3 ms·
How? The login screen only allows 4 digit pins, and if you get it right then you have to confirm with 2FA.
by ec59cb1659 4y ago
How? The login screen only allows 4 digit pins, and if you get it right then you have to confirm with 2FA.
- Nullificus 4y agoGetting the correct phone number and pin combo is step one. That's the four digit pin. Step two is as many tries at the 2FA as you would like. The format is 0#####. It will take some time for sure, but you get to control the phone number as your prize Alternatively, the 4-digit pin is the security for their support line. You can obtain that without guessing the 2FA. Social engineering takes care of the rest.
- ec59cb1659 4y agoMobile account authorization is critical for national security because of the rampant requirement to use cellphones as 2FA / password reset for everything else, including GC Key itself. The government needs to step in. The question is what particular person in the government has the power and motivation to do so. Have you tried the CCTS? CSE? They might have some power, but the upcoming potential Cyber Security C-26 act should spell it out for them. It should be doable to find some big fish to take this on, especially since everyone is vulnerable to SIM swaps assuming every other Canadian phone company has such lax security.
- Nullificus 4y agoI worked with the Office of the Privacy Commissioner of Canada(OPC) on this a few years ago. I don't have credentials and that's enough for them not to take it seriously. I'm the only reason the 2FA is there. That change was the only change they would commit to. A few days ago is the first time since that I've logged into my account. I'm planning to contact the Competition Bureau tomorrow with the information. They are currently looking at Freedom's viability under a significantly less powerful company than Shaw Communications Inc.
- ec59cb1659 4y agoI dunno, but it doesn't really seem like Privacy or Competition is the right angle for this, they're luxuries after all, and it's not really relevant for those political maneuverings. Security is more important. The right actors could hack the entire financial system and more with these kinds of vulnerabilities, with targeted sim swaps. Take for example, the currently unfolding Twitter hack that puts 400m Twitter users' phone numbers up for grabs - including every big fish there is. Call yourself an anonymous Russian hacker and that might get their attention.
- Nullificus 4y agoI will reach out to CSE and CCTS when they open as well.
- ec59cb1659 4y agoThanks a lot for doing this!
- TYMorningCoffee 4y agoFrom the article it was not clear that the 2FA was the 5 digit pin. 10 guess every 10 minutes with an expectation that after 5000 guesses you'll have a correct guess is 3.4 days (500*10 minutes).
- Nullificus 4y agoThere's no timing limits but your own, the only limit I could note is 10 per code. You have to guess a lot, but you don't get stopped. There's also nothing you can do as a target, even if you know you're a target. Support cannot disable your account.
- TYMorningCoffee 4y agoAh wow, no pause after As a comparison, banks' 2FA will get disabled after too many resets.