4 ms·
Security and Privacy Risks of Number Recycling at Mobile Carriers in the U.S. [pdf]
- throwawaysea 5y agoGreat paper. It covers common attacks and highlights the dangers of SMS 2FA and phone number based identities. The two carriers in this study, TMobile and Verizon, changed their practices in response to this study: > In October 2020 we provided an initial notification of our findings to the carri- ers we studied and to CTIA, the U.S. trade association repre- senting the wireless communications industry. > In December 2020, T-Mobile informed us that after review- ing our research, it had updated its number change support page to 1) remind subscribers to update their contact number on bank accounts and social media profiles, and 2) specify the FCC-mandated number aging period. Along with raising subscriber awareness, it also informed us that customer ser- vice agent manuals had been updated to emphasize those two points during relevant interactions, effective early December.1 > In December 2020, CTIA informed us that after reviewing our research, Verizon had updated its public-facing support document for number cancellations, suspensions, and transfers to 1) remind subscribers to update their contacts and unlink their business and online accounts, and 2) specify the FCC- mandated minimum aging period (45 days).2
- prox 5y ago45 days seems awfully short?
- ClumsyPilot 5y agoExactly
- exabrial 5y agoEveryone, please stop SMS as a 2FA. It's not. Cell carriers are not secure by any stretch of the imagination. Your entire identity should not be in the hands of these companies. At this point there needs to be legislation or lawsuits, as it's out of hand. Apple is the worst offender, you can't create an account without it.
- lotsofpulp 5y agoEven the federal government uses it for things like IRS and Social Security login.
- cookiengineer 5y agoAnd there they are, lurking around with an OsmoComBB device and waiting to strike. SS7 is such a bad concept on every level. Everyone can listen, everyone can intercept, everyone can track. Back in the days I lost one of my domains because of 2FA via SMS, and I've learned my lesson. Sadly lots of companies don't understand that broadcasting a secure login token via an unencrypted transport protocol to the world is a bad idea.
- zrm 5y agoThis exactly. The title here is Security and Privacy Risks of Number Recycling, but number recycling isn't the problem. It's like pointing the finger at IP address recycling. That's not it. It's that people are using SMS as 2FA when they ought not to be.