5 ms·
Mr Krebs, Please do your due diligence. The attack vector only works for Landlines, VOIP, Toll-free. Upstream agreements already block Mobile carriers. Furthe
by wealthyyy 6y ago
Mr Krebs, Please do your due diligence. The attack vector only works for Landlines, VOIP, Toll-free.
Upstream agreements already block Mobile carriers.
Further, SMS from Short Codes are blocked by default. You can only receive SMS from long-numbers. Eg Wicker ..
- wealthyyy 6y agoThe attack also works with Canadian carriers.
- jeroenhd 6y agoIt works for at least one mobile carrier, as demonstrated in the article Krebs references [1]. One carrier is enough. The ability to hijack text messages through an online service was also shown in an article Krebs' source mentioned [2]. Perhaps you're right that upstream agreements with mobile carriers should already be blocked, but in practice it's been proven not to be. There was a change to NetNumber's systems on 11 March to combat this, but there's no guarantee that their competitors don't have similar flaws or that the measures taken were good enough to stop the attack in practice. Even still, if the problem might be fixed in the entire US, that doesn't mean anything for the rest of the world. [1]: https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-16-dollars-sakari-netnumber https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1... [2]: https://lucky225.medium.com/its-time-to-stop-using-sms-for-anything-203c41361c80 https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
- wealthyyy 6y agoAll your references are pointing to Lucky225 who is trying to market his anti-fraud product. NetNumber has no competitors. It's a routing database. The Vice article is a paid piece. This attack doesn't work with any of US Mobile carriers.
- wealthyyy 6y agoPlease see my comments at this thread, https://news.ycombinator.com/item?id=26468892 https://news.ycombinator.com/item?id=26468892 A lot of people confirmed this as FUD.
- dataflow 6y ago> The attack vector only works for Landlines, VOIP, Toll-free. I'm confused, didn't the article say "A few minutes after they entered my T-Mobile number into Sakari, Lucky225 started receiving text messages that were meant for me"? T-Mobile is a normal cellular carrier here isn't it? What part of it required a VOIP line? P.S. You can edit your old comments instead of leaving 4 different ones in the same thread. EDIT: Looking at this 5-day-old user's history, I think it's safe to say we shouldn't take the comments at face value: https://news.ycombinator.com/item?id=26455000 https://news.ycombinator.com/item?id=26455000 https://news.ycombinator.com/item?id=26472770 https://news.ycombinator.com/item?id=26472770 https://news.ycombinator.com/item?id=26464287 https://news.ycombinator.com/item?id=26464287
- homero 6y agoHe's saying Lucky225 lied to market his service https://okeymonitor.com/ https://okeymonitor.com/ in the article.
- dataflow 6y agoLucky225 lied about... what exactly? The Vice reporter literally says "Then he showed he had received texts that were meant for me that he had intercepted. Later he took over my WhatsApp account, too, and texted a friend pretending to be me."
- fatnoah 6y ago>Upstream agreements already block Mobile carriers. Further, SMS from Short Codes are blocked by default. You can only receive SMS from long-numbers. Eg Wicker . I've built a very similar product to ZipWhip. These restrictions are likely enforced by ZipWhip, there is nothing structural at the NetNumber or other level that technically prevents you from taking over SMS message routing or receiving messages from short codes on mobile numbers. Submit the SPID change to NetNumber and you're off and running! The secujrity It is worth noting that the mobile carriers will periodically "reset" these changes to fix the routing (T-Mobile is one of the more aggressive ones here) and that continued violations by MVNOs like Sakari would eventually result in a loss of access for them. In Sakari's case, they were doing no due diligence or much to prevent the fraud. My own company's workflow for landlines placed a telephone call to the customer's number to give them a code to use in the registration process (remember, the attack noted in the article doesn't port the number, it just reroutes SMS). For toll-free numbers, we required legal documentation to prove that you owned the number. We also didn't allow any mobile numbers to be registered at any time.