11 ms·
How SMS fraud works and how to guard against it
- AdamJacobMuller 4y agoThis makes the assumption that Twitter blocked it due to SMS fraud. While that's a plausible theory an equally plausible theory is that they were worried about account hijacking and security (and allowed twitter blue subscribers to continue to use it on a you can pay me to be stupid context) which seems equally plausible. I take issue with a lot of the assumptions in the article but this is funny: > Identify and block premium rate phone numbers, using libphonenumber. Whilst this seems promising, I don’t know how reliable the data and how effective this approach is. here's this purpose-built and well maintained* library from google which does exactly what I want but i'm not even going to consider it. * the actual number database has been updated 5x so far this year: https://github.com/google/libphonenumber/commits/master/metadata/metadata.zip https://github.com/google/libphonenumber/commits/master/meta...
- cfn 4y agoElon Musk said that they were being fleeced by SMS fraud when the change was announced.
- lostlogin 4y agoDoes Elon stating something make it more or less likely to be true?
- jbverschoor 4y agoAnd not for blue? It’s just a lame excuse foe the insane price of als using twilio. If he stated the truth: sms validation is costing millions per week, twillio would lose quite some customers, because companies would finally realize there’s another way that’s cheaper
- from 4y agoBlue means they’re spending $10 a month or whatever it is. No fraudster is gonna buy a VCC for Twitter Blue and pay $10 an account when there are a million other sites they could target for $0.
- jbverschoor 4y agoThe point is, Elon's rhetoric is that sms is less secure, but then he only allows it for twitter blue. It's utter bs.. It's just that he doesn't want to pay 5-10ct per 2fa request for lal these users. And I fully agree with him
- apuchitnis 4y agoauthor here: Hey Adam - Elon has mentioned SMS fraud being the reason for blocking it on several occasions. See here: https://commsrisk.com/elon-musk-has-radical-solution-for-a2p-sms-fraud-twitter-turns-off-2-factor-authentication-by-sms https://commsrisk.com/elon-musk-has-radical-solution-for-a2p.... Re libphonenumber: I think you misread me? I was definitely saying consider it :) I just don't have much personal experience with that approach.
- from 4y agoThe numbers are most of the time not premium in the 1-900 sense of the word. They can just appear to be regular mobile or landline numbers in another country and would not be picked up by that library, at least not reliably. There are databases that track some of these numbers but they are usually sold to telcos and are pretty expensive. The only solution is rate limits per number, per IP, and set a max price per SMS of $0.05-$0.10 or so (make your Papua New Guinea users use an Authenticator app instead).
- csharpminor 4y agoIMO WhatsApp is also a great option for 2FA in many countries. OTP is one of the approved outbound templates that WA will let you deliver without an inbound message.
- singleshot_ 4y agoFraud requires that someone make a misrepresentation. Who makes a misrepresentation when SMS fraud is committed? What is the misrepresentation? Is there any chance that this isn’t actually fraud and that companies who send out tons of text messages to any number a person specifies are just paying for their extraordinarily poor design?
- Tijdreiziger 4y agoThe attacker misrepresents themselves as a legitimate user who just wants to set up 2FA on their account.
- apuchitnis 4y agoI think the fraud here is that the user isn't an actual, legitimate user of the web service. Maybe 'user fraud' is a better term to use here.
- robust-cactus 4y agoIt's definitely fraud and it's definitely detectable when a 10000 block prefix of numbers sends 100x more SMS than every other prefix out of the blue. It's basically a referral marketing campaign where the fraudster does revenue share with local sketchy infrastructure providers.
- singleshot_ 4y agoI mean, it feels like stealing but it would be complicated to build a case around a fraud charge given that no one ever actively told a lie. Maybe this is taken care of in the user agreement or the terms of services? “User warrants that he is not trying to profit by use of the two factor auth system?” I’ve never read an agreement like this one.
- grammers 4y ago[flagged]
- jalk 4y agoYou should probably read the article - it's about tricking services to send SMS' to your premium number so that you earn money every time you trick the service into sending a text message to you
- JohnFen 4y ago> Noone send them anymore. Except for the overwhelming majority of everyone I know.
- pg_bot 4y agoIf you haven't done this, set the MaxPrice field when sending SMS with an API provider such as Twilio. The message will fail to send if the cost of the sms exceeds the price you set. https://support.twilio.com/hc/en-us/articles/360014170533-Using-MaxPrice-with-Twilio-SMS https://support.twilio.com/hc/en-us/articles/360014170533-Us...
- apuchitnis 4y agoauthor here: awesome, thanks for sharing this pg_bot! :)
- kyledrake 4y agoWhat would be the reasonable value to set maxprice to?
- dheera 4y agoHow is this fraud? If you require me to use SMS (deprecated), you are doing me a disservice and you should pay for the consequences. Use e-mail. It's free, works across countries, across SIM cards, allows for alphanumeric IDs, and is decentralized and not controlled by telcos.
- axelthegerman 4y agoSome folks build (or use) telecommunication systems that work for (cell) phones. Believe it or not but for receiving a notification via text message you nobody needs to install any apps or even require a smartphone and/or internet access :)
- Arch-TK 4y agoI really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
- cultofmetatron 4y agomy phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone
- lotsofpulp 4y agoI use Strongbox to backup TOTP in Keepass databases.
- malfist 4y agoThat's good for you, is grandma going to do that?
- yonixw 4y agoI'm a programmer and when I was told to store backup codes, I saw the site still has a "Forgot Password?" button so I dismissed it as a QUICK way to recovery, Not the ONLY way! The only one who told me losing backup codes means losing your data forever was my bitcoin wallet. (Ironic)
- GoblinSlayer 4y agoTOTP is only needed if you use very a weak password, which shouldn't be a thing with keepass.
- lotsofpulp 4y agoWhat if your password is leaked from some website’s database or you have a keylogger or someone somehow sees it? Wouldn’t it help then?
- molodec 4y agoThe article is describing one type of SMS Fraud, but I think Twitter got attacked using SMS Traffic Pumping Fraud. Twilio has the explanation https://support.twilio.com/hc/en-us/articles/8360406023067-SMS-Traffic-Pumping-Fraud https://support.twilio.com/hc/en-us/articles/8360406023067-S...
- apuchitnis 4y agoAh yep - the one I describe is the same as the one Twilio discuss.
- lgats 4y agowhere can i get a premium sms phone number? ( for research purposes )
- waynesonfire 4y agoGood, SMS for auth is terrible. Let me use my yubikey or authentication app.
- 71a54xd 4y agoI feel like the easiest workaround is to a) not use an email with your name in it for any important login b) don't use those emails for more than one service c) use a separate SIM and device for 2FA (mint mobile etc) / banking apps that aren't up to speed with non SMS 2fa. It pains me to say this since Bank of America sucks, but their system now supports adding a Yubikey for login, nearly as good as Schwab before they stopped issuing physical TOTP tokens in 2020.
- axelthegerman 4y ago> separate SIM and device for 2FA Are you really suggesting having 5 different devices with separate SIM cards to receive 2FA messages? What exactly is the point here, just having different numbers? In that case some kind of text message forwarding service that gives you multiple virtual numbers would (still not free but much more reasonable than dealing with multiple devices)
- 71a54xd 4y agoNope, one dedicated device for 2FA. Dedicated email for each account.
- csharpminor 4y agoAnother technology to read up on is Silent Network Auth: https://www.twilio.com/blog/silent-network-authentication-sna-overview#technical-overview https://www.twilio.com/blog/silent-network-authentication-sn... If you operate a mobile app, this allows you to force a data packet over the device’s SIM that the carrier can validate. Platforms like Twilio/Boku have worked with the carriers to provide an API for this. SMS is completely removed from the process and SMS pumping becomes a non issue. Another option that could be mentioned in the article is using WhatsApp for OTP delivery. It’s the de facto messaging app in many countries with scketchy carriers, precisely because people don’t enjoy paying 5 cents per SMS.
- apuchitnis 4y agoauthor here: these are great ideas, thank you!
- axelthegerman 4y ago> using WhatsApp for OTP delivery. It’s the de facto messaging app in many countries with scketchy carriers I don't think that would go over very well in the less sketchy countries - I know many folks (myself included) who would be up in arms if a service requires WhatsApp just to send an OTP - in that (and any) case I'd prefer 2FA via authenticator apps
- anonymous344 4y agohow is this even possible? must be usa?right? in finland non-standard numbers must start with different numbers so its easy to block them as invalid.
- apuchitnis 4y agoauthor here: part of the problem is that there are many countries, each with their own complex scheme for identifying premium numbers. it's not a straight-forward task, though libphonenumber (I believe) aims to make this easier.
- tzs 4y agoOT: what do people do who sign up for a site from their phones or tablets do when the site gives them a QR code to scan to set up TOTP? I've only ever signed up for such sites from my desktop, so it was easy to use my phone or tablet camera to get the QR code from my desktop's screen. How do you scan a QR code that is on your phone's screen using your phone?