Owners of 1-Time Passcode Theft Service Plead Guilty
krebsonsecurity.com
krebsonsecurity.com
Unrelated, but at the start of the year, a lot of Payoneer customers from Argentina lost their savings in the platform* due to someone having access to the OTP codes. Payoneer said it wasn't on their side the error, and evidence suggested that it was an error in Movistar, because all the victims were customers of that particular telco. As far as I know, Payoneer didn't return the money and Movistar was never charged or anything (rumours say it was a Movistar employee who sold SMS with the OTP).
And if you ask why a lot of Argentina people use Payoneer and keep their savings there, it's a bit long to explain but basically is their way to get paid in USD outside the country without paying taxes (fair and unfair ones) and without getting their payments converted automatically to ARS pesos using a bad rate.
Thankfully, that's not true. Class action lawsuits can and do successfully target widespread industry malpractice. My first job out of college was as a paralegal, helping over 90 million American plaintiffs sue nearly every major life insurance company in the country for the previously common "standard behavior" of insurance agents convincing policyholders to periodically "roll over" their accounts, to the sole benefit of the agents and their employers. The settlement payout for each participant was typically meager -- but the malpractice was stopped.
We'll see how much Crowdstrike pays out.
They work great if you assume that everybody has a smartphone (as opposed to a feature phone), that they don't have their phones stolen every other month, that they know how to set up an authenticator app, that they'll remember to reconfigure everything properly when migrating to a new phone and won't immediately throw the old one away and so on.
This problem is made even worse by the notoriously bad UX of most authenticator apps, notably the lack of automatic iCloud / Google Drive backup functionality and their inability to automatically show the code on screen whenever it's needed.
The nice thing about SMS is that you can outsource most of the support burden to carriers, which have to handle it anyway. Carriers have the advantage that they usually speak the user's language, have an office relatively nearby, and can verify your government ID in person if need be.
I'd say reliability counts for more in these cases, and SMS was designed for unreliability, like UDP. So I'd be more concerned about the relationships and gateways from MFA services to send out their codes, and ensure that they can be received in a timely fashion. This message will self-destruct in ten minutes.
A part of it is mandated by regulation, most countries require carriers to let their customers port their phone numbers out. When handling those port out requests, they don't necessarily have enough data to decide whether the request is legitimate or not, yet refusing such requests too often would draw the ire of regulators, which is something no carrier wants.
This would be a terrible assumption even for upper-middle-class people!
It's sort of ironic that the Krebs article indicates that these dudes were specifically targeting the "most secure" OTP methods we know: authentication apps, rather than SMS or email codes.
They were simply using social engineering and human trust to bypass the industry's best technical practices.
SMS and email are side-channel communications, so the attacker would need to intercept them, and hopefully suppress the legitimate receipt as well. I'd get kind of worried if my bank sent me an unsolicited code. But a consumer may be more credulous when their "bank" calls in to request one from them...
They also do seem to check that it's actually a hardware key, i.e. software authenticators like Google's or Apple's default solutions don't work.
And then there's crazier shit like https://krebsonsecurity.com/2024/03/blackcat-ransomware-grou...
(/jk)
[1] https://www.searchengine.show/listen/search-engine-1/what-s-... [2] https://www.404media.co/
Why wouldn’t there be? It’s not like an economy needs anything more than a medium of exchange and a kind-of-functional guarantee of nonviolence to arise. If you have that, you don’t need to arrange for a market, it will just happen, more or less. (Healthy or not is another question.)
Anyway, yes, there’s phishing for hire, bring-your-own-payload exploitation for hire, ransomware for hire, and of course DDoS for hire. Captcha solving for hire is legitimate enough to occasionally get posted on HN (and I don’t think it shouldn’t be). People’s residential or mobile internet connections for hire, hijacked via free VPN browser extensions and mobile ad SDKs, are legitimate enough to be sold via advertising conglomerates (but I think they shouldn’t be).
A market isn’t something you build, it’s something you have to actively prevent.
Other places where freedom is limited have similar characteristics, I remember that we had a sort of food market when I was a child at a boarding school.
The other time I couldn’t do that for reasons I don’t remember and paid cash at a store to get one. What I got was a tiny thing that looks exatly like a small postage stamp of the standard almost-square shape (which is itself funny because all the actual French postage stamps I used were twice as large) except it cost the aforementioned ~60€. Needless to say, I was terrified I’d lose it the whole hour or so before I handed it over to a clerk.
Wikipedia tells me this was a common approach once[1].
They are thieves? They would probably theft for the service, not pay for it.
It's actually kind of a stupid economic policy to make it hard. If someone wants to store money in your country that's good for you.
This is false and I challenge you to name these countries. Also, not certain about your definition of "super easy". I interpret it as say "hi" to the teller, give my ID and get my bank account.
If you do know a bank/branch that supports opening for tourist foreigners with just an ID+Phone, my email is in my account page and I'd appreciate if you pass that info.
1. Get a +86 phone number at any China Mobile. You only need your passport and some initial (e.g. 100RMB) cash
2. I opened a bona fide ICBC account at one of the ICBC branches in Shanghai with that +86 phone number, passport with 10-year tourist L visa, 100RMB initial deposit cash, and using my hotel address.
Note that not all branch tellers know HOW to open an account with a foreign passport. Go to one of the larger branches, not the hole-in-the-wall ones. If one branch refuses you the account on grounds of a tourist visa, try another branch. It's not illegal, just not every worker knows the rules. Their electronic system is most definitely able to handle it. I was able to open the account at the 2nd branch I hit up.
They did not ask for proof of address, proof of work, or residence permit. I just told them I frequently visit China for business and may relocate in the future for work (true at the time, I was there frequently for my startup), and the dude was cool with that.
I was able to link that ICBC account to AliPay and WeChat and use everything normally, including flight, train, and hotel bookings. Access to day-to-day mobile payments was the main reason I created the account.
This was 2016, by the way, I don't know if anything has changed, but my account still works fine.
Caveats:
- Your +86 phone number will not work outside China and you cannot enable global roaming until you have had the number for 6+ months according to what I was told. So before you leave China, switch it to the cheapest phone plan and load the account with prepaid cash so that the phone number doesn't expire and disappear. If it disappears, your bank account's electronic UI may also become inaccessible (due to the stupid SMS verification) until you go back in-person to the branch and show them your ID and get it re-linked to a new phone number.
- After your passport expires, all bank transactions including WeChat/AliPay transactions will also fail. You will need to go in-person to a branch with your new passport to get that updated.
If you are not a US citizen, and have a good relationship with a global bank it can be as easy as making a phone call.
I managed to buy a YouTube sub in Venezuela with my regular debit card, though. What store were you buying from that needed a local bank account?
Unless you're a US citizen, of course.
Completely seriously, you and everyone else reading this need to not just "know" this, but believe it and feel it.
Too often I feel like programmers are like fat 50-year-olds talking smack on the locker room about how doomed the other team is because they know the importance of MD5-hashing passwords in the database, and they have no idea they're going out on to the field against an NFL team.
Of course, where this metaphor breaks down is that these metaphorical lardasses will not be able to fail to notice them getting their asses handed to them, whereas in the security space, their real-world analogs may not even notice they were hacked.
It's brutal out there. Even the open source tooling is far more sophisticated that most people reading this realize, and that constitutes the baseline, not the top end. There's an underground economy, and it is sponsored by many entities with deep pockets, including large-scale criminal enterprises, some of which can rival "real" companies in scale, and government-backed operations of all sorts.
You're not up against a stray hacker bumbling into your system. If you've got assets worth anything, you're up against professional organizations. If you are responsible for anything that matters, take the threats seriously.
As you mention, the other issue is that this is often invisible (or even hidden by) to those who created the system that allowed the extraction.
why did you go out of your way to insult fat 50 year olds?
any NFL team would absolutely crush any allstar team of programmers in their 20s, even if they were selected for regularly doing triathlons and a lot of lifting. Any NFL team would beat the NCAA Division 1 champion football team. (for non-USA, that's a university team, the same teams that supply most of the players to the NFL, but only a fraction of even a championship team actually make it)
I wouldn't bet against a fat 50 year old retired NFL players team against any "we know MD5 squad"
You are only offended on behalf of hypothetical other people, seeing an opportunity to score political points.
Not only am I not impressed, I am disgusted. Being offended on behalf of other hypothetical people to score political points at other people's expense is a scourge on our culture.
Some examples:
We have had multiple attempts to use AI as imposters to convince well-wishing colleagues into doing things they shouldn't - a complicated technique that has seen success for the hackers on some occassions[0] - which requires infilitrating numerous accounts etc. This one is the "hollywood romanticized" idea of hacking because it is in realtime with actual people operating the stolen accounts, but using AI to mask their appearance and voice.
Sleeper infiltration - someone will find and breach an exploit, only to patch it, but leave a new backdoor. They then let it sleep for many months, eventually coming back to use it only to (attempt to) completely remove any trace of their presence. inb4 anyone says "ah but they probably copied/did something else you don't know about!" We've had those, too, but some really do just exploit, patch, then leave. Probably to deny someone else or something.
A really fascinating moment for me was watching a seceng spinup a honeypot and it took less than a minute for some attacks to start hitting it.
[0]: https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-k...
You might enjoy "Lying for Money: How Legendary Frauds Reveal the Workings of the World", which talks a bit about frauds as existing as a parasitic economy with its own parasites, etc.
One was showing products advertised on FB at an extremely cheap price. You think you're buying a widget but instead deep in the language you're buying a weekly service that shoots up to $100 a week. If you call to complain against the company you bought from, they tell you they won't cancel as you signed a contract.
In this particular case the security researcher reached out FB (privately, reporting it did not work) and showed the vast web of accounts buying ads and promoting it, which were soon banned.
You see tons of messages of just random new accounts, posting to strangers commenting on like a meme post, saying “I love your posts, I’d like to get to know you better, dm me on telegram…” or “I have earned $123,456 in 4 days thanks to the crypto genius Steve Bob [link to other fake profile]” - reporting them usually results in a “we didn’t take down the content” result. Any human knows this is pure fraud.
The reality is the police are more than happy to act when the criminals involved can be identified, and are under their jurisdiction, and you can get the attention of the right department - that's just a very rare set of circumstances.
The Act explicitly mentions prosecution of offences committed abroad.
Going after scammers overseas will commonly cost in the millions per case. It's insanely expensive, and there are a lot of scammers.
Their chat log (apparently) makes it clear they were independent operators, at least.
They did get away with it for two years (2019 to 2021) and the article states there are other small groups doing exactly the same thing right here right now, so it isn't that stupid to think you could get away with it if you are very careful (and at least a bit lucky) and know when to cash out & move on.
[1] Source: I am that poor ex-bike owner and I know anecdotally my experience is not unusual. I live in a nice area and a person in my neighbourhood had the steering wheel of their car stolen (for some reason) again, the police did nothing.
Webauthn is a more complex alternative and it is phishing-resistant, because each credential is tied to a domain, which means that a look-alike phishing website doesn't work. But you need to use a hardware token or a special service like Windows Hello or Apple's FaceID to manage your credentials. https://en.wikipedia.org/wiki/WebAuthn
If you can copy the credentials to your own new device, an adversary can copy them to their device also.
Physical webauthn tokens are obviously better, but software webauthn is the second best thing. Software TOTP is a good bit worse, and SMS OTP shouldn't even qualify as a secure method
For everything else, WebAuthN based on a software authenticator is both more secure and more convenient than passwords, and realistically even than TOTP (having a higher takeover risk but lower phishing risk).
When they would log in to the bank, the service otp.agency would robocall the customer saying that someone was fraudulently accessing their account which was insidiously true, but then the resolution was false, the service would ask them to enter their one time passcode that was texted to them by the actual bank.
This is funny because sms could already be intercepted vis SS7 and is inherently insecure for one time passcodes that banks swear by, but this service wasn't doing that.
The issue is that people are afraid (to lose their money) and aren't educated about the risks, and who/what they should pay attention to, so they hand it over anyway.
People need to learn to fail shut.
Even if you are educated, you’re still confronted with insecure security measures and stonewalled by the customer service agent that’s asking you to complete a measure, until you complete it
Getting a call with another nonsensical security measure would be onbrand
Like FirstDirect changing the password requirements for their app from the already far from best practice "between 5 and 9 case-sensitive alphanumeric" down to "6 digits" and making a show and dance about this being "just as secure as before"…
Suffice it to say that I've spread my financial resources a bit more widely than that one organisation now (and I'm considering a more complete move, but a lot of the competition is no better). I want there to be more than my unlocked phone and give digits between the bulk of my money and anyone who wants access to it.
I don’t know, I’m already logged in to the online banking I can just go to profile and see what’s there. I’ll read it but this isn’t secure
“Thanks! That matches what I have on file too!”
They'd call me to confirm a payment and ask me to identify myself, it wasn't even a payment I was making at that moment. At least now with the current tech it's done via the app etc at point of sale.
Your CorpName verification code is 305825. Do not share this code. CorpName will never call you for this code.
It's clear CorpName is trying to defend against this exact sort of attack in the last two sentences, but it's boilerplate we've all seen many times before. Who reads it anymore? The bigger problem is unaddressed: "ABC verification code" is vague. This is security information devoid of security context.A better written message would read,
A computer in Seattle, WA is logging into your account on the CorpName website. If this is you, enter 384909 to authorize.
Or, A wire transfer of $300 to X has been requested using your debit card ending in 9934. To authorize the transfer, enter 468909.
I think asking people for authorization without atomically telling them what they're authorizing is properly viewed as a type of vulnerability.Showing their faces accomplishes three main things.
1. It disambiguates them from people who share their names. You can now see that it isn't the Callum Picari you went to school with.
2. It acts as a warning to the community. You may have been a victim of these people, but not known their names. Seeing a photo might jog your memory and enable you to report further crimes.
3. It is a disincentive. If you are planning on committing a crime, you will know that your face will be in the media if caught.
Hence, if you're found guilty and it's false, you need an exoneration.