the SIM. Is it possible to have SMS v2 that's safer like we went from 2G to 5G?
No, because https://xkcd.com/927/
The world is filled with strongly authenticated messaging solutions. There's an excellent one available from literally every major tech company. Technology is not the problem here.
The only solid way to prevent phishing is non-forwardable credentials, ie FIDO/U2F. We need to make this easier and more ubiquitous.
The Internet, for better or worse, has taught me a healthy amount of skepticism, plus I definitely had not bought any gifts (how is it a gift if I buy it myself?). But I can see how it is easy to fall for these scams if you aren't used to looking for them.
Your package delivery details are incorrect and we cannot deliver. https://usppagestrport.com/2vlv
Obvious phishing attack, but you know some people are going to fall for it.The amount of cruft involved in SMS delivery is unbelievable, and phone numbers are neither particularly stable, nor particularly well protected against takeovers.
This can work against you of course, so a good strategy is to get a burner phone and port that number to your VoIP provider.
https://www.npac.com/canadian-number-portability/the-npac-ne...
Would love to know how to maintain a US SMS presence without sketchy obviously for spammers products.
Canadian telcos are basically a scam (and Virgin is now my top hated one, assholes).
2FA using phone numbers is idiotic.
I think in the end she put one of the numbers down in the application after a little pursuasion.
Mentioned this to a friend who works at Google on their messaging products. His take: "Yup. It's a mess"
I also have to wonder how Google Voice has survived Google's ax all these years.
The infinite surveillance capacity of an monitored voice line?
Millennia of training data for AI speech synthesis and recognition?
After porting a second number into Google Voice (and involving Google Fi) I lost access to the first. A 50+ year old phone number that everyone important to me already had memorized.
If you call the number now, it’s answered by a Google voice subscriber message. So I know the number is still with Google. I just can’t access it anymore.
I'll be here all week.
Also relying on something from a commercial entity that's so easy to fake is weird.
There's this weird thing that de facto you need state residency and a permanent address to live "normally," have government ID, etc. but there's not AFAIK any actual specific legal requirement to have same.
Instagram and Facebook will quickly disable your account and demand a real phone number. I recently had a delivery app inform me at signup that it's not even a real phone number (it happily slurped up the submitted Voice number and later sent me ads about pizza anyway)
But that doesn’t work for 2FA. I ended up locked out of my online banking accounts for my whole trip and it was a huge headache. My recommendation would be to port your number over to Google Fi and then just use that in whatever country you’re going to. It’s a bit more expensive that local cell service in many countries, but there’s nothing like having your phone just work wherever you go.
Start from first principles, what do we really need to know about a person? What could we build? On the other hand, maybe if it's too good it'll be bad for privacy, and escaping into the shadows, should that become necessary for someone.
I'm not necessarily saying this is a good idea. It's just an interesting potential solution.
I've paid the $20 Google charges to make a number "permanent" once for myself and a couple of times for organizations.
For myself, it's a highly secure phone number. I still only use a phone number when I absolutely have to, like with Twitter, preferring to use a hardware key or Authy.
For organizations, it's like an answering machine. My kids' soccer club had a cell phone that was supposed to be answered by the VP when parents or coaches had messages. It was much easier to port the number into Google Voice, put it into Do Not Disturb mode permanently, and have the transcriptions forwarded to the VP on the extremely rare occasions that there were any.
I'm not paying $450/month to roam...
That's cheap. My Austrian provider charges 1 Euro per 100 KB when roaming in Canada (no - that's not a typo). So for 10 GB that's a cheap 100k Euros.
I currently have plan for 22€ that gives me unlimited everything in my country (maybe there is cap to minutes but I don't call much) including unlimited data + 10gb data in EU.
I remember that in Canada I was paying through the nose for some basic pathetic plan though.
- SMS delivery is not always very reliable when roaming.
- Prepaid SIMs usually expire after a while of not topping them up.
- Good luck losing one of these SIMs and getting a replacement abroad. (eSIMs make this both better and worse.)
Never had missed SMS while roaming and I don't use prepaid as primary number. Have had same number for 20 years now.
There is a guide or something to help you with that?
I know that is just a simple task, but it is a really long chain of stuff to do and prevent yourself being at the other side of your services
My best advice is to find alternatives and don't depend on anything that depends on a phone number. Things can ALWAYS turn wrong.
Should be obvious but you will lose your phone service, so you want to time it close to when you are leaving.
So for me 2fa is pretty much the only thing I still use SMS for. Which makes a suspicious sms stand out a lot more.
I wish we'd stop using it for 2fa though because it was never meant to be hardened for this.
What happened was that the networks were capitalising on that. SMS was historically quite expensive so it became a big cash cow. SMS bits must have been made of gold because they were hundreds of times more expensive than other bits.
WhatsApp completely killed SMS usage here however. Leading to some carriers wanting to charge extra for WhatsApp usage to recuperate some of the 'lost' revenue. This sparked a big discussion about net neutrality which was then enshrined in EU law, so the discussion was finished. By this time, SMS became practically free but it was too late.
This is only partially true. There are also countries like France where WhatsApp only has a Market share of about 22%. Switzerland is very split too, I personally know more people using signal or telegram than 'still using' WhatsApp.
Most people I know use WhatsApp (I refuse, and since I run Lineage OS without Google services I simply tell people my phone doesn't support it), Signal, or Telegram.
Reality is if you ask someone 'do you have whatsapp' or just message them a lot more than 22% will have WhatsApp in a way or another I guess. Buts it's not what they choose if someone asks which app they prefer.
Just as nearly everyone I know has telegram but I highly doubt it's their main way of communicating for most.
One of the things I like about it is group messaging. The seamless images/files, the encryptuon...
And I don't think most mainstream users feel this as a lockin. After all whatever phone they can buy they can install whatsapp on it (and soon even import their hitory!).
Personally I prefer Matrix. Not a fan of Signal either due to the ban on 3rd party apps.
At least Germany and Austria heavily rely on SMS-OTP for all kinds of services, banking and otherwise. I've never received an OTP via WhatsApp.
Austria even has an eIDAS-compatible e-signature scheme based on SMS-OTP that allows people to create a legally binding PDF signature using SMS-OTP and a static password...
SMS is actually easier, with email I have to go into the outlook app.
I was of course in a different country in Europe. Since it’s a mini-continent and all that.
Ironically, my email inbox is much better protected than my SIM/phone number.
That said, my phone number is significantly easier to take over than my email address and mailbox.
By forcing the users to validate with a phone number, they're essentially pushing their spam problems upstream and out of their hands. More sophisticated actors know it's possible to automate SMS verification, but it does stop a lot of spam at the door.
Google does this very well: They require a phone number of spam account creation prevention – once. After that, I can delete the phone number from my account and use a FIDO key, TOTP or any other 2FA method.
Uber's screw-up has given Lyft a few thousand dollars.
Come up with a good alternative and make yourself a billionaire.
Difficulty: Good alternative.
Not as simple: stuff arrive in the spam folder. Some providers just reject your valid mail (my main email tld is exotic, it causes lots of troubles). People receive so much junk they lose your message in 1000 of unread mails or are afraid of checking them.
Not as interoperable: there are new kids that just don't have emails setup on their phone. They check them once a month at home on the computer. Email is for old people (although text is getting there too).
Plus email is almost as easy to spoof and intercept, so the gain would be minimal.
I'm sure there are a few people without email on their phones but I don't think the number is dramatically different than those without SMS right now. If I have cell signal I have email, but I can have email without SMS access.
In the US populated area, maybe.
In the French country side, definitely not.
E.G: last week, my brother wanted to try one of my service account on his ipad (we set it up only on his computer). He tried to connect with my password, but any new device requires a 2FA. So he calls me, and I gave it to him.
Now, in this particular example, I was at home, so I had access to internet.
But I'm often traveling to places where I don't.
In fact, I lived in Mali for 2 year where this has been a big trouble for all administrative stuff. Nowadays, I would assume a lot of Malian people have a phone numbers, but no emails, anyway.
But without going that far, the French country sides have plenty of places where you get text but not internet. And being in a car or train is often enough for that.
I don't think SMS is a good 2FA. I have 3 yukikeys at home.
But I believe any geek should first spend a month working in a call center before making a comment about 2FA.
There is a looooong tail of things getting wrong, and there is a reason corporations chose SMS: they tried all the rest, and it was worse.
Now thing are getting better with in app 2FA notifications, but of course it assumes you have a smartphone.
> I'm sometimes in zones without internet but my mum call me and ask me to give her some confirmation code I receive.
We're talking about multifactor authentication here. Where/how are you authenticating without internet access?
> Email is for old people
I guess that makes me old. Does that disqualify me from using multifactor authentication?
> Not as simple: stuff arrive in the spam folder. Some providers just reject your valid mail (my main email tld is exotic, it causes lots of troubles).
All of this happens to me with SMS much more often than it does with email.
> Plus email is almost as easy to spoof and intercept,
Agreed on spoofing, but that's not a problem for OTP authentication. Complete disagree on interception – I believe SMS is much easier to intercept, on average.
Imagine what that could look like with voice AI getting better and better.
It just was not one of the design goals. My understanding of caller id is that anyone can put anything there--it was made decades ago to serve as convenience--not to verify.
Likewise with the sender id in SMS.
It's a good lesson on how protocols are hijacked. Someone thought it was a good idea to send text messages. Another person decided to leverage it for security. Ét voila, we have a security apparatus that isn't very secure.
It was made decades ago as a profit center when the telephone network was a monopoly company operating an isolated network.
Because only the monopoly phone company operated and had access to the isolated telephone network, there was no need for any authentication or verification because all caller ID data came from "themselves" and they were not going to start trying to scam themselves.
It (caller id) was a profit center because when it first rolled out it cost somewhere in the range of $20 to $30 per month. The phone company was already tracking which number called which other number for billing purposes, and they found a way to monetize that tracking by allowing the call receiver a tiny sliver of visibility into their billing tracking data, all for a nice sum per month. It rolled out circa 1985 or so and factoring for inflation that $20/month fee at the time was the equivalent today of paying $54.33/month. All for data that was effectively free to the phone company because they were already tracking it for long distance billing purposes and/or for local toll purposes if one was on a "local toll plan" instead of an "unlimited" plan.
Not familiar with SMS Sender ID Verification, but after quick Google, I was unable to find any signs that it counters SMS spoofing.
SMS as a 2FA channel is broken. There are so many vulnerabilities that it just makes no sense to use; for example: corrupt telco employees, SS7, sim card cloning, sim swap, spoofing, governments, etc.
Beyond that, if you’re located or traveling internationally, it’s a nightmare to deal with.
NIST has not recommended SMS based 2FA since 2016:
https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo...
I send lots of 2FA SMS for a number of banks here in Europe and they - because of the costs after PSD2[1] went live - want users to use their app for getting notifications as 2FA. They have launched several communication campaigns over the last 2-3 years, but only 30% of users have migrated from SMS to in-app notifications, mostly because they won't even install their app.
Then, we have uses cases where users don't have a regular relation with your business (p.e. e-sign for consumer goods financing on spot). In this case, I would say that SMS is the only channel you have to serve these users.
For better or worse, I do not see SMS disappearing anytime soon.
[1] https://ec.europa.eu/info/law/payment-services-psd-2-directi...
There are people who don't have a cell phone because they see it as a distraction engine that will gobble up their life. Digital addictive drugs. But it's almost impossible to maintain this stance in modern life. Have you seen the trend of restaurants that no longer print menus? Instead there is a QR code that opens up their website to get the menu. Every service now wanting SMS verification adds to their problems.
I personally only use throwaway rental numbers on the web, basically giving me the worst security possible for any kind of account that falls back to SMS for security.
There are also services that are specialized on providing the right number for a one time fee. This usually works well, but more often than not destroys future account security (they all will give numbers out again, not relevant what they claim)
I could literally write a book about my life without a 'real' phone number.
I wouldn’t count on this, but I’m trying to give a business money. Most are happy to satisfy reasonable requests.
So I went to the restaurant next door. If you can't even bother to scribble a menu on a chalkboard, you're not a real business.
Probably talk to them? I'm not sure where you're going with this because a paper menu isn't going to help with blindness.
This is a trend here in Brazil. And do they send you to a lightweight, mobile-optimized web page? No way in hell, you can be pretty damn sure they will send you to a 20MB PDF that was designed for printing.
It's mind boggling how insane this is.
Well yes, doesn't literally everything need a phone number to work these days? Can't open a bank account, can't get paid, can't pay bills, can't exist.
2FA is ideally user generated to begin with, and not the other way around.
This is more to check the box and state to the court you tried your best.
P.S. Example: We had serious issues when people gave Google their phone numbers and the corporate accounts got hijacked.
You say 'even' but it's hard to make sure apps aren't able to track me at all, and I while I trust my bank to keep my money safe I don't trust their app to be tracker-free.
There's Authy that does backups and you can even run it on a computer (even Linux!). 1Password can store OTPs, too, and is also backed up. There are probably a bunch of others and I'd expect KeePass to be able to do backups.
Plus, you're usually able to get the OTP seed which you can store on your own. This usually shows up as "can't scan this code?" or similar when registering.
I'm now traveling overseas, and have a local SIM in my phone. I have an older iPhone, so no dual-SIM for me. If I had to receive an SMS I guess it would still be better than my older Galaxy S5 which required a reboot, but it'd still be a pain to have to switch SIMs.
If I lost my Phone but still had my laptop, I'd be AOK with my current OTP setup. Except for a few sites which don't allow me to have anything else besides an SMS, but luckily they're not critical.
not true. that QR code you scanned to add the key to your app? well, that was your key. you could have saved it somewhere else secure that does allow exporting.
Unfortunately many of these apps treat the private keys like the app owns it which is where people run into trouble. Some will even back up to the app provider's cloud service which is just asking for it to be stolen.
Most people don't. The average person doesn't even know that's a thing since like 1 in 100 services prompts you to even do that.
Unless you go back into the 2FA interface after the fact, there's no indication that app-based is even an option for Google accounts.
They faked Bank’s message, and send the link with the same UI of the bank. Many people got hacked.
I got a few messages like this. The only thing I could do was informing my friend (none-tech) to avoid these things.
And for what it's worth - origin bound OTP codes aren't _strongly_ bound - there isn't anything physically stopping someone from typing that short 6 digit code into a phishing site. Compare with a Magic Link token - you're much less likely to take `https://example.com?token=some-long-uuid` and manually enter that code somewhere else.
I didn't want to explain that in the article because I don't think it adds value.
I suggest you read up on the SMS protocol, basically anyone on the network, if able to inject any arbitrary packet into it, can.
If you don't even want to buy equipment or even code, take a look at AWS SNS or (i believe) Twilio too.
No idea what a good alternative is though. Preferably something federated though
It’s difficult to know if URLs are legit or not. HTTPS used to be a good enough indication of legit URLs, but not anymore.
You could also think on googling the company. But those ads that look like real search results are well known to include scam websites!
I’m a developer and I find it difficult to distinguish some URLs. Now imagine how difficult it can be for grandpa or really any person out there that doesn’t know about these kind of scams.