Any idea how G and A were compromised, password reuse?
Any idea how G and A were compromised, password reuse?
I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.
But if the attacker already has your info, then couldn't they just add another line to your mobile plan, so your handset continues working, just with a new, unbeknownst to you phone number? That way it wouldn't be noticable on the handset.
The real question is how long do you think it would take you to break into your own Gmail account after the passwords been changed and the attached phone numbers also been changed?
Probably longer than it would take an attacker to drain bank accounts, I figure.
Or, you know, they can just bribe the store employees. Has happened before, still happens, will keep happening as long as a phone number is considered important for anything at all.
Moreover, you don't want it to be tied to your identity. The fact that anyone can pretend to be you and hijack your phone number is exactly what makes it insecure.
A stolen phone can of course be a problem as well, but at least it's somewhat under my control and I may notice pretty quickly when it's gone.
I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items.
And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.
Edit: I can't actually find a help article, but it's under "Try another way to sign-in" and they'll text you a verification code to your registered account phone number.
Does anyone know if Authy uses SMS for any kind of recovery? I don’t see an option in the security settings
https://support.authy.com/hc/en-us/articles/360012427914-Is-...
I’ll agree though that Authy’s docs are really ambiguous about account recovery.
I wonder then what the point is of having 2FA at all if you can just click a few buttons to bypass them with an SMS.
Were you specifically targeted in any way that would make the attackers go find your phone number and perform the swap?