14 ms·
This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact th
by tuxone 6y ago
This huge leak has definitely killed the SMS text messaging service. Sender can be spoofed and spam/scam/phishing have reached an intolerable level. The fact that they can cross reference you and then produce a more personalized content is huge. Changing password is easy (ok less easy if you recycle it) but changing phone number is something that I am not even relaxed to do.
- blackoil 6y ago> Sender can be spoofed Is this worldwide or US? I for now trust the senderid and assume them to be valid if they are coming from bank etc. I also haven't heard of anyone spoofing SMS. Should I be more cautious?
- Aaargh20318 6y ago> Is this worldwide or US? Worldwide. SMS is just like e-mail, you can put anything you want in the sender field. You should absolutely not trust SMS.
- mrtksn 6y agoAny idea on the extra security measures? In Turkey for example, when you change your SIM card the 2FA from the banks will stop working and you need to call your bank to re-activate it. That of course seems like a measure to prevent SIM cloning but maybe there are some security protections against spoofing. In many places SMS is a popular way to do payments and 2FA for high security applications.
- rincebrain 6y agoWhere does SMS get used to do payments? (...and how?) SMS for 2FA is known to be a very bad idea, and some security experts have been shouting about the need to stop doing that for a while. I also can't see any country managing to implement more restrictions on SMS without either breaking a lot of "legitimate" sources of SMS or being ineffective outside of a very narrow window (e.g. only blocking forged SMS for numbers originating within one country)
- e3bc54b2 6y ago> Where does SMS get used to do payments? (...and how?) In India, for every card transaction, for every DMAT transaction, for every password/PIN change SMS is used as 2FA. It is also mandated to require SMS 2FA for every one of these cases. If my bank has any means to use TOTP/Yubikey, it is absolutely not made obvious, led alone clear or even possible.
- rincebrain 6y agoOkay, so SMS gets used as 2FA for all those things, not somehow a primary method of creating transactions, correct? Unfortunately, quickly looking, [1] suggests at least one of the listed services for sending arbitrarily forged SMS messages explicitly works in India, so it seems like this is still true for you. :( [1] - https://www.usethistip.com/5-websites-to-send-anonymous-or-fake-sms.html https://www.usethistip.com/5-websites-to-send-anonymous-or-f...
- lucb1e 6y ago"Where?!" Everywhere. It's being phased out in many places, but as a rule of thumb, mostly everywhere still. "known to be very bad ... been shouting ..." Right, yeah, to put it in some perspective remember that you're talking second factor here. This is not your login, this is a secondary confirmation and you still need some serious motivation to bypass it. It's definitely doable, I work in security and I know what kind of attacks you're thinking of, but it's not the opportunistic kind of thing that a common thief will do without technical research and planning it out. If you know how to do it, you can probably find better jobs than this. It also doesn't scale well because you can only use it on people whose bank login you've already cracked in the first place.
- rincebrain 6y agoI'd never seen or heard of it being used for payments before, which is why I asked - I'd heard of phone numbers being used as account names (effectively) in some payment systems, but being involved in the workflow of making payments is entirely novel to me. I'm aware it's not your login, but it feels the same as asking someone for publicly searchable information to "verify your identity" - an additional "security" step that doesn't actually slow down any attacker more dedicated than a passing whim, but makes people feel good about whoever is using it, when there are better options that don't have the problems of SMS. Yes, it doesn't scale well to bulk attacking, but most of my interactions are with people who take reasonable precautions like keeping their machines patched, not installing random crap from the internet, and generally avoiding other fun ways people get swept up in low-hanging fruit campaigns. SMS 2FA is better than no 2FA at all, it's just frustrating to watch many companies deploy it and go home when there are better options, some of which solely also require a phone. edited to correct my statement: I originally said "SMS 2FA is better than no 2FA at all in a number of cases", but no, I'm pretty confident it's strictly better, even with all my laments about it.
- Nextgrid 6y agoCarriers can indeed expose APIs for banks and other third-parties to check if a SIM has recently been reissued, but that's a separate problem from spoofing.
- 74d-fe6-2c6 6y agoAre there Android apps for that?
- v1nc 6y agoHushsms is one, but requires Xposed Framework.
- NavinF 6y agoDoes that let you spoof sender address on any phone? I was under the impression that you had to create an account with a SIP provide to do that. (Btw a Google search for "Hushsms" results in shady/cancerous app stores that all seem to mirror each other. Where is the official website/thread?)
- escalt 6y agoI'm absolutely no expert on this, but I think your provider would usually filter this spoofing attempt out, just like with IP spoofing. But if you're in the right spot in the network (e.g. your provider doesn't check for spoofing or you're your own "provider") you can do whatever you want. Another problem with Android could be that the operating system might not have enough control over the SIM-Card/Modem to spoof phone numbers. I have heard about people using some services to send/call from spoofed numbers though
- lmilcin 6y agoActually, I trust e-mail more than SMS. With e-mail at least you can look at the headers and if you know which part you can trust you can verify where it came from. With SMS there is no such possibility.
- prower 6y agoI'm pretty sure Italy requires a company to register to an official list before being able to put a personalized sender ID in your SMS communications. I'm not sure about the inner workings but seems far from "whatever you want". I kinda assumed this was a widespread modus operandi, apparently it's not?
- smcleod 6y agoAbsolutely do not trust the SMS sender name or message content in any country. SMS can be spoofed so easily anyone can do it.
- tokamak-teapot 6y agoI can confirm this happens in the UK.
- cosmodisk 6y agoWe heavily use programmatic SMS sending at work. There are two options how it could appear on the recipient's end: as a normal phone number, to which you can reply,etc. We had to purchase a dedicated number for this. The other option is to simply put whatever sender ID you want- we use company name.This way you can't reply to the message,so we mainly use it for marketing purposes. Nothing stops me from replacing <company_name> with <random_number_belonging_to_bank>
- sbarre 6y agoNever trust caller ID or senderid on phone calls or SMS. The reason is that phone companies interoperate grudgingly and do the minimum required to pass calls and messages between each other, and also most phone companies are 100+ year old companies who have just layered modern tech on top of their old stuff. They handle a massive unending stream of calls/messages and they can't possibly validate each one (even if they wanted to), so when a call comes into your provider (mobile or land line) it comes with all the metadata fields (sender, etc) populated, and your provider just passes that along without any verification. This was less of a problem with there was a reasonably limited number of phone companies (a few per country) and they were all large enterprises.. Now with the rise of Twilio and tons of other pay-as-you-go companies that can hook into the global phone network to send calls and messages, and MVNOs (virtual phone companies that sit on top of the incumbent ones), there are too many players to track and in the name of convenience (and cost-savings) we haven't kept up with the verification part of the chain.
- pbhjpbhj 6y ago>they can't possibly validate each one // Why not? They don't pass on all metadata, that's part of the problem. If a call originates in $foreign_country, the sender gets to spoof it as a local call (sometimes they even use your own phone number). Are you really telling me there's no way to tell the difference between an off-shore call and a local one. It seems if this were true that billing is impossible, yet somehow the origin gets billed (though admittedly that might only be the immediate upstream, but usually this will be enough to disambiguate a scam call). Phone companies make money from scammers. It doesn't seem to be a technical bar, rather a financial disinclination that stops phone companies from robust action.
- qilo 6y agoThere are valid use cases for spoofing caller ID. It’s been a long time since I dabbled with Asterisk (IP PBX), IIRC, by default the call forwarding/redirection function uses metadata from the original incoming call. Let’s say, you’ve programmed your PBX that after 30 seconds of incoming call ringing, you want to redirect/forward the call (that is to make a new leg, and then connect them together) to your mobile phone number. I’m pretty sure, on your mobile phone you’d want to see the original caller’s number for incoming call, not the PBX’s phone number.
- misnome 6y agoThis is probably overkill to say but to be sure: Never trust any information from SMS, or from a telephone call (or email) - both SMS and CallerID can both be trivially spoofed, and frequently are. If they have e.g. found out what bank you use, they can make the number look like it came from your bank ("See, this number is listed on the back of your card" is a common approach) If you get a call or SMS requiring followup, then look/ask for a reference number and a publicly listed number you can call back on - _and verify this number is listed on the organisation website before calling_, ideally on a telephone you know they can't "hold the line open" on (less of a problem now people mostly don't have landlines). It's okay to "engage" with a caller as long as you are careful to not give up any personal information - especially in cases where it's a bank they should be fine with you refusing security until you can call back. Don't ever relay information between channels e.g. if you _think_ you are talking to the bank, don't relay the contents of a 2-factor SMS you get, even if they say they are "sending" one to you. There have been cases where scammers have called the bank at the same time as calling the mark, so that when the scamee called the bank on a different line the bank verified that "they" were on another line. In reflection, it's kind of crazy the things you have to be suspicious/paranoid and aware of, I'm not surprised that even competent/intelligent people get scammed, it often seems that the infrastructure that we rely on for trust is even flimsier than you could imagine. Probably there are more extreme cases where these general rules aren't enough but probably unless you are a big CEO or something you are below the targeting threshold (see e.g. https://nakedsecurity.sophos.com/2019/09/05/scammers-deepfake-ceos-voice-to-talk-underling-into-243000-transfer/ https://nakedsecurity.sophos.com/2019/09/05/scammers-deepfak... which will probably only become easier over time). A healthy skepticism about complicated workflows is probably helpful.
- varispeed 6y agoFacebook didn't even change user Ids. You can look up those people accounts to find even more information. It is crazy they got away with it.
- wunderflix 6y agoCould someone elaborate on what the worst-case exploit would be for those number that got leaked? How would a scenario look like? Asking for a friend whose number got exposed...
- ThalesX 6y agoWhat some spammers do in my country for example, is call old people and pretend their (grand/)children were involved in an accident and ask for money for quick interventions (the hospital is out of funds, bla bla). It's sometimes hit or miss cause the person might be next to them, or they just talked, or sometimes they can't figure out if you have a daughter or a son etc. With a correlated leak like this, it's super easy for me to find your profile, see who you are, what you look like, even from just your profile picture I could potentially see you have a daughter yourself, so I can target your mother that something happened to her granddaughter and you, which would make her pay up even faster possibly.
- mcintyre1994 6y agoIt's still going to be a scam message, but they can use your Facebook ID to see everything public on your profile now, as well as the other fields in the leak like full name, location, bio, birthday. So whatever the most convincing scam message somebody can come up with is combining all of that data. Off the top of my head, "happy birthday here's a gift from us" messages from companies leading to phishing pages and personalised fake register to vote pages relating to upcoming elections in your area. It's not really new data, it's just scam SMS I've received in the past has never shown any sign of knowing anything other than my phone number. Now you can buy phone numbers and pull personalisation data unrestricted from your copy of Facebook's database for each of them. I'm sure sophisticated scammers already were, but now everyone will.
- muzani 6y agoBirthday is a form of identity verification too, for password reset.
- 6y ago
- aboringusername 6y agoCan anyone on HN please explain why, why, WHY are we still using SMS/telephony which has exactly 0 encryption wh---I guess that's the reason? It's insane. I've heard banks using SMS!!!! To send a code. We have TOTP for that! Or even perhaps a push notification or something better than bloody SMS. I refuse to use the networking system altogether. No phones, no calls. Of course you do 'need' a number so I keep one handy, but I haven't read a text or made a phone call in a long while. It needs to die. NOW. Outlaw SMS!
- bogwog 6y agoI don't know anything about the technical details with this, but I wonder why mobile service providers don't just kill off regular SMS and calling, and start providing service exclusively through data connections? The infrastructure for that old stuff can't be free for them, there must be some significant costs associated with it. Maybe Starlink will be able to provide a mobile phone service that only offers a data connection one day, and that will be the "disruption" the mobile industry needs.
- gmueckl 6y agoAs far as I know, newer cell phone standards only define how to transmit data. Phone calls are simply layered on top of that.
- fsflover 6y agohttps://xkcd.com/2365/ https://xkcd.com/2365/
- workethics 6y agoIt's because SMS works without data. I doubt that most of the people that complain about SMS live in rural areas. It seems to be more of a US thing. The country is so large that unless you live in a city you just won't be able to get data reliably. This leaves SMS as the only form of phone communication that isn't a voice call.
- Matrixik 6y ago
- dotancohen 6y ago> This huge leak has definitely killed the > SMS text messaging service. So with this breach, one now must use WhatsApp for messaging contacts? That is rather convenient for Facebook. As someone who has much friction already convincing people to use SMS with me instead of the WhatsApp account that I've never had (nor a Facebook account), making SMS even more problematic is great for Facebook. Many people assume bad intentions or some other undesirable status when telling them that I don't have WhatsApp and that I'm not willing to install it.
- Mediterraneo10 6y agoThe reason that Whatsapp massively took off in certain parts of the world, and to an extent even replaced the public-telephone system (e.g. restaurants and other local businesses may even want to be contacted by Whatsapp, not phone), is because SMS is expensive, but data is not. Sure, you might be in a part of the world where SMS is a viable option, but for many people it no longer is, and instead of asking for SMS you might suggest an alternative like Telegram or Signal.
- dotancohen 6y agoI've been trying to get people to use Telegram for years. For whatever reason, everybody wants to hear why Telegram is acceptable to me but WhatsApp is not, but they are not patient enough to even try to digest the answer in the majority of cases. And people will install any privacy-invading games or icon packs with no problem, but not another instant messenger. I have no idea what is behind this phenomenon.