5 ms·
How does it work? Why is it so easy?
by maym86 8y ago
How does it work? Why is it so easy?
- jeanlucas 8y agoSMS is not exactly the most secure protocol. But you do not need to use SMS for 2fa, that's a misconception.
- bena 8y agoIsn't it effectively plaintext? I don't know too much about the SMS protocol. But I do know that most protocols do start out plaintext because programmers are lazy and optimistic.
- village-idiot 8y agoThat’s one part of the problem. The other part is that it’s actually quite easy to convince most cell phone carriers to change the SIM card associated with a given phone number. Once you’ve pulled that off hijacking the account is easy.
- marcosdumay 8y agoIt's not exactly plaintext. Last time I saw it was using broken crypto (may have changed since then, but I doubt it), and it encrypts the data hop by hop, so that if you insert yourself as a hop, you'll just have decrypt (with your keys), read and encrypt it.
- 0xfeba 8y agoWell there's a few issues. The SS7 (https://en.wikipedia.org/wiki/Signalling_System_No._7 https://en.wikipedia.org/wiki/Signalling_System_No._7) does not have any authentication so anything over the telephone networks can be easily MITM'd. And at provider's stores they are too eager to please a "customer" so social engineering is very effective at swapping SIM cards out and hijacking your number.
- m-p-3 8y agoSearch for SS7, it's a swiss cheese of vulnerabilities.
- cryptonector 8y agoIt's easy because a) the signaling system in use is pathetically insecure, b) the wireless protocols are pathetically insecure.