11 ms·
Yep. Everyone has been saying SMS is not a secure channel for forever now, and this is only one of many possible attacks that can be used to trivially bypass SM
by orclev 9y ago
Yep. Everyone has been saying SMS is not a secure channel for forever now, and this is only one of many possible attacks that can be used to trivially bypass SMS based auth. It's sad but true that in general banks have some of the weakest security on the internet, most online games do a better job protecting user accounts from unauthorized access.
- eis 9y agoIt's sad but I have to agree. My local bank suddenly changed their Mastercard Securecode online verification scheme from a password to either SMS 2FA (for which they charge 9 cents per SMS and don't even support all numbers) or some really shitty mobile app which has a rating of 1.7 on the play store with tons and tons of people complaining that it just doesn't work and now renders their CC totally useless. I'm sure they are losing customers left and right. Mobile phones (especially Android) are incredibly insecure. Why not use these little token generators like in the past? Another bank of mine can't issue proper bank reference letters anymore which are required in many cases to open other accounts or form a company. The same bank also stopped the Visa support of their debit cards so they are practically useless apart from using at the ATM. Another bank with a business account can't issue credit cards anymore. For many transfers they require tons of verification and paperwork, opening a new account gets harder and harder. I have to fill out a stupid W-8ben form even though I have nothing to do with the US. It goes on and on. It seems in the past 5 or so years banks in general have gone into a slow but steady self-destruct mode - especially with all that speculation in the debt casino. Banking is becoming a more and more frustrating experience even though it's so core to our society.
- WorldMaker 9y agoAll of my banks are still Wish-It-Were-2FA and doing the silly "Security Question" bonus passwords dance. If someone were to point out to me an American bank that was doing the right thing technically, I'd probably switch in an instance, but at this point I've interacted with all of the major US banks and they all seem to be security idiots.
- matt_wulfeck 9y agoTrue but SMS was the only available 2fa for a long time. In fact, it's still largely the only available 2fa for most things (sadly). As bad as it is, it's better than just a straight password.
- hinkley 9y agoBlizzard Entertainment Group had better security for imaginary currency for five years than most financial organizations have today. They were handing out key fobs at conventions. It's not that they aren't available. It's that only a couple places (like online brokerages) even bother.
- zxcvbn4038 9y agoThe banks didn't get the memo from NIST and if anything they are getting worse - they are actually ramping up their use of callback and SMS authentication. Last month I had several apps force an SMS authentication because I hand't logged in since paying bills the prior month. One app disabled Touch ID and forced an SMS auth before I could log in again. One bank locked me out of my account entirely because you can't log in or contact custom service without receiving an SMS code (no voice option), but their system refuses to send SMS to my number. It would be great if the banks supported TOTP and U2F keys (or if they managed passwords correctly and didn't limit the length or force absurd character recipes). I once applied for a job at a top 3 bank's IT security area and on the way to the interview room I noticed that every single desk had a well worn copy of Computer Security For Dummies. I think that may be the root cause of all banking security problems right there.
- techsupporter 9y ago> One bank locked me out of my account entirely because you can't log in or contact custom service without receiving an SMS code (no voice option), but their system refuses to send SMS to my number. I have this problem with one of my credit card issuers (not the two I mentioned elsewhere in this thread) and they're going to lose me as a customer as a result. I can't log into any online banking without receiving a phone call or SMS and I'm prompted to enter a number at which I can receive such a thing. The problem is, I am entering the number that I know the bank has but entering that number--or any other number I own--is met with "hmm, it doesn't look like that number belongs to you." Of course it doesn't considering my mobile phone service is paid for through my LLC and this is a personal credit card account. When I tried calling them, I'm told that, again, I need to verify myself with an SMS and, no, the number I have used for a decade is not sufficient. At least they've now returned to mailing me paper statements. Once I've verified that my last automatic payment has moved away from them as of next month, the card gets canceled. If I can't cancel by phone, I'll cancel by mail. If I can't cancel by mail, I'll just leave it in a drawer and watch my mail for any new statements until the card is canceled for inactivity.